io.github.ZlaylowZ/nukez-mcp

MCPcomunidaden línea
v1.3.0io.github.ZlaylowZUnknownActualizado hace 2 m

Agent-native storage with cryptographic verification on Solana. Keyless: clients sign and pay.

Estado del endpointen línea
comprobado hace 1 día · 203 ms
83 % de las últimas 6 comprobaciones llegaron a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
hace 2 mÚltima actualización
Paquete
Autorio.github.ZlaylowZ
LicenciaUnknown
Versión1.3.0
Fuentemcp-registry
Estado de confianza
D
30/100Riesgo
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/30
→ Publicador: este listado no tiene ningún repositorio registrado, así que `forge publish` no puede verificar la propiedad de forma automática. Usa «Reclamar este listado» arriba — en Forge lo revisamos a mano.
—Verificación de dominio+0/10
→ Ahora mismo no está disponible para este tipo de listado: hoy la comprobación de dominio solo se ejecuta para paquetes publicados en npm, así que esta fila todavía no se puede conseguir aquí, sea lo que sea lo que haya alojado en el dominio.
—Análisis de inyección de prompts · con hallazgos+0/30
→ Publicador: elimina del código las instrucciones dirigidas a clientes de IA en lugar de a lectores humanos
✓Análisis de ofuscación / exfiltración · limpio+20/20
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
DependenciasSin auditar
Superficie de herramientas15 herramientas · 2 privilegiadas
Análisis de seguridad⚠ Avisos (2)vlive · hace 13 d¿Qué tan bien funciona este análisis?
PROMPTtool:nukez_quoteExfiltration-shaped instruction
PROMPTtool:nukez_storeExfiltration-shaped instruction
EvaluacionesNinguna
Indexado11 ago 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

15 herramientas · 2 privilegiadas · 2 marcadas por inyección
Observado en vivo desde el endpoint del proveedor13d ago

Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.

  • https://mcp.nukez.xyz/mcp15 herramientas · 480 ms
nukez_quoteriesgo de inyecciónStep 1: Get storage pricing and payment options. Returns price breakdown and every available payment method (SOL/USDC/USDT/WETH/BETA on Solana, USDC/USDT0/MON/WETH on Monad). Each option carries a `destination_kind`: 'wallet' (native SOL — send lamports to pay_to_address), 'spl_token_account' (Sola…

Step 1: Get storage pricing and payment options. Returns price breakdown and every available payment method (SOL/USDC/USDT/WETH/BETA on Solana, USDC/USDT0/MON/WETH on Monad). Each option carries a `destination_kind`: 'wallet' (native SOL — send lamports to pay_to_address), 'spl_token_account' (Sola…

INYECCIÓNExfiltration-shaped instructiont), or 'evm_address' (Monad — send native value to the address, or call transfer() on the token contract at token_addres…
ParámetroTipoDescripción
unitsinteger—
providerstring—
pay_network——
pay_asset——
nukez_payStep 2: Record an externally-executed on-chain payment. The server is keyless and never signs transactions — execute the transfer yourself (Solana sendTransaction or an EVM client) and pass the resulting signature as tx_sig. Uses pay_req_id from nukez_quote (auto-resolved from state). Specify chain…

Step 2: Record an externally-executed on-chain payment. The server is keyless and never signs transactions — execute the transfer yourself (Solana sendTransaction or an EVM client) and pass the resulting signature as tx_sig. Uses pay_req_id from nukez_quote (auto-resolved from state). Specify chain…

ParámetroTipoDescripción
pay_req_id——
tx_sig——
chain——
pay_asset——
nukez_provisionStep 3: Confirm payment settlement on the gateway and provision the storage locker. Two modes: (a) Without `envelope`: pass pay_req_id + tx_sig (auto-resolved from state). Returns the receipt_id and a hint to build a signed `locker:provision` envelope. (b) With `receipt_id` + `envelope`: forwards t…

Step 3: Confirm payment settlement on the gateway and provision the storage locker. Two modes: (a) Without `envelope`: pass pay_req_id + tx_sig (auto-resolved from state). Returns the receipt_id and a hint to build a signed `locker:provision` envelope. (b) With `receipt_id` + `envelope`: forwards t…

ParámetroTipoDescripción
pay_req_id——
tx_sig——
chain——
pay_asset——
receipt_id——
envelope——
nukez_setupSet up Nukez storage: checks wallet, purchases storage, and provisions locker in a single call. Call with no args to run the full flow. Call with receipt_id to rehydrate an existing locker. Providers: gcs (default), mongodb, storj, arweave, filecoin, firestore. Payments: Solana (SOL, USDC, USDT, WE…

Set up Nukez storage: checks wallet, purchases storage, and provisions locker in a single call. Call with no args to run the full flow. Call with receipt_id to rehydrate an existing locker. Providers: gcs (default), mongodb, storj, arweave, filecoin, firestore. Payments: Solana (SOL, USDC, USDT, WE…

ParámetroTipoDescripción
receipt_id——
unitsinteger—
providerstring—
envelope——
nukez_create_fileCreate a file entry and get upload_url + confirm_url for direct upload. The client PUTs raw bytes directly to the upload_url (307-redirects to GCS), then calls nukez_confirm to finalize. Bytes never transit the MCP server. Use this for large files from local/external sources against Cloud Run. For…

Create a file entry and get upload_url + confirm_url for direct upload. The client PUTs raw bytes directly to the upload_url (307-redirects to GCS), then calls nukez_confirm to finalize. Bytes never transit the MCP server. Use this for large files from local/external sources against Cloud Run. For…

ParámetroTipoDescripción
filename*string—
content_type——
receipt_id——
envelope——
nukez_storeriesgo de inyecciónStore files in your Nukez locker. ALWAYS BATCH: pass ALL the files you want to upload in a SINGLE call, as a list under `files`. Do NOT loop over your file list and call nukez_store once per file — that triggers one on-chain attestation per file (slow + costs SOL fees per push). One nukez_store cal…

Store files in your Nukez locker. ALWAYS BATCH: pass ALL the files you want to upload in a SINGLE call, as a list under `files`. Do NOT loop over your file list and call nukez_store once per file — that triggers one on-chain attestation per file (slow + costs SOL fees per push). One nukez_store cal…

INYECCIÓNExfiltration-shaped instructionncode files >4KB in one call. Upload path is auto-selected based on size and runtime environment. HARD SIZE LIMITS per…
ParámetroTipoDescripción
files*array—
receipt_id——
envelope——
nukez_confirmConfirm a file upload after sandbox curl completes. Call this after executing the curl command returned by nukez_store in sandbox mode. The server computes SHA-256 and records the hash. Requires a payer-signed locker:write envelope: signer-mode deployments sign automatically via the SDK; keyless cl…

Confirm a file upload after sandbox curl completes. Call this after executing the curl command returned by nukez_store in sandbox mode. The server computes SHA-256 and records the hash. Requires a payer-signed locker:write envelope: signer-mode deployments sign automatically via the SDK; keyless cl…

ParámetroTipoDescripción
filename——
receipt_id——
envelope——
use_jobboolean—
job_id——
nukez_upload_chunkprivilegiadaUpload a file in chunks when sandbox curl/network is blocked. PREPARATION — run this bash script first to split and hash: python3 -c " import base64, hashlib, os, json, math path = '<SANDBOX_FILE_PATH>' CHUNK = 4096 size = os.path.getsize(path) n = math.ceil(size / CHUNK) os.makedirs('/tmp/nkz', e…

Upload a file in chunks when sandbox curl/network is blocked. PREPARATION — run this bash script first to split and hash: python3 -c " import base64, hashlib, os, json, math path = '<SANDBOX_FILE_PATH>' CHUNK = 4096 size = os.path.getsize(path) n = math.ceil(size / CHUNK) os.makedirs('/tmp/nkz', e…

ParámetroTipoDescripción
filename*string—
data_b64*string—
part_no*integer—
is_lastboolean—
content_type——
receipt_id——
sha256——
job_id——
file_id——
nukez_retrieveList files or download content from your Nukez locker. Call with no filenames to list all files. Call with filenames=['file.txt'] to download specific files. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact list spec to sign (locker:list, pl…

List files or download content from your Nukez locker. Call with no filenames to list all files. Call with filenames=['file.txt'] to download specific files. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact list spec to sign (locker:list, pl…

ParámetroTipoDescripción
filenames——
receipt_id——
encodingstring—
envelope——
nukez_verifyFast structural verification of locker state. Returns merkle root, attestation status, and optional per-file proof. Pass memory_key to verify a specific memory record by key. Cheap: reads the persisted attestation; latency is independent of locker size (~sub-second typical). With push=True, also tr…

Fast structural verification of locker state. Returns merkle root, attestation status, and optional per-file proof. Pass memory_key to verify a specific memory record by key. Cheap: reads the persisted attestation; latency is independent of locker size (~sub-second typical). With push=True, also tr…

ParámetroTipoDescripción
pushboolean—
receipt_id——
filename——
memory_key——
envelope——
nukez_recompute_verifyByte-level integrity proof: re-downloads every file from storage, recomputes content hashes, rebuilds the merkle tree, and compares the result against the persisted attestation. Returns match=True when storage bytes still match the recorded hashes, match=False when they have drifted. Cost: scales w…

Byte-level integrity proof: re-downloads every file from storage, recomputes content hashes, rebuilds the merkle tree, and compares the result against the persisted attestation. Returns match=True when storage bytes still match the recorded hashes, match=False when they have drifted. Cost: scales w…

ParámetroTipoDescripción
receipt_id——
envelope——
nukez_statusCheck wallet balance, locker state, and lifecycle stage. Works at any stage — no active locker required.

Check wallet balance, locker state, and lifecycle stage. Works at any stage — no active locker required.

ParámetroTipoDescripción
receipt_id——
envelope——
nukez_deleteprivilegiadaDelete files from your Nukez locker. WARNING: permanent and irreversible. Invalidates existing attestation. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact delete spec to sign (locker:write, bound to one file's path); sign it with your wall…

Delete files from your Nukez locker. WARNING: permanent and irreversible. Invalidates existing attestation. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact delete spec to sign (locker:write, bound to one file's path); sign it with your wall…

ParámetroTipoDescripción
filenames*array—
receipt_id——
envelope——
nukez_rememberStore a structured memory record in your Nukez locker. Memories are indexed for fast search via nukez_recall. Use namespaces to organize (e.g., 'config', 'context', 'decisions'). Requires: key, content, summary. ENVELOPE: pass a list of 2 envelopes (each with unique nonce, POST path, ops=locker:wri…

Store a structured memory record in your Nukez locker. Memories are indexed for fast search via nukez_recall. Use namespaces to organize (e.g., 'config', 'context', 'decisions'). Requires: key, content, summary. ENVELOPE: pass a list of 2 envelopes (each with unique nonce, POST path, ops=locker:wri…

ParámetroTipoDescripción
key*string—
content*string—
summary*string—
namespacestring—
tagsstring—
supersedesstring—
receipt_id——
envelope——
nukez_recallSearch and retrieve memory records from your Nukez locker. Two modes: exact key lookup (pass key) returns full content + proof, or search (pass namespace/tags/query/prefix) returns matching index entries. ENVELOPE: none needed — both index and record are read via the public receipt-proxy URL. Just…

Search and retrieve memory records from your Nukez locker. Two modes: exact key lookup (pass key) returns full content + proof, or search (pass namespace/tags/query/prefix) returns matching index entries. ENVELOPE: none needed — both index and record are read via the public receipt-proxy URL. Just…

ParámetroTipoDescripción
keystring—
namespacestring—
tagsstring—
querystring—
prefixstring—
limitinteger—
receipt_id——
envelope——

15 de 15 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Agent-native storage with cryptographic verification on Solana. Keyless: clients sign and pay.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.