Mcp Rona — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Rona (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol server for RONA (rona.ca). It exposes RONA's catalogue — product search, product detail, online availability and a store finder — to MCP clients such as Claude and Cursor.
Unofficial. This project is not affiliated with, endorsed by, or sponsored by RONA inc. It reads publicly available endpoints of rona.ca for personal, noncommercial use. Respect RONA's terms of service and use responsibly.
| Tool | Description |
|---|---|
rona_search | Product search / listings by keyword. Returns products (SKU, name, brand, model, rating, category, URL, image), total count, facets and sort options. Keywords that map to a category page fall back to a best-effort product list. |
rona_product | Full product card by SKU: name, brand, model, description, image, rating, barcode, category path, URL and online availability. |
rona_store_availability | Online purchasability (inventory status) of a SKU. |
rona_stores | Find stores nearest a Canadian postal code (geocoded) or to latitude/longitude — id, name, banner, address, phone, coordinates, distance (km), time zone, URL and opening hours. |
rona_search| Param | Type | Default | Notes | |||||
|---|---|---|---|---|---|---|---|---|
query | string | — | Search keyword (required). | |||||
lang | en \ | fr | en | Language for facet labels. | ||||
sort | relevance \ | price-asc \ | price-desc \ | rating \ | newest \ | best-sellers | relevance | Sort order. |
page | int ≥ 1 | 1 | 1-indexed page. | |||||
pageSize | int (1–60) | 24 | Results per page. | |||||
brand | string | — | Filter by a brand facet value, e.g. DEWALT. |
rona_product| Param | Type | Default | Notes | |
|---|---|---|---|---|
sku | string | — | Product SKU / item number (required), e.g. 00277649. | |
lang | en \ | fr | en | Response language. |
rona_store_availability| Param | Type | Default | Notes | |
|---|---|---|---|---|
sku | string | — | Product SKU / item number (required). | |
lang | en \ | fr | en | Response language. |
rona_stores| Param | Type | Default | Notes | |
|---|---|---|---|---|
postalCode | string | — | Canadian postal code, e.g. M5V 2T6. Geocoded to coordinates. | |
latitude / longitude | number | — | Alternative to postalCode. | |
lang | en \ | fr | en | Language for store URLs. |
limit | int (1–50) | 10 | Max stores to return. |
The store locator geosorts by coordinates only, so a postal code is first geocoded via api.zippopotam.us (free, no key). Distance is reported by RONA's API, with a local haversine fallback.RONA does not expose unit prices or real-time per-store stock (quantities, aisle/bay) through its public APIs:
JavaScript challenge that a headless client cannot solve.
So price is reported as null, and availability is limited to online purchasability (Available / Unavailable). Search, product detail and the store finder are fully functional.
rona.ca is behind Cloudflare, which gates requests on both the HTTP version and the client's TLS (JA3) fingerprint. Node's native HTTP stack (fetch/undici) gets 403; only `curl --http2` is allowlisted, so every request shells out to curl. No cookies are required for the public endpoints used here.
| Surface | Host | Used for |
|---|---|---|
| Constructor.io | tvbajuset-zone.cnstrc.com | search, product lookup |
| App API (BFF) | www.rona.ca/v2/api | store finder |
| WebSphere Commerce REST | www.rona.ca/wcs | online availability |
Requirement: curl with HTTP/2 support must be on PATH (standard on macOS and most Linux distros).
npm install
npm run build
npm start # runs the MCP server on stdioQuick smoke test of the search layer:
node --input-type=module -e 'import {search} from "./dist/search.js"; console.log(await search({query:"drill", pageSize:3}))'Inspect with the MCP Inspector:
npm run inspectAdd to your MCP client config (e.g. Claude Desktop claude_desktop_config.json), pointing at the built entrypoint:
{
"mcpServers": {
"rona": {
"command": "node",
"args": ["/absolute/path/to/mcp_rona/dist/index.js"]
}
}
}src/
index.ts MCP server + tool registration (stdio)
rona.ts curl --http2 transport for rona.ca + Constructor.io
search.ts rona_search (Constructor.io search + category-redirect fallback)
product.ts rona_product + rona_store_availability (catalogue + WCS availability)
stores.ts rona_stores (postal-code geocode → store locator)PolyForm Noncommercial License 1.0.0 — free to use, modify and share for noncommercial purposes. Commercial use requires a separate license from the author.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.