proxy-shopping: buy anywhere with crypto through a proxy shopper
OCI · GHCR.IO/PAD01G/PROXY-SHOPPING-MCP · SCANNED OCT 8
Buy at cash-only or unsupported shops with BTC via a proxy shopper and 2-of-3 escrow, or earn as one
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security0
- No malware scan is available for this kind of package: the supply-chain vendors we use do not cover it. This is a permanent gap in our coverage, not a finding about the package.Unverified
- Known CVEs could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
- Install-script risk not yet assessed.Unverified
- Dependency health could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 7 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability73
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3173 tokens (~167/item across 19 items; 19 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
- Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the proxy-shopping: buy anywhere with crypto through a proxy… MCP server?
proxy-shopping: buy anywhere with crypto through a proxy… runs locally as a container image, launched with docker run --rm -i -e PS_NETWORK -e PS_DATA_DIR -e PS_LAB_URL -e PS_CONFIG_URL ghcr.io/pad01g/proxy-shopping-mcp:0.1.2. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.
oci · ghcr.io/pad01g/proxy-shopping-mcp
claude mcp add pad01g-proxy-shopping -- docker run --rm -i -e PS_NETWORK -e PS_DATA_DIR -e PS_LAB_URL -e PS_CONFIG_URL ghcr.io/pad01g/proxy-shopping-mcp:0.1.2
This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"mcpServers": {
"pad01g-proxy-shopping": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"PS_NETWORK",
"-e",
"PS_DATA_DIR",
"-e",
"PS_LAB_URL",
"-e",
"PS_CONFIG_URL",
"ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"
]
}
}
} This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"servers": {
"pad01g-proxy-shopping": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"PS_NETWORK",
"-e",
"PS_DATA_DIR",
"-e",
"PS_LAB_URL",
"-e",
"PS_CONFIG_URL",
"ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"
]
}
}
} This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
codex mcp add pad01g-proxy-shopping -- docker run --rm -i -e PS_NETWORK -e PS_DATA_DIR -e PS_LAB_URL -e PS_CONFIG_URL ghcr.io/pad01g/proxy-shopping-mcp:0.1.2
This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pad01g-proxy-shopping": {
"type": "local",
"command": [
"docker",
"run",
"--rm",
"-i",
"-e",
"PS_NETWORK",
"-e",
"PS_DATA_DIR",
"-e",
"PS_LAB_URL",
"-e",
"PS_CONFIG_URL",
"ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"
],
"enabled": true
}
}
} This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
mcp_servers:
pad01g-proxy-shopping:
command: "docker"
args: ["run", "--rm", "-i", "-e", "PS_NETWORK", "-e", "PS_DATA_DIR", "-e", "PS_LAB_URL", "-e", "PS_CONFIG_URL", "ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"] This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"McpServers": {
"pad01g-proxy-shopping": {
"Transport": "stdio",
"Command": "docker",
"Arguments": [
"run",
"--rm",
"-i",
"-e",
"PS_NETWORK",
"-e",
"PS_DATA_DIR",
"-e",
"PS_LAB_URL",
"-e",
"PS_CONFIG_URL",
"ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"
]
}
}
} This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"mcpServers": {
"pad01g-proxy-shopping": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"PS_NETWORK",
"-e",
"PS_DATA_DIR",
"-e",
"PS_LAB_URL",
"-e",
"PS_CONFIG_URL",
"ghcr.io/pad01g/proxy-shopping-mcp:0.1.2"
]
}
}
} This image reads PS_NETWORK, PS_DATA_DIR, PS_LAB_URL and PS_CONFIG_URL. Set them in your client's env block for this server; docker run -e passes each one through to the container.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 8 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 30. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 30 Sept 26 +1
- Schema quality: 106 → 167 ▼ functional
- Tool coverage: 64% → 100% ▲ functional
- Stability: unverified → 0.03 ▲ functional
- Schema quality: good → excellent functional
- Package version: 0.1.0 → 0.1.2 functional
- Package version: 0.1.0 → 0.1.1 functional
- 29 Sept 26 40
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Analysed oci/ghcr.io/pad01g/proxy-shopping-mcp@0.1.2
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | oci |
| Reason | No attestation published |
Background: How many MCP packages publish verified provenance →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
accept_quote Accept a quote ~138
Step 3: accept a quoted order (sends a signed acceptance to the shopper; nothing is paid yet — fund_order pays). Only for status quoted. A quote that failed validation is refused. A quote whose rate deviates strongly (> 10 %) from our sources, or could not be checked, is not accepted until you call again with acknowledge_rate_deviation: true — ask your human first.
| Name | Type | Req | Description |
|---|---|---|---|
| acknowledge_rate_deviation | boolean | – | true to accept although the quote needs an acknowledgement (strong rate deviation or rate not checkable) |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
accept_refund_offer Accept the shopper's refund ~132
Moves money: co-sign and broadcast a cooperative refund the shopper offered (e.g. the item was sold out or delivery failed), returning the funds to your wallet. Refused if the offer does not pay you as the refund template requires. Without confirm: true it shows the offer and its check. Errors if there is no offer (get_order shows refund_offer).
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
become_shopper Earn as a proxy shopper ~179
Return a step-by-step plan to earn fees as a proxy shopper (buying at local shops for remote users who pay into the escrow): requirements (always-online host, Docker, the Go node and shopper-bot images, card or cash regions), fees and risks, an honest status of the network, a ps-main node config and compose file, and how to get listed through the registry (then registry_entry). Local, no network, nothing is started.
| Name | Type | Req | Description |
|---|---|---|---|
| cash_regions | array | – | regions where you can pay cash in person (e.g. JP-13-13104) |
| fee_bps | integer | – | your fee in basis points (100 = 1 %) |
| name | string | – | your shopper display name |
| regions | array | – | regions you serve, as region codes (e.g. JP-13) |
No output schema declared.
No examples provided.
cancel_order Cancel an order before funding ~101
Cancel an order that is not funded yet (requested, quoted or accepted) and tell the shopper (best effort). Refused once funding has started — then use open_dispute, accept_refund_offer or refund_after_timelock. Nothing is paid or refunded.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
| reason | string | – | reason sent to the shopper (default "cancelled by user") |
No output schema declared.
No examples provided.
confirm_receipt Confirm receipt and pay the shopper ~179
Step 5, moves money: the items arrived and are right, so sign the escrow payout to the shopper (release); the shopper co-signs and broadcasts it. Irreversible. Without confirm: true it only returns the payout (amount, recipient) and a warning if the shopper has not reported delivery. With confirm: true it signs and waits up to wait_seconds for the payout on chain. If the items did not arrive or are wrong, use open_dispute instead.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
| wait_seconds | integer | – | how long to wait for the on-chain completion, in seconds (default 20) |
No output schema declared.
No examples provided.
countersign_ruling Countersign the ruling ~117
Moves money: add your signature to the escrow's ruling transaction (2 of 3) and broadcast it, settling the dispute. Refused if the transaction does not pay the ruled split. Without confirm: true it returns the same review as review_ruling. Ask your human before confirming.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
export_backup Export the recovery words ~102
Show this agent's 12-word BIP39 mnemonic, which controls the identity and every order's escrow key, with restore instructions. Only with confirm: true — the words then stay in the conversation, and anyone who sees them can take the funds; use only when your human asks for a backup. Local, no network.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
No output schema declared.
No examples provided.
find_offers Find proxy shoppers for a shop ~208
Step 1 of buying from a cash-only or crypto-unsupported shop: list the trusted proxy shopper × escrow combinations that serve this shop, region and payment method. Each offer has an index, the shopper's fee, delivery days, cash regions and order limit, the escrow's fees and dispute SLA, and which operator list (under which coordinator) vouches for it. Pass the index to request_quote with the same shop_url, region and payment. Read-only; an empty list means nobody serves that shop/region yet (network_info shows what exists).
| Name | Type | Req | Description |
|---|---|---|---|
| payment | string | – | how you pay: btc-signet (default; the only one on ps-main) or usdc-evm |
| region | string | yes | the shop's region code, prefix-matched: country 'JP', prefecture 'JP-13', Japanese municipality 'JP-13-13104' |
| shop_url | string | yes | the shop's URL, e.g. https://shop.example/ |
No output schema declared.
No examples provided.
fund_order Pay into the escrow ~175
Step 4, moves money: pay the quoted lock amount into the per-order 2-of-3 escrow (BTC P2WSH address or USDC Safe) plus the escrow upfront fee, from this wallet. Only for status accepted/funding. Without confirm: true it only returns the recipients, amounts and network fee (a preview; call it first). With confirm: true it signs and broadcasts. The funds can then leave only with 2 of 3 signatures, by the shopper alone after T1, or by you alone after T2. Ask your human before confirming.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
get_order Order status ~164
Show one order: status, quote and its validation, funding, purchase, tracking, dispute, ruling, refund offer and settlement, the recent timeline, and next_steps telling which tool to call next. Optionally waits (bounded) until the order reaches one of wait_for, e.g. ["quoted","rejected"] after request_quote. Read-only (local order state, kept up to date by the running session).
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
| wait_for | array | – | return as soon as the status is one of these (e.g. ["quoted","rejected"] or ["completed"]) |
| wait_seconds | integer | – | upper bound for wait_for, in seconds (default 30) |
No output schema declared.
No examples provided.
list_orders List orders ~87
List this agent's orders (from its data dir), newest first, with status, shop, items, lock amount and next steps. Use it to find an order id or to see what needs attention; get_order shows one order in full. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | most orders to return (default 20) |
| status | array | – | only orders in these statuses |
No output schema declared.
No examples provided.
network_info Network status ~158
Show which proxy-shopping network this server is on (ps-main = public Nostr relays + BTC signet, or the local lab), its relays, trusted coordinators, chains, timelock policy, and how many shopper × escrow combinations are trusted right now (with their regions and operator lists). Call it first in a session: on a new network there may be no shoppers yet, and then find_offers will return nothing. Read-only; re-reads the trust lists from the relays and the registry unless refresh is false. Returns a summary and the details as JSON.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | re-read the trust lists from the relays and the registry (default true); false uses the last snapshot and is faster |
No output schema declared.
No examples provided.
open_dispute Open a dispute ~204
Ask the escrow to decide a funded order: items not delivered, wrong item, or the shopper not releasing. Sends the claim with all signed order messages as evidence (copy to the shopper) and the key that lets the escrow decrypt the delivery address. No funds move now; the escrow later rules a split, which you check with review_ruling and execute with countersign_ruling. Without confirm: true it only shows what would be sent.
| Name | Type | Req | Description |
|---|---|---|---|
| claim | string | yes | what went wrong |
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
| requested_split | object | – | the split you ask for, as integers in sats (BTC) or USDC base units (6 decimals) |
| text | string | yes | your explanation for the escrow (facts, dates, tracking) |
No output schema declared.
No examples provided.
refund_after_timelock Take the funds back after T2 ~141
Moves money, last resort: after the T2 timelock you alone can take the locked funds back to your wallet (e.g. the shopper disappeared). Without confirm: true it shows T2, the current block height or chain time, whether T2 is reached, and the amount. Before T2 the chain rejects it; prefer accept_refund_offer or open_dispute while the shopper responds.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true to really do it (sign / send / broadcast); omitted or false = preview only, nothing happens |
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
registry_entry Registry entry for getting listed ~395
Return the exact JSON file and path to add in a pull request to github.com/pad01g/proxy-shopping-registry, so a shopper, escrow, operator or coordinator gets listed once the maintainer merges it: shoppers/<name>.json {pk, contact, description, regions (cash regions), payments, escrows}; escrows/<name>.json {pk, contact, description, sla_days}; operators/<name>.json {pk, contact, description, regions}; coordinators/<name>.json {pk, contact, description, url?, bundle?}. Uses this data dir's identity pubkey unless pubkey is given (a shopper entry must carry the shopper node's key). Local; opens no pull request itself.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle | string | – | coordinator: https URL of your signed events.json |
| contact | string | yes | how reviewers and users reach you, e.g. "github:<user>" or "nostr:npub1…" |
| description | string | yes | one or two sentences: what you do, where, how |
| escrows | array | – | shopper (required): names of the escrows/<name>.json you work with |
| name | string | yes | file name: a-z, 0-9 and - (other characters are turned into -) |
| payments | array | – | shopper: default ["btc-signet"] (the only payment on ps-main) |
| pubkey | string | – | 64 hex Nostr public key (psctl keys: nostr_pubkey) |
| regions | array | – | shopper: your cash regions; operator: where you list (JP, JP-13, JP-13-13104) |
| role | string | yes | which list to join |
| sla_days | integer | – | escrow: most days from a dispute to your ruling (default 14) |
| url | string | – | coordinator: https URL of your page |
No output schema declared.
No examples provided.
report Report a shopper or escrow ~111
Report the order's shopper or escrow to the operator that listed them, attaching the order's signed messages as evidence (e.g. a dishonest ruling, a quote that failed validation, no delivery). Sends one signed message; no funds move and the order is not changed otherwise. The operator may remove them from its list.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
| subject | string | yes | whom to report |
| text | string | yes | what happened |
No output schema declared.
No examples provided.
request_quote Request a quote from a proxy shopper ~382
Step 2: create an order with one shopper × escrow combination (offer_index from the last find_offers with the same shop_url, region and payment, or both shopper and escrow pubkeys) and wait up to wait_seconds for the quote. Sends a signed, encrypted order request over Nostr; the delivery address is encrypted for the shopper (the escrow can read it only in a dispute). Nothing is paid. Returns the order id, the price breakdown, and our validation of the quote: rate deviation from our own rate sources, the recomputed 2-of-3 escrow address, the timelocks T1/T2. If no quote arrives in time the order stays open; follow it with get_order. Next: accept_quote or cancel_order.
| Name | Type | Req | Description |
|---|---|---|---|
| address | object | yes | delivery address; encrypted end to end for the shopper |
| escrow | string | – | escrow's pubkey (64 hex), instead of offer_index; needs shopper too |
| items | array | yes | items to buy at the shop (1–20 lines) |
| offer_index | integer | – | index of the offer in the last find_offers result (same shop_url, region, payment) |
| payment | string | – | btc-signet (default) or usdc-evm; must match the find_offers call |
| region | string | yes | the shop's region code, prefix-matched: country 'JP', prefecture 'JP-13', Japanese municipality 'JP-13-13104' |
| shop_url | string | yes | the shop's URL, e.g. https://shop.example/ |
| shopper | string | – | shopper's pubkey (64 hex), instead of offer_index; needs escrow too |
| wait_seconds | integer | – | how long to wait for the quote, in seconds (default 60; 0 = do not wait) |
No output schema declared.
No examples provided.
review_ruling Review the escrow's ruling ~93
Show the escrow's ruling for a disputed order — the split between you, the shopper and the escrow fee, and its reason — and whether the escrow's transaction really pays exactly that split. Read-only. If it matches, countersign_ruling executes it; if not, do not countersign and consider report.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | yes | order id (32 hex characters) from request_quote or list_orders |
No output schema declared.
No examples provided.
wallet Wallet and identity ~107
Show this agent's identity (Nostr pubkey), its BTC signet address and balance, and where the network has USDC its EVM address with USDC and ETH balances. Use it before fund_order to check that the wallet can pay the quote, and to get the address to fund (signet faucet; on the lab: lab_faucet). Read-only: queries the chain, never signs. The key is created on first run in the data dir; export_backup shows it.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the proxy-shopping: buy anywhere with crypto through a proxy… MCP server?
proxy-shopping: buy anywhere with crypto through a proxy… is an MCP server listed in the public MCP registry as io.github.pad01g/proxy-shopping. Buy at cash-only or unsupported shops with BTC via a proxy shopper and 2-of-3 escrow, or earn as one. This page covers its container image (ghcr.io/pad01g/proxy-shopping-mcp).
Is the proxy-shopping: buy anywhere with crypto through a proxy… MCP server safe to use?
proxy-shopping: buy anywhere with crypto through a proxy… scores 44 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the proxy-shopping: buy anywhere with crypto through a proxy… MCP server expose?
proxy-shopping: buy anywhere with crypto through a proxy… exposes 19 tools: network_info, wallet, find_offers, request_quote, get_order, and 14 more. Their descriptions and schemas cost roughly 3,173 tokens of context every time the server is loaded.
Is the proxy-shopping: buy anywhere with crypto through a proxy… MCP server still maintained?
proxy-shopping: buy anywhere with crypto through a proxy… is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the proxy-shopping: buy anywhere with crypto through a proxy… MCP server under?
proxy-shopping: buy anywhere with crypto through a proxy… declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.