io.github.matthewdtowles/iwantmymtg-mcp
NPM · IWANTMYMTG-MCP · SCANNED AUG 4
Query Magic: The Gathering cards, sets, and prices and manage your I Want My MTG collection.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security83
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (97 of 101), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to matthewdtowles/iwantmymtg-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 3 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability79
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 4565 tokens (~76/item across 60 items; 60 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage88
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 63% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · iwantmymtg-mcp
claude mcp add matthewdtowles-iwantmymtg-mcp -- npx -y iwantmymtg-mcp
codex mcp add matthewdtowles-iwantmymtg-mcp -- npx -y iwantmymtg-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"matthewdtowles-iwantmymtg-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"iwantmymtg-mcp"
],
"enabled": true
}
}
} openclaw mcp add matthewdtowles-iwantmymtg-mcp --command npx --arg -y --arg iwantmymtg-mcp
mcp_servers:
matthewdtowles-iwantmymtg-mcp:
command: "npx"
args: ["-y", "iwantmymtg-mcp"] {
"mcpServers": {
"matthewdtowles-iwantmymtg-mcp": {
"command": "npx",
"args": [
"-y",
"iwantmymtg-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Aug 26 −1
- CVE-2026-69207 affects this package: medium ▼ security
- Known CVEs: partial → fail ▼ security
- 3 Aug 26 +44
- Known CVEs: unverified → partial ▲ security
- Install scripts: unverified → pass ▲ security
- Provenance: unverified → pass ▲ security
- The attested source repository moved: matthewdtowles/iwantmymtg-mcp security
- Stability: unverified → 0.23 ▲ functional
- MCP protocol: unverified → pass ▲ functional
- Maintenance: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- License: unverified → pass ▲ functional
- Schema quality: unverified → excellent ▲ functional
- Licence: MIT functional
- 2 Aug 26 −3
- Provenance: pass → unverified ▼ security
- Install scripts: pass → unverified ▼ security
- Malware scan: unverified → pass ▲ security
- The attested source repository moved: matthewdtowles/iwantmymtg-mcp security
- Maintenance: pass → unverified ▼ functional
- License: pass → unverified ▼ functional
- Licence: MIT functional
- 1 Aug 26 −7
- Stability: 0.13 → unverified ▼ security
- Capabilities: pass → unverified ▼ functional
- 31 Jul 26 0
- Malware scan: pass → unverified ▼ security
- Provenance: unverified → pass ▲ security
- Install scripts: unverified → pass ▲ security
- The attested source repository moved: matthewdtowles/iwantmymtg-mcp security
- Maintenance: unverified → pass ▲ functional
- License: unverified → pass ▲ functional
- First check of Stability: 0.13 functional
- First check of MCP protocol: pass functional
- Licence: MIT functional
- Package version: 0.6.9 → 0.7.0 functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +21
- Tool coverage: unverified → 100 ▲ functional
- First check of Tool coverage: 62 functional
- First check of Schema quality: fail functional
- First check of Schema quality: pass functional
- First check of Schema quality: unverified functional
- 27 Jul 26 24
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Aug 2026 · Analysed npm/[email protected]
Provenance verified
Ecosystem: npm · Outcome: verified
Reason: verified
- Source repo:
- matthewdtowles/iwantmymtg-mcp
- Certificate issuer:
- https://token.actions.githubusercontent.com
- Certificate SAN:
- https://github.com/matthewdtowles/iwantmymtg-mcp/.github/workflows/ci.yml@refs/heads/main
- Rekor log index:
- 2305381939
- Predicate type:
- https://slsa.dev/provenance/v1
- Subject digest:
- sha512:8097f74770ee587060d46abaf33384ca9cf1c9fc5064f660597f33a0c953c342156bc72ecb7c4fc5c7b81cb5a4275e5f99967196aac07eb7826ecf52f
- Discovery method:
- attestation_endpoint
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-8j4g-w8fx-2239 | CVE-2026-69207 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
Dependencies 97 packages
97 packages in the resolved dependency tree · 97 deprecated · 29 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
remove_sealed_inventory ~57
Remove a sealed product from the authenticated user's inventory entirely. Premium-gated. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| sealedProductUuid | string | yes | Sealed product UUID. Get it from get_sealed_products or get_sealed_product. |
No output schema declared.
No examples provided.
search_cards ~224
Search Magic: The Gathering cards by name (substring), set code, rarity, type, or format legality. Returns a paginated list with prices and basic metadata. Use this for catalog lookups; for a specific printing prefer get_card with set+number.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | — | Filter to cards with a legality entry in this format (e.g. 'modern', 'commander'). |
| legality | string | — | Used with 'format'. Defaults to 'legal' when format is set. |
| limit | integer | — | Page size (max 100). |
| page | integer | — | 1-based page index. |
| q | string | — | Substring to search card name + flavor name. Optional; omit to filter purely by setCode/rarity/type/format. |
| rarity | string | — | Filter by rarity. |
| setCode | string | — | 3-5 character set code (e.g. 'lea', 'mh3'). |
| type | string | — | Substring match against card type line (e.g. 'Goblin', 'Instant'). |
No output schema declared.
No examples provided.
search_sets ~48
List Magic: The Gathering sets, optionally paginated. Returns set code, name, release date, type, and aggregate prices.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | — |
| page | integer | — | — |
No output schema declared.
No examples provided.
set_deck_card_quantity ~134
Set the absolute quantity for a card + board in a deck (not a delta). A quantity of 0 removes the row. Use add_deck_card to increment instead. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| cardId | string | yes | Internal IWMM card UUID. Get from search_cards or get_card. |
| deckId | integer | yes | Deck id. Get from list_decks or create_deck. |
| isSideboard | boolean | yes | Which board the row belongs to. Mainboard and sideboard are separate rows. |
| quantity | integer | yes | Absolute quantity to set. 0 removes the row. |
No output schema declared.
No examples provided.
set_sealed_inventory ~102
Add or update a sealed product in the authenticated user's inventory by setting its absolute quantity (upserts the row for that product). This is a real write and is Premium-gated. Use remove_sealed_inventory to delete a row. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| quantity | integer | yes | Absolute quantity to set for this product. |
| sealedProductUuid | string | yes | Sealed product UUID. Get it from get_sealed_products or get_sealed_product. |
No output schema declared.
No examples provided.
update_buy_list ~115
Set the absolute quantity for a buy-list card+finish (not a delta). A quantity of 0 removes the row. Use add_buy_list to increment instead. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| cardId | string | yes | Internal IWMM card UUID. Get from search_cards or get_card. |
| isFoil | boolean | — | Whether this is the foil variant. Foil and non-foil are separate rows. Defaults to false. |
| quantity | integer | yes | Absolute quantity to set. 0 removes the row. |
No output schema declared.
No examples provided.
update_deck ~74
Rename a deck or change its format. Omitting format clears it. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| deckId | integer | yes | Deck id. Get from list_decks or create_deck. |
| format | string | — | Target format. Omit for no format. |
| name | string | yes | New deck name. |
No output schema declared.
No examples provided.
update_inventory ~45
Update quantities for one or more existing inventory rows. Accepts a batch. Use remove_inventory to delete a row entirely. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | — |
No output schema declared.
No examples provided.
update_price_alert ~85
Update an existing price alert. Pass null for a threshold to clear it (Premium only - free users must keep exactly one direction). isActive toggles enable/disable without deleting. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| decreasePct | — | — | — |
| id | integer | yes | Alert ID from list_price_alerts. |
| increasePct | — | — | — |
| isActive | boolean | — | — |
No output schema declared.
No examples provided.
update_transaction ~106
Update an existing transaction by ID. Only the fields supplied are changed. Card identity and type (BUY/SELL) cannot be changed via this endpoint - delete and re-create instead. Requires IWMM_API_KEY.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | — | — |
| fees | number | — | — |
| id | integer | yes | Transaction ID from list_transactions. |
| notes | string | — | — |
| pricePerUnit | number | — | — |
| quantity | integer | — | — |
| source | string | — | — |
No output schema declared.
No examples provided.