io.github.MeMikko/hoodgrow-mcp
NPM · HOODGROW-MCP · 2 COMPONENTS · SCANNED SEP 27
Robinhood Chain stock token data — price, split-adjusted supply, DeFi, corporate actions, movers.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security99
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 115 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to MeMikko/hoodgrow-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 37 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2283 tokens (~163/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
- Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.MeMikko/hoodgrow-mcp server?
io.github.MeMikko/hoodgrow-mcp runs locally as an npm package, launched with npx -y hoodgrow-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · hoodgrow-mcp
claude mcp add memikko-hoodgrow-mcp -- npx -y hoodgrow-mcp
{
"mcpServers": {
"memikko-hoodgrow-mcp": {
"command": "npx",
"args": [
"-y",
"hoodgrow-mcp"
]
}
}
} {
"servers": {
"memikko-hoodgrow-mcp": {
"command": "npx",
"args": [
"-y",
"hoodgrow-mcp"
]
}
}
} codex mcp add memikko-hoodgrow-mcp -- npx -y hoodgrow-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"memikko-hoodgrow-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"hoodgrow-mcp"
],
"enabled": true
}
}
} openclaw mcp add memikko-hoodgrow-mcp --command npx --arg -y --arg hoodgrow-mcp
mcp_servers:
memikko-hoodgrow-mcp:
command: "npx"
args: ["-y", "hoodgrow-mcp"] {
"McpServers": {
"memikko-hoodgrow-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"hoodgrow-mcp"
]
}
}
} assistant mcp add memikko-hoodgrow-mcp -t stdio -c npx -a -y hoodgrow-mcp
{
"mcpServers": {
"memikko-hoodgrow-mcp": {
"command": "npx",
"args": [
"-y",
"hoodgrow-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 27 Sept 26 −3
- Stability: pass → 0.77 functional
- 26 Sept 26 0
- Stability: 0.97 → pass security
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 −3
- Stability: pass → 0.80 functional
- 18 Sept 26 0
- Stability: 0.97 → pass security
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Analysed npm/hoodgrow-mcp@0.9.1
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | MeMikko/hoodgrow-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/MeMikko/hoodgrow-mcp/.github/workflows/publish.yml@refs/tags/v0.9.1 |
| Rekor log index | 2531201772 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:c7a2977cf21a35ff18d60a9f9a1f5eb6c2b3dfe8f1705bf1b4502cbca2e8f03c465664b9c90cabef5c0f1268ff61e2788f9fcaace14e34331a606d4b3 |
Background: How many MCP packages publish verified provenance →
Dependencies 115 packages
| Packages resolved | 115 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
buy_credits Buy a HoodGrow prepaid credit bundle ~138
Pays for one prepaid credit bundle via x402 (see list_credit_bundles for ids/prices) — a REAL, irreversible USDC payment on Base mainnet. Requires HOODGROW_PRIVATE_KEY to be configured (a bearer-key setup is already free and has no use for credits). The balance lands once settlement confirms; call get_credit_balance to verify. To actually start spending it instead of paying x402 per call, set HOODGROW_USE_CREDITS=true and restart this server.
| Name | Type | Req | Description |
|---|---|---|---|
| bundleId | string | yes | Bundle id from list_credit_bundles, e.g. "10", "50", "200". |
No output schema declared.
No examples provided.
get_base_tokens Get HoodGrow Base B20 token registry ~152
Base mainnet (chain 8453) B20 native-equity-token registry — verified on-chain metadata (symbol, name, decimals) for a fixed set of known tokens, plus a liveness signal. PRE-LAUNCH: every token currently has zero minted supply — no price, no DEX liquidity, no holders exist yet. status flips to "live" automatically once totalSupply() > 0 on-chain; do not treat a pre_launch entry as tradable. $0.05 via x402, or 1 daily unit with a free API key. Read directly from the token contracts on Base (chain 8453) and refreshed every 4 hours; status reflects on-chain totalSupply().
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_catalog Get HoodGrow token catalog ~210
Free catalog and live price feed for all Robinhood Chain stock tokens. Use for token discovery, spot prices, and tracking market movers. Returns symbol, name, contract address, live price, price source, 24h change and corporate-action adjusted supply for every listed token, plus pending and recent corporate actions. No API key, no payment, and it spends none of a key's daily units. Carries no per-token DeFi depth — use get_token or get_defi for that. Prices are read from Chainlink feeds on-chain, not relayed from an off-chain aggregator, and refreshed every 15 minutes — each response is that snapshot, with observedAt giving its exact age. priceSource says which tokens resolved a feed and which fell back. Supply is corporate-action adjusted (totalSupply x ERC-8056 uiMultiplier), not raw. Detected from the token contract's own ERC-8056 state every minute, ahead of the official registry's cache, which is mirrored alongside for history.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_corporate_actions Get HoodGrow corporate actions ~114
Pending (on-chain staged) and recent (official Robinhood ledger) corporate actions — splits, dividends, name changes. Pass a symbol to scope to one token (cheaper); omit it for every tracked token's corporate actions. Detected from the token contract's own ERC-8056 state every minute, ahead of the official registry's cache, which is mirrored alongside for history.
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | – | Ticker symbol to scope to, e.g. "NVDA". Omit for all tokens. |
No output schema declared.
No examples provided.
get_credit_balance Get HoodGrow prepaid credit balance ~39
This wallet's current prepaid credit balance — free (no x402 charge, no credit spend). Requires HOODGROW_PRIVATE_KEY to be configured.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_defi Get HoodGrow token DeFi detail ~129
Every Morpho lending market (as loan asset OR collateral, both roles labeled) and Uniswap V3 pool involving one token — the full picture for comparing yield/ borrow options, not just the single best-APY figure in get_token. $0.05 via x402, or 1 daily unit with a free API key. Fails for an unknown symbol. Morpho market and Uniswap V3 pool state, read on-chain and snapshotted every 15 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Ticker symbol, e.g. "NVDA" (case-insensitive). |
No output schema declared.
No examples provided.
get_holders Get HoodGrow token holder analytics ~142
Holder-count trend, 24h net total_supply change (real mint/burn — creation/ redemption of the underlying tokenized shares, distinct from a corporate-action multiplier change), and top-holder concentration for one token. $0.05 via x402, or 1 daily unit with a free API key. Fails for an unknown symbol. Explorer-sourced, refreshed every 4 hours; supply changes derived from on-chain supply snapshots.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many top holders to return, 1-50. Defaults to 10. |
| symbol | string | yes | Ticker symbol, e.g. "NVDA" (case-insensitive). |
No output schema declared.
No examples provided.
get_markets Get HoodGrow market movers ~198
Market movers across the Robinhood Chain stock-token catalog: top gainers and losers by 24h price change, highest 24h swap volume, and deepest Uniswap V3 liquidity (TVL). limit caps each list (1-50, default 10); gainers/losers can be empty when the market is flat (e.g. weekends). $0.05 via x402, or 1 daily unit with a free API key. Prices are read from Chainlink feeds on-chain, not relayed from an off-chain aggregator, and refreshed every 15 minutes — each response is that snapshot, with observedAt giving its exact age. priceSource says which tokens resolved a feed and which fell back. Morpho market and Uniswap V3 pool state, read on-chain and snapshotted every 15 minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max entries per list, 1-50. Defaults to 10. |
No output schema declared.
No examples provided.
get_ohlc Get HoodGrow OHLC price candles ~257
OHLC price candles for backtesting, bucketed from price history already collected every ~15 min. Each candle also carries volumeUsd/swapCount — USD swap volume across the token's Uniswap V3 pools, null for buckets older than the volume indexer's backfill window. Defaults to the last 30 days if from/to are omitted; window capped at 730 days. $0.05 via x402, or 1 daily unit with a free API key. Fails for an unknown symbol. Prices are read from Chainlink feeds on-chain, not relayed from an off-chain aggregator, and refreshed every 15 minutes — each response is that snapshot, with observedAt giving its exact age. priceSource says which tokens resolved a feed and which fell back.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | ISO 8601 start (default: 30 days before `to`). |
| interval | string | yes | Candle bucket size. |
| limit | integer | – | Max candles to return, 1-1000. Defaults to 500. |
| symbol | string | yes | Ticker symbol, e.g. "NVDA" (case-insensitive). |
| to | string | – | ISO 8601 end (default: now). |
No output schema declared.
No examples provided.
get_slippage Get HoodGrow trade price-impact estimate ~241
How much a USD-sized trade would move the price, per Uniswap V3 pool this token trades on — plus bestPoolAddress/bestEffectivePrice picking the best of them for you. Per-pool estimate, not an optimal multi-pool route/split. Exact within each pool's currently active tick range; a likelyCrossesTick flag on a result means the trade is probably large enough that this may understate real slippage — consider splitting into smaller tranches (TWAP) instead. $0.05 via x402, or 1 daily unit with a free API key. Fails for an unknown symbol. Computed per pool from the most recent Uniswap V3 pool snapshot (refreshed every 15 minutes, not read live at request time) — an estimate derived from reserves, not a quoted or executable price.
| Name | Type | Req | Description |
|---|---|---|---|
| amountUsd | number | yes | Trade size in USD. |
| side | string | yes | "buy" spends USDG for the stock token, "sell" spends the stock token for USDG. |
| symbol | string | yes | Ticker symbol, e.g. "NVDA" (case-insensitive). |
No output schema declared.
No examples provided.
get_token Get one HoodGrow token ~209
One Robinhood Chain stock token by symbol (e.g. NVDA): live price, corporate-action adjusted supply, DeFi depth, and pending/recent corporate actions. Unlike the free catalog this carries the token's DeFi depth ($0.05 via x402, or 1 of the 40 daily units with a free API key). Fails for an unknown symbol. Prices are read from Chainlink feeds on-chain, not relayed from an off-chain aggregator, and refreshed every 15 minutes — each response is that snapshot, with observedAt giving its exact age. priceSource says which tokens resolved a feed and which fell back. Supply is corporate-action adjusted (totalSupply x ERC-8056 uiMultiplier), not raw. Detected from the token contract's own ERC-8056 state every minute, ahead of the official registry's cache, which is mirrored alongside for history.
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Ticker symbol, e.g. "NVDA" (case-insensitive). |
No output schema declared.
No examples provided.
get_trades Get HoodGrow recent large trades ~163
Recent large (whale) trades in Robinhood Chain stock-token Uniswap V3 pools, newest first — each with a buy/sell side, USD size, and transaction hash. Omit symbol for the global feed. limit caps the list (1-100, default 20). $0.05 via x402, or 1 daily unit with a free API key. Indexed from Uniswap V3 Swap events on-chain; side and USD size are derived from the USDG leg of each swap.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max trades to return, 1-100. Defaults to 20. |
| symbol | string | – | Filter to one token, e.g. "NVDA" (case-insensitive). Omit for the global feed. |
No output schema declared.
No examples provided.
list_credit_bundles List HoodGrow prepaid credit bundles ~79
Current prepaid credit bundle catalog ({id: {priceUsd, creditUsd}}) — free, no credentials required. A bundle is paid once via x402 (buy_credits) and spent down over many calls afterward via a cheap wallet signature instead of a fresh on-chain payment per call — see HOODGROW_USE_CREDITS.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
register_credit_webhook Register a HoodGrow corporate-action webhook ~212
Register (or update) a credit-funded corporate-action webhook for this wallet: HoodGrow then POSTs each matching corporate_action.* event to your url, signed x-hoodgrow-signature (verify it before trusting the body). Requires HOODGROW_PRIVATE_KEY. Registering is FREE — no payment here; each delivered event is billed per-event against your prepaid credit balance (buy_credits/get_credit_balance), so an idle webhook costs nothing. symbols restricts delivery — and, since billing is per delivered event, what you're charged for — to just those tokens; omit for every token's events. Returns webhookSecret (shown once — store it). This is the credit-funded path; a Builder-subscription webhook is set from the website instead.
| Name | Type | Req | Description |
|---|---|---|---|
| symbols | array | – | Restrict delivery (and per-event billing) to these symbols, e.g. ["NVDA","INTC"]. Omit for all tokens. |
| url | string | yes | HTTPS URL HoodGrow POSTs each corporate-action event to. |
No output schema declared.
No examples provided.
What is the io.github.MeMikko/hoodgrow-mcp server?
io.github.MeMikko/hoodgrow-mcp is listed in the public MCP registry as io.github.MeMikko/hoodgrow-mcp. Robinhood Chain stock token data, price, split-adjusted supply, DeFi, corporate actions, movers. This page covers its npm package (hoodgrow-mcp).
Is the io.github.MeMikko/hoodgrow-mcp server safe to use?
io.github.MeMikko/hoodgrow-mcp scores 91 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 27 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.MeMikko/hoodgrow-mcp server expose?
io.github.MeMikko/hoodgrow-mcp exposes 14 tools: get_catalog, get_token, get_corporate_actions, get_defi, get_holders, and 9 more. Their descriptions and schemas cost roughly 2,283 tokens of context every time the server is loaded.
Is the io.github.MeMikko/hoodgrow-mcp server still maintained?
io.github.MeMikko/hoodgrow-mcp is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.MeMikko/hoodgrow-mcp server under?
io.github.MeMikko/hoodgrow-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.