Mcp Commerce — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Commerce (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Reference Model Context Protocol (MCP) server for K-product cross-border commerce — five canonical tools that every agent-ready storefront should expose.
| # | Tool | Purpose |
|---|---|---|
| 1 | search_product | Keyword / category / price / locale search across the K-product catalog |
| 2 | get_product | Fetch a single SKU's full detail (i18n title/description, HS code, ship-from, lead time) |
| 3 | create_cart | Build cart with destination — returns itemized quote (subtotal + shipping + duty + import tax) |
| 4 | quote_checkout | Re-quote cart immediately before checkout (refresh FX/duty), returns canonical CartMandate VC |
| 5 | submit_intent | Submit AP2 IntentMandate VC + signed CartMandate, returns checkout URL + signed PaymentMandate |
Canonical 5-tool surface per the Semore MCP commerce spec. Production Semore MCP server runs at <https://mcp.semore.net>. This OSS package ships schemas + reference handlers so merchants can validate integrations locally.
npm install @semore/mcp-commerce zod// Claude Desktop config — `claude_desktop_config.json`
{
"mcpServers": {
"semore": {
"command": "npx",
"args": ["-y", "@semore/mcp-commerce"]
}
}
}Or discover via the official MCP Registry:
curl "https://registry.modelcontextprotocol.io/v0/servers?search=semore"
# → io.github.semorehq/[email protected]import { searchProductTool } from "@semore/mcp-commerce/tools/search-product";
const parsed = searchProductTool.inputSchema.parse({
q: "sunscreen",
lang: "en",
category: "kbeauty",
limit: 10,
});
const result = await searchProductTool.handler(parsed);import { createMcpServer } from "@semore/mcp-commerce";
const server = createMcpServer({
// Wire your own catalog / cart / order resolvers here.
// Default skeleton resolvers return deterministic fixtures useful for local tests.
});
// Then expose over your preferred transport (stdio, streamable-http, SSE).| Adapter | Spec | Status |
|---|---|---|
| @semore/acp-adapter | ACP (Stripe / PayPal) | LIVE |
| @semore/ap2-adapter | AP2 (Google) — IntentMandate / CartMandate / PaymentMandate VC | LIVE |
| @semore/ucp-adapter | UCP (Google + Shopify) | LIVE |
| Visa TAP / MC Agent Pay | Network agentic standards | Phase 1 (signup) |
did:web:semore.net Ed25519 mandate signing (4-party card model preserved)/ucp/capability endpoint advertises commerce.search/commerce.cart/commerce.checkout[email protected] · GitHub @semorehqApache-2.0 — see LICENSE.
Copyright (c) Semore Founding Team.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.