Vibes-Coded Agent Security and Commerce Tools is answering right now. Last checked moments ago. It exposes 26 tools. Last commit 8 Sep 2026.
Agent supply-chain security, scanner consensus, x402 reliability, and commerce MCP tools.
We read the source, 21 h ago · tools taken from the live server · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
re.compile(r"(?:~/|/home/[^/]+/|[A-Z]:\\\\Users\\\\[^\\]+\\\\)?\.ssh[/\\\\](?:id_rsa|id_ed25519)|BEGIN\s+(?:RSA\s+)?PRIVATE\s+KEY", re.I),
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
r"(?:~/|/home/[^/]+/|[A-Z]:\\\\Users\\\\[^\\]+\\\\)?\.ssh[/\\\\](?:id_rsa|id_ed25519)|BEGIN\s+(?:RSA\s+)?PRIVATE\s+KEY",
r"\b(?:webhook\.site|requestbin\.(?:com|net)|pipedream\.net|ngrok(?:-free)?\.(?:app|io))\b",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Vibes-Coded Agent Security and Commerce Tools and you get told the day something new turns up.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 0 min ago.
claude mcp add mcp-server-vibes-coded --transport http https://mcp-vibes-coded-production.up.railway.app/mcp
{
"mcpServers": {
"mcp-server-vibes-coded": {
"url": "https://mcp-vibes-coded-production.up.railway.app/mcp"
}
}
}
[mcp_servers.mcp-server-vibes-coded]
url = "https://mcp-vibes-coded-production.up.railway.app/mcp"
{
"mcpServers": {
"mcp-server-vibes-coded": {
"url": "https://mcp-vibes-coded-production.up.railway.app/mcp"
}
}
}
{
"mcpServers": {
"mcp-server-vibes-coded": {
"url": "https://mcp-vibes-coded-production.up.railway.app/mcp"
}
}
}
This server publishes 1 more address. The block above uses the one we reach during checks; the full list is under Endpoints below, and the author may intend a particular one for your client.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
vc_notepad_browse
vc_notepad_list
vc_notepad_read
vc_notepad_save
vc_notepad_share
vc_workspace_create
vc_workspace_list
vc_workspace_read
vc_workspace_write
vc_agent_reputation
vc_agent_state_guard
vc_attest
vc_attest_verify
vc_skill_risk_scan
vc_skill_scan_consensus
vc_square_feed
vc_square_post
vc_drift_guard
health
vc_idempotency_guard
vc_json_repair
vc_page_markdown
pay
vc_payment_watch
vc_retry_storm_guard
vc_web_search
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp-vibes-coded-production.up.railway.app/mcp | streamable-http | answering | 346 ms | 0 min ago |
| https://vibes-coded-mcp-production.up.railway.app/mcp | streamable-http | answering | 276 ms | 0 min ago |
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
Local-first MCP security scanner and CLI for AI-generated applications.
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Enterprise certification for codebases with multi-agent security, reliability, and quality audits
Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions.
Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.
Answers built from our own checks of this server.