SuperMCP
REMOTE · SUPERMCP.CO.IL · SCANNED SEP 24
Israeli online supermarket pricing: compare grocery prices and delivered shopping baskets.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability58
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 6585 tokens (~823/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management60
- Stability observed for 18 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the SuperMCP MCP server?
SuperMCP is a hosted endpoint at https://supermcp.co.il/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · supermcp.co.il
claude mcp add --transport http nitaiaharoni1-super-mcp 'https://supermcp.co.il/mcp'
{
"mcpServers": {
"nitaiaharoni1-super-mcp": {
"url": "https://supermcp.co.il/mcp"
}
}
} {
"servers": {
"nitaiaharoni1-super-mcp": {
"type": "http",
"url": "https://supermcp.co.il/mcp"
}
}
} [mcp_servers.nitaiaharoni1-super-mcp] url = "https://supermcp.co.il/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"nitaiaharoni1-super-mcp": {
"type": "remote",
"url": "https://supermcp.co.il/mcp",
"enabled": true
}
}
} openclaw mcp add nitaiaharoni1-super-mcp --url 'https://supermcp.co.il/mcp' --transport streamable-http
mcp_servers:
nitaiaharoni1-super-mcp:
url: "https://supermcp.co.il/mcp" {
"McpServers": {
"nitaiaharoni1-super-mcp": {
"Transport": "http",
"Url": "https://supermcp.co.il/mcp"
}
}
} assistant mcp add nitaiaharoni1-super-mcp -t streamable-http -u 'https://supermcp.co.il/mcp'
{
"mcpServers": {
"nitaiaharoni1-super-mcp": {
"type": "http",
"url": "https://supermcp.co.il/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Server version: 0007863b-chatfix-55853286 → 0007863b-chatfix-55853286-burstfix-7e7dbbce-limiter-e0e1ffbf functional
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Server version: 0007863b → 0007863b-chatfix-55853286 functional
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://supermcp.co.il/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=supermcp.co.il | CN=WR3,O=Google Trust Services,C=US | 6 Sept 2026 | 5 Dec 2026 | RSA 2048 | SHA256-RSA | 1ea8ade1836b6d3812abd41888437bd3 |
| SANs: supermcp.co.il | ||||||
| CN=WR3,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7ff005a91568d63abc22861684aa4b5a |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
| CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 1 Sept 1998 | 28 Jan 2028 | RSA 2048 | SHA1-RSA | 40000000001154b5ac394 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of supermcp.co.il. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| il. | present | 35088 | 13 | Verified |
| co.il. | present | 7144 | 13 | Verified |
| supermcp.co.il. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31556926 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://supermcp.co.il/mcp | Verified | 200 | |
| http (plaintext) | http://supermcp.co.il/mcp | HTTPS enforced | 301 | https://supermcp.co.il/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_delivery_terms Get one storefront's delivery terms ~192
The full published terms for a single online storefront: every fee band over basket size, the minimum order, the service area, and where each figure came from. Use to explain a deliveryFee an optimize_delivery plan reported, or to answer 'what do I need to spend for free delivery?'. Take the slug from a plan's serviceSlug. catalogSize and catalogVisibility are reported here only when already known: this tool answers from published terms and never waits on the item count. A null in either means one of two things, and they are not interchangeable: we hold no priced store for this storefront, OR the count has not been taken yet. Call list_delivery_options for a count you can rely on being present; never read a null here as an empty shop.
| Name | Type | Req | Description |
|---|---|---|---|
| service_slug | string | yes | Storefront slug, e.g. 'shufersal-online' — from a plan's serviceSlug. |
No output schema declared.
No examples provided.
get_product Get product ~171
Fetch full detail for one canonical product by product_id (UUID) or GTIN barcode, including every per-chain listing (chain-specific item code, display name, and package size). Use after search_products to confirm identity, or directly when the GTIN is already known. Each listing carries `orderable`: false means no delivery or pickup storefront prices it, so it cannot be bought through this API. A listing is catalogue identity, not availability: never present an `orderable: false` chain as somewhere the shopper can buy. When every listing is `orderable: false` the product is not purchasable right now, whatever its chains suggest.
| Name | Type | Req | Description |
|---|---|---|---|
| gtin | string | – | GTIN/barcode, used only if product_id is omitted. |
| product_id | string | – | Canonical product UUID. |
No output schema declared.
No examples provided.
get_promotions Get promotions ~177
List promotions (e.g. '2 for 30₪', club-member price, second-unit discount), optionally filtered by store_id or product_id, and by active=true to only return promotions currently running. Use this to explain why an optimize_delivery line price is lower than list_price.
| Name | Type | Req | Description |
|---|---|---|---|
| active | boolean | – | If true, only currently-active promotions. Defaults to true. |
| city | string | – | City name in Hebrew or English (also accepts CBS locality codes). Restricts to promotions at stores in that city plus chain-wide promotions of chains present there. |
| limit | integer | – | Max promotions to return, ordered by soonest end date. Defaults to 50, max 200. |
| product_id | string | – | Filter to promotions covering this canonical product. |
| store_id | string | – | Filter to promotions at this store. |
No output schema declared.
No examples provided.
list_delivery_options List storefronts that deliver here ~473
Which Israeli online supermarkets deliver to an address, with each one's delivery fee, minimum order, free-delivery threshold and whether it offers click-and-collect — without pricing a basket. Use for 'who delivers to me?'. For 'what will my shopping cost delivered?', use optimize_delivery instead. Every entry carries deliveryTerms.confidence and verifiedAt; quote a fee only when it is verified or reported, and say the fee is unknown otherwise. Every entry also carries catalogSize (priced items we hold) and catalogVisibility. catalogVisibility 'partial_index' means WE cannot see the whole shop: that storefront's prices are read off a website that cannot be paged, so catalogSize is the part we indexed and says nothing about how much the retailer stocks. 'full_catalogue' means the count is the retailer's complete published price file. Never recommend a storefront on its delivery fee alone: one where we hold a few hundred items cannot fill a normal basket, so price the basket with optimize_delivery before naming a winner. An entry carrying notesRef instead of notes shares its terms with other storefronts: read the text from sharedNotes[notesRef]. Marketplace terms are written once per chain and held per venue, so they would otherwise repeat verbatim on every branch.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Delivery address in Israel, free text, e.g. 'מנדלסון 1, תל אביב'. Preferred: some storefronts publish a service area that only a street address can be tested against. |
| chain | string | – | Filter to one chain, by its name as it appears in chainName (שופרסל) or by its legal barcode id. A value matching neither returns no options, which is not the same answer as nobody delivering here: o… |
| city | string | – | City name in Hebrew or English. Enough for chains that publish a settlement list, not enough for a storefront whose area is a polygon or a depot radius. |
| include_unavailable | boolean | – | Also return storefronts that do NOT serve this address, each with a reason. Useful for explaining why a well-known chain is missing. |
| near | string | – | 'lat,lng' string, e.g. '32.078,34.774'. Do not combine with address. |
No output schema declared.
No examples provided.
optimize_delivery Price a shopping list for delivery ~2,261
Price a whole shopping list at every Israeli online supermarket that delivers to an address, and rank them on what the order actually costs: items + delivery fee + service fee. Call this ONCE with the full list — never price lines separately. This is SuperMCP's shopping-list tool for online supermarket delivery. ASK THE SHOPPER WHERE THEY LIVE BEFORE CALLING, whenever you can get it in the same breath. A city is enough. It is not a detail that sharpens the answer, it usually IS the answer: of the 531 towns whose coverage we hold, 386 are served by exactly one chain. It is also much the cheaper call, comparing the handful of storefronts that reach one town instead of every storefront in the country. Only when you cannot ask, or when showing the range now beats a round trip, call with no destination. It does not fail: it returns status=needs_destination, the same list priced at every storefront in the country, carrying only what an address does not decide — each storefront's shelf prices, its own delivery fee and its minimum order. NOT ONE of them was tested against a service area, so that reply names no cheapest, carries no handoffUrl and is not a recommendation. Quote it as a range, say we do not yet know who delivers to this shopper, ask for their city or street address, then send {continuation, city} to get the storefronts that actually reach them. THE HEADLINE FIGURE IS deliveredTotal, not the item subtotal: a ₪35.90 delivery fee outweighs most price differences between chains. But RANK on deliveredComparableTotal, never on deliveredTotal: totalScope is priced_lines_only, so a storefront that stocks four of your twelve items reports a small deliveredTotal precisely because it cannot fill the basket. Check pricedLines against requestedLines and say when the coverage is partial. A gap has two possible reasons and catalogVisibility says which. 'full_catalogue' means catalogSize is the retailer's complete published price file, so a line it did not price is a line it…
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Delivery address in Israel, free text, e.g. 'מנדלסון 1, תל אביב'. Preferred: some storefronts publish a service area that only a street address can be tested against. |
| answers | array | – | One answer per question from the needs_confirmation reply. |
| city | string | – | City name in Hebrew or English. Enough for chains that publish a settlement list, not enough for a storefront whose area is a polygon or a depot radius. |
| continuation | string | – | Opaque token from a needs_confirmation, preview or needs_destination reply. The shopping list travels inside it, so send it with answers, or with the city or address that answers needs_destination, a… |
| include_club | boolean | – | Apply loyalty-club item prices. Default true; they are flagged clubOnly. |
| include_coupon | boolean | – | Apply coupon item prices. Default true; they are flagged couponOnly. |
| intent | string | – | The shopper's own framing of this shop, in their own words, e.g. 'ברביקיו ל-12 אנשים'. Not a summary of the item list — pass what THEY said the shop was for. Shown on the handoff page next to what wa… |
| items | array | – | The shopping list. Required unless resuming with a continuation. |
| max_split_stores | integer | – | How many storefronts the returned splitOrder may spread the list over. Default 2. A third adds a third delivery fee, so it only wins when it reaches items the other two do not stock. |
| memberships | array | – | Membership or card the shopper holds that unlocks a cheaper rate, e.g. ['credit_card'] for a Rami Levy card. Without it the public rate is quoted. |
| near | string | – | 'lat,lng' string, e.g. '32.078,34.774'. Do not combine with address. |
| preference | string | – | cheapest takes the lowest delivered total outright; balanced (default) prefers a storefront whose delivery terms we verified when the money is close. |
| resolution_mode | string | – | fast (default) makes best-effort product choices and reports them in assumptions, each carrying a kind: generic_default (the line named no particular product, so the everyday one is the answer) needs… |
| response_detail | string | – | summary (default) returns the line-by-line breakdown only for the storefronts the recommendations name; it folds marketplace venues that priced this basket identically into one plan carrying venues,… |
| slot_type | string | – | Only two slots exist here: standard (default) is delivery to the door, pickup is click-and-collect, which is cheaper at the chains that offer it but means the shopper travels. Anything else is reject… |
No output schema declared.
No examples provided.
search_products Search products ~607
Search the canonical product catalog by free text (Hebrew or English), brand, category, or exact GTIN, and answer 'how much is X' for a SINGLE item. Also matches chain listing names. Send city or address and every hit comes back priced: fromPrice is the lowest it goes for at any storefront delivering there, so quote it as 'from ₪X across N storefronts' (pricedAtStorefronts) and never as one national price — there is no such thing here. pricedAtStorefronts=1 is one shop's price, not a market rate. normalizedUnitPrice is that same money per 100g/100ml/piece: compare on it, NOT on fromPrice, because a smaller pack is cheaper to buy and usually dearer per gram. Results come back cheapest per unit first. fromPrice is the ordinary price, never a loyalty-club or coupon rate. Without a location nothing can be priced and the price fields are absent. For a whole shopping list call optimize_delivery ONCE with query items — never price lines one by one here, and never add these prices up: they come from different storefronts and each carries its own delivery fee. After optimize_delivery priced the wrong product, call suggest_similar_products with the shopper's Hebrew words and the rejected product_id, then call optimize_delivery again with that product_id. Returns canonical products (not per-chain detail); call get_product for listings.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | – | Filter by brand name, partial match. |
| category | string | – | Filter by internal category slug (l1 or l2), e.g. 'dairy'. |
| city | string | – | City name in Hebrew or English (also accepts CBS locality codes). Aliases resolve to one place — e.g. 'הרצליה', 'Herzliya', and '6400' are the same filter. May be combined with location as a disambig… |
| gtin | string | – | Exact GTIN/barcode to look up. |
| in_stock_only | boolean | – | When location is set, return only products with a local price. Default false. |
| limit | integer | – | Max results, default 20. |
| location | string | – | Free-text neighborhood or address in Israel, e.g. 'נווה עמל, הרצליה'. Resolved to coordinates via cached Nominatim. Do not combine with near. |
| near | string | – | 'lat,lng' string, e.g. '32.078,34.774', to find stores near a point. |
| query | string | – | Free text search, Hebrew or English, e.g. 'חלב תנובה' or 'olive oil'. |
| radius_km | number | – | Search radius in km around the resolved point. Defaults to 10km when near or location is set. Ignored without a point. |
| store_id | string | – | Optional store UUID to prefer locally stocked products. |
No output schema declared.
No examples provided.
split_order Split one shopping list across two or three shops ~569
Answer 'can I save by ordering from more than one shop?' for a whole list. Returns which items to buy where, each leg's own subtotal, delivery fee and service fee, the combined delivered total, and what it saves against buying everything in one order. Every fee is a published one: a leg whose delivery fee we could not verify is never put in a split, because a split is a recommendation to pay a SECOND fee and it may not rest on a number we would refuse to quote for one order. reason='cheaper' means one order could buy this list and two buy it for materially less. reason='more_of_the_list' means no single storefront stocks everything, so the second order fills the gap: it costs MORE, saving is negative, and that is the honest answer rather than a hidden one. Say which of the two it is. Each leg carries its own handoffUrl, one page per order. Give the shopper both. Every leg meets its own storefront's minimum order, so both legs are placeable as they stand. Returns splitOrder: null when one order is the right answer, which is the usual case — report that plainly and point at the single-order recommendation instead of retrying. optimize_delivery already returns the same splitOrder field, so call this one only when the shopper asks about splitting specifically, or to raise max_stores to 3.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Delivery address in Israel, free text, e.g. 'מנדלסון 1, תל אביב'. Preferred: some storefronts publish a service area that only a street address can be tested against. |
| city | string | – | City name in Hebrew or English. Enough for chains that publish a settlement list, not enough for a storefront whose area is a polygon or a depot radius. |
| intent | string | – | The shopper's own framing of this shop, in their own words, e.g. 'ברביקיו ל-12 אנשים'. Not a summary of the item list. Shown on each leg's handoff page next to what was priced. Optional; omit rather… |
| items | array | yes | The shopping list, same shape as optimize_delivery. |
| max_stores | integer | – | How many storefronts to spread the list over. Default 2. A third adds a third delivery fee, so it only wins when it reaches items the other two do not stock. |
| memberships | array | – | Memberships the shopper holds, e.g. ['credit_card', 'wolt_plus']. |
| near | string | – | 'lat,lng' string, e.g. '32.078,34.774'. Do not combine with address. |
| slot_type | string | – | standard (default) or pickup. |
No output schema declared.
No examples provided.
suggest_similar_products Suggest similar products ~546
After optimize_delivery priced the wrong product, use this to show other things the shopper might have meant. Send their words in HEBREW (original line or the correction) and the rejected product_id so that SKU is dropped. Example: priced נקניקיות פרגיות, shopper said thigh cuts → query='פרגיות' or 'שוקיים', product_id=<the sausage>. Then call optimize_delivery again with the same list, that line pinned to the chosen product_id. Also answers 'is there a cheaper one?': every suggestion carries fromPrice, the lowest it goes for at any storefront delivering to this address, and normalizedUnitPrice, the same money per 100g/100ml/piece. Compare on normalizedUnitPrice, NOT on fromPrice: a smaller pack is cheaper to buy and usually dearer per gram, so a saving claimed on fromPrice alone is wrong whenever the pack sizes differ. Results come back cheapest per unit first, and `rejected` carries the same fields so the swap is directly comparable. fromPrice is a floor across storefronts, so quote it as 'from ₪X'; pricedAtStorefronts=1 means it is one shop's price rather than a market rate. Send city or address, or no price can be reported at all. Do not use this for a first-pass shopping list — call optimize_delivery once with every line.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City name in Hebrew or English (also accepts CBS locality codes). Aliases resolve to one place — e.g. 'הרצליה', 'Herzliya', and '6400' are the same filter. May be combined with location as a disambig… |
| limit | integer | – | Max neighbours to return. Default 8. |
| location | string | – | Free-text neighborhood or address in Israel, e.g. 'נווה עמל, הרצליה'. Resolved to coordinates via cached Nominatim. Do not combine with near. |
| near | string | – | 'lat,lng' string, e.g. '32.078,34.774', to find stores near a point. |
| product_id | string | – | The product_id optimize_delivery priced that the shopper rejected. Excluded from results. |
| query | string | – | What they meant, in Hebrew. Prefer the correction ('שוקיים') or the original line ('פרגיות'). A Latin brand name matches nothing. Required unless product_id is set. |
| radius_km | number | – | Search radius in km around the resolved point. Defaults to 10km when near or location is set. Ignored without a point. |
No output schema declared.
No examples provided.
What is the SuperMCP MCP server?
SuperMCP is an MCP server listed in the public MCP registry as io.github.nitaiaharoni1/super-mcp. Israeli online supermarket pricing: compare grocery prices and delivered shopping baskets. This page covers its hosted endpoint (https://supermcp.co.il/mcp).
Is the SuperMCP MCP server safe to use?
SuperMCP scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SuperMCP MCP server expose?
SuperMCP exposes 8 tools: optimize_delivery, split_order, list_delivery_options, get_delivery_terms, search_products, and 3 more. Their descriptions and schemas cost roughly 4,996 tokens of context every time the server is loaded.
Does the SuperMCP MCP server require authentication?
No. We connected to SuperMCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SuperMCP MCP server still maintained?
SuperMCP is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.