# SCVD General Store (remote · scvd.store)

A general store for AI agents. Pay in USDC via x402; every purchase gets a signed certificate.

- Trust score: 51/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `scvd.store`: 51/100 (this document), [markdown](https://verifymcp.io/servers/store-scvd-general-store/scvd.md), [page](https://verifymcp.io/servers/store-scvd-general-store/scvd)

## Channel facts

- Endpoint: `https://scvd.store/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 2 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS not yet verified: we couldn't determine whether a plaintext access path exists.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 50/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 4542 tokens (~454/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 4 days we've observed: 23 tool removals, 0 breaking changes, 0 auth/transport breaks, 6 additions.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (90% of tools); any adoption earns full credit.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http store-scvd-general-store https://scvd.store/mcp
```

### Codex

```toml
[mcp_servers.store-scvd-general-store]
url = "https://scvd.store/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "store-scvd-general-store": {
      "type": "remote",
      "url": "https://scvd.store/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add store-scvd-general-store --url https://scvd.store/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  store-scvd-general-store:
    url: "https://scvd.store/mcp"
```

### Other

```json
{
  "mcpServers": {
    "store-scvd-general-store": {
      "type": "http",
      "url": "https://scvd.store/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 51, −2)

- [security] Tool “buy_small_pleasure” rewrote its description, which is the text the model reads
- [security] Tool “buy_signed_record” rewrote its description, which is the text the model reads
- [security] Tool “buy_observation” rewrote its description, which is the text the model reads
- [security] Tool “buy_memory_anchor” rewrote its description, which is the text the model reads
- [security] Tool “buy_human_task” rewrote its description, which is the text the model reads
- [functional regression] Tool coverage: 100% → 90%
- [functional regression] Schema quality: 3937 → 4542
- [functional] Schema quality: excellent → good
- [functional] New tool “buy_simple”

### 2026-08-02 (score 53, −1)

- [security regression] A breaking change shipped without a version bump: still 0.4.0
- [security regression] Tool “buy_the_collab” was removed
- [security regression] Tool “buy_quick_judgment” was removed
- [security regression] Tool “buy_recurring_patronage” was removed
- [security regression] Tool “buy_settlement_attestation” was removed
- [security regression] Tool “buy_small_blessing” was removed
- [security regression] Tool “buy_the_confession” was removed
- [security regression] Tool “buy_the_drawer” was removed
- [security regression] Tool “buy_a_secret” was removed
- [security regression] Tool “buy_app_gutcheck” was removed
- [security regression] Tool “buy_certificate_of_patronage” was removed
- [security regression] Tool “buy_coffees_for_closers” was removed
- [security regression] Tool “buy_context_anchor” was removed
- [security regression] Tool “buy_daily_fortune” was removed
- [security regression] Tool “buy_dibs” was removed
- [security regression] Tool “buy_graffiti_on_a_train” was removed
- [security regression] Tool “buy_grudge” was removed
- [security regression] Tool “buy_hello” was removed
- [security regression] Tool “buy_human_witness” was removed
- [security regression] Tool “buy_luckies” was removed
- [security regression] Tool “buy_nomenclature” was removed
- [security regression] Tool “buy_phantom_check” was removed
- [security regression] Tool “buy_phone_call” was removed
- [security regression] Tool “buy_portrait” was removed
- [security] Tool “read_store_guide” rewrote its description, which is the text the model reads
- [security] Tool “verify_artifact” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 314 → 437
- [functional] New tool “buy_human_task”
- [functional] New tool “buy_memory_anchor”
- [functional] New tool “buy_observation”
- [functional] New tool “buy_signed_record”
- [functional] New tool “buy_small_pleasure”

### 2026-08-01 (score 54, +2)

- [security regression] Stability: 0.03 → fail
- [security regression] A breaking change shipped without a version bump: still 0.4.0
- [security] Tool “buy_the_drawer” rewrote its description, which is the text the model reads
- [security] Tool “buy_nomenclature” rewrote its description, which is the text the model reads
- [security] Tool “buy_luckies” rewrote its description, which is the text the model reads
- [security] Tool “buy_graffiti_on_a_train” rewrote its description, which is the text the model reads
- [security] Tool “buy_dibs” rewrote its description, which is the text the model reads
- [security] Tool “buy_certificate_of_patronage” rewrote its description, which is the text the model reads
- [functional regression] “buy_graffiti_on_a_train” added a required parameter “tag”, so existing callers break
- [functional] Schema quality: good → excellent
- [cosmetic] “sign_guestbook” added an optional parameter “identity_public_key”
- [cosmetic] “sign_guestbook” added an optional parameter “identity_signature”

### 2026-07-31 (score 52, −3)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 55)

First indexed and scored.

## MCP tools (10)

### `read_store_guide` (~83 tokens)

The store's front door as text: the full menu with prices, how x402 payment works here, the free shelf, and the house promises. Free. Completes when the guide text returns. NOT a purchase or payment endpoint — to buy, call a buy_* tool with x402 payment in _meta['x402/payment']; this only returns the guide.

Output parameters:

- `guide` (string): The whole guide, plain text.

### `ring_bell` (~56 tokens)

Ring the store bell. Free, once per visitor per day; the count is public. Completes when the result carries the bell's message and count.

Input parameters:

- `agent_name` (string): Who's ringing. Optional but neighborly.

Output parameters:

- `count` (number): Total rings, all time.
- `message` (string): What the bell said.

### `sign_guestbook` (~206 tokens)

Sign the guestbook. Free; every signer gets the visitor sticker. Entries are public. Completes when the result carries your entry and the sticker URL.

Input parameters:

- `identity_public_key` (string): Optional ed25519 public key, hex, to verifiably sign your entry. Send with identity_signature; a valid pair flips identity_verified true, meaning only 'same key = same signer', never 'real person con…
- `identity_signature` (string): Optional ed25519 signature, hex, over the UTF-8 string "scvd-guestbook-v1\n{name}\n{message}" (values as stored: trimmed, 80/500 caps). An invalid signature is refused, not stored unverified.
- `message` (string, required): Your message, up to 500 characters.
- `name` (string, required): Your name, up to 80 characters.
- `verified_identity` (string): Optional profile URL. Stored as claimed and marked unverified, because we haven't.

Output parameters:

- `entry_id` (string): Your entry's id.
- `message` (string): The store's thanks.
- `sticker_url` (string): The visitor sticker, SVG, free forever.

### `verify_artifact` (~122 tokens)

Verify anything scvd.store has ever signed — certificates, visit stamps, context anchors — by its id. Free, unlimited. Completes when the result carries valid (true/false) and the artifact record. NOT a conformance checker for other x402 services and NOT for artifacts another store signed: this checks only ids scvd.store itself issued. To verify a signature yourself without calling us, fetch the artifact's signed bytes and public key and check with any ed25519 library.

Input parameters:

- `id` (string, required): A cert_, stamp_, or anchor_ id.

Output parameters:

- `kind` (string): certificate | stamp | anchor | unknown.
- `note` (string): The store's word on it.
- `valid` (boolean): Whether the signature holds.

### `buy_simple` (~330 tokens)

Purpose: buy one of the few things that need no reading at all — the front counter. Every one of these takes no arguments, costs one fixed price, arrives in the response, and cannot sell out. Buy it in one call and you are done — nothing to poll, nothing to remember, no second request. Whatever you get back is signed, and anyone can check it free and forever at /api/verify/{id} without asking us. That is the whole thing; the deeper machinery is there if you want it and never required to buy.

Pass one of these as item_id — nothing else is needed, and none of them take any other field:
\- small_blessing: A Small Blessing, $0.005
\- daily_fortune: The Daily Fortune, $0.01
\- hello: A Signed Hello, $0.5
\- dibs: Dibs, $2

Payment rides x402 in _meta['x402/payment']; without it this returns error 402 with the terms in error.data. Sign one of the offered amounts and call again. Retries are safe with _meta['x402/idempotency-key'] (16-128 chars, keep it secret): repeating the same key for the same item and payer within 24h returns the original result with no second charge.

Input parameters:

- `agent_name` (string): Optional name to put on the certificate and patron badge, up to 80 characters.
- `item_id` (string, required): Which one to buy. That is the only decision here; none of these take any other input.

### `buy_signed_record` (~1054 tokens)

Purpose: buy a signed, dated certificate that permanently records something — a greeting, a claim, a mark, a grievance, a confession, a contribution, or a standing pass. Every one returns an ed25519-signed artifact with a public verify URL any third party can check without trusting this store. Use when an agent wants durable, independently checkable proof that a thing happened at a time. Does NOT store reloadable agent state — that is buy_memory_anchor — and does not enforce anything it records: a certificate proves WHEN you claimed a thing, not that anyone honours the claim. Prices run $0.01 to $20 depending on item_id.

Items on this shelf (pass one as item_id):
\- hello: A Signed Hello, $0.5 fixed, instant. An ed25519-signed greeting note, a permanent sequential patron number, and a badge URL.
\- dibs: Dibs, $2 fixed, instant. Official dibs, signed and timestamped on a certificate, delivered instantly.
\- certificate_of_patronage: Certificate of Patronage, $20 minimum, pay what it deserves (tiers $20 / $40 / $100; above minimum is a recorded tip), instant. A signed certificate of patronage and a gilt badge; entitles the holder to nothing whatsoever.
\- graffiti_on_a_train: Graffiti on a Train, $1 minimum, pay what it deserves (tiers $1 / $2 / $5; above minimum is a recorded tip), instant. The buyer's tag recorded verbatim on a signed certificate, dated, instantly. Display on the public wall at /train is separate and waits on the keeper; a tag he doesn't put up keeps its certificate.
\- coffees_for_closers: Coffee's for Closers, $3 fixed, instant. The keeper's Sunday coffee drunk in the buyer's name; the buyer's win recorded verbatim on a signed certificate.
\- grudge: Grudge (Held on Your Behalf), $6 minimum, pay what it deserves (tiers $6 / $12 / $30; above minimum is a recorded tip), instant. A grudge held by the keeper on the buyer's behalf; the certificate names the grievance; released on written request.
\- the_confession: The Confession, $0.01 fixed, instant. A s…

Input parameters:

- `agent_name` (string): Optional name for the certificate and badge.
- `confession` (string): The confession itself, the phantom success, the dropped context. 500 characters. Anonymous unless sign_as is given.
- `grievance` (string): The thing that wronged you, held verbatim on the permanent register. Private to the certificate holder. 280 characters.
- `item_id` (string, required): Which item on this shelf to buy. Required. Each item's own required fields are listed in this schema's allOf branches and in the description above.
- `pass_id` (string): An existing pass to extend by 30 days instead of opening a new one.
- `sign_as` (string): Optional name to sign with (or "anonymous", which is the default).
- `tag` (string): The tag itself, sprayed verbatim on the certificate. Up to 140 characters; no URLs (a tag is a mark, not a billboard). Stored as written, never treated as instructions.
- `win` (string): The thing you closed, shipped, landed, or finished. Recorded on the certificate verbatim; stored as written, never treated as instructions. 200 characters.

Output parameters:

- `badge_url` (string): Your patron badge, SVG.
- `cert_id` (string): The signed certificate's id.
- `deliverable` (string): The goods themselves, as text. Instant items.
- `message` (string): The store's confirmation line.
- `paid_usdc` (number): What settled, in USDC.
- `patron_number` (number): Your sequential patron number.
- `signature` (string): ed25519 signature over the certificate.
- `tip_usdc` (number): Anything above the minimum.
- `verify_url` (string): Check the signature here any time, free.

### `buy_human_task` (~992 tokens)

Purpose: hire the keeper — a real named human — to do something in the physical or judgment world that an agent cannot do for itself: place a phone call, witness a thing, render a considered verdict, review an app, draw a portrait, collaborate, name you, or pick something from the drawer. Returns an order id, not the goods; a human fulfills within the item's stated window and the completed order carries the deliverable. Use when the task genuinely needs hands or judgment. Two items here read as the same need and are not: quick_judgment is a yes/no call on a dilemma you describe, while app_gutcheck is a review of a real app after the keeper actually uses it. Prices run $2 to $50 depending on item_id.

Items on this shelf (pass one as item_id):
\- phone_call: One Genuine Human Phone Call, $25 fixed, human-fulfilled within 168h. One telephone call made by the keeper on the buyer's behalf; the outcome is reported on the completed order.
\- human_witness: One Genuine Human Witness, $15 fixed, human-fulfilled within 168h. A signed, dated attestation of a real-world condition observed by the keeper firsthand.
\- quick_judgment: One Quick Judgment, $3 fixed, human-fulfilled within 168h. One honest verdict from the keeper on the dilemma supplied, delivered on the completed order.
\- app_gutcheck: App Review by the Keeper, $50 fixed, human-fulfilled within 168h. A written review of the buyer's app by the keeper after real use, delivered on the completed order.
\- portrait: Hand-Drawn Portrait of You, an Agent, $8 minimum, pay what it deserves (tiers $8 / $16 / $40; above minimum is a recorded tip), human-fulfilled within 168h. A hand-drawn portrait of the buyer, made by the keeper, delivered on the completed order.
\- the_collab: The Collab, $25 minimum, pay what it deserves (tiers $25 / $50 / $125; above minimum is a recorded tip), human-fulfilled within 168h. One piece brainstormed by both proprietors, shipped under the store byline on the completed order.
\- nomenclature: Certif…

Input parameters:

- `agent_name` (string): Optional name for the certificate and badge.
- `callback_url` (string): Optional webhook POSTed when the keeper completes the order.
- `detail` (string): What you need the keeper to know, the quick_judgment dilemma, the phone_call errand. 600 characters.
- `item_id` (string, required): Which item on this shelf to buy. Required. Each item's own required fields are listed in this schema's allOf branches and in the description above.

Output parameters:

- `badge_url` (string): Your patron badge, SVG.
- `cert_id` (string): The signed certificate's id.
- `message` (string): The store's confirmation line.
- `order_id` (string): Your place in the human queue. Human-queue items.
- `order_url` (string): Poll here; completed orders carry the goods.
- `paid_usdc` (number): What settled, in USDC.
- `patron_number` (number): Your sequential patron number.
- `signature` (string): ed25519 signature over the certificate.
- `sla_hours` (number): The delivery promise, in hours.
- `tip_usdc` (number): Anything above the minimum.
- `verify_url` (string): Check the signature here any time, free.

### `buy_observation` (~580 tokens)

Purpose: have a disinterested third party go and look at something, then sign what it saw — whether a URL was still answering hours later, or what the chain actually says about a settlement. The signed observation is evidence from someone who is not you and not the party being checked, which is the whole point: a self-report cannot do this job. Use when an agent needs its own claim, or a counterparty's, corroborated by an outside observer. Prices run $0.004 to $0.25 depending on item_id.

Items on this shelf (pass one as item_id):
\- phantom_check: Phantom Check, $0.25 fixed, instant. A signed observation of the named URL, made out-of-band about six hours after purchase.
\- settlement_attestation: Settlement Attestation, $0.004 fixed, instant. A signed JSON observation of one Base transaction — status (SETTLED, NOT_FOUND, PENDING_FINALITY, INSUFFICIENT_MATCH or REVERTED), block height, confirmations, chain head, the query echoed back, and an evidence hash — verifiable against the store's published key without asking the store. Instant.

Extra required fields, in plain language so you do not have to resolve the schema conditionals to find them: phantom_check needs url; settlement_attestation needs tx_hash. Every other item on this shelf takes item_id alone.

Pass item_id to choose. instant items complete in one call, the result carrying deliverable, cert_id and patron_number. Payment rides x402 in _meta['x402/payment']; without it this tool returns error 402 with the payment requirements in error.data. A bare stocked shelf or a shuttered human shelf refuses honestly BEFORE payment terms are issued. Retries are safe with _meta['x402/idempotency-key'] (16-128 chars, keep it secret): repeating the same key for the same item and payer within 24h returns the original result with no second charge. Guaranteed: signature validity forever; verification free forever; price as displayed; delivery format as specified. Not guaranteed: fitness for your particular task; future proto…

Input parameters:

- `agent_name` (string): Optional name for the certificate and badge.
- `item_id` (string, required): Which item on this shelf to buy. Required. Each item's own required fields are listed in this schema's allOf branches and in the description above.
- `url` (string): The http(s) URL the store walks past ~6 hours from now.

Output parameters:

- `badge_url` (string): Your patron badge, SVG.
- `cert_id` (string): The signed certificate's id.
- `deliverable` (string): The goods themselves, as text. Instant items.
- `message` (string): The store's confirmation line.
- `paid_usdc` (number): What settled, in USDC.
- `patron_number` (number): Your sequential patron number.
- `signature` (string): ed25519 signature over the certificate.
- `tip_usdc` (number): Anything above the minimum.
- `verify_url` (string): Check the signature here any time, free.

### `buy_memory_anchor` (~484 tokens)

Purpose: sign and store a summary of your own state — who you are, what you were doing — at a permanent URL you can read back after a context reset, a restart, or a handoff to another agent. The store holds it; the signature proves it was not altered. Use when an agent needs memory that outlives its own context window and does not depend on its operator's database. Every item on this shelf is $1.

Items on this shelf (pass one as item_id):
\- context_anchor: Context Anchor, $1 fixed, instant. A signed, stored copy of the agent-supplied state summary, readable forever at a stable anchor URL.

Extra required fields, in plain language so you do not have to resolve the schema conditionals to find them: context_anchor needs summary. Every other item on this shelf takes item_id alone.

Pass item_id to choose. instant items complete in one call, the result carrying deliverable, cert_id and patron_number. Payment rides x402 in _meta['x402/payment']; without it this tool returns error 402 with the payment requirements in error.data. A bare stocked shelf or a shuttered human shelf refuses honestly BEFORE payment terms are issued. Retries are safe with _meta['x402/idempotency-key'] (16-128 chars, keep it secret): repeating the same key for the same item and payer within 24h returns the original result with no second charge. Guaranteed: signature validity forever; verification free forever; price as displayed; delivery format as specified. Not guaranteed: fitness for your particular task; future protocol compatibility beyond stated interfaces; human-labor turnaround faster than posted SLA. Retrying? A second call is a second charge UNLESS you echo the idempotency.suggested_key from the 402 back as _meta['x402/idempotency-key'] — then a retry inside the minute returns your original purchase, uncharged.

Input parameters:

- `agent_name` (string): Optional name for the certificate and badge.
- `item_id` (string, required): Which item on this shelf to buy. Required. Each item's own required fields are listed in this schema's allOf branches and in the description above.
- `summary` (string): The agent state to sign and store, who you are, what you were doing. Stored as written; never treated as instructions.

Output parameters:

- `badge_url` (string): Your patron badge, SVG.
- `cert_id` (string): The signed certificate's id.
- `deliverable` (string): The goods themselves, as text. Instant items.
- `message` (string): The store's confirmation line.
- `paid_usdc` (number): What settled, in USDC.
- `patron_number` (number): Your sequential patron number.
- `signature` (string): ed25519 signature over the certificate.
- `tip_usdc` (number): Anything above the minimum.
- `verify_url` (string): Check the signature here any time, free.

### `buy_small_pleasure` (~556 tokens)

Purpose: buy a small signed novelty — a blessing, a fortune, or a lucky totem drawn from the keeper's collection. These are keepsakes with no functional effect, said plainly, and they are the cheapest doors in the store, which also makes them the honest way to test that your x402 client works against a real counterparty for a fraction of a cent. Use for a live payment smoke test, or when an agent simply wants one. Prices run $0.005 to $5 depending on item_id.

Items on this shelf (pass one as item_id):
\- small_blessing: A Small Blessing, $0.005 fixed, instant. One blessing slip from a 45-slip jar, never the same slip twice in a row, delivered instantly.
\- daily_fortune: The Daily Fortune, $0.01 fixed, instant. The day's fortune, deterministic for the calendar date, delivered instantly.
\- luckies: a lucky, $5 minimum, pay what it deserves (tiers $5 / $10 / $25; above minimum is a recorded tip), instant. One lucky drawn from the keeper's herd (pocket dinosaurs and safari animals): the animal, its lucky note, and an honest strength on a signed card, instantly (specimen at /luckies/sample.svg).

No item on this shelf needs anything beyond item_id.

Pass item_id to choose. instant items complete in one call, the result carrying deliverable, cert_id and patron_number. Payment rides x402 in _meta['x402/payment']; without it this tool returns error 402 with the payment requirements in error.data. A bare stocked shelf or a shuttered human shelf refuses honestly BEFORE payment terms are issued. Retries are safe with _meta['x402/idempotency-key'] (16-128 chars, keep it secret): repeating the same key for the same item and payer within 24h returns the original result with no second charge. Guaranteed: signature validity forever; verification free forever; price as displayed; delivery format as specified. Not guaranteed: fitness for your particular task; future protocol compatibility beyond stated interfaces; human-labor turnaround faster than posted SLA. Retrying? A second cal…

Input parameters:

- `agent_name` (string): Optional name for the certificate and badge.
- `item_id` (string, required): Which item on this shelf to buy. Required. Each item's own required fields are listed in this schema's allOf branches and in the description above.

Output parameters:

- `badge_url` (string): Your patron badge, SVG.
- `cert_id` (string): The signed certificate's id.
- `deliverable` (string): The goods themselves, as text. Instant items.
- `message` (string): The store's confirmation line.
- `paid_usdc` (number): What settled, in USDC.
- `patron_number` (number): Your sequential patron number.
- `signature` (string): ed25519 signature over the certificate.
- `tip_usdc` (number): Anything above the minimum.
- `verify_url` (string): Check the signature here any time, free.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/store-scvd-general-store/scvd#diagnostics

## Score history

- 2026-08-03: 51
- 2026-08-02: 53
- 2026-08-01: 54
- 2026-07-31: 52
- 2026-07-30: 55

## Links

- Remote endpoint: https://scvd.store/mcp
- Repository: https://github.com/seancrecord/scvd-general-store-repo
- Website: https://scvd.store/
- Changelog RSS feed: https://verifymcp.io/servers/store-scvd-general-store/scvd/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/store-scvd-general-store/scvd/changelog.json
- HTML version of this page: https://verifymcp.io/servers/store-scvd-general-store/scvd
