# io.github.ZlaylowZ/nukez-mcp

Agent-native storage with cryptographic verification on Solana. Keyless: clients sign and pay.

- **Type:** MCP server
- **Trust:** 30/100 (D), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.3.0
- **Author:** io.github.ZlaylowZ
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.nukez.xyz/mcp
- **Source:** https://nukez.xyz/docs/mcp
- **Endpoint health:** reachable (last checked 2026-10-03T22:53:13.204Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

30/100 (D), scored on the content rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: findings present
- Obfuscation scan: clean
- Evidence age: 12 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-22T17:18:24.591Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (warning) in the `nukez_quote` tool: Exfiltration-shaped instruction
- injection-shaped content (warning) in the `nukez_store` tool: Exfiltration-shaped instruction

## Tools

15 declared. Observed from a live `tools/list` probe.
- `nukez_quote` — Step 1: Get storage pricing and payment options. Returns price breakdown and every available payment method (SOL/USDC/USDT/WETH/BETA on Solana, USDC/USDT0/MON/W
- `nukez_pay` — Step 2: Record an externally-executed on-chain payment. The server is keyless and never signs transactions — execute the transfer yourself (Solana sendTransacti
- `nukez_provision` — Step 3: Confirm payment settlement on the gateway and provision the storage locker. Two modes: (a) Without `envelope`: pass pay_req_id + tx_sig (auto-resolved f
- `nukez_setup` — Set up Nukez storage: checks wallet, purchases storage, and provisions locker in a single call. Call with no args to run the full flow. Call with receipt_id to 
- `nukez_create_file` — Create a file entry and get upload_url + confirm_url for direct upload. The client PUTs raw bytes directly to the upload_url (307-redirects to GCS), then calls 
- `nukez_store` — Store files in your Nukez locker. ALWAYS BATCH: pass ALL the files you want to upload in a SINGLE call, as a list under `files`. Do NOT loop over your file list
- `nukez_confirm` — Confirm a file upload after sandbox curl completes. Call this after executing the curl command returned by nukez_store in sandbox mode. The server computes SHA-
- `nukez_upload_chunk` — Upload a file in chunks when sandbox curl/network is blocked. PREPARATION — run this bash script first to split and hash: python3 -c " import base64, hashlib, o
- `nukez_retrieve` — List files or download content from your Nukez locker. Call with no filenames to list all files. Call with filenames=['file.txt'] to download specific files. KE
- `nukez_verify` — Fast structural verification of locker state. Returns merkle root, attestation status, and optional per-file proof. Pass memory_key to verify a specific memory 
- `nukez_recompute_verify` — Byte-level integrity proof: re-downloads every file from storage, recomputes content hashes, rebuilds the merkle tree, and compares the result against the persi
- `nukez_status` — Check wallet balance, locker state, and lifecycle stage. Works at any stage — no active locker required.
- `nukez_delete` — Delete files from your Nukez locker. WARNING: permanent and irreversible. Invalidates existing attestation. KEYLESS (hosted) SERVER: a call without `envelope` r
- `nukez_remember` — Store a structured memory record in your Nukez locker. Memories are indexed for fast search via nukez_recall. Use namespaces to organize (e.g., 'config', 'conte
- `nukez_recall` — Search and retrieve memory records from your Nukez locker. Two modes: exact key lookup (pass key) returns full content + proof, or search (pass namespace/tags/q

## Install

**Verdict: do-not-install** — Do not install: 2 injection-shaped patterns found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 2 injection-shaped patterns found in this entry's own text — it may try to steer the model that loads it. — tool:nukez_quote: Exfiltration-shaped instruction · tool:nukez_store: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 33, ceiling 57 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.ZlaylowZ%2Fnukez-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.ZlaylowZ%2Fnukez-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.ZlaylowZ%2Fnukez-mcp
- HTML page: https://forgeregistry.com/registry/io.github.ZlaylowZ%2Fnukez-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
