.codex-plugin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .codex-plugin (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center"> <h1>@cyanheads/coingecko-mcp-server</h1> <p><b>Market data for 15,000+ cryptocurrencies — prices, history, trends, and deep coin metadata via CoinGecko.</b> <div>8 Tools • 2 Resources • 1 Prompt</div> </p> </div>
<div align="center">
</div>
<div align="center">
</div>
<div align="center">
Keyless by default · runs locally. No API key required — an optional CoinGecko Demo key raises the rate ceiling. Runs as a local stdio/HTTP server; there is no public hosted instance, since CoinGecko's terms do not permit redistributing their data. Data provided by CoinGecko.
</div>
Eight tools covering the crypto market-data spine — slug resolution first, then prices, ranked markets, deep coin profiles, historical series, trending, and global macro stats. CoinGecko keys all data by slug (bitcoin, ethereum), not ticker (BTC, ETH), so coingecko_search_coins is the entry point that feeds every ID-keyed tool.
| Tool | Description |
|---|---|
coingecko_search_coins | Resolve a coin name or ticker symbol to a CoinGecko ID (slug). The required first step before any ID-keyed tool. |
coingecko_get_prices | Current price and core market stats for one or more coins in one or more currencies. Batch up to 250 slugs; reports unresolved ids in a missing field. |
coingecko_list_markets | Ranked market table — top coins by market cap, volume, or 24h change, optionally filtered to a category. |
coingecko_get_coin | Deep single-coin profile — description, links, market data, developer activity, community, sentiment. sections trims the large record. |
coingecko_get_market_chart | Historical price, market cap, and volume series. recent (last N days, auto-granularity) or range (explicit Unix-second window) mode. |
coingecko_get_trending | Coins trending on CoinGecko in the last 24 hours, by search volume. |
coingecko_get_global | Global crypto market snapshot — total market cap and volume, BTC/ETH dominance, active counts, ongoing ICOs, 24h change. |
coingecko_list_categories | Coin categories (category_id + display name) — the valid slugs for coingecko_list_markets's category filter. |
coingecko_search_coinsResolve a name or ticker to the CoinGecko slug every other tool keys on.
ETH/USDC) — returns ranked candidates with id, symbol, name, and market_cap_rank to disambiguatecoingecko_get_pricesCurrent price and core market stats (market cap, 24h volume, 24h change) for a batch of coins in a batch of currencies.
(id, currency) that returned a price200 upstream rather than an error; this tool diffs requested-vs-returned ids and lists the gaps in a missing field, so a typo reads as "unresolved", not "nonexistent"all_missing only when no requested id resolvedcoingecko_list_marketsThe entry point for "top 20 DeFi coins" or "biggest gainers today".
category_id from coingecko_list_categoriespage and per_page (up to 250 rows); discloses when a page is fullunknown_categorycoingecko_get_coinThe full picture for "tell me everything about Ethereum".
profile, market, links, developer, community, sentiment; pass sections to fetch only what you need (the full record is large)vs_currencycategories here are display names (e.g. "Layer 1 (L1)"), distinct from the category_id slugs returned by coingecko_list_categoriescoingecko_get_market_chartHistorical series for trend and charting questions (use coingecko_get_prices for the current snapshot).
recent mode: last N days, with granularity auto-scaling by span (≤1 day → ~5-min, 2–90 → hourly, >90 → daily); pass days (or "max")range mode: an explicit window via from/to as Unix secondscoingecko_get_prices last-updated is in seconds)coingecko_get_trendingA heartbeat for "what's hot in crypto right now". No parameters.
| Type | Name | Description |
|---|---|---|
| Resource | coingecko://coin/{id} | Deep coin record by slug — same data as coingecko_get_coin (full record, USD market figures). |
| Resource | coingecko://global | Global crypto market snapshot — same data as coingecko_get_global. |
| Prompt | coingecko_coin_research | Guides a full single-coin research pass through the search → get_coin → get_market_chart → get_global chain. |
All resource data is also reachable via tools — the resources mirror coingecko_get_coin and coingecko_get_global exactly, so tool-only clients lose nothing. Large collections (markets, categories) are not exposed as resources; use coingecko_list_markets and coingecko_list_categories instead.
Built on @cyanheads/mcp-ts-core:
none, jwt, oauthin-memory, filesystem, Supabase, Cloudflare KV/R2/D1CoinGecko-specific:
x-cg-demo-api-key) raises the rate ceiling with no other config changeRetry-After is honoredcoin_not_found, 429 → rate_limited, the /simple/price silent miss handled as a missing field, not an error)Agent-friendly output:
coingecko_search_coinscoingecko_get_prices reports unresolved ids and dropped currencies instead of failing; truncation and applied filters are disclosed via enrichmentAdd the following to your MCP client configuration file. No API key is required — set COINGECKO_API_KEY only to attach the higher CoinGecko Demo tier (see Configuration).
{
"mcpServers": {
"coingecko-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/coingecko-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"coingecko-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/coingecko-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"coingecko-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/coingecko-mcp-server:latest"
]
}
}
}To attach a CoinGecko Demo key, add "COINGECKO_API_KEY": "your-demo-key" to the env block (or -e COINGECKO_API_KEY=your-demo-key for Docker).
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpRefer to "your MCP client configuration file" generically — different clients use different config paths and this server isn't client-specific.
git clone https://github.com/cyanheads/coingecko-mcp-server.gitcd coingecko-mcp-serverbun installcp .env.example .env
# the server runs with no .env at all; edit only to set COINGECKO_API_KEYThe server runs with zero configuration. The one server-specific variable is optional:
| Variable | Description | Default |
|---|---|---|
COINGECKO_API_KEY | Optional CoinGecko Demo API key. When set, it is sent as the x-cg-demo-api-key header for the dedicated Demo tier (10k/mo, 100 req/min); the base URL is unchanged. Absent → keyless public tier (shared, IP-throttled). | — |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for the HTTP server. | 3010 |
MCP_HTTP_ENDPOINT_PATH | HTTP endpoint path. | /mcp |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
LOGS_DIR | Directory for log files (Node.js only). | <project-root>/logs |
STORAGE_PROVIDER_TYPE | Storage backend. | in-memory |
OTEL_ENABLED | Enable OpenTelemetry instrumentation (spans, metrics, completion logs). | false |
See .env.example for the full list of optional overrides.
Rate limits and freshness. The keyless public tier shares an IP-throttled pool, so bursty multi-tool workflows can hit 429s under light load; the server backs off and retries, but cannot raise the ceiling — a free Demo key does. CoinGecko data refreshes roughly every 60 seconds and is not tick-level.
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against specdocker build -t coingecko-mcp-server .
docker run --rm -e MCP_TRANSPORT_TYPE=http -p 3010:3010 coingecko-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/coingecko-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools/resources/prompts and inits the CoinGecko service. |
src/config | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools | Tool definitions (*.tool.ts). |
src/mcp-server/resources | Resource definitions (*.resource.ts). |
src/mcp-server/prompts | Prompt definitions (*.prompt.ts). |
src/services/coingecko | CoinGecko v3 REST API service — HTTP client, retry/error mapping, response normalization, domain types. |
tests/ | Unit and integration tests mirroring src/. |
See CLAUDE.md/AGENTS.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagecreateApp() arrays in src/index.tsIssues and pull requests are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testApache-2.0 — see LICENSE for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.