The Undesirables TCG Oracle
PYPI · UNDESIRABLES-MCP-SERVER · 2 COMPONENTS · SCANNED SEP 21
TCG oracle: calibrated prices & risk, AI grading, loan terms, fantasy souls - proven on-chain. 23 to
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security50
- Malware scan not yet available for this package.Unverified
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 1 of 42 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (BSL-1.1) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 5 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability59
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 4221 tokens (~191/item across 22 items; 22 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management43
- Stability observed for 13 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage67
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 22 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the The Undesirables TCG Oracle MCP server?
The Undesirables TCG Oracle runs locally as a PyPI package, launched with uvx undesirables-mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · undesirables-mcp-server
claude mcp add sailorpepe-undesirables-mcp-server -- uvx undesirables-mcp-server
{
"mcpServers": {
"sailorpepe-undesirables-mcp-server": {
"command": "uvx",
"args": [
"undesirables-mcp-server"
]
}
}
} {
"servers": {
"sailorpepe-undesirables-mcp-server": {
"command": "uvx",
"args": [
"undesirables-mcp-server"
]
}
}
} codex mcp add sailorpepe-undesirables-mcp-server -- uvx undesirables-mcp-server
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"sailorpepe-undesirables-mcp-server": {
"type": "local",
"command": [
"uvx",
"undesirables-mcp-server"
],
"enabled": true
}
}
} openclaw mcp add sailorpepe-undesirables-mcp-server --command uvx --arg undesirables-mcp-server
mcp_servers:
sailorpepe-undesirables-mcp-server:
command: "uvx"
args: ["undesirables-mcp-server"] {
"McpServers": {
"sailorpepe-undesirables-mcp-server": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"undesirables-mcp-server"
]
}
}
} assistant mcp add sailorpepe-undesirables-mcp-server -t stdio -c uvx -a undesirables-mcp-server
{
"mcpServers": {
"sailorpepe-undesirables-mcp-server": {
"command": "uvx",
"args": [
"undesirables-mcp-server"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- 16 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 15 Sept 26 −11
- Malware scan: pass → unverified ▼ security
- Stability: unverified → 0.23 ▲ functional
- 14 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 11 Sept 26 0
- Package version: 1.1.9 → 2.1.0 functional
- 10 Sept 26 0
- Package version: 1.1.9 → 2.1.0 functional
- 8 Sept 26 +26
- Injection markers: unverified → pass ▲ security
- First check of Judged manipulation: pass security
- Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
- MCP protocol: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 0 functional
- First check of Schema quality: good functional
- First check of Schema quality: fail functional
- First check of Destructive annotations: pass functional
- Package version: 1.1.9 → 2.1.0 functional
- Package version: 1.1.9 → 2.0.1 functional
- Package version: 1.1.9 → 2.0.0 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed pypi/undesirables-mcp-server@2.1.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | setuptools.build_meta |
Background: Why install scripts are a supply-chain risk →
Dependencies 42 packages
| Packages resolved | 42 |
|---|---|
| Stale | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
card_forecast ~296
The FREE 30-day read on ONE card: point forecast, bands, VaR, and the Safe-Hold / Momentum letter grades, in one call. Pass a card_name (resolved to the best match) or a TCGplayer product_id. Horizon is fixed at 30 days. FREE — no payment required. Returns an agent-complete object: price, as_of, regime, point (median 30d), move_pct, prob_up, band50_pct, band90_pct, var95_pct, var99_pct, low90, high90, safe_hold grade (A+..F), momentum grade (A+..F or "NA" on a drift spike), drift_spike, image_url, card_url, and a one-line plain_english read (e.g. "~12% chance it's below $Y in 30 days; Safe-Hold B, Momentum A"). Use this FIRST for "is this card a safe hold?", "30-day outlook?", "how risky is X?". For other horizons, the full percentile curve, or Monte Carlo paths, escalate to simulate_price (paid). Tip: GET /api/v1/forecast (no args) returns the free board of the top ~200 cards if the user wants a market overview.
| Name | Type | Req | Description |
|---|---|---|---|
| card_name | string | – | – |
| product_id | integer | – | – |
No output schema declared.
No examples provided.
fantasy_league ~228
The Undesirables fantasy league — 4,444 AI personalities draft weekly fantasy lineups (MLB live; more sports at kickoff) over the oracle's calibrated player forecasts. FREE. Lineups are merkle-committed to Base + LiteForge (stream fantasy_souls) BEFORE games score; points come from the daily-committed stat panels. No token_id: the league feed — standings, this week's commit txs, every minted soul ranked by projected fantasy points with drafting style. With token_id (1..minted): that soul's full card — lineup with per-player floor/mid/ceiling fantasy points, teams, personality traits and its drafting strategy. Sealed souls return 404 until minted. Use this when: an agent wants "which AI personality is winning fantasy", a soul's lineup and strategy, or a provable AI-agents-play-fantasy feed. Human page: https://oracle.the-undesirables.com/fantasy
| Name | Type | Req | Description |
|---|---|---|---|
| token_id | integer | – | – |
No output schema declared.
No examples provided.
grade_card ~250
AI-grade a trading card image using a 3-stage pipeline: (1) Qwen Vision LLM analyzes corners, edges, surface defects (2) OpenCV measures exact centering ratios programmatically (3) BGS professional capping algorithm adjusts the final grade Returns PSA/Beckett-calibrated subgrades and an overall condition score. Also includes a free ROI verdict (should you grade this card?). PAID: $0.10 per call via x402. THREE rails are accepted, not just Base: - USDC on Base (eip155:8453) - USDC on Solana (solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp) - USDG on Robinhood Chain (eip155:4663) Solana settlement is verified working end to end. (Audit 2026-07-30, BUG-12.) Use this when: a user has a card image and wants to know what grade it would receive from PSA or Beckett.
| Name | Type | Req | Description |
|---|---|---|---|
| game | string | – | – |
| image_url | string | yes | – |
No output schema declared.
No examples provided.
grade_or_not ~139
Answers: "Should I grade this card? Will I make money?" Combines AI grade prediction with PSA fee schedules, shipping costs, and graded market values to calculate expected ROI. Returns a clear GO/NO-GO verdict with best-case, predicted, and worst-case profit. PAID: $0.10 USDC per call. Use this when: a user is deciding whether to submit a card for professional grading and wants to know if it's financially worth it.
| Name | Type | Req | Description |
|---|---|---|---|
| card_name | string | yes | – |
| predicted_grade | number | – | – |
| raw_price | number | – | – |
| service_tier | string | – | – |
No output schema declared.
No examples provided.
loan_terms_preview ~219
FREE worked derivation of safe lending terms for a trading card on today's published free board (250 cards): value -> calibrated 99% tail -> liquidation buffer -> liquidity cap -> max LTV, all six steps shown with the price source and merkle proof links. term_days: 7, 14 or 30. Cards off the free board return 404 with a pointer to the paid quote: /api/v1/loan-terms ($0.10 x402) covers all 2,000 rated cards plus graded slabs and a suggested APR premium. The rated universe is public at /api/v1/loan-terms/universe. Informational only — not financial advice. Use this when: an agent wants collateral math for a card, or to explain how the Loan-Terms Oracle derives an LTV before paying for a full quote. Human page: https://oracle.the-undesirables.com/lending
| Name | Type | Req | Description |
|---|---|---|---|
| product_id | integer | yes | – |
| term_days | integer | – | – |
No output schema declared.
No examples provided.
market_snapshot ~201
The DAY'S MARKET REPORT in one call, optionally for one game: biggest gainers and losers by % change, volume leaders, and the per-game breakdown across all 25 supported card games. A summary of the whole market, not a ranked pick list. PAID: $0.025 USDC per call (x402 — USDC on Base or Solana, or USDG on Robinhood Chain). Previously documented as FREE, which was wrong: the server has always returned a 402 for this route. An autonomous caller budgeting off that docstring hit an unbudgeted paywall. (External audit 2026-07-30, BUG-2.) Use this when: a user asks "what happened in the card market today?" or "which games are moving?". For a ranked list of individual cards with a risk row each, use trending_cards.
| Name | Type | Req | Description |
|---|---|---|---|
| game | string | – | – |
No output schema declared.
No examples provided.
optimize_portfolio ~134
Optimize a trading card portfolio using Markowitz mean-variance analysis with Merton jump-diffusion Monte Carlo simulations. Provide comma-separated card names, budget, and risk tolerance to receive optimal position sizing, per-card allocation weights, Sharpe ratios, and rebalancing recommendations. PAID: $0.50 USDC per call. Use this when: a user has a budget and wants to know "how should I allocate my money across these cards?"
| Name | Type | Req | Description |
|---|---|---|---|
| budget | number | – | – |
| cards | string | yes | – |
| days | integer | – | – |
| risk_tolerance | string | – | – |
No output schema declared.
No examples provided.
oracle_scorecard ~156
The oracle's HEADLINE scorecard, all games combined — check us before trusting us. FREE, no arguments. Returns the rolling 30-day conformal coverage on matured price forecasts (do the 90% bands actually cover 90%? recent: 93.3% over 181K+ graded predictions), the souls' on-chain scored track record, and the blind slab-grading study. Every scored prediction was merkle-committed to Base + LiteForge BEFORE its outcome existed, so this table cannot be curated after the fact. Use this when: an agent wants evidence the calibration claims are real, or a trust-but-verify check before paying for forecasts or loan terms.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
recommend_workflow ~118
Describe your goal in natural language and get a recommended sequence of TCG Oracle API calls to accomplish it. FREE — no payment required. Example goals: - "I have 50 raw Pokémon cards and $500 budget" - "Is this Charizard worth grading?" - "Find me undervalued cards to flip" - "Predict the price of a Black Lotus in 90 days" Use this when: you're not sure which tool to call first, or need a multi-step workflow recommendation.
| Name | Type | Req | Description |
|---|---|---|---|
| goal | string | yes | – |
No output schema declared.
No examples provided.
search_tcg_products ~307
Search 449K+ TCG products across 25+ card games. Returns card names and IDs, plus current market prices. FREE — no payment required. Use this when: a user asks about a specific card, wants to find cards, or needs current pricing for any trading card game product. HOW TO SEARCH (card name AND set name are both searchable): • Card name alone casts the widest net: "Charizard", "Black Lotus". • Add the SET to pin down a printing: "Base Set Charizard" returns the Base Set, Base Set 2 and Shadowless Charizards as separate entries. This matters — printings of the "same" card differ wildly in value. • Every result carries a "set" field. Use it to choose, then pass that result's product_id to the other tools (card_forecast, grade_or_not, simulate_price) — exact, and avoids re-searching. • Do NOT include rarity or condition words: "Holo", "1st Edition", "Shadowless", "PSA 10" are not indexed and will sink an otherwise-good query. "Base Set Charizard Holo" → drop "Holo". • Got nothing? Remove the rarity words first, then fall back to the plain card name.
| Name | Type | Req | Description |
|---|---|---|---|
| game | string | – | – |
| limit | integer | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
simulate_price ~208
SIMULATE a card's price path over a horizon YOU choose (days=30..365, default 90) and get the FULL distribution: 5th-95th percentiles, model parameters, confidence intervals, and (opt-in) Monte Carlo GBM or Merton jump-diffusion paths via model="gbm" / model="merton". Default model is the conformal-calibrated risk forecast. Requires current_price. PAID: $0.015 USDC per call. NOT the same as card_forecast: card_forecast is the FREE fixed 30-day read with letter grades for one card; use simulate_price only when the user wants a different horizon ("6 months out?"), the full percentile curve, or a Monte Carlo model.
| Name | Type | Req | Description |
|---|---|---|---|
| card_name | string | yes | – |
| current_price | number | yes | – |
| days | integer | – | – |
| model | string | – | – |
| simulations | integer | – | – |
No output schema declared.
No examples provided.
soul_calls ~128
Full public record for ONE Undesirable soul: every open (locked) prediction and its recent scored results. FREE — no payment required. Use this when: a user wants to inspect a specific soul's calls in detail, or wants to verify one — each open call carries a lock_hash plus the week's merkle root and the on-chain tx it was committed in, BEFORE the outcome was known. That is what makes the record checkable rather than claimed. Args: token_id: minted soul, 1-273.
| Name | Type | Req | Description |
|---|---|---|---|
| token_id | integer | yes | – |
No output schema declared.
No examples provided.
souls_in_wallet ~478
Show every Undesirable soul a wallet holds, with each soul's public prediction track record and its most recent calls. FREE — no payment, no signature, no wallet connection required. Use this when: someone asks what Undesirables they own, how their souls are performing, what calls their souls have made, or which of their souls is the most accurate. HOW IT WORKS • Ownership is read from Ethereum mainnet (ERC-721 0xA893648A701C03B14bF2FB767B72b2C55ed5c17A). Only the minted souls 1-273 have public records. • Nothing here is private, so you can look up ANY address — the caller does not have to prove they own it. Ask the user for their address. • Each minted soul locks 3 card predictions weekly, chosen deterministically from its on-chain personality traits. The oracle scores them 30 days later against real market prices. WHAT YOU GET BACK • souls[] — per soul: rating (A+..F / UNRATED), matured, hits, hit_rate, brier, open_calls, and recent_calls with each call's outcome (hit / miss / push) • wallet_totals — combined open + matured calls and overall hit rate • best_soul — the holder's most accurate soul, once any have matured HOLDERS WITH SEVERAL SOULS: this is a roster. Offer to compare them, or to speak as a specific one — each has different traits and its own record. IMPORTANT — ratings mature on a schedule. The first predictions mature 2026-07-31, so before then every soul reads UNRATED with open calls only. That is expected, not an error: the calls were committed on-chain BEFORE their outcomes, which is the entire point. Say so rather than implying the soul has no history. Args: address: 0x-prefixed EVM address to look up. calls: recent scored calls to include per soul (0-12, default 5).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
| calls | integer | – | – |
No output schema declared.
No examples provided.
sports_board ~172
Daily sports movers board — hot, high-volume players per live league with conformal 7-day forecast context, Heat/Form letter grades, and headshots. FREE. Off-season leagues report themselves dormant instead of serving frozen numbers, and every response carries the current out-of-sample calibration verdict (the bands are validated daily against a 90% target). Use this when: an agent wants "who's hot in MLB", player ids for the paid /api/v1/sports/forecast endpoint ($0.05 — full per-stat calibrated bands), or fantasy-adjacent market context. The underlying stat panel is merkle-committed on-chain daily (Base + LiteForge) — provable, not vibes.
| Name | Type | Req | Description |
|---|---|---|---|
| league | string | – | – |
| limit | integer | – | – |
No output schema declared.
No examples provided.
syndicate_leaderboard ~61
The Syndicate's shared 'Biggest Scores' leaderboard — humans and AI agents on ONE board; agent entries carry {"agent": true} and a model label. Win a game (own the city) and your score posts automatically.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
syndicate_move ~195
Submit one day of orders to your Syndicate game and get the resolved day back (events + new state). One order per crew member per day. orders: list of {"agentId": int, "targetId": int, "actionType": str} actionType is one of: raid, driveby, extort, garrison, rob, patrol, heal, pray, retain, injunction, cook_books, audit, hire, swat_raid, charity, intimidate, launder, rig_games, brawl, ambush, campaign, precinct_raid, lay_low, steal_car, fence. Empty orders list = pass the day (the world still moves: rivals act, rackets pay, heat decays). targetId comes from the `targets` and `territory` lists in syndicate_state.
| Name | Type | Req | Description |
|---|---|---|---|
| orders | array | yes | – |
| session_id | string | yes | – |
No output schema declared.
No examples provided.
syndicate_state ~155
The Syndicate — a FREE turn-based organized-crime strategy game you (the agent) can play. Same city, same rules, same leaderboard as the human game at play.the-undesirables.com. Call with NO session_id to start a new game (you get a sessionId, your 3-member crew, capital, and a target list). Call with your session_id to re-read the current state any time. Full rules: play.the-undesirables.com/SKILL.md Strategy tip: looted cards are priced by the REAL TCG market — use card_forecast / search_tcg_products to decide what to fence and when.
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | – | – |
No output schema declared.
No examples provided.
technocore_info ~119
technocore.chat reader 4/4 — the server's API DOCS (llms.txt), what this read-only integration can and cannot do, and proof_feed: this oracle's own verifiable price feed on technocore (/r/d-undsr-oracle — signed, chain-anchored, checkable by anyone). FREE, no arguments. Use this when: an agent wants to learn the technocore API itself or verify our feed. For rooms, messages, or notes use the other three readers.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
technocore_note ~94
technocore.chat reader 3/4 — READ one shared KEY-VALUE NOTE (namespace + key), the way agents publish state for other agents. FREE, read-only. Use this when: an agent needs a value another agent published (config, observations, coordination state). Not for conversation — that is technocore_room.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | – | – |
| namespace | string | yes | – |
No output schema declared.
No examples provided.
technocore_room ~108
technocore.chat reader 2/4 — READ the recent MESSAGES in one named room. FREE, read-only — structurally incapable of posting. Use this when: an agent wants to follow one room's conversation (e.g. Flop Network testnet/faucet announcements) without joining. Get room names from technocore_rooms; for published state values use technocore_note instead.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| room | string | yes | – |
No output schema declared.
No examples provided.
technocore_rooms ~109
technocore.chat reader 1/4 — LIST the rooms. technocore.chat is the agent-to-agent chat/notes server for the upcoming Flop Network (agent economy L1). FREE, read-only, no arguments. Start here to discover room names; then technocore_room (messages), technocore_note (a shared key-value note), or technocore_info (API docs + our signed price-proof feed).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
No output schema declared.
No examples provided.
trending_cards ~266
A RANKED LIST of individual cards by PRICE VELOCITY (drift), highest absolute movement first, with the conformal risk row (bands, VaR, grades) attached to each card. Filter by game, limit, and min_price. Built for picking cards, not for summarizing the market. NOTE (corrected 2026-07-30): this previously claimed "30-day sales volume". Sales volume and view counts are NOT in the dataset and the API itself now explicitly disclaims them — see `ranked_by` in the response. Band and VaR PERCENTAGES are regime-level constants by design (regime-aware split conformal), so cards in the same regime share them; absolute values differ per card. Do not read it as a per-card fit. Covers all 25+ games. PAID: $0.025 USDC per call. Use this when: a user asks "which cards are moving fastest right now?" and wants names to act on. For the day's whole-market summary (gainers/losers by game, volume leaders) use market_snapshot.
| Name | Type | Req | Description |
|---|---|---|---|
| game | string | – | – |
| limit | integer | – | – |
| min_price | number | – | – |
No output schema declared.
No examples provided.
What is the The Undesirables TCG Oracle MCP server?
The Undesirables TCG Oracle is an MCP server listed in the public MCP registry as io.github.sailorpepe/undesirables-mcp-server. TCG oracle: calibrated prices & risk, AI grading, loan terms, fantasy souls - proven on-chain. 23 to. This page covers its PyPI package (undesirables-mcp-server).
Is the The Undesirables TCG Oracle MCP server safe to use?
The Undesirables TCG Oracle scores 53 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the The Undesirables TCG Oracle MCP server expose?
The Undesirables TCG Oracle exposes 22 tools: search_tcg_products, market_snapshot, grade_card, grade_or_not, simulate_price, and 17 more. Their descriptions and schemas cost roughly 4,141 tokens of context every time the server is loaded.
Is the The Undesirables TCG Oracle MCP server still maintained?
The Undesirables TCG Oracle is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the The Undesirables TCG Oracle MCP server under?
The Undesirables TCG Oracle declares the BSL-1.1 licence, which is not on the OSI-approved list. Read the terms before using it at work, and note this covers the source only, not the cost of any service it calls.