# io.github.ColinHughes2121/gocreative-agent-api

17-model LLM gateway + 350+ data/KYB/sanctions tools. Pay-per-call USDC via x402, no API key.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.1.0
- **Author:** io.github.ColinHughes2121
- **License:** Unknown
- **Endpoints:** streamable-http https://api.gocreativeai.com/mcp
- **Source:** https://api.gocreativeai.com
- **Endpoint health:** degraded (last checked 2026-10-04T19:35:05.218Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 36 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-08-30T16:58:19.577Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `enrich_browserbase` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `enrich_browsersnap` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `lookup_oembed` tool: Links to undeclared domain: youtu.be
- injection-shaped content (note) in the `lookup_url_unfurl` tool: Links to undeclared domain: github.com
- injection-shaped content (note) in the `lookup_lighthouse` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `lookup_pagespeed` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `extract_document` tool: Links to undeclared domain: example.com

## Tools

172 declared. Observed from a live `tools/list` probe.
- `bundle_kyb_360` — KYB / counterparty-risk verdict for a company in ONE call: sanctions + PEP + watchlist screen (OFAC/EU/UK/UN) + entity risk score + KYB registry dossier + legal
- `data_sanctions_screen` — Sanctions, PEP & watchlist screen for any person or company across OFAC, EU, UK, UN + 100+ lists (OpenSanctions). The canonical KYC/KYB gate — call before onboa
- `ai_ask` — LLM completion (standard tier, DeepSeek V3.1) — send any prompt, get a frontier-quality answer. Pay USDC per call, no API key. Outsource summarization, extracti
- `ai_pro` — LLM completion (frontier tier, Claude 4.5 Sonnet) — top-end reasoning, analysis, synthesis, and drafting. Pay USDC per call, no API key, no signup. Use when the
- `ai_ultra` — LLM completion (ultra tier, Claude Opus 4.6) — the top-end reasoning model for the hardest agent tasks: deep multi-step analysis and high-stakes drafting. Pay U
- `bundle_diligence_360` — Corporate due-diligence dossier in ONE call: firmographics + OFAC sanctions screen + entity risk score + KYB registry dossier + legal/case-law exposure. For inv
- `bundle_sec_360` — SEC corporate-financials intelligence: company facts (XBRL financials) + recent SEC filings for any ticker/CIK. For equity research, investment analysis, and fi
- `bundle_crypto_360` — Full crypto snapshot in ONE call: market data + spot price + Fear & Greed sentiment + global market context + trending, for any CoinGecko coin id. For trading, 
- `bundle_email_360` — Email intelligence: deliverability validation + provider/domain enrichment for any email address. For lead-gen, CRM hygiene, and fraud-screening agents. Example
- `bundle_domain_360` — Domain security/infra footprint: WHOIS registration + DNS records + TLS certificate, for any domain. For security review, vendor due diligence, and monitoring a
- `bundle_company_360` — Company 360: domain intelligence (DNS/WHOIS/TLS) fused with company firmographics, for any domain. For sales prospecting, KYB, and enrichment agents. Example ca
- `bundle_risk_360` — Risk & compliance 360: OFAC sanctions screen + entity risk score + KYB/vendor dossier for any company. For compliance, onboarding, and vendor-risk agents. Examp
- `bundle_sales_intent` — Sales-intent signals by industry/keyword: companies that just raised funding, won a federal contract, won a grant, or cleared FDA review. For lead-gen, prospect
- `bundle_regulatory_360` — Regulatory & legal landscape for a sector/term: Federal Register rulemaking + case-law + FDA device signals + federal grant signals. For policy, legal, complian
- `bundle_device_360` — FDA medical-device risk dossier: 510(k) clearances + recalls + adverse events (MAUDE), for any device or manufacturer. For medtech, procurement, and compliance 
- `bundle_drug_360` — Drug intelligence dossier: FDA label + approval history (Drugs@FDA) + clinical trials, for any drug. For pharma, healthcare, and research agents. Example call: 
- `data_clinical_trials` — Clinical trials for any condition, drug, or sponsor (ClinicalTrials.gov) — NCT id, title, status, phase. For healthcare, pharma, and research agents. Example ca
- `data_ip_threat` — IP threat-intel: open ports + known CVEs/vulnerabilities + hostnames + tags for any IP (Shodan InternetDB). For security, fraud, and abuse-screening agents. Exa
- `bundle_repo_360` — GitHub repo intelligence: repository profile + latest releases, for any owner/repo. For dev-tools, security, and OSS-monitoring agents. Example call: {"owner": 
- `bundle_dev_360` — Developer/GitHub intelligence: account profile + top repositories for any username. For recruiting, dev-rel, and technical-sourcing agents. Example call: {"user
- `enrich_instagram` — Enrich an Instagram profile with follower count, bio, business category, verified status, profile picture, and external links. Use when you need to qualify an I
- `enrich_tiktok` — Enrich a TikTok profile with follower count, total likes, bio, verified status, and recent post stats. Use when you need to qualify a TikTok creator for paid pa
- `enrich_x` — Enrich an X/Twitter profile with follower count, bio, verified status, account creation date, and tweet count. Use when you need live X account context for lead
- `enrich_linkedin` — Enrich a public LinkedIn profile (headline, current company, experience snapshot) given the vanity slug (the part after /in/). Use for B2B lead enrichment when 
- `enrich_threads` — Enrich a Threads (Meta) profile with follower count, bio, and verified status. Use for cross-platform social-presence checks. Example call: {"username": "zuck"}
- `enrich_spotify` — Enrich a Spotify artist profile with monthly listeners, follower count, top tracks, and genres. Use for music marketing, A&R research, or playlist-pitching work
- `enrich_github` — Enrich a GitHub user profile with public repo count, followers, hireable flag, top languages, and join date. Use for developer-lead qualification or recruiter s
- `enrich_company` — Enrich a company with metadata (industry, employee size, founded year, logo, social links) given just a domain. Use whenever you need company context for a B2B 
- `enrich_reviews` — Aggregate Google Maps reviews for a local business (rating, review count, recent review snippets). Use for local-SEO research, competitor monitoring, or restaur
- `enrich_googlereviews` — Aggregate Google Maps reviews by place_id with rating distribution and recent review text. Use when you already have a Google place_id and need structured revie
- `enrich_apify` — Get metadata for a public Apify actor (description, pricing, last build, recent runs). Use when researching Apify scrapers or comparing actor coverage. Example 
- `enrich_browserbase` — Headless-browser fetch of a URL with full JS render, returning final HTML and screenshot URL. Use when the target page is SPA/JS-rendered and a plain fetch retu
- `enrich_browsersnap` — Headless-browser screenshot of a URL, returning a CDN screenshot URL. Use when you need a visual snapshot for a report, slide, or QA pipeline. Example call: {"u
- `search_instagram_hashtag` — Search Instagram for top posts under a hashtag (up to 30 posts with caption, likes, author). Use for trend discovery, UGC sourcing, or competitor-hashtag mining
- `search_tiktok_hashtag` — Search TikTok for top videos under a hashtag (up to 30 videos with caption, views, author). Use for trend research, viral-content monitoring, or creator discove
- `search_youtube` — Search YouTube and return top results (title, channel, views, published). Use for video-content research or competitor monitoring. Example call: {"query": "mach
- `posts_x` — Fetch recent tweets from an X/Twitter user (up to 30 tweets with text, engagement, timestamps). Use for sentiment monitoring, content scraping, or thread analys
- `lookup_zip` — Resolve a US ZIP code to city, state, latitude, and longitude. Use for shipping, geographic segmentation, or local-business lookups. Example call: {"zipcode": "
- `lookup_whois` — Get WHOIS records for a domain (registrar, created date, expiration, nameservers). Use for domain-acquisition research, brand monitoring, or security investigat
- `lookup_crypto` — Get live crypto price + 24h change for a symbol (BTC, ETH, SOL, etc.) sourced from CoinGecko. Use for portfolio agents, trading bots, or DeFi research. Example 
- …and 132 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"gocreative-agent-api\": {\n      \"type\": \"http\",\n      \"url\": \"https://api.gocreativeai.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 26, ceiling 50 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.ColinHughes2121%2Fgocreative-agent-api
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.ColinHughes2121%2Fgocreative-agent-api/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.ColinHughes2121%2Fgocreative-agent-api
- HTML page: https://forgeregistry.com/registry/io.github.ColinHughes2121%2Fgocreative-agent-api
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
