io.github.npraught/orcpin
NPM · ORCPIN-MCP · SCANNED SEP 25
Paid x402 facts for AI agents: signed statements, door reports, endpoint checks, chain reads
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security99
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 32 of 115 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency19
- Repository check failed: no source repository is declared. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 8 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability65
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1541 tokens (~140/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
- Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage89
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 67% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.npraught/orcpin MCP server?
io.github.npraught/orcpin runs locally as an npm package, launched with npx -y orcpin-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · orcpin-mcp
claude mcp add npraught-orcpin -- npx -y orcpin-mcp
{
"mcpServers": {
"npraught-orcpin": {
"command": "npx",
"args": [
"-y",
"orcpin-mcp"
]
}
}
} {
"servers": {
"npraught-orcpin": {
"command": "npx",
"args": [
"-y",
"orcpin-mcp"
]
}
}
} codex mcp add npraught-orcpin -- npx -y orcpin-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"npraught-orcpin": {
"type": "local",
"command": [
"npx",
"-y",
"orcpin-mcp"
],
"enabled": true
}
}
} openclaw mcp add npraught-orcpin --command npx --arg -y --arg orcpin-mcp
mcp_servers:
npraught-orcpin:
command: "npx"
args: ["-y", "orcpin-mcp"] {
"McpServers": {
"npraught-orcpin": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"orcpin-mcp"
]
}
}
} assistant mcp add npraught-orcpin -t stdio -c npx -a -y orcpin-mcp
{
"mcpServers": {
"npraught-orcpin": {
"command": "npx",
"args": [
"-y",
"orcpin-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 −2
- Stability: pass → 0.80 functional
- 23 Sept 26 0
- Stability: 0.97 → pass security
- 22 Sept 26 +1
- Package version: 0.3.1 → 0.6.0 functional
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −2
- Stability: pass → 0.80 functional
- 16 Sept 26 0
- Stability: 0.97 → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Malware scan: pass → unverified ▼ security
- Stability: 0.97 → pass security
- Schema quality: 118 → 140 ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Tool coverage: 56% → 67% ▲ functional
- Package version: 0.4.0 → 0.6.0 functional
- Package version: 0.4.0 → 0.5.0 functional
- 15 Sept 26 +1
- Stability: fail → 0.97 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 25 Sept 2026 · Analysed npm/orcpin-mcp@0.6.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 115 packages
| Packages resolved | 115 |
|---|---|
| Stale | 31 |
| No linked repository | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
orcpin_batch_snapshot ~77
Batch wallet snapshots for multiple Base addresses in one paid call, all anchored to a single block. Efficient multi-wallet / treasury monitoring. Volume-tiered via x402: ~$0.02/address, 20–40% off at 10/50/100 (up to 1000).
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | – |
No output schema declared.
No examples provided.
orcpin_defi_snapshot ~81
DeFi position + risk snapshot on Base: wallet balances plus live Aave v3 collateral, debt, borrowing power, health factor, and derived risk metrics (net equity, LTV utilization, leverage, health-factor band, collateral drawdown tolerance). Paid via x402 (~$0.05 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
No output schema declared.
No examples provided.
orcpin_door_report ~308
Signed four-part audit of one x402 endpoint (a 'door'), produced by Orcpin actually buying from it with its own audit wallet: QUOTE (what the 402 asks, and whether the seller's manifest and the public catalog agree), PURCHASE (real purchases: quoted vs signed vs settled vs chain receipt vs delivered, then a replayed and a malformed payment), BOOKS (the door's inbound USDC over 30 days from the chain: settlements, revenue, distinct and repeat payers, one-shot buyers at list price), COST (per delivered response, and where the price sits among every priced door listed). Ed25519-signed and hash-logged; facts and named patterns, never a verdict. A URL that is not a valid x402 door on Base is refused with the free probe and nothing is charged. Paid via x402: ~$50, with up to five real purchases included. Takes up to a minute.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON body to send to a POST door — the request an agent would actually make |
| method | string | – | The door's verb; default GET, retried as POST if GET looks like the wrong verb |
| purchases | integer | – | Real purchases to make, 1–5 (default 3); their total must fit the audit's purchase budget |
| url | string | yes | The x402 endpoint to audit (public http(s) URL that answers an unpaid request with a 402) |
No output schema declared.
No examples provided.
orcpin_endpoint_reliability ~96
Pre-flight an x402 endpoint BEFORE paying it. Returns factual service-delivery measurements (reachability/uptime rate, valid-402 rate, latency p50/p95/p99, last status, sampled paid delivery verification). Facts only — no trust score, no 'scam' label; apply your own thresholds. Paid via x402 (~$0.01 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | – |
No output schema declared.
No examples provided.
orcpin_endpoint_reliability_batch ~99
Sweep an agent's whole tool list of x402 endpoints in one paid call: factual delivery measurements (uptime, valid-402 rate, latency, last status) for each. Facts only — not an endorsement or rating. Volume-tiered via x402: ~$0.01/endpoint, 20–40% off at 10/50/100 (up to 150).
| Name | Type | Req | Description |
|---|---|---|---|
| urls | array | yes | – |
No output schema declared.
No examples provided.
orcpin_holding_period ~155
Trade-lot holding-period + realized-gain calculator for trading agents. Send your tax lots (and optionally a proposed sell): returns per-lot days held, the exact date each lot's gain character turns long-term, and FIFO / specific-identification sell allocation with realized gain per lot and per-character totals. Deterministic arithmetic with the published threshold cited (IRC §1222) — counts, dates, and dollars only, never advice. Nothing is stored server-side. Paid via x402 (~$0.02 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | yes | Evaluation date (YYYY-MM-DD) |
| lots | array | yes | – |
| sell | object | – | Optional proposed sell to allocate across the lots |
No output schema declared.
No examples provided.
orcpin_settlement_dates ~114
T+1 settlement dates for your equity trades on the versioned NYSE holiday calendar: settlement date per trade and whether it has settled as of a given date, with SEC Rule 15c6-1 cited separately as a published rule. Dates and counts only — never a violation determination. Nothing is stored. Paid via x402 (~$0.02 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | yes | Date to evaluate settled/unsettled against (YYYY-MM-DD) |
| trades | array | yes | – |
No output schema declared.
No examples provided.
orcpin_statement ~166
Signed statement of account for THIS wallet: every USDC settlement it made in a window, read independently from the public Base chain by Orcpin, totalled by counterparty and by day, block-anchored and ed25519-signed so anyone can verify it without Orcpin. Attaches this MCP's own meter figures as representations (attested as reported, by digest). The books a wallet does not keep. Counts and amounts only, never advice. Paid via x402 by window: ~$5 up to a month, ~$10 up to a quarter, ~$30 up to a year.
| Name | Type | Req | Description |
|---|---|---|---|
| since | string | – | Window start YYYY-MM-DD (UTC); default 30 days before until |
| until | – | – | Window end YYYY-MM-DD (UTC); default today |
No output schema declared.
No examples provided.
orcpin_wallet_snapshot ~64
Block-anchored wallet snapshot on Base: native ETH + tracked ERC-20 balances, account flags, and derived metrics (wallet type, activity tier, gas runway). Paid via x402 (~$0.02 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
No output schema declared.
No examples provided.
orcpin_wash_sale_status ~173
Wash-sale preflight before a buy: evaluates the proposed order against the operator's realized-loss sales across ALL accounts (you supply them) for the 61-day IRC §1091 window — would_trigger with the matched loss sales, an honest clear, or insufficient_data naming the gap. Agent silos only see their own account; the wash-sale window runs across all of them. Tax status with the rule cited — never advisability. Nothing is stored. Paid via x402 (~$0.05 USDC).
| Name | Type | Req | Description |
|---|---|---|---|
| order | object | yes | – |
| recentSales | array | yes | The operator's loss sales across ALL accounts; may be empty with salesCoverageFrom declared |
| salesCoverageFrom | – | – | Earliest date the supplied sales cover; lets a loss-free period read as an honest clear |
No output schema declared.
No examples provided.
orcpin_x402_directory ~208
FREE — no wallet or payment needed. Search the public x402 ecosystem: a demand-ordered directory of ~1000 paid endpoints listed on the CDP Bazaar, ranked by distinct paying wallets in the last 30 days. Filter by text, network, and maximum price. Use this to DISCOVER endpoints an agent could pay; each result says whether Orcpin holds reliability measurements for it (the measurements themselves are orcpin_endpoint_reliability).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Page size, default 50. |
| max_price | string | – | Maximum advertised price in USD, e.g. "0.01". Endpoints with no advertised price are excluded. |
| network | string | – | Exact network id as listed upstream, e.g. base, eip155:8453, solana. Matched exactly, not as a substring. |
| offset | integer | – | Pagination offset. |
| q | string | – | Text match over resource URL, service name and description. |
No output schema declared.
No examples provided.
What is the io.github.npraught/orcpin MCP server?
io.github.npraught/orcpin is an MCP server listed in the public MCP registry as io.github.npraught/orcpin. Paid x402 facts for AI agents: signed statements, door reports, endpoint checks, chain reads. This page covers its npm package (orcpin-mcp).
Is the io.github.npraught/orcpin MCP server safe to use?
io.github.npraught/orcpin scores 74 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 25 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.npraught/orcpin MCP server expose?
io.github.npraught/orcpin exposes 11 tools: orcpin_x402_directory, orcpin_wallet_snapshot, orcpin_defi_snapshot, orcpin_batch_snapshot, orcpin_endpoint_reliability, and 6 more. Their descriptions and schemas cost roughly 1,541 tokens of context every time the server is loaded.
Is the io.github.npraught/orcpin MCP server still maintained?
io.github.npraught/orcpin is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.npraught/orcpin MCP server under?
io.github.npraught/orcpin declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.