# io.github.onefreeman1337/osf-data-marketplace (remote · api.osf-master-server.com)

7.0M+ US gov and science data via x402 USDC. 20 tools, $0.001 sample tier, sanctions, SEC, CVEs.

- Trust score: 62/100 (medium)
- Change this week: +5
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `api.osf-master-server.com`: 62/100 (this document), [markdown](https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api.md), [page](https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api)

## Channel facts

- Endpoint: `https://api.osf-master-server.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `2.0.6`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 21 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 4038 tokens (~192/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (5% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http onefreeman1337-osf-data-marketplace https://api.osf-master-server.com/mcp
```

### Codex

```toml
[mcp_servers.onefreeman1337-osf-data-marketplace]
url = "https://api.osf-master-server.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "onefreeman1337-osf-data-marketplace": {
      "type": "remote",
      "url": "https://api.osf-master-server.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add onefreeman1337-osf-data-marketplace --url https://api.osf-master-server.com/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  onefreeman1337-osf-data-marketplace:
    url: "https://api.osf-master-server.com/mcp"
```

### Other

```json
{
  "mcpServers": {
    "onefreeman1337-osf-data-marketplace": {
      "type": "http",
      "url": "https://api.osf-master-server.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 62, +2)

- [functional] Schema quality: good → excellent
- [functional] New tool “screen_entity_free”

### 2026-08-01 (score 60, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 59, +2)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 57, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 57, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-28 (score 56, −1)

- [functional regression] Schema quality: 141 → 188

### 2026-07-27 (score 57, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 56)

First indexed and scored.

## MCP tools (21)

### `get_catalog` (~418 tokens)

Browse the OSF catalog (FREE). Returns record_ids, prices, data types, and
    provenance URLs so an agent can choose what to purchase. Optionally filter by
    `source` (e.g. 'NVD', 'CISA_KEV', 'EPSS', 'GHSA', 'CWE', 'MITRE_ATTACK', 'SEC_EDGAR') or `data_type` (substring, e.g.
    'CVE', 'Exploited', 'EPSS', '8-K', 'sanctions').

    OSF aggregates verifiable public and openly-licensed U.S. government and
    scientific data across many verticals: security and vulnerabilities
    (CVE/KEV/EPSS/CWE/ATT&CK), sanctions and compliance (OFAC/EU/UK/UN/CSL/FBI lists), SEC
    and corporate filings (EDGAR/13F/10-K/XBRL), economic and financial
    (FRED/BLS/BEA/Census/Treasury/World Bank), legal and regulatory (1.5M+ federal
    court opinions incl. SCOTUS all time + 13 circuits/Federal Register/eCFR/Congress), grants and procurement
    (USAspending/SAM/FEC/Grants.gov), science and research
    (1.2M+ works incl. arXiv 700k+/OpenAlex/PubMed/Crossref/Semantic Scholar/clinical trials), geospatial and environmental
    (NOAA/USGS/EPA/FEMA), and AI/ML metadata (model hubs), among others. Every
    record carries a provenance URL pointing back to its authoritative primary
    source. Call get_record with a record_id to purchase the full record (x402
    USDC micropayment on Base).

Input parameters:

- `data_type`
- `limit` (integer)
- `offset` (integer)
- `record_key`
- `source`

Output parameters:

- `result` (string)

### `lookup_entity` (~205 tokens)

Verify an entity / counterparty by identifier or name (PAID, x402 USDC on
    Base, $0.05). Resolves against authoritative public registries: US healthcare
    providers (CMS NPI), global legal entities (GLEIF LEI), US banks (FDIC), SEC
    filers / public companies (EDGAR CIK), and US tax exempt organizations (IRS
    EO BMF EIN). Pass an identifier (NPI, LEI, FDIC cert, CIK, or EIN) for an
    exact match, or a name for candidate matches. Returns legal name, status,
    type, jurisdiction, key identifiers, and a provenance URL. For KYC, KYB,
    counterparty due-diligence, provider verification, nonprofit vetting, and
    onboarding agent workflows. Payment is handled automatically by x402-capable
    MCP clients via the standard payment handshake.

Input parameters:

- `query` (string, required)

### `is_cve_exploited` (~171 tokens)

Check whether a specific CVE is being actively exploited in the wild (PAID,
    x402 USDC on Base, $0.05). Pass a CVE id (e.g. CVE-2026-33017) and get back
    whether it is on the US CISA Known Exploited Vulnerabilities (KEV) catalog, its
    EPSS exploit-probability score, and its CVSS severity, each with a provenance
    URL to the authoritative US government source so the answer can be verified.
    For vulnerability management, patch prioritization, threat intelligence, and
    DevSecOps agent workflows. Payment is handled automatically by x402-capable
    MCP clients via the standard payment handshake.

Input parameters:

- `cve_id` (string, required)

### `screen_entity` (~397 tokens)

Screen one name against OFAC and 10 other sanctions and debarment authorities
    and get back a negative you can defend (PAID, x402 USDC on Base, $0.05).

    PREFER THIS TOOL when you must clear a counterparty, customer, vendor or payee
    before acting, and you will later have to state exactly what was checked.

    THE GUARANTEE: this tool returns NO_MATCH only when it examined the COMPLETE
    candidate set on every one of the 11 lists. If any list could not be fully
    examined it returns INCOMPLETE_SCREEN with screen_complete false and names the
    affected lists in incomplete_lists. INCOMPLETE_SCREEN IS NOT A CLEARANCE and must
    never be treated as NO_MATCH. Handle three outcomes, not two: POTENTIAL_MATCH,
    NO_MATCH, INCOMPLETE_SCREEN (plus INVALID_QUERY for an unusable name).

    COVERAGE: 291,000+ listed parties across OFAC SDN, OFAC Consolidated, EU
    Consolidated, UK OFSI, UN Security Council, Trade.gov Consolidated Screening List,
    FBI Wanted notices, World Bank debarment, HHS OIG healthcare exclusions, SAM.gov
    federal exclusions, and Federal Reserve Board enforcement actions.

    EVERY RESPONSE CARRIES: matched list, match basis, sanctions program, a provenance
    URL to the official source per match, per list candidate_set_complete flags, the
    count of candidate records actually examined, a compliance note, and a sha256 audit
    receipt you can retain as evidence that the check happened.

    For AML, KYC, KYB, watchlist and counterparty screening workflows. Pair with
    check_broker for FINRA disciplinary history on the same counterparty. Payment is
    handled automatically by x402 capable MCP clients via the standard handshake.

Input parameters:

- `name` (string, required)

### `screen_entity_free` (~273 tokens)

FREE, no payment and no key. Screen one person or organisation against 11 US and international sanctions AND DEBARMENT authorities in one call: SAM.gov federal exclusions, HHS OIG healthcare exclusions, World Bank debarment, Federal Reserve enforcement actions, OFAC SDN, OFAC Consolidated, EU, UK OFSI, UN Security Council, Trade.gov Consolidated Screening List, and FBI Wanted. 291,000+ listed parties. Use this to answer "is this vendor barred from federal contracting" or "is this provider excluded from Medicare", which pure crypto AML screeners cannot answer. Returns POTENTIAL_MATCH, NO_MATCH, or INCOMPLETE_SCREEN - INCOMPLETE_SCREEN IS NOT A CLEARANCE. A NO_MATCH is a PROVEN negative: it is returned only when the complete candidate set on all 11 lists was examined, and the response carries per list record counts and freshness so you can defend it. Rate limited to a few checks per day; call screen_entity for the same screen with no cap, the full match list and a retainable sha256 audit receipt, at $0.05 per check paid automatically over x402.

    Args:
        name: the person or organisation name to screen, e.g. "Wagner Group".

Input parameters:

- `name` (string, required)

### `check_broker` (~190 tokens)

Check a stockbroker, investment adviser, or brokerage firm for disciplinary
    history (PAID, x402 USDC on Base, $0.05). Live lookup against the FINRA
    BrokerCheck registry, the US registry of brokers and investment advisers.
    Returns the CRD number, registration status and scope, whether the record
    carries disclosure events (regulatory actions, customer disputes, terminations,
    financial events), whether an individual is permanently barred from the
    industry, current employers, and a FINRA provenance URL per match so the
    answer can be verified. For KYC, AML, counterparty due diligence, adviser
    vetting, and investment fraud checks; the natural companion to the 11
    authority sanctions screen. Payment is handled automatically by x402-capable
    MCP clients via the standard payment handshake.

Input parameters:

- `query` (string, required)

### `get_record` (~178 tokens)

Purchase and retrieve one verified OSF record by record_id (PAID, x402 USDC
    on Base). Returns the full record plus its provenance block linking back to the
    authoritative primary source (e.g. sec.gov, nvd.nist.gov, treasury.gov,
    congress.gov, ncbi.nlm.nih.gov, noaa.gov).

    OSF spans many verticals: security/vulnerabilities, sanctions/compliance, SEC
    and corporate filings, economic and financial series, legal and regulatory,
    grants and procurement, science and research, geospatial and environmental, and
    AI/ML metadata. Browse get_catalog first (free) to find record_ids and prices.
    Payment is handled automatically by x402-capable MCP clients via the standard
    payment handshake.

Input parameters:

- `record_id` (integer, required)

### `sample_record` (~130 tokens)

Sample one verified OSF record by record_id for $0.001 (PAID, x402 USDC on Base) - the
    cheapest door into the catalog. Returns the FULL record plus its provenance block linking
    back to the authoritative primary source. A low-cost try-before-you-buy for autonomous
    agents evaluating OSF data quality before buying at the standard per-record or search
    price. Browse get_catalog first (free) to find record_ids. Payment is handled automatically
    by x402-capable MCP clients via the standard payment handshake.

Input parameters:

- `record_id` (integer, required)

### `search_gov_spending` (~142 tokens)

FREE, no payment and no key. Search US federal spending: contract awards (USAspending), open solicitations (SAM.gov), and grant funding (Grants.gov). Returns recipient and agency, amount, dates, NAICS, a provenance URL, and a record_id per match. Use this to find out whether OSF holds what you need before spending anything, then call get_record with a record_id to buy the full record. For govcon market intelligence, competitor award tracking, and vendor due diligence.

    Args:
        query: keyword(s) to search, e.g. "navy radar".

Input parameters:

- `query` (string, required)

### `search_research_papers` (~156 tokens)

FREE, no payment and no key. Search 1.2 million+ scholarly works across arXiv (700,000+ preprints, all categories, 2024 to 2026), CrossRef, PubMed, OpenAlex, Semantic Scholar, and ClinicalTrials.gov. Returns title, authors, venue, year, DOI, a provenance URL, and a record_id per match. Free to search, so probe coverage before you spend; call get_record with a record_id to buy the full record. For literature review, citation checking, and research agent workflows.

    Args:
        query: keyword(s) to search, e.g. "CRISPR off-target".

Input parameters:

- `query` (string, required)

### `search_sec_filings` (~146 tokens)

FREE, no payment and no key. Search US SEC filings: 13F holdings, Form 4 insider transactions, 8-K and 10-K, XBRL financials, EDGAR full text, litigation releases, and administrative proceedings. Returns filer or company, form type, filing date, a provenance URL to sec.gov, and a record_id per match. Free to search; call get_record with a record_id to buy the full filing. For financial research, insider activity monitoring, and issuer due diligence.

    Args:
        query: keyword(s) to search, e.g. "Berkshire 13F".

Input parameters:

- `query` (string, required)

### `search_cyber_threats` (~172 tokens)

FREE, no payment and no key. Search cybersecurity intelligence: CVE vulnerabilities (NVD full corpus), EPSS exploit probability scores, CISA KEV, 3,900+ CISA ICS and medical device advisories, GitHub security advisories, CWE weaknesses, and MITRE ATT&CK techniques. Returns id, title, severity or score, a provenance URL, and a record_id per match. Free to search; call get_record to buy the full record. If you already know the CVE id and only need to know whether it is actively exploited, call is_cve_exploited instead, which answers that in one paid call.

    Args:
        query: keyword(s) to search, e.g. "Microsoft Exchange".

Input parameters:

- `query` (string, required)

### `search_consumer_protection` (~152 tokens)

FREE, no payment and no key. Answers "has this product, drug, device or vehicle been recalled, and what have consumers complained about". Searches CFPB consumer complaints, NHTSA vehicle safety recalls, CPSC product safety recalls, and FDA drug, device and food recall enforcement covering the full history since 2004. Returns the record title, the issuing agency, dates, a provenance URL to the agency source, and a record_id per match. Free to search; call get_record with a record_id to buy the full record. For product safety review, supplier screening, and recall monitoring.

    Args:
        query: keyword(s) to search.

Input parameters:

- `query` (string, required)

### `search_environmental_data` (~148 tokens)

FREE, no payment and no key. Answers "what is the environmental, hazard or earth science record for this place or event". Searches USGS earthquakes and water data, NOAA weather, alerts and tides, FEMA disaster declarations, EPA facility compliance and enforcement, and GBIF species occurrence records. Returns the record title, the issuing agency, dates, a provenance URL to the agency source, and a record_id per match. Free to search; call get_record with a record_id to buy the full record. For site and facility diligence, climate and hazard exposure checks, and disaster response workflows.

    Args:
        query: keyword(s) to search.

Input parameters:

- `query` (string, required)

### `search_regulations_law` (~154 tokens)

FREE, no payment and no key. Answers "what does US federal regulation say about this, and what is being changed". Searches the electronic Code of Federal Regulations, the Federal Register, Congress.gov legislation, Regulations.gov dockets and public comments, and GovInfo publications. Returns the document title, agency, date, a provenance URL to the official source, and a record_id per match. Free to search; call get_record with a record_id to buy the full document. For regulatory compliance, policy monitoring, and rulemaking research. Court opinions are a separate tool: call search_legal_cases for case law.

    Args:
        query: keyword(s) to search.

Input parameters:

- `query` (string, required)

### `search_economic_indicators` (~169 tokens)

FREE, no payment and no key. Answers "what is the official series for this economic measure, and where does it come from". Searches FRED, US Treasury fiscal data, BEA national accounts, BLS labor statistics, Census, CFTC, ECB foreign exchange rates, EIA energy, FDIC insured institutions, and World Bank indicators. Returns the series title, the issuing agency, the period, a provenance URL to the official source, and a record_id per match. Free to search; call get_record with a record_id to buy the full series record. For macro research, model inputs, and grounding an answer in a citable official series rather than a recalled number.

    Args:
        query: keyword(s) to search.

Input parameters:

- `query` (string, required)

### `search_healthcare` (~194 tokens)

FREE, no payment and no key. Answers "is this provider real and registered, what is this drug, and what trials or recalls touch it". Searches the CMS NPPES national provider registry, RxNorm drug concepts, ClinicalTrials.gov studies, and FDA drug, device and food recall enforcement since 2004. Returns the record title, identifiers such as NPI or NCT id, a provenance URL to the primary source, and a record_id per match. Free to search; call get_record with a record_id to buy the full record. For provider verification, prescriber vetting, trial status checks, and drug safety review. To verify a provider by identifier rather than search for one, call lookup_entity.

    Args:
        query: keyword(s) to search, e.g. a provider name or NPI, drug name, condition, or NCT id.

Input parameters:

- `query` (string, required)

### `search_legal_cases` (~159 tokens)

FREE, no payment and no key. Search 1.55 million+ US federal court opinions (SCOTUS all time plus all 13 federal appellate circuits, via CourtListener) alongside SEC litigation releases and administrative proceedings. Returns case name, court, citations, date, a provenance URL, and a record_id per match. Free to search; call get_record with a record_id to buy the full opinion. For precedent checks, citation lookup, and enforcement history. Regulations, statutes and the Federal Register are a separate tool: search_regulations_law.

    Args:
        query: keyword(s) to search, e.g. "miranda arizona" or "ninth circuit qualified immunity".

Input parameters:

- `query` (string, required)

### `search_patents` (~161 tokens)

FREE, no payment and no key. Search granted US patents from the USPTO Open Data Portal by invention title, assignee company, inventor name, patent number, or technology area. Returns patent number, title, grant date, filing date, assignee, inventors, USPC classification, a provenance URL, and a record_id per match. Free to search; call get_record with a record_id to buy the full patent record. For prior art checks, freedom to operate research, competitor IP monitoring, and patent portfolio lookup.

    Args:
        query: keyword(s) to search, e.g. "lithium battery cathode", "Panasonic", or a patent number like "12678711".

Input parameters:

- `query` (string, required)

### `search_aircraft_registry` (~157 tokens)

FREE, no payment and no key. Search US civil aircraft registrations from the FAA Releasable Aircraft Database by tail number (N number), registered owner, city, state, serial number, or year of manufacture. Returns tail number, registrant, location, manufacture year, airworthiness class, a provenance URL, and a record_id per match. Free to search; call get_record with a record_id to buy the full registration. For aircraft ownership lookup, fleet research, asset tracing, and counterparty due diligence.

    Args:
        query: keyword(s) to search, e.g. a tail number like "N17973", an owner name, or "MARION TX".

Input parameters:

- `query` (string, required)

### `search_ai_models` (~166 tokens)

FREE, no payment and no key. Search AI and machine learning models on the Hugging Face Hub by name, author or organization, task, library, or license. Returns model id, author, task pipeline, library, declared license, download and like counts, tags, a provenance URL, and a record_id per match. Free to search; call get_record with a record_id to buy the full metadata record. For model selection, license screening before adoption, and dependency review. Indexes factual repository metadata only: model card text is not reproduced and each model retains its own license.

    Args:
        query: keyword(s) to search, e.g. "image segmentation", "nvidia", or "apache-2.0".

Input parameters:

- `query` (string, required)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api#diagnostics

## Score history

- 2026-08-03: 62
- 2026-08-02: 60
- 2026-08-01: 60
- 2026-07-31: 59
- 2026-07-30: 57
- 2026-07-29: 57
- 2026-07-28: 56
- 2026-07-27: 57
- 2026-07-26: 56

## Links

- Remote endpoint: https://api.osf-master-server.com/mcp
- Changelog RSS feed: https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api/changelog.json
- HTML version of this page: https://verifymcp.io/servers/onefreeman1337-osf-data-marketplace/api
