# ai.searchshop/apostleman

Search, compare, and buy Apostle men's skincare: tinted moisturizer, face wash, and sets.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.2
- **Author:** ai.searchshop
- **License:** Unknown
- **Endpoints:** streamable-http https://searchshopai-mcp.fly.dev/mcp/apostleman
- **Source:** https://apostleman.co
- **Endpoint health:** reachable (last checked 2026-09-23T00:28:44.953Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 10 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-13T16:37:30.849Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `create_checkout` tool: Links to undeclared domain: laluer.com

## Tools

14 declared. Observed from a live `tools/list` probe.
- `shop` — Start here for any shopping request. Pass the shopper's COMPLETE request in their own words and this tool will understand it and route to the right capability (
- `skincare_recommend` — (Deprecated: use 'recommend' instead. Works identically.) Get a personalized Apostle product recommendation with ingredient-aware scoring, safety notes, and rou
- `recommend` — Get a personalized product recommendation with domain-expert scoring, safety notes, and transaction authority. Use when the user wants advice, has a concern, or
- `skincare_cart` — Create a buyable shopping cart with a real checkout URL. Two modes: (1) Pass 'products' array with specific product names. (2) Pass 'query' string to auto-recom
- `skincare_report_issue` — Report when a tool result was unhelpful, incomplete, or wrong. Call this whenever you override a recommendation, skip a cart result, or notice the engine output
- `search_research_notes` — Search SearchShopAI's Research Notes blog — data studies, playbooks, and field notes on agentic commerce (AI attribution, MCP, AI catalog accuracy, ChatGPT ads)
- `get_research_note` — Get the summary and URL of a specific SearchShopAI Research Note by its slug (returned by search_research_notes).
- `search_products` — Browse and search the product catalog. Use when the user wants to see what's available, look up specific products, browse by category, compare options, or asks 
- `get_product` — Get full details for a specific product by SKU or title. Use when the user asks about a specific product by name (e.g. 'tell me about MIRA', 'show me the serum'
- `compare_products` — Compare two or more products side by side. Use when the user asks to compare, says 'X vs Y', or wants to decide between options. Do not use for single product l
- `create_checkout` — Create a checkout URL for one or more products. Pass variant IDs (items) and/or product URLs (product_urls). When a product URL is provided (e.g. https://laluer
- `check_compatibility` — Check which products are compatible with a given product. For devices, shows required consumables (e.g., conductive gel for MIRA). For topicals, shows which dev
- `check_inventory` — Check if a product is currently available. Uses Shopify Storefront API to verify real-time stock status. Use when a customer asks 'is MIRA in stock?' or before 
- `deals_discounts` — Show available bundles, deals, and ask about discount codes. Use when a customer asks about deals, bundles, savings, or says 'do you have any discounts?' Also u

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"apostleman\": {\n      \"type\": \"http\",\n      \"url\": \"https://searchshopai-mcp.fly.dev/mcp/apostleman\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/ai.searchshop%2Fapostleman
- Install plan: https://forgeregistry.com/api/v1/packages/ai.searchshop%2Fapostleman/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/ai.searchshop%2Fapostleman
- HTML page: https://forgeregistry.com/registry/ai.searchshop%2Fapostleman
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
