fi.northpoint/marketing-compliance

MCPcommunitylive
v1.0.0fi.northpointUnknownUpdated 1mo ago

Crypto marketing compliance rulesets over MCP: MiCA, FCA, GDPR, SEC, MAS, VARA. Not legal advice.

Endpoint healthlive
checked 5 days ago · 522ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorfi.northpoint
LicenseUnknown
Version1.0.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface13 tools · none privileged
Security scan✓ Cleanvlive · 5d agoHow well does this scan work?
EvalsNone
IndexedAug 17, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

13 tools · none privileged
Observed live from the vendor's endpoint5d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://northpoint.fi/api/mcp13 tools · 522ms
list_regimesList every marketing-compliance regime NorthPoint can check (MiCA, FCA financial promotions, GDPR/ePrivacy, SEC, MAS, VARA, TGE launch readiness, AEO visibility), with the free and subscriber rule counts for each. No API key required. Call this first to discover what is available.

List every marketing-compliance regime NorthPoint can check (MiCA, FCA financial promotions, GDPR/ePrivacy, SEC, MAS, VARA, TGE launch readiness, AEO visibility), with the free and subscriber rule counts for each. No API key required. Call this first to discover what is available.

No input schema was published for this tool.

get_lite_rulesetReturn the FREE lite ruleset for one regime as markdown, so YOU (the calling model) can audit a marketing asset against it directly — no NorthPoint API key needed and no round trip. Use this to check crypto/fintech marketing copy against real regulatory rules before it is published. For the full 25…

Return the FREE lite ruleset for one regime as markdown, so YOU (the calling model) can audit a marketing asset against it directly — no NorthPoint API key needed and no round trip. Use this to check crypto/fintech marketing copy against real regulatory rules before it is published. For the full 25…

ParameterTypeDescription
regime*stringWhich regime's free ruleset to return.
run_mica_pro_checkRun the full MiCA (EU cryptoasset marketing) self-audit on a marketing asset. ~40 rules covering Title II–IV, ESMA guidance, and operator-grade interpretive notes. Returns verdict, per-rule analysis, and rewrite suggestions.

Run the full MiCA (EU cryptoasset marketing) self-audit on a marketing asset. ~40 rules covering Title II–IV, ESMA guidance, and operator-grade interpretive notes. Returns verdict, per-rule analysis, and rewrite suggestions.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_gdpr_pro_checkRun the full GDPR + ePrivacy marketing self-audit (~30 rules). Cookie banners, email/SMS opt-in, signup forms, privacy notices, marketing automation, ad-pixel placement. Returns verdict, per-rule analysis, and rewrite suggestions.

Run the full GDPR + ePrivacy marketing self-audit (~30 rules). Cookie banners, email/SMS opt-in, signup forms, privacy notices, marketing automation, ad-pixel placement. Returns verdict, per-rule analysis, and rewrite suggestions.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_fca_pro_checkRun the full FCA UK financial-promotions self-audit for cryptoasset marketing (~25 rules). Section 21 FSMA, COBS 4.12A, PERG 8, the October 2023 cryptoasset regime, HTX precedent. Returns verdict + per-rule analysis + rewrite suggestions.

Run the full FCA UK financial-promotions self-audit for cryptoasset marketing (~25 rules). Section 21 FSMA, COBS 4.12A, PERG 8, the October 2023 cryptoasset regime, HTX precedent. Returns verdict + per-rule analysis + rewrite suggestions.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_sec_pro_checkRun the SEC retail communications self-audit (~25 rules) for US-touching crypto marketing. FINRA Rule 2210, anti-fraud, Reg BI, finfluencer compensation disclosures, securities-status framing.

Run the SEC retail communications self-audit (~25 rules) for US-touching crypto marketing. FINRA Rule 2210, anti-fraud, Reg BI, finfluencer compensation disclosures, securities-status framing.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_mas_pro_checkRun the full MAS Singapore DPT marketing self-audit (~35–40 rules). PS Act, Notice PSN02, January 2022 prohibition on public-space DPT advertising, AML/CFT communications requirements.

Run the full MAS Singapore DPT marketing self-audit (~35–40 rules). PS Act, Notice PSN02, January 2022 prohibition on public-space DPT advertising, AML/CFT communications requirements.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_vara_pro_checkRun the full VARA Dubai marketing self-audit (~35–40 rules). Marketing & Promotions Rulebook, pre-approval requirements, KOL contracts, risk warnings, prohibited content.

Run the full VARA Dubai marketing self-audit (~35–40 rules). Marketing & Promotions Rulebook, pre-approval requirements, KOL contracts, risk warnings, prohibited content.

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_tge_readiness_checkRun the full TGE / token-launch marketing readiness audit (28 rules) across MiCA offer-to-public + Article 88, FCA financial promotions, SEC/Howey, MAS and VARA — in one multi-jurisdiction pass. For launch surfaces: landing page, airdrop/points page, staking copy, announcement thread, launch deck,…

Run the full TGE / token-launch marketing readiness audit (28 rules) across MiCA offer-to-public + Article 88, FCA financial promotions, SEC/Howey, MAS and VARA — in one multi-jurisdiction pass. For launch surfaces: landing page, airdrop/points page, staking copy, announcement thread, launch deck,…

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_aeo_visibility_checkRun the AEO / GEO (Answer Engine / Generative Engine Optimization) visibility audit (12 rules). Analyses whether AI answer engines (ChatGPT, Perplexity, Claude, Gemini) will cite the project for its category, and the gaps stopping it. Returns a 0–100 citeability score, per-engine read, per-rule ana…

Run the AEO / GEO (Answer Engine / Generative Engine Optimization) visibility audit (12 rules). Analyses whether AI answer engines (ChatGPT, Perplexity, Claude, Gemini) will cite the project for its category, and the gaps stopping it. Returns a 0–100 citeability score, per-engine read, per-rule ana…

ParameterTypeDescription
textstringThe marketing asset text to audit (landing-page copy, ad text, email body, X post, KOL contract, whitepaper excerpt, press release, etc.).
urlstringPublic URL to fetch and audit instead of pasting text. Server-side fetched with SSRF guards.
asset_typestringOptional hint to the auditor about asset type: landing_page | ad | email | x_post | kol_contract | whitepaper | press_release.
run_ad_creative_checkCross-jurisdiction ad-creative compliance scan (~30 rules). Pass an image URL, base64 image, or just a landing-page URL plus caption — the scanner extracts on-image text, evaluates prominence/contrast/dark patterns/disclosures, and returns a full audit.

Cross-jurisdiction ad-creative compliance scan (~30 rules). Pass an image URL, base64 image, or just a landing-page URL plus caption — the scanner extracts on-image text, evaluates prominence/contrast/dark patterns/disclosures, and returns a full audit.

ParameterTypeDescription
textstringOptional text accompanying the ad creative (caption or alt copy).
urlstringPublic URL of a landing page connected to the creative — fetched server-side.
image_urlstringHTTPS URL of the ad creative image (jpeg/png/gif/webp, <= 5 MB).
image_b64stringBase64-encoded image bytes (or data: URL). Use this if the image is not publicly hosted.
captionstringOptional caption text shown with the creative on social.
get_latest_signalReturn the last N days of NorthPoint's competitor + regulatory + narrative signal feed. Daily-rebuilt digest of what moved in crypto marketing/regulation.

Return the last N days of NorthPoint's competitor + regulatory + narrative signal feed. Daily-rebuilt digest of what moved in crypto marketing/regulation.

ParameterTypeDescription
daysintegerLookback window in days (default 7, max 90).
search_signalsText-search NorthPoint's signal feed for a keyword or phrase across competitor/regulatory/narrative entries.

Text-search NorthPoint's signal feed for a keyword or phrase across competitor/regulatory/narrative entries.

ParameterTypeDescription
query*stringFree-text query — matches title, body, subject, tags.
daysintegerLookback window in days (default 30, max 365).

13 of 13 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Crypto marketing compliance rulesets over MCP: MiCA, FCA, GDPR, SEC, MAS, VARA. Not legal advice.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.