io.github.kewelin/ecpro-mcp
REMOTE · ECPRO.TW · SCANNED SEP 20
台灣電商情報與商品比價:跨通路查 momo、PChome、品牌官網即時價格與歷史最低價、偵測網站電商技術、搜尋電商知識庫。資料來源 ecpro.tw。
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 17 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1915 tokens (~112/item across 17 items; 17 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 17 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.kewelin/ecpro-mcp server?
io.github.kewelin/ecpro-mcp is a hosted endpoint at https://ecpro.tw/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · ecpro.tw
claude mcp add --transport http kewelin-ecpro-mcp 'https://ecpro.tw/mcp'
{
"mcpServers": {
"kewelin-ecpro-mcp": {
"url": "https://ecpro.tw/mcp"
}
}
} {
"servers": {
"kewelin-ecpro-mcp": {
"type": "http",
"url": "https://ecpro.tw/mcp"
}
}
} [mcp_servers.kewelin-ecpro-mcp] url = "https://ecpro.tw/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"kewelin-ecpro-mcp": {
"type": "remote",
"url": "https://ecpro.tw/mcp",
"enabled": true
}
}
} openclaw mcp add kewelin-ecpro-mcp --url 'https://ecpro.tw/mcp' --transport streamable-http
mcp_servers:
kewelin-ecpro-mcp:
url: "https://ecpro.tw/mcp" {
"McpServers": {
"kewelin-ecpro-mcp": {
"Transport": "http",
"Url": "https://ecpro.tw/mcp"
}
}
} assistant mcp add kewelin-ecpro-mcp -t streamable-http -u 'https://ecpro.tw/mcp'
{
"mcpServers": {
"kewelin-ecpro-mcp": {
"type": "http",
"url": "https://ecpro.tw/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 8 Sept 26 0
- Stability: 0.97 → pass security
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 −1
- Stability: pass → 0.93 functional
- 30 Aug 26 +56
- Injection markers: unverified → pass ▲ security
- Stability: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 17 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- Endpoint reachability: not serving MCP → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- MCP protocol: unverified → pass ▲ functional
- 29 Aug 26 −56
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: Schema not yet verified: we couldn't read the endpoint's schema. functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://ecpro.tw/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=ecpro.tw | CN=WE1,O=Google Trust Services,C=US | 14 Sept 2026 | 13 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 3b33361d961f243613fda827b0b14098 |
| SANs: ecpro.tw, *.ecpro.tw | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of ecpro.tw. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| tw. | present | 46902 | 13 | Verified |
| ecpro.tw. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ecpro.tw/mcp | Verified | 200 | |
| http (plaintext) | http://ecpro.tw/mcp | HTTPS enforced | 301 | https://ecpro.tw/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
category_price_range ~94
查某個商品品類在台灣的整體行情:最低價、中位數、平均、最高價與各價格帶。使用者問「○○大概多少錢」「○○行情」「多少預算能買到○○」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | 品類,例如「藍牙喇叭」「氣炸鍋」「除濕機」 |
No output schema declared.
No examples provided.
check_store_safety ~101
檢查一個台灣網購網站是否安全:比對 8.8 萬筆詐騙通報名單、是否已收錄建檔、有無營運公司登記。使用者買東西前問「這網站安全嗎/是不是詐騙/可以信任嗎」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | 網站網址或網域,例如 example.com.tw |
No output schema declared.
No examples provided.
compare_prices ~93
比較某商品在 momo、PChome 與台灣品牌官網的價格,回傳整體最低價、各通路最低價與候選清單。使用者問「哪裡買最便宜」「幫我比價」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | 商品關鍵字,越精確越好,例如「SONY SRS-XB100」 |
No output schema declared.
No examples provided.
convert_price ~76
把台幣金額換算成美金、日圓、人民幣等主要外幣(即時匯率)。使用者問「這個多少美金/日圓」「跨境比價」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| amount_twd | number | yes | 台幣金額 |
No output schema declared.
No examples provided.
cross_channel_gaps ~91
找出同一款商品在 momo、PChome、品牌官網之間價差最大的排行:選對通路能省最多的商品清單。使用者問「哪些東西不同通路差很多」「同款哪裡買最便宜」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | 回傳筆數,預設 15,最多 30 |
No output schema declared.
No examples provided.
detect_site_tech ~83
即時偵測任一網站使用的電商技術:開店平台(SHOPLINE / 91APP / Shopify / WooCommerce 等)、金流、廣告像素、分析追蹤與行銷工具。輸入網址或網域。
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | 網址或網域,例如 example.com.tw |
No output schema declared.
No examples provided.
find_deals ~155
找台灣電商目前的優惠:今天跌到歷史新低的商品、折扣最深的商品,或某品類的最低價。使用者問「今天有什麼好康/降價」「有什麼便宜的○○」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | 可選,指定品類看該品類最低價,例如「氣炸鍋」「藍牙喇叭」 |
| limit | number | – | 回傳筆數,預設 15,最多 30 |
| type | string | – | 優惠類型:lowest(跌到歷史新低,預設)|discount(折扣最深) |
No output schema declared.
No examples provided.
find_sites_by_tech ~113
反查台灣有哪些網站使用某個電商技術(開店平台、金流、廣告像素、分析工具)。使用者問「用 SHOPLINE 的台灣網站有哪些」「哪些站在用綠界金流」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | 回傳筆數,預設 20,最多 50 |
| tech | string | yes | 技術名稱,例如「SHOPLINE」「CYBERBIZ」「綠界」「Meta Pixel」 |
No output schema declared.
No examples provided.
get_ecommerce_article ~70
用 slug 取得 ECPRO 電商博士單篇文章的完整內容(純文字),含常見問答(FAQ)。先用 search_ecommerce_articles 找到 slug 再呼叫。
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | 文章 slug,例如 aov-average-order-value-optimization |
No output schema declared.
No examples provided.
get_price_history ~67
取得單一商品的歷史價格走勢(日期+價格),判斷現在是不是低點、是不是真優惠。offer_id 由 search_products / compare_prices 的結果取得。
| Name | Type | Req | Description |
|---|---|---|---|
| offer_id | string | yes | 商品 offer_id,例如 momo:15014911 |
No output schema declared.
No examples provided.
list_article_categories ~44
列出 ECPRO 電商博士知識庫的所有文章分類與各分類文章數,用來了解知識庫涵蓋範圍。
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lookup_food_barcode ~69
用商品條碼查食品的成分、營養、過敏原(Open Food Facts 全球食品資料庫)。使用者掃到條碼、問食品成分/營養時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| barcode | string | yes | 商品條碼(EAN/UPC 數字) |
No output schema declared.
No examples provided.
price_match_check ~100
幫使用者檢查一個商品是否買貴了:輸入商品名稱與你付的價格,回傳其他通路有沒有更便宜、能省多少。使用者問「我買的○○貴了嗎」「這價格合理嗎」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| paid_price | number | yes | 你付的價格(元) |
| product | string | yes | 商品名稱或關鍵字 |
No output schema declared.
No examples provided.
recommend_by_budget ~135
依預算和情境推薦台灣商品:送禮、學生、租屋族、居家辦公等。使用者問「X 元送禮推薦什麼」「租屋族該買什麼」「學生 3C 推薦」時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| budget | number | yes | 預算上限(元) |
| category | string | – | 可選,指定品類,例如「藍牙耳機」 |
| scene | string | – | 可選情境關鍵字,例如「送禮」「租屋」「學生」「露營」「居家辦公」 |
No output schema declared.
No examples provided.
search_ecommerce_articles ~194
搜尋 ECPRO 電商博士的電商經營知識文章(繁體中文,涵蓋行銷、傳播、品牌、廣告流量、轉換優化、會員回購、金流財務、物流營運、數據 KPI、跨境通路、AI 應用等)。回傳標題、摘要、分類與網址。回答台灣電商經營、開店、行銷、廣告、數據等問題時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | 可選分類,例如「廣告與流量」「金流定價財務」「會員與回購」 |
| limit | number | – | 回傳筆數,預設 8,最多 20 |
| query | string | yes | 關鍵字,例如「客單價」「Meta 廣告」「跨境」「復購」 |
No output schema declared.
No examples provided.
search_products ~193
搜尋台灣電商商品與價格(涵蓋 momo、PChome 24h 與台灣品牌官網)。回傳商品名、目前價格、通路與購買連結,依價格由低到高。使用者想買某商品、問價格、要推薦選購時使用。
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | 限定通路:momo|pchome|official(品牌官網),可選 |
| limit | number | – | 回傳筆數,預設 10,最多 20 |
| max_price | number | – | 價格上限(元),可選 |
| min_price | number | – | 價格下限(元),可選 |
| query | string | yes | 商品關鍵字,例如「藍牙喇叭」「氣炸鍋」「Marshall 喇叭」 |
No output schema declared.
No examples provided.
should_i_buy_now ~94
判斷某商品現在是不是買點:用歷史價與近期趨勢分析「該買還是等」。使用者問「○○現在該買嗎」「這價格划算嗎」「還會再降嗎」時使用。offer_id 由 search_products / compare_prices 取得。
| Name | Type | Req | Description |
|---|---|---|---|
| offer_id | string | yes | 商品 offer_id,例如 momo:15014911 |
No output schema declared.
No examples provided.
What is the io.github.kewelin/ecpro-mcp server?
io.github.kewelin/ecpro-mcp is listed in the public MCP registry as io.github.kewelin/ecpro-mcp. 台灣電商情報與商品比價:跨通路查 momo、PChome、品牌官網即時價格與歷史最低價、偵測網站電商技術、搜尋電商知識庫。資料來源 ecpro.tw。 This page covers its hosted endpoint (https://ecpro.tw/mcp).
Is the io.github.kewelin/ecpro-mcp server safe to use?
io.github.kewelin/ecpro-mcp scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.kewelin/ecpro-mcp server expose?
io.github.kewelin/ecpro-mcp exposes 17 tools: search_ecommerce_articles, get_ecommerce_article, detect_site_tech, list_article_categories, search_products, and 12 more. Their descriptions and schemas cost roughly 1,772 tokens of context every time the server is loaded.
Does the io.github.kewelin/ecpro-mcp server require authentication?
No. We connected to io.github.kewelin/ecpro-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.kewelin/ecpro-mcp server still maintained?
io.github.kewelin/ecpro-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.