# it.marketpilot/marketpilot

Korean SMB marketing: browse, pay by card link, track orders. No login to start; OAuth to link.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.4.0
- **Author:** it.marketpilot
- **License:** Unknown
- **Endpoints:** streamable-http https://api.marketpilot.it/mcp
- **Source:** https://www.marketpilot.it
- **Endpoint health:** reachable (last checked 2026-09-29T22:37:50.039Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-29T22:37:50.039Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `signup` tool: Links to undeclared domain: marketpilot.it

## Tools

18 declared. Observed from a live `tools/list` probe.
- `whoami` — 지금 이 연결의 신원과 권한, 쓸 수 있는 툴 전체를 돌려줘요. 회사 데이터를 다루는 작업을 시작하기 전에 한 번 부르면, 서버에 새로 추가된 기능까지 재접속 없이 알 수 있어요. "뭘 할 수 있어?", "권한이 어떻게 돼?" 같은 질문에도 이걸 쓰세요. 어떤 툴이 안 보이면 unava
- `list_products` — 주문 가능한 마케팅 상품 목록(상품 ID·이름·분류·단가·최소/최대 수량)을 조회합니다. aiOrderable=false 인 상품은 결제 링크로 주문할 수 없고 웹사이트나 상담(submit_inquiry)으로 안내해야 합니다. 로그인(키) 없이도 쓸 수 있어요.
- `get_product` — 상품 1개의 상세(단가·수량 제약)와 집행에 필요한 입력 항목(formFields)을 조회합니다. 결제 링크를 만들기 전에 수량 제약을 확인하세요.
- `search_places` — 네이버 플레이스를 업체명·키워드로 검색합니다. 사용자의 매장을 특정해 placeId·업체명·주소를 얻는 용도입니다.
- `create_checkout` — 카드로 결제할 수 있는 결제 링크를 만듭니다. 상품 ID 와 수량만 넣으면 금액은 서버가 계산해요(단가를 직접 넣을 수 없어요). 응답의 checkoutUrl 을 사용자에게 그대로 보여주세요. 링크를 열면 품목·금액을 확인하고 카드·간편결제로 바로 결제할 수 있고, 회원가입은 필요 없어
- `get_checkout_status` — 결제 링크의 상태(결제 대기·결제 완료·만료)와 결제 후 만들어진 주문의 진행 상황을 확인합니다. 사용자가 "결제했어요"라고 하면 이 툴로 확인하고, setupUrl 이 있으면 집행 정보(매장 주소 등) 입력을 안내하세요.
- `submit_inquiry` — 상담·견적 문의를 접수합니다. 담당자가 영업일 1일 이내에 이메일로 회신해요. aiOrderable=false 인 상품(문의형·복잡한 견적), 원하는 게 카탈로그에 없을 때, 또는 사용자가 사람과 이야기하고 싶어할 때 사용하세요. 이름·이메일은 반드시 사용자에게 직접 물어보고 넣으세요 
- `send_signup_code` — [회원가입 1단계] 사용자의 휴대폰으로 인증번호 문자를 보냅니다. 사용자가 가입을 원한다고 분명히 말했을 때만 호출하세요. 문자를 받은 사용자에게 번호를 물어본 뒤 signup 으로 넘기세요. 결제 링크(create_checkout)는 가입 없이도 쓸 수 있어요.
- `signup` — [회원가입 2단계] 인증번호를 확인하고 계정을 만듭니다. 아이디·비밀번호·이름은 사용자에게 직접 받으세요(임의로 짓지 마세요). 약관 동의는 사람의 의사표시예요 — 사용자에게 이용약관(https://www.marketpilot.it/terms)과 개인정보처리방침(https://www.m
- `quote_order` — [주문 1단계] 견적을 요청합니다. 총액·포인트 잔액·부족분과 15분 유효한 quoteToken을 돌려줍니다. 돈이 나가지 않는 안전한 호출입니다.
- `create_order` — [주문 2단계] 견적을 확정해 실제 주문을 생성합니다. 포인트가 즉시 차감되므로, 반드시 사용자에게 상품·수량·금액을 확인받은 뒤 confirm:true로 호출하세요.
- `list_my_orders` — 내 주문 내역을 조회합니다. status로 필터할 수 있어요 (paid=결제완료, in_progress=진행중, completed=완료, refunded=환불, stopped=중단).
- `get_my_order` — 주문 1건의 진행 상황을 조회합니다. status/statusLabel(결제완료→진행중→완료), phaseLabel(상품별 세부 단계), progress(수량 진행률·결과물 링크·단계 — 제공 상품만), recentLogs(진행 로그 최신순)를 반환해요. "내 주문 어떻게 돼가?" 같은
- `get_point_balance` — 포인트 잔액을 조회합니다. 1P = 1원이며 주문 결제는 포인트로 이뤄집니다.
- `request_point_charge` — 포인트 충전을 신청합니다. 응답의 transfer(무통장 입금 계좌·입금자명·금액)를 사용자에게 안내하세요. 실제 이체는 사용자가 직접 해야 하며, 입금자명·금액이 일치하면 몇 분 내 자동 충전됩니다.
- `list_charge_requests` — 내 포인트 충전 신청 내역을 조회합니다.
- `get_charge_request` — 충전 신청 1건의 상태를 확인합니다. 입금 후 status가 CONFIRMED(충전 완료)로 바뀌었는지 확인하는 용도입니다.
- `cancel_charge_request` — 입금 대기(PENDING) 상태의 충전 신청을 취소합니다.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"marketpilot\": {\n      \"type\": \"http\",\n      \"url\": \"https://api.marketpilot.it/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/it.marketpilot%2Fmarketpilot
- Install plan: https://forgeregistry.com/api/v1/packages/it.marketpilot%2Fmarketpilot/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/it.marketpilot%2Fmarketpilot
- HTML page: https://forgeregistry.com/registry/it.marketpilot%2Fmarketpilot
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
