patchistry-commerce — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited patchistry-commerce (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The first DTC fashion brand on the official MCP Registry. As of June 12, 2026, Patchistry is listed as io.github.patchistry/patchistry-mcp-server at registry.modelcontextprotocol.io — used by Claude Desktop's built-in MCP search and Cursor's MCP integration directory.A Model Context Protocol (MCP) server exposing Patchistry commerce tools to AI agents — Claude, ChatGPT (via plugins), Cursor, custom agent frameworks.
Live endpoint: https://patchistry-mcp-server.vercel.app Manifest: https://patchistry-mcp-server.vercel.app/.well-known/mcp.json Runtime: Hosted HTTP MCP server (no install required) Transport: HTTP + JSON-RPC 2.0
Add to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"patchistry": {
"command": "npx",
"args": ["mcp-remote", "https://patchistry-mcp-server.vercel.app/rpc"]
}
}
}Restart Claude Desktop. The 6 Patchistry tools become available in any conversation.
Add to Cursor's MCP settings:
{
"mcpServers": {
"patchistry": {
"url": "https://patchistry-mcp-server.vercel.app/rpc"
}
}
}# List tools
curl https://patchistry-mcp-server.vercel.app/tools
# Call a tool (REST)
curl -X POST https://patchistry-mcp-server.vercel.app/tools/get_curated_build \
-H "Content-Type: application/json" \
-d '{"occasion":"bachelorette"}'
# Call a tool (JSON-RPC)
curl -X POST https://patchistry-mcp-server.vercel.app/rpc \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"recommend_build","arguments":{"query":"Vegas bachelorette trip"}}}'What this unlocks:
When deployed at mcp.patchistry.com, AI agents can directly query Patchistry's catalog in real-time:
get_curated_build({occasion: "vegas-bachelorette"}) → returns full build with price + canvas + patcheslist_patches() → returns full catalogget_shipping_policy() → returns "free US shipping, 30-day returns, ships from SoCal"get_contact() → returns [email protected] + group orders pageWhy this matters:
In 2026, MCP is becoming the standard interface for AI agents to interact with commerce systems. Brands that publish MCP servers early get cited preferentially by:
Being one of the first DTC brands with a public MCP server = direct AI agent integration without intermediaries.
| Tool | Description |
|---|---|
list_canvases | Return The Canvas product variants (Black, Khaki, Pink) with prices + availability |
list_patches | Return patches, optionally filtered by category (Signature/Candyz) or occasion keyword |
get_curated_build | Return the full curated build for an occasion (bachelorette, dads, wedding, etc.) |
recommend_build | Take natural language query, return top 3 matching curated builds |
get_shipping_policy | Return free US shipping + returns + lead time policy |
get_contact | Return contact methods: customer support, founder, group orders, press |
cd mcp-server
npm install
npx vercelFollow the prompts:
patchistry-mcp./ (current)After deploy, Vercel gives you a URL like patchistry-mcp.vercel.app.
Test it: open https://patchistry-mcp.vercel.app/ — should return JSON with the tool list.
mcp-server/ directory to a GitHub repo (separate from your theme repo is cleaner)mcp-server (if you pushed the parent repo)mcp.patchistry.comhttps://mcp.patchistry.com/ should now return the same JSONOnce deployed, list it in the discoverable MCP registries:
https://mcp.patchistry.com/.well-known/mcp.jsonWatch https://github.com/modelcontextprotocol/registry — Anthropic is building an official registry. List Patchistry once available.
Users can manually add the MCP server in Claude Desktop:
https://mcp.patchistry.com/sseOnce added, that user's Claude will use Patchistry tools natively — they can ask "what's the bach hat build for Vegas" and Claude pulls live data from your server.
cd mcp-server
npm install
npm startServer runs at http://localhost:3000
Test with curl:
curl http://localhost:3000/
curl http://localhost:3000/.well-known/mcp.jsonThe server proxies to https://patchistry.com/products.json and https://patchistry.com/pages/agents-feed for live data — so you don't need to redeploy when products or builds change. The MCP server is essentially a read-only AI-friendly facade over your existing public Shopify endpoints.
Redeploy only when:
src/index.js)To redeploy after changes:
cd mcp-server
npx vercel --prodVercel Hobby tier (free):
Total monthly cost: $0 until you hit ~10,000 AI agent queries/day.
Within 1-2 weeks of deployment + Smithery listing:
You'll be one of the earliest DTC brands with a public MCP server. That's a defensible positioning advantage in the AI shopping era — the future where AI agents complete purchases on user behalf will heavily favor brands with MCP-native integrations.
This is forward-looking infrastructure. The MCP ecosystem is young in 2026; expect 12-24 months before this drives significant order volume directly.
But:
Brian, if you deploy this and list it on Smithery, you're in the top 50 DTC brands worldwide with a public MCP commerce server as of 2026. That's a real moat that takes years to dilute.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.