NOSTOS
REMOTE · MCP.NOSTOS.MARKET · 2 COMPONENTS · SCANNED SEP 22
Retro games and vintage apparel in Duluth, GA. Live catalog, prices, trade-in offers, policies.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 14 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1393 tokens (~99/item across 14 items; 14 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the NOSTOS MCP server?
NOSTOS is a hosted endpoint at https://mcp.nostos.market/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.nostos.market
claude mcp add --transport http market-nostos-nostos 'https://mcp.nostos.market/mcp'
{
"mcpServers": {
"market-nostos-nostos": {
"url": "https://mcp.nostos.market/mcp"
}
}
} {
"servers": {
"market-nostos-nostos": {
"type": "http",
"url": "https://mcp.nostos.market/mcp"
}
}
} [mcp_servers.market-nostos-nostos] url = "https://mcp.nostos.market/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"market-nostos-nostos": {
"type": "remote",
"url": "https://mcp.nostos.market/mcp",
"enabled": true
}
}
} openclaw mcp add market-nostos-nostos --url 'https://mcp.nostos.market/mcp' --transport streamable-http
mcp_servers:
market-nostos-nostos:
url: "https://mcp.nostos.market/mcp" {
"McpServers": {
"market-nostos-nostos": {
"Transport": "http",
"Url": "https://mcp.nostos.market/mcp"
}
}
} assistant mcp add market-nostos-nostos -t streamable-http -u 'https://mcp.nostos.market/mcp'
{
"mcpServers": {
"market-nostos-nostos": {
"type": "http",
"url": "https://mcp.nostos.market/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 2 Aug 26 0
- Schema quality: unverified → excellent ▲ functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.nostos.market/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=nostos.market | CN=WE1,O=Google Trust Services,C=US | 2 Aug 2026 | 31 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 3a087c79958fa1530ec6d678a15ed4f8 |
| SANs: nostos.market, mcp.nostos.market, *.mcp.nostos.market | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.nostos.market. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| market. | present | 40531 | 8 | Verified |
| nostos.market. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.nostos.market/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.nostos.market/mcp | HTTPS enforced | 301 | https://mcp.nostos.market/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_availability Live availability ~84
Real-time status (available, reserved, sold, or invalid) for up to 50 SKUs at once. The live source of truth; the catalog can lag a recent sale.
| Name | Type | Req | Description |
|---|---|---|---|
| skus | array | yes | SKUs to check, up to 50, e.g. ['NOST-VGS-0075','NOST-VGS-0076']. |
No output schema declared.
No examples provided.
get_buying_policy Buying policy ~45
What NOSTOS buys and declines, how cash and store-credit offers are calculated, bounty premiums, basket caps, the free shipping label threshold, and the trade-in process.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_condition_grading_rubric Condition grading rubric ~71
The NOSTOS condition grading vocabulary and the criteria for each grade, with region-code meanings. Optionally filter to one department.
| Name | Type | Req | Description |
|---|---|---|---|
| department | string | – | Optional department filter, e.g. 'VG - Software', 'CLTH - Vintage Apparel'. Omit for the full rubric. |
No output schema declared.
No examples provided.
get_credit_policy Store credit policy ~39
How NOSTOS store credit works: the 15% uplift over cash, the in-store drop-off bonus, the return bonus, and redemption.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_item Item details ~58
Full details for one SKU: description, condition notes, price, region, image, and a direct product URL, plus real-time availability.
| Name | Type | Req | Description |
|---|---|---|---|
| sku | string | yes | The product SKU, e.g. 'NOST-VGS-0075'. |
No output schema declared.
No examples provided.
get_return_policy Return policy ~43
The NOSTOS return policy: 14-day window, eligible reasons, free return shipping on valid claims, refund timing, and the 110% store-credit option.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_shipping_estimate Shipping policy ~93
The NOSTOS shipping policy for a destination country (US, Canada, or not-yet-active international), including the free prepaid trade-in label threshold. Policy, not a live carrier rate.
| Name | Type | Req | Description |
|---|---|---|---|
| destination_country | string | yes | ISO-3166-1 alpha-2 destination country code, e.g. 'US', 'CA'. |
| item_count | integer | – | Number of items. Default 1. |
No output schema declared.
No examples provided.
get_store_info Store info ~40
NOSTOS store information: address, hours, contact, mission, tagline, categories, area served, social links, and current online and storefront status.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_trade_in_offer_estimate Trade-in offer estimate ~78
Cash and store-credit totals for a basket of items to sell, with free-shipping eligibility and whether the basket routes to a personal review. Persists nothing. Provide each item's buyPrice from lookup_market_price.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Basket of items to sell. Use lookup_market_price to get each item's buyPrice first. |
No output schema declared.
No examples provided.
list_departments Departments in stock ~40
List the store departments currently in stock (e.g. 'VG - Software', 'CLTH - Vintage Apparel'), each with a count of available items.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_platforms Platforms in stock ~25
List the console platforms currently in stock, each with a count of available items.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_recent_drops Recent drops ~48
List the most recently added in-stock items, newest first. The answer to what is new at NOSTOS.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max items to return. Default 10. |
No output schema declared.
No examples provided.
lookup_market_price Market price lookup ~105
Estimated market value (loose, CIB, and new) for a game or console from current PriceCharting guide data, plus the NOSTOS cash and store-credit buy offers.
| Name | Type | Req | Description |
|---|---|---|---|
| condition | string | – | Optional condition to focus the result on. |
| name | string | yes | Title to look up, e.g. 'Mario Kart 64'. |
| platform | string | – | Platform hint to disambiguate, e.g. 'N64', 'Saturn'. |
No output schema declared.
No examples provided.
search_inventory Search the catalog ~245
Search the live NOSTOS catalog of retro games, consoles, and vintage apparel. Free-text query plus platform, department, region, condition, and price filters. Returns online-buyable items by default. Every item is unique and individually graded.
| Name | Type | Req | Description |
|---|---|---|---|
| condition | string | – | Filter by exact condition, e.g. 'Loose', 'CIB', 'New'. |
| department | string | – | Filter by department (substring), e.g. 'VG - Software', 'Apparel'. |
| includeSold | boolean | – | Include sold and in-store-only items. Default false (online-buyable only). |
| limit | integer | – | Max results to return. Default 20. |
| maxPrice | number | – | Maximum price in USD. |
| minPrice | number | – | Minimum price in USD. |
| platform | string | – | Filter by platform (case-insensitive substring), e.g. 'Saturn', 'N64', 'Game Boy'. |
| query | string | – | Free-text match across name, description, genre, and platform. All words must match. |
| region | string | – | Filter by exact region code, e.g. 'JP', 'US', 'PAL'. |
No output schema declared.
No examples provided.
What is the NOSTOS MCP server?
NOSTOS is an MCP server listed in the public MCP registry as market.nostos/nostos. Retro games and vintage apparel in Duluth, GA. Live catalog, prices, trade-in offers, policies. This page covers its hosted endpoint (https://mcp.nostos.market/mcp).
Is the NOSTOS MCP server safe to use?
NOSTOS scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the NOSTOS MCP server expose?
NOSTOS exposes 14 tools: search_inventory, get_item, check_availability, list_platforms, list_departments, and 9 more. Their descriptions and schemas cost roughly 1,014 tokens of context every time the server is loaded.
Does the NOSTOS MCP server require authentication?
No. We connected to NOSTOS without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the NOSTOS MCP server still maintained?
NOSTOS is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.