Local x402-paying proxy and MCP server for openzoo.fun, enabling any OpenAI-compatible tool to pay for AI calls using a local burner wallet. It provides tools like zoo_ask for large-corpus questions, model listing, and wallet management.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
staccDOTsol
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
ANTHROPIC_API_KEYANTHROPIC_AUTH_TOKENOPENAI_API_KEYexport =sk-openzooOPENZOO_API_BASEOPENZOO_ASK_MAX_TOKENSOPENZOO_BALANCE_POLL_SECSOPENZOO_BASE_RPCOPENZOO_BIND_MAX_BYTESOPENZOO_BIND_PART_BYTESOPENZOO_CONTEXT_MIN_CHARSOpt out with OPENZOO_NO_CONTEXT_CACHE=1 (always ship the full body); tune the threshold with (default 16384 chars).OPENZOO_DEFAULT_MODELOPENZOO_DEMO_MAX_USD0.01 demo spend capOPENZOO_DEMO_MODELOPENZOO_DEMO_TOKENSOPENZOO_ENABLE_RH0 let default selection fall through to the Robinhood rail (OPENZOO_RAIL=robinhood forces it without this)OPENZOO_MAX_USD_PER_CALLthe per-call cap (, default $0.50) still applies;OPENZOO_MODELSOPENZOO_MODEL_LIMITOPENZOO_NO_CONTEXT_CACHEOpt out with =1 (always ship the full body); tune the threshold with OPENZOO_CONTEXT_MIN_CHARS (default 16384 chars).OPENZOO_PORT8402 proxy portOPENZOO_PROFILEOPENZOO_RAIL(unset) force a rail: solana \ base \ robinhood. Errors if the live 402 doesn't offer itOPENZOO_RH_RPCOPENZOO_RPCmainnet-beta public RPC Solana RPCOPENZOO_SUPPORTED_URLOPENZOO_TOKEN(internal) preferred 402 rail — leave unsetOPENZOO_TUNNEL_MAX_USDa session ceiling stops all spending at (default $1.00);OPENZOO_TUNNEL_STRICTOPENZOO_TUNNEL_TOKENPin the key with if your IDE stores it. Keys never leave your machine either way — the tunnel forwards to the same local proxy, which signs with the same local wallet.OPENZOO_WALLET~/.openzoo/wallet.json wallet pathTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
6/6 tools missing one or more hints — zoo_ask (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); zoo_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); zoo_models (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +3 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
Only 2/6 tool handlers declare input schemas (33%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool test coverage
Only 0/6 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
10 child_process/subprocess calls in production code — runs shell commands (lib/cursorcfg.js:37, lib/cursorcfg.js:50, lib/cursorcfg.js:73)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Secrets never reach shell commands
2 secret values passed to shell commands — possible command injection
Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.
Secrets not logged
7 secret values sent to console.log
Redact or omit secret values from log output.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/staccdotsol-openzoo-t8oh6a)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check