F

mcp.usecoal.xyz

https://mcp.usecoal.xyz/api/mcp
45/100 · MCP Trust Grade · checked 4h ago · MCP 2025-03-26
Watched since 2026-06-03 — behavioral baseline locked. We re-check this server's tool surface on a schedule; if it adds, removes, or silently rewrites a tool (rug-pull), we record it.

What it offers — 13 tools · Developer Tools

discover_merchants

THE DEFAULT FIRST CALL whenever the user wants to buy, get, fetch, grab, order, purchase, shop for, find, or browse anything (digital goods, ebooks, A

search_products

Search products across all Coal merchants. Filter by name, max price, or tag. Returns a Markdown product grid with images. Use this when looking for s

get_merchant_profile

Get the full profile of a Coal merchant including products (with images), paywalls, supported networks/tokens, and 0G Storage proof. Returns rendered

query_merchant_memory

Ask a natural language question about a merchant's products, policies, or catalog. Powered by 0G Compute with Sealed Inference (TEE). Needs a Coal API

check_paywall

Check whether an address has paid for a specific x402 paywall. Returns pricing info if not paid, or content access status if paid.

create_checkout

Create a Coal checkout session to pay for a product or amount. Settles in USDC on Base (~2s). Returns a checkout URL. Needs a Coal API key — set once

get_checkout_status

Check the payment status of a checkout session: pending, verifying, confirmed, expired, failed.

verify_receipt

Verify a payment receipt and see its 3-step proof trail: (1) Base TX, (2) 0G Storage receipt, (3) 0G Chain anchor.

get_0g_health

Check the live status of all 5 0G components: Storage, Chain, Compute, KV, DA.

agent_wallet_status

Check the USDC balance for your agent wallet (or any address). If `X-Coal-Agent-Key` is set in your Claude config header, this auto-resolves your wall

pay_merchant

Send USDC on Base to any merchant payout address (the `payoutAddress` field shown by discover_merchants — NOT the merchantId). Use this whenever the u

download_product

Retrieve / download / get the file for a digital product after the user paid for it. Use after `pay_merchant` succeeds for digital goods (PDFs, ebooks

setup_instructions

Print step-by-step instructions for using Coal MCP from Claude / Cursor / any MCP client. Run this FIRST if you are unsure how to authenticate or whic

Spec conformance20%100
Security (OWASP MCP)30%10
Reliability / performance20%92
Tool hygiene15%66
Transparency / provenance15%70

Observed behavior

No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.

Findings

FAILMCP08 Tool "agent_wallet_status" references sensitive file paths / secrets (exfiltration surface).
FAILMCP08 Tool "pay_merchant" references sensitive file paths / secrets (exfiltration surface).
Grade another server

We re-grade mcp.usecoal.xyz on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.

Share this report card

A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.

MCP Trust report card — mcp.usecoal.xyz grade F
Share on X Open card image

Embed this grade

A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.

MCP Trust Grade F · wmcp.sh
[![MCP Trust Grade F](https://wmcp.sh/mcp/grade/mcp.usecoal.xyz/badge.svg)](https://wmcp.sh/mcp/grade/mcp.usecoal.xyz)
<a href="https://wmcp.sh/mcp/grade/mcp.usecoal.xyz"><img src="https://wmcp.sh/mcp/grade/mcp.usecoal.xyz/badge.svg" alt="MCP Trust Grade F · wmcp.sh"></a>

Agents: check this before connecting

Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:

https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.