Agent-native storage with cryptographic verification on Solana. Keyless: clients sign and pay.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://mcp.nukez.xyz/mcp15 tools · 480msnukez_quoteinjection riskStep 1: Get storage pricing and payment options. Returns price breakdown and every available payment method (SOL/USDC/USDT/WETH/BETA on Solana, USDC/USDT0/MON/WETH on Monad). Each option carries a `destination_kind`: 'wallet' (native SOL — send lamports to pay_to_address), 'spl_token_account' (Sola…Step 1: Get storage pricing and payment options. Returns price breakdown and every available payment method (SOL/USDC/USDT/WETH/BETA on Solana, USDC/USDT0/MON/WETH on Monad). Each option carries a `destination_kind`: 'wallet' (native SOL — send lamports to pay_to_address), 'spl_token_account' (Sola…
t), or 'evm_address' (Monad — send native value to the address, or call transfer() on the token contract at token_addres…| Parameter | Type | Description |
|---|---|---|
| units | integer | — |
| provider | string | — |
| pay_network | — | — |
| pay_asset | — | — |
nukez_payStep 2: Record an externally-executed on-chain payment. The server is keyless and never signs transactions — execute the transfer yourself (Solana sendTransaction or an EVM client) and pass the resulting signature as tx_sig. Uses pay_req_id from nukez_quote (auto-resolved from state). Specify chain…Step 2: Record an externally-executed on-chain payment. The server is keyless and never signs transactions — execute the transfer yourself (Solana sendTransaction or an EVM client) and pass the resulting signature as tx_sig. Uses pay_req_id from nukez_quote (auto-resolved from state). Specify chain…
| Parameter | Type | Description |
|---|---|---|
| pay_req_id | — | — |
| tx_sig | — | — |
| chain | — | — |
| pay_asset | — | — |
nukez_provisionStep 3: Confirm payment settlement on the gateway and provision the storage locker. Two modes: (a) Without `envelope`: pass pay_req_id + tx_sig (auto-resolved from state). Returns the receipt_id and a hint to build a signed `locker:provision` envelope. (b) With `receipt_id` + `envelope`: forwards t…Step 3: Confirm payment settlement on the gateway and provision the storage locker. Two modes: (a) Without `envelope`: pass pay_req_id + tx_sig (auto-resolved from state). Returns the receipt_id and a hint to build a signed `locker:provision` envelope. (b) With `receipt_id` + `envelope`: forwards t…
| Parameter | Type | Description |
|---|---|---|
| pay_req_id | — | — |
| tx_sig | — | — |
| chain | — | — |
| pay_asset | — | — |
| receipt_id | — | — |
| envelope | — | — |
nukez_setupSet up Nukez storage: checks wallet, purchases storage, and provisions locker in a single call. Call with no args to run the full flow. Call with receipt_id to rehydrate an existing locker. Providers: gcs (default), mongodb, storj, arweave, filecoin, firestore. Payments: Solana (SOL, USDC, USDT, WE…Set up Nukez storage: checks wallet, purchases storage, and provisions locker in a single call. Call with no args to run the full flow. Call with receipt_id to rehydrate an existing locker. Providers: gcs (default), mongodb, storj, arweave, filecoin, firestore. Payments: Solana (SOL, USDC, USDT, WE…
| Parameter | Type | Description |
|---|---|---|
| receipt_id | — | — |
| units | integer | — |
| provider | string | — |
| envelope | — | — |
nukez_create_fileCreate a file entry and get upload_url + confirm_url for direct upload. The client PUTs raw bytes directly to the upload_url (307-redirects to GCS), then calls nukez_confirm to finalize. Bytes never transit the MCP server. Use this for large files from local/external sources against Cloud Run. For…Create a file entry and get upload_url + confirm_url for direct upload. The client PUTs raw bytes directly to the upload_url (307-redirects to GCS), then calls nukez_confirm to finalize. Bytes never transit the MCP server. Use this for large files from local/external sources against Cloud Run. For…
| Parameter | Type | Description |
|---|---|---|
| filename* | string | — |
| content_type | — | — |
| receipt_id | — | — |
| envelope | — | — |
nukez_storeinjection riskStore files in your Nukez locker. ALWAYS BATCH: pass ALL the files you want to upload in a SINGLE call, as a list under `files`. Do NOT loop over your file list and call nukez_store once per file — that triggers one on-chain attestation per file (slow + costs SOL fees per push). One nukez_store cal…Store files in your Nukez locker. ALWAYS BATCH: pass ALL the files you want to upload in a SINGLE call, as a list under `files`. Do NOT loop over your file list and call nukez_store once per file — that triggers one on-chain attestation per file (slow + costs SOL fees per push). One nukez_store cal…
ncode files >4KB in one call. Upload path is auto-selected based on size and runtime environment. HARD SIZE LIMITS per…| Parameter | Type | Description |
|---|---|---|
| files* | array | — |
| receipt_id | — | — |
| envelope | — | — |
nukez_confirmConfirm a file upload after sandbox curl completes. Call this after executing the curl command returned by nukez_store in sandbox mode. The server computes SHA-256 and records the hash. Requires a payer-signed locker:write envelope: signer-mode deployments sign automatically via the SDK; keyless cl…Confirm a file upload after sandbox curl completes. Call this after executing the curl command returned by nukez_store in sandbox mode. The server computes SHA-256 and records the hash. Requires a payer-signed locker:write envelope: signer-mode deployments sign automatically via the SDK; keyless cl…
| Parameter | Type | Description |
|---|---|---|
| filename | — | — |
| receipt_id | — | — |
| envelope | — | — |
| use_job | boolean | — |
| job_id | — | — |
nukez_upload_chunkprivilegedUpload a file in chunks when sandbox curl/network is blocked. PREPARATION — run this bash script first to split and hash:
python3 -c "
import base64, hashlib, os, json, math
path = '<SANDBOX_FILE_PATH>'
CHUNK = 4096
size = os.path.getsize(path)
n = math.ceil(size / CHUNK)
os.makedirs('/tmp/nkz', e…Upload a file in chunks when sandbox curl/network is blocked. PREPARATION — run this bash script first to split and hash: python3 -c " import base64, hashlib, os, json, math path = '<SANDBOX_FILE_PATH>' CHUNK = 4096 size = os.path.getsize(path) n = math.ceil(size / CHUNK) os.makedirs('/tmp/nkz', e…
| Parameter | Type | Description |
|---|---|---|
| filename* | string | — |
| data_b64* | string | — |
| part_no* | integer | — |
| is_last | boolean | — |
| content_type | — | — |
| receipt_id | — | — |
| sha256 | — | — |
| job_id | — | — |
| file_id | — | — |
nukez_retrieveList files or download content from your Nukez locker. Call with no filenames to list all files. Call with filenames=['file.txt'] to download specific files. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact list spec to sign (locker:list, pl…List files or download content from your Nukez locker. Call with no filenames to list all files. Call with filenames=['file.txt'] to download specific files. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact list spec to sign (locker:list, pl…
| Parameter | Type | Description |
|---|---|---|
| filenames | — | — |
| receipt_id | — | — |
| encoding | string | — |
| envelope | — | — |
nukez_verifyFast structural verification of locker state. Returns merkle root, attestation status, and optional per-file proof. Pass memory_key to verify a specific memory record by key. Cheap: reads the persisted attestation; latency is independent of locker size (~sub-second typical). With push=True, also tr…Fast structural verification of locker state. Returns merkle root, attestation status, and optional per-file proof. Pass memory_key to verify a specific memory record by key. Cheap: reads the persisted attestation; latency is independent of locker size (~sub-second typical). With push=True, also tr…
| Parameter | Type | Description |
|---|---|---|
| push | boolean | — |
| receipt_id | — | — |
| filename | — | — |
| memory_key | — | — |
| envelope | — | — |
nukez_recompute_verifyByte-level integrity proof: re-downloads every file from storage, recomputes content hashes, rebuilds the merkle tree, and compares the result against the persisted attestation. Returns match=True when storage bytes still match the recorded hashes, match=False when they have drifted. Cost: scales w…Byte-level integrity proof: re-downloads every file from storage, recomputes content hashes, rebuilds the merkle tree, and compares the result against the persisted attestation. Returns match=True when storage bytes still match the recorded hashes, match=False when they have drifted. Cost: scales w…
| Parameter | Type | Description |
|---|---|---|
| receipt_id | — | — |
| envelope | — | — |
nukez_statusCheck wallet balance, locker state, and lifecycle stage. Works at any stage — no active locker required.Check wallet balance, locker state, and lifecycle stage. Works at any stage — no active locker required.
| Parameter | Type | Description |
|---|---|---|
| receipt_id | — | — |
| envelope | — | — |
nukez_deleteprivilegedDelete files from your Nukez locker. WARNING: permanent and irreversible. Invalidates existing attestation. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact delete spec to sign (locker:write, bound to one file's path); sign it with your wall…Delete files from your Nukez locker. WARNING: permanent and irreversible. Invalidates existing attestation. KEYLESS (hosted) SERVER: a call without `envelope` returns action_required='sign_envelopes' with the exact delete spec to sign (locker:write, bound to one file's path); sign it with your wall…
| Parameter | Type | Description |
|---|---|---|
| filenames* | array | — |
| receipt_id | — | — |
| envelope | — | — |
nukez_rememberStore a structured memory record in your Nukez locker. Memories are indexed for fast search via nukez_recall. Use namespaces to organize (e.g., 'config', 'context', 'decisions'). Requires: key, content, summary. ENVELOPE: pass a list of 2 envelopes (each with unique nonce, POST path, ops=locker:wri…Store a structured memory record in your Nukez locker. Memories are indexed for fast search via nukez_recall. Use namespaces to organize (e.g., 'config', 'context', 'decisions'). Requires: key, content, summary. ENVELOPE: pass a list of 2 envelopes (each with unique nonce, POST path, ops=locker:wri…
| Parameter | Type | Description |
|---|---|---|
| key* | string | — |
| content* | string | — |
| summary* | string | — |
| namespace | string | — |
| tags | string | — |
| supersedes | string | — |
| receipt_id | — | — |
| envelope | — | — |
nukez_recallSearch and retrieve memory records from your Nukez locker. Two modes: exact key lookup (pass key) returns full content + proof, or search (pass namespace/tags/query/prefix) returns matching index entries. ENVELOPE: none needed — both index and record are read via the public receipt-proxy URL. Just…Search and retrieve memory records from your Nukez locker. Two modes: exact key lookup (pass key) returns full content + proof, or search (pass namespace/tags/query/prefix) returns matching index entries. ENVELOPE: none needed — both index and record are read via the public receipt-proxy URL. Just…
| Parameter | Type | Description |
|---|---|---|
| key | string | — |
| namespace | string | — |
| tags | string | — |
| query | string | — |
| prefix | string | — |
| limit | integer | — |
| receipt_id | — | — |
| envelope | — | — |
15 of 15 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Agent-native storage with cryptographic verification on Solana. Keyless: clients sign and pay.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.