# io.github.Jorgeperez0825/v12-dfs

AI-driven DFS lineup optimizer for MLB & NBA — build FanDuel & DraftKings lineups via MCP.

- **Type:** MCP server
- **Trust:** 30/100 (D), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.github.Jorgeperez0825
- **License:** Unknown
- **Endpoints:** streamable-http https://v12dfs-production.up.railway.app/mcp
- **Source:** https://v12dfs-production.up.railway.app/mcp
- **Endpoint health:** reachable (last checked 2026-10-03T06:28:47.388Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

30/100 (D), scored on the content rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: findings present
- Obfuscation scan: clean
- Evidence age: 30 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-05T15:33:34.217Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (warning) in the `agent_guide` tool: Exfiltration-shaped instruction
- injection-shaped content (warning) in the `fill_template` tool: Exfiltration-shaped instruction

## Tools

34 declared. Observed from a live `tools/list` probe.
- `agent_guide` — Agent Guide Self-serve onboarding: connect any agent (Claude/MCP or REST) to drive the V12 motor, the same engine the dashboard agent uses. No auth. Returns cop
- `health_check` — Health ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json **Example Response:** ```json { "status": "Status", "versio
- `health_v12` — Health V12 Deep health check for the V12 pipeline. Surfaces: - last nightly regression run (pass/fail + per-slate deltas) - regression baseline metadata - recen
- `list_slates` — Get Slates List available V12 slates for today. Returns slate IDs, game counts, and lock times. ### Responses: **200**: Successful Response (Success Response) C
- `get_slate_players` — Get Slate Players Endpoint Get the V12 player pool for a specific slate ID. ### Responses: **200**: Successful Response (Success Response) Content-Type: applica
- `slate_health` — Slate Health Pre-flight diagnostic for a slate. Returns whether odds, projections, matchup, and FD master-session are ready BEFORE the agent invokes /v1/generat
- `slate_refresh` — Slate Refresh Re-fetch projections + odds + slate metadata for a date. Writes to the configured store (Supabase in prod). Returns a summary dict (date, slate_id
- `slate_diff` — Slate Diff Compute what changed since a previously-stored snapshot. Body shape: { "slate_id": 32867, "date": "2026-05-11", "sport": "NBA", "site": "FD", "previo
- `list_presets` — Get Presets List the available strategy presets (gpp_pro_pattern, gpp_sniper, gpp_balanced, gpp_volume, cash_grinder, gpp_contrarian, gpp_mass_entry) with their
- `generate_lineups` — Generate Lineups ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json **Example Response:** ```json { "status": "Status
- `run_mlb_postmortem` — Run Mlb Postmortem ### Responses: **200**: Successful Response (Success Response) Content-Type: application/json **Example Response:** ```json { "status": "Stat
- `list_contests` — Contest Registry List contest strategy registry entries for agents and the dashboard. ### Responses: **200**: Successful Response (Success Response) Content-Typ
- `list_live_contests` — Live Contests Return latest V12 contest context without backend identifiers. ### Responses: **200**: Successful Response (Success Response) Content-Type: applic
- `contest_semaforo` — Contest Semaforo VIP-only: per-contest play/skip verdict from the owner's verified P&L bands + structure gates + rake/fill math. See core/data/contest_semaforo.
- `scout_field` — Scout Field VIP-only (owner order 8/16): opponent-scouting profiles for the small single-entry band. The owner's $65 table runs the SAME regulars nightly; this 
- `contest_advice` — Contest Advice Advice for a concrete contest name. Resolves the name against the LIVE lobby FIRST so a real live contest is never reported missing (the curated 
- `fill_template` — Fill Template Fill a downloaded FanDuel/DK entries-template with already-generated lineups WITHOUT re-running the optimizer — the MCP-callable equivalent of the
- `admin_issue_key` — Issue Key Idempotently issue a user's API key and ALWAYS return the paste-able connect block. Returns the email's existing active key (or mints one) so a user k
- `betting_agent_guide` — Betting Agent Guide How any agent uses the MLB betting tools + how to read the output. ### Responses: **200**: Successful Response (Success Response) Content-Ty
- `betting_player_form` — Player Form Streak / splits / recent form for any player ('racha de X'). ### Responses: **200**: Successful Response (Success Response) Content-Type: applicatio
- `betting_analyze_prop` — Analyze Prop Model a single player's prop vs tonight's FanDuel line -> edge. ### Responses: **200**: Successful Response (Success Response) Content-Type: applic
- `betting_scan_edges` — Scan Edges Tonight's prop board ranked by model edge (VALUE first). ### Responses: **200**: Successful Response (Success Response) Content-Type: application/jso
- `betting_best_bets` — Best Bets THE board sweep — scans EVERY main prop market (HR/RBI/hit/total_bases/ 2+hits/stolen_base) in one call and returns the top edges across all of them, 
- `betting_build_parlay` — Build Parlay Deterministic parlay analysis for BOTH leg shapes. Body: {legs:[...], ticket_odds?}. PROP legs {name, prop, threshold} keep the legacy correlation-
- `betting_log_bet` — Log Bet Record a bet you placed (per user) so we can track P&L + CLV over time. Body: {uid, market, selection, odds (American), stake, line?, prop?, team?, game
- `betting_my_bets` — My Bets A user's bet history + P&L / CLV summary. avg_clv_pct > 0 over time = you're beating the closing line = real edge (the only durable proof). ### Response
- `betting_settle_bet` — Settle Bet Settle a logged bet. Body: {uid, bet_id, result: won|lost|push, closing_odds?}. closing_odds lets us compute CLV (did you beat the close). ### Respon
- `betting_cross_book` — Cross Book Cross-book value: FanDuel vs DraftKings (DK pulled via ESPN's public API, no key/WS). LINE_SHOP (the books hang different numbers — take the easier s
- `betting_game_lines` — Game Lines GAME markets — moneyline / run total / run line for today's MLB games. This answers the 'quién gana / cuántas carreras / pronóstico Yankees vs Toront
- `betting_market` — Market FULL FanDuel market board for a team's game — EVERY market with real odds + de-vig fair price, so NO market question goes unanswered. Game lines (ML / to
- `betting_sharp` — Sharp SHARP value — FanDuel vs PINNACLE (the sharpest book, ~2% hold). Pinnacle's de-vigged line ≈ TRUE probability, so this is the most reliable value signal i
- `betting_game_model` — Game Model MODEL the GAME run markets — TEAM TOTALS (over/under) and NRFI/YRFI — vs the FanDuel line, MARKET-ANCHORED: expected_runs = the book's de-vigged impl
- `betting_matchup` — Matchup GROUNDING — the real game for a team today: probable pitchers + the POSTED lineup (ACTUAL player names from MLB statsapi) + the market line + the CONTEX
- `betting_market_movers` — Market Movers MARKET pattern (not model opinion): how FanDuel lines MOVED today, from the captured snapshots. A line that shortened = money coming in (sharp/new

## Install

**Verdict: do-not-install** — Do not install: 2 injection-shaped patterns found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 2 injection-shaped patterns found in this entry's own text — it may try to steer the model that loads it. — tool:agent_guide: Exfiltration-shaped instruction · tool:fill_template#lineups: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.Jorgeperez0825%2Fv12-dfs
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.Jorgeperez0825%2Fv12-dfs/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.Jorgeperez0825%2Fv12-dfs
- HTML page: https://forgeregistry.com/registry/io.github.Jorgeperez0825%2Fv12-dfs
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
