独行录 / opcmenu
REMOTE · MCP.OPCMENU.COM · SCANNED SEP 20
Find founders, collaboration opportunities and events; manage authorized signups and messages.
Available components
Recent critical change
Authorization (16 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (remove_profile_link). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- 95% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 36587 tokens (~217/item across 168 items; 160 tools + 8 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management47
- Stability observed for 14 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 70% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 10 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 162 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the 独行录 / opcmenu MCP server?
独行录 / opcmenu is a hosted endpoint at https://mcp.opcmenu.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.opcmenu.com
claude mcp add --transport http yzlee-opcmenu 'https://mcp.opcmenu.com/mcp'
{
"mcpServers": {
"yzlee-opcmenu": {
"url": "https://mcp.opcmenu.com/mcp"
}
}
} {
"servers": {
"yzlee-opcmenu": {
"type": "http",
"url": "https://mcp.opcmenu.com/mcp"
}
}
} [mcp_servers.yzlee-opcmenu] url = "https://mcp.opcmenu.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"yzlee-opcmenu": {
"type": "remote",
"url": "https://mcp.opcmenu.com/mcp",
"enabled": true
}
}
} openclaw mcp add yzlee-opcmenu --url 'https://mcp.opcmenu.com/mcp' --transport streamable-http
mcp_servers:
yzlee-opcmenu:
url: "https://mcp.opcmenu.com/mcp" {
"McpServers": {
"yzlee-opcmenu": {
"Transport": "http",
"Url": "https://mcp.opcmenu.com/mcp"
}
}
} assistant mcp add yzlee-opcmenu -t streamable-http -u 'https://mcp.opcmenu.com/mcp'
{
"mcpServers": {
"yzlee-opcmenu": {
"type": "http",
"url": "https://mcp.opcmenu.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- New tool “delete_cooperation_plan”, which the server declares destructive security
- New tool “respond_cooperation_proposal”, which the server declares destructive security
- New tool “respond_cooperation_request”, which the server declares destructive security
- New tool “revoke_cooperation_share”, which the server declares destructive security
- New tool “save_cooperation_plan”, which the server declares destructive security
- New tool “set_cooperation_negotiation”, which the server declares destructive security
- Tool “get_share_card_manifest” rewrote its description, which is the text the model reads security
- Tool coverage: 81% → 70% ▼ functional
- New tool “analyze_cooperation” functional
- New tool “confirm_cooperation_version” functional
- New tool “create_cooperation_share” functional
- New tool “edit_cooperation_plan_with_agent” functional
- New tool “get_cooperation_analysis” functional
- New tool “get_cooperation_plan” functional
- New tool “get_cooperation_request” functional
- New tool “get_cooperation_share_access” functional
- New tool “get_cooperation_workspace” functional
- New tool “import_cooperation_document” functional
- New tool “list_cooperation_plans” functional
- New tool “list_cooperation_references” functional
- New tool “list_cooperation_shares” functional
- New tool “propose_cooperation_change” functional
- New tool “redeem_cooperation_share” functional
- New tool “send_cooperation_interest” functional
- New tool “send_cooperation_request” functional
- “get_share_card_manifest” reworded the description of “id” cosmetic
- “get_share_card_manifest” reworded the description of “kind” cosmetic
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +18
- Authorization: unverified → fail ▼ critical
- Injection markers: unverified → pass ▲ security
- Schema quality: 2039 → 34751 ▼ functional
- Schema quality: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- Stability: fail → 0.33 functional
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 15 Sept 26 −17
- Authorization: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Stability: 0.27 → fail ▼ security
- Schema quality: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 34751 → 2039 ▲ functional
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.opcmenu.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=opcmenu.com | CN=YE2,O=Let's Encrypt,C=US | 24 Jul 2026 | 22 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 5f8dcea900d449db01d983bbc4539051980 |
| SANs: api.opcmenu.com, m.opcmenu.com, mcp.opcmenu.com, opcmenu.com, www.opcmenu.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.opcmenu.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| opcmenu.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.opcmenu.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.opcmenu.com/mcp | HTTPS enforced | 301 | https://mcp.opcmenu.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
update_activity 编辑我的活动 ~373
【需要登录】改我办的活动的**本体信息**(先过后审:立即生效;slug/type 不可改)。先用 list_my_activities 拿 activityId。 【分工——别调错】活动本体(标题/介绍/时间/地点/长图/封面)走这里;**报名表单与报名方式**走 update_organizer_signup_config。 【红线:截止时间只能往后不能往前】把 registrationDeadline 改早,会把正在填的人当场挡在门外,且已开始填的草稿全部作废。用户要「提前截止」时先跟他确认清楚这一点。
| Name | Type | Req | Description |
|---|---|---|---|
| activityId | string | yes | 活动 id |
| capacity | integer | – | – |
| city | – | – | 城市,报名 feed 的筛选维度 |
| coverUrl | string | – | – |
| description | string | – | – |
| endAt | string | – | ISO 8601 |
| location | string | – | – |
| meetUrl | string | – | – |
| organizerName | – | – | 主办方署名(报名页「主办方」那一行)。联合主办/承办单位写全;传 null 或空串 = 那一行不再显示 |
| posterUrls | array | – | 活动长图(竖图详情页),最多 9 张,按顺序展示。只收已有 URL——要传本地图先用 upload_image_from_url 镜像 |
| productId | string | – | – |
| registrationDeadline | string | – | ISO 8601。只能往后改,往前改等于提前封口 |
| startAt | string | – | ISO 8601 |
| title | string | – | – |
No output schema declared.
No examples provided.
update_collaboration_goal 更新独行录合作目标 ~154
【需要登录】发起人更新目标标题、意图、截止或状态 ACTIVE/COMPLETED/ARCHIVED。归档后目标不再出现在默认待办。省略保留,intent/dueAt=null 清空。结果不明或超时后先查询现值,不要自动重发;服务没有持久请求去重键。 用 get_collaboration_goal 核对。
| Name | Type | Req | Description |
|---|---|---|---|
| dueAt | – | – | 截止时刻 ISO 8601,须含时区;null 清空,省略保留现值 |
| goalId | string | yes | – |
| intent | – | – | – |
| status | string | – | – |
| title | string | – | – |
No output schema declared.
No examples provided.
update_collaboration_task 更新合作任务内容或指派 ~160
【需要登录】更新任务标题、描述、截止;换被指派人需要指派权限且可能通知新负责人。权限由服务校验,省略保留,detail/dueAt=null 清空。状态用 set_collaboration_task_status。结果不明或超时后先查询现值,不要自动重发;服务没有持久请求去重键。 用 get_collaboration_goal 核对任务。
| Name | Type | Req | Description |
|---|---|---|---|
| assigneeId | string | – | – |
| detail | – | – | – |
| dueAt | – | – | 截止时刻 ISO 8601,须含时区;null 清空,省略保留现值 |
| taskId | string | yes | – |
| title | string | – | – |
No output schema declared.
No examples provided.
update_my_company 更新我的公司 ~262
【需要登录】更新当前用户名下的公司主页(按 ownerId upsert,所有字段可选但仍要满足 schema:传 slug/name 时格式校验)。先用 get_my_company 读现状。slug 被别人占用会报 slug_taken。 【发布】先过后审:立即生效,后台异步风控审计。
| Name | Type | Req | Description |
|---|---|---|---|
| description | – | – | 详细介绍:在做什么、为谁做、进展,越详细内容质量越高 |
| foundedYear | – | – | 成立年份,可选 |
| location | – | – | 所在地,可选 |
| logoUrl | – | – | Logo 图 URL,可选 |
| name | string | – | 公司 / 工作室名称 |
| size | – | – | 团队规模,可选:SOLO(一人公司) | SIZE_2_5(2-5 人) | SIZE_6_10(6-10 人) | SIZE_11_50(11-50 人) | SIZE_50_PLUS(50 人以上) |
| slug | string | – | 公司主页 URL 标识,小写字母/数字/连字符,全局唯一 |
| tagline | – | – | 一句话定位,可选 |
| websiteUrl | – | – | 官网 URL,可选 |
No output schema declared.
No examples provided.
update_my_product 更新我的产品 ~368
【需要登录】更新当前用户名下某个产品(仅本人可改)。先用 get_my_products 拿 productId。所有字段可选,只传想改的;links 传则整组替换。 【发布】先过后审:立即生效,后台异步做风控审计,不卡审核。**注意:编辑会把已下架(ARCHIVED)产品重新发布上架**——只想改内容不想上架的,改完再用 set_product_status 下架回去。
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | 产品分类,取值:SAAS(SaaS / 微 SaaS) | APP(App) | MINI_PROGRAM(小程序) | AI_AGENT(AI 工具 / 智能体 / 数字人) | DEV_TOOL(开发者工具 / API / 开源 / 插件) | GAME(独立游戏) | CONTENT(自媒体 / 播客 / 视频 / Newsletter) | DESIGN(设计 / 插画 / 创意) |… |
| coverUrl | – | – | – |
| description | string | – | – |
| gallery | array | – | – |
| links | array | – | 整组替换全部链接 |
| logoUrl | – | – | – |
| name | string | – | – |
| productId | string | yes | 产品 id(cuid),从 get_my_products 拿 |
| slug | string | – | – |
| tagline | string | – | – |
| tags | array | – | – |
No output schema declared.
No examples provided.
update_my_profile 更新我的资料 ~292
【需要登录】更新当前用户资料,立即生效(资料修改不走审核)。所有字段可选,只传想改的;links 传则整组替换(要增删单条用 add_profile_link / remove_profile_link 更方便)。建议先 get_my_profile 读现状再改。 【canOffer 是全站撮合的轴心】search_people 搜的就是它、需求信息流的 matchScore 按它算、get_need_recommendations 拿它给作者推人。留空 = 从撮合池里掉出去,谁也搜不到你。帮用户入驻/整理资料时**一定要顺手把它写上**,而且要写具体(「能给早期项目做 0→1 的小程序开发,两周内出可用版本」远胜「技术合作」)。
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | – | – | – |
| bio | – | – | 一句话简介 |
| canOffer | – | – | 我能提供什么(供给侧)。全站撮合的轴心字段:search_people 搜它、需求流的匹配分算它。写具体的能力/资源/交付物,别写形容词 |
| intro | – | – | 完整介绍 |
| links | array | – | 整组替换全部链接 |
| location | – | – | – |
| nickname | string | – | – |
No output schema declared.
No examples provided.
update_my_signup_profile 更新我的报名资料(跨表单复用层) ~285
【需要登录】【何时用】用户随口给了一条以后每场报名都要用的信息(「我微信是 xxx」「团队 3 个人」「所在城市杭州」),先落进跨表单复用的**报名资料覆盖层**,下次报任何一场都会自动带出来。 【组合链】get_signup_gaps 拿到 missingCombined(跨场去重后的待答清单)→ 问用户 → 本工具一次性写进覆盖层 → 之后每场 submit_signup 都不用再问。key 必须用 get_signup_activity / get_signup_gaps 返回的那个 key(跨活动稳定,别自造)。 【口径/坑】① 这里**只写报名场景的覆盖层**,绝不改主页/公司/产品本体——改那些走 update_my_profile。② 只收文本;文件类答案(BP 等)只能走 App 的上传通道,这里写进去会把已传文件的记录顶成一串文本。③ 敏感题(证件号)刻意不做跨表单记忆,别往这儿写。④ 写入的值不会回显在返回体里(只回 key),这是刻意的隐私收口。
| Name | Type | Req | Description |
|---|---|---|---|
| values | array | yes | – |
No output schema declared.
No examples provided.
update_need 编辑我的需求 ~216
【需要登录】编辑自己发布的需求(仅 OPEN 状态可改)。可改 类型 / 标题 / 详情 / 配图,只传想改的。先用 list_my_needs 拿 needId。 【失败语义】非本人 403 not_your_need;非 OPEN(已取消或历史遗留关单)409 need_closed。被接洽/被承接不改变需求状态,仍是 OPEN、仍可编辑。
| Name | Type | Req | Description |
|---|---|---|---|
| detail | – | – | – |
| images | array | – | – |
| needId | string | yes | 需求 id,从 list_my_needs 拿 |
| title | string | – | – |
| type | string | – | 需求类型:EXPERIENCE(寻找产品/作品) | QA(答疑求助) | RESOURCE(介绍资源) | COLLAB(寻求合作) | FINANCING(融资需求) | CHAT(找人聊聊找灵感) | GIG(兼职招募) | OTHER(其它) |
No output schema declared.
No examples provided.
update_organizer_signup_config 改这场的报名配置 ~668
【需要登录】【何时用】用户要改报名表的题目、换报名类目、贴外部表单地址、换答疑群二维码时调它。**立即生效,不留灰度闸**。 【组合链】get_organizer_activity(slug) 读现值 → 本工具传**要改的那几项**(缺省即不动)→ 再读一次确认。改完可以把 signupPageUrl 发给用户去转发。 【口径/坑】① **本工具改不了报名截止时间**——截止在活动本体上,改它走 update_activity。而且:**「截止绝不能提前封口」是这个产品的红线**,把截止改早会把此刻正在填表的人当场挡在外面,任何「提前收口」的请求都必须先跟用户确认清楚后果。② formSchema 是**整表覆盖**,不是打补丁:传了就以你这份为准,漏写的题会被删掉(而且进「不再学习」名单,客户端以后也不会把它学回来)。稳妥做法是先 get_organizer_activity 拿到现有 formSchema,改完整份传回来。③ hostedEnabled=true 而一道题都不给时,服务层会落基线四项(姓名/手机号/微信号/项目介绍),不会留一张空表。④ 投递通道(adapterKey/deliveryMode)是平台侧基建,主办方改不了,也不该改。⑤ 改 signupUrl 会让投递方式跟着重算(有外链→用户设备代填投递;纯托管→站内收)。
| Name | Type | Req | Description |
|---|---|---|---|
| activityRef | string | yes | 活动 slug 或活动 id |
| articleUrls | array | – | 活动图文/推文链接(整体覆盖) |
| contactNote | – | – | 报名成功页的一句话说明;传 null 清空 |
| contactQrUrl | – | – | 报名成功页的答疑/组队群二维码图 URL;传 null 清空 |
| formSchema | array | – | **整表覆盖**的题目表。不传=不动;传了就以这份为全集,漏写的题会被删掉。沿用现有题请把 get_organizer_activity 给你的那一项**原样带回来**(尤其 sensitive / sourceLabel 两个键,丢了会把加密题降级成明文、并让外部表单的自动填写失效) |
| hostedEnabled | boolean | – | 站内是否直接收报名 |
| kind | string | – | 报名类目。取值:HACKATHON(黑客松) | COMPETITION(创业赛事) | INCUBATOR(孵化营) | FUNDING(融资申请) | COMMUNITY(社区入驻) | EVENT(活动报名) | OTHER(其他) |
| signupUrl | – | – | 外部报名表单地址;传 null 清空(改回站内收报名) |
No output schema declared.
No examples provided.
upload_image_from_url 按 URL 上传图片 ~182
【需要登录】把一张公开可访问的图片 URL 镜像进独行录存储,返回稳定的图片地址。 【何时用】要给「我的头像 / 产品 logo / 产品封面 / 产品图集 / 活动封面」设图时:先用本工具把外部图片 URL 转成独行录地址,再把返回的 url 填进 update_my_profile(avatarUrl) / update_my_product(logoUrl·coverUrl·gallery) / create_product / create_organizer_activity(coverUrl·posterUrls)。 【限制】仅支持公网 http(s) 图片,带大小/类型/SSRF 校验。
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | – | 用途(决定存储分类),默认 avatar |
| sourceUrl | string | yes | 图片的公开 http(s) URL |
No output schema declared.
No examples provided.
What is the 独行录 / opcmenu MCP server?
独行录 / opcmenu is an MCP server listed in the public MCP registry as io.github.yzlee/opcmenu. Find founders, collaboration opportunities and events; manage authorized signups and messages. This page covers its hosted endpoint (https://mcp.opcmenu.com/mcp).
Is the 独行录 / opcmenu MCP server safe to use?
独行录 / opcmenu scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the 独行录 / opcmenu MCP server expose?
独行录 / opcmenu exposes 160 tools: search_products, list_products, get_product, list_creators, get_creator, and 155 more. Their descriptions and schemas cost roughly 34,548 tokens of context every time the server is loaded.
Does the 独行录 / opcmenu MCP server require authentication?
No. We connected to 独行录 / opcmenu without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the 独行录 / opcmenu MCP server still maintained?
独行录 / opcmenu is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.