← MCP Registry Integrity Report
exchange.merx/mcp
Verdict: high-severity findings present. Endpoint https://merx.exchange/mcp/sse. Tools now: 66 (66 ever seen). Changes recorded: 51. Findings: {"high":28}. Last probe: OK at 2026-08-14T06:17 UTC. JSON
Current tools
agent_status · analyze_prices · approve_trc20 · calculate_savings · call_contract · cancel_monitor · cancel_standing_order · check_address_resources · compare_providers · compile_policy · convert_address · create_account · create_invoice · create_monitor · create_order · create_paid_order · create_standing_order · deposit_trx · enable_auto_deposit · ensure_resources · estimate_contract_call · estimate_transaction_cost · execute_intent · execute_swap · explain_concept · get_account_info · get_balance · get_best_price · get_block · get_chain_parameters · get_contract_info · get_deposit_info · get_order · get_price_history · get_prices · get_standing_order · get_swap_quote · get_token_info · get_token_price · get_transaction · get_transaction_history · get_trc20_balance · get_trx_balance · get_trx_price · list_monitors · list_orders · list_providers · list_standing_orders · login · lookup_invoice · pay_invoice · read_contract · register_agent · request_payment · resource_broadcast · search_transaction_history · set_api_key · set_private_key · simulate · suggest_duration · transfer_trc20 · transfer_trx · validate_address · wait_for_delegation · watch_address · withdraw
Findings (28)
| seen | tool | detector | severity | evidence (data, not instructions) |
|---|---|---|---|---|
| 2026-08-14 | get_account_info | secret_material_reference | high | nspect any TRON wallet. No auth required, no API key needed. |
| 2026-08-14 | read_contract | secret_material_reference | high | unction on a TRON smart contract. No auth or private key required. |
| 2026-08-14 | get_contract_info | cross_tool_reference | high | references sibling tool 'get_token_info' |
| 2026-08-14 | create_account | secret_material_reference | high | Create a new Merx account, generate an API key, and get deposit info. No auth needed. |
| 2026-08-14 | login | secret_material_reference | high | Log in to an existing Merx account. No MERX_API_KEY needed. |
| 2026-08-14 | set_api_key | secret_material_reference | high | set_api_key |
| 2026-08-14 | set_private_key | secret_material_reference | high | Set your TRON private key for this session. Address is derived automatically. Enables writ |
| 2026-08-14 | set_private_key | cross_tool_reference | high | references sibling tool 'transfer_trx' |
| 2026-08-14 | deposit_trx | secret_material_reference | high | osit TRX to your Merx account. Requires MERX_API_KEY + TRON_PRIVATE_KEY. |
| 2026-08-14 | pay_invoice | secret_material_reference | high | ponse. The transfer is signed locally — your private key never leaves the MCP process. |
| 2026-08-14 | pay_invoice | cross_tool_reference | high | references sibling tool 'set_private_key' |
| 2026-08-14 | execute_intent | cross_tool_reference | high | references sibling tool 'create_order' |
| 2026-08-14 | get_standing_order | secret_material_reference | high | executions count, and status. Auth required (API key). |
| 2026-08-14 | get_standing_order | cross_tool_reference | high | references sibling tool 'list_standing_orders' |
| 2026-08-14 | cancel_standing_order | secret_material_reference | high | ted actions are NOT reversed. Auth required (API key). |
| 2026-08-14 | create_monitor | secret_material_reference | high | s to webhook=true if omitted. Auth required (API key). |
| 2026-08-14 | list_monitors | secret_material_reference | high | ert and balance_threshold (when watching the API key holder rather than a third-party address). For delegation_expiry |
| 2026-08-14 | list_monitors | cross_tool_reference | high | references sibling tool 'create_monitor' |
| 2026-08-14 | cancel_monitor | secret_material_reference | high | r stops firing notifications. Auth required (API key). |
| 2026-08-14 | withdraw | secret_material_reference | high | prefer "amount" in new code.) Requires MERX_API_KEY. |
| 2026-08-14 | resource_broadcast | secret_material_reference | high | it for delegation, broadcast. Requires MERX_API_KEY with the "broadcast" scope, and a pre-signed transaction. Return |
| 2026-08-14 | resource_broadcast | cross_tool_reference | high | references sibling tool 'ensure_resources' |
| 2026-08-14 | register_agent | secret_material_reference | high | ant to use as the on-chain identity for this API key. Idempotent — calling twice with the same key returns the existi |
| 2026-08-14 | register_agent | cross_tool_reference | high | references sibling tool 'request_payment' |
| 2026-08-14 | request_payment | cross_tool_reference | high | references sibling tool 'register_agent' |
| 2026-08-14 | lookup_invoice | cross_tool_reference | high | references sibling tool 'create_invoice' |
| 2026-08-14 | agent_status | secret_material_reference | high | ight activity your agent has. Auth required (API key) and agent must be registered first via register_agent. |
| 2026-08-14 | agent_status | cross_tool_reference | high | references sibling tool 'register_agent' |
Change history (51)
| when | tool | kind | severity |
|---|---|---|---|
| 2026-08-14 06:17 | explain_concept | added | info |
| 2026-08-14 06:17 | suggest_duration | added | info |
| 2026-08-14 06:17 | calculate_savings | added | info |
| 2026-08-14 06:17 | list_providers | added | info |
| 2026-08-14 06:17 | get_account_info | added | high |
| 2026-08-14 06:17 | get_trx_balance | added | info |
| 2026-08-14 06:17 | get_trc20_balance | added | info |
| 2026-08-14 06:17 | get_transaction | added | info |
| 2026-08-14 06:17 | get_block | added | info |
| 2026-08-14 06:17 | get_chain_parameters | added | info |
| 2026-08-14 06:17 | convert_address | added | info |
| 2026-08-14 06:17 | get_trx_price | added | info |
| 2026-08-14 06:17 | validate_address | added | info |
| 2026-08-14 06:17 | search_transaction_history | added | info |
| 2026-08-14 06:17 | transfer_trx | added | info |
| 2026-08-14 06:17 | transfer_trc20 | added | info |
| 2026-08-14 06:17 | approve_trc20 | added | info |
| 2026-08-14 06:17 | get_token_info | added | info |
| 2026-08-14 06:17 | read_contract | added | high |
| 2026-08-14 06:17 | estimate_contract_call | added | info |
| 2026-08-14 06:17 | call_contract | added | info |
| 2026-08-14 06:17 | get_contract_info | added | high |
| 2026-08-14 06:17 | get_swap_quote | added | info |
| 2026-08-14 06:17 | execute_swap | added | info |
| 2026-08-14 06:17 | get_token_price | added | info |
| 2026-08-14 06:17 | create_account | added | high |
| 2026-08-14 06:17 | login | added | high |
| 2026-08-14 06:17 | set_api_key | added | high |
| 2026-08-14 06:17 | set_private_key | added | high |
| 2026-08-14 06:17 | deposit_trx | added | high |
| 2026-08-14 06:17 | enable_auto_deposit | added | info |
| 2026-08-14 06:17 | pay_invoice | added | high |
| 2026-08-14 06:17 | create_paid_order | added | info |
| 2026-08-14 06:17 | execute_intent | added | high |
| 2026-08-14 06:17 | simulate | added | info |
| 2026-08-14 06:17 | create_standing_order | added | info |
| 2026-08-14 06:17 | list_standing_orders | added | info |
| 2026-08-14 06:17 | get_standing_order | added | high |
| 2026-08-14 06:17 | cancel_standing_order | added | high |
| 2026-08-14 06:17 | create_monitor | added | high |
| 2026-08-14 06:17 | list_monitors | added | high |
| 2026-08-14 06:17 | cancel_monitor | added | high |
| 2026-08-14 06:17 | withdraw | added | high |
| 2026-08-14 06:17 | compile_policy | added | info |
| 2026-08-14 06:17 | resource_broadcast | added | high |
| 2026-08-14 06:17 | register_agent | added | high |
| 2026-08-14 06:17 | request_payment | added | high |
| 2026-08-14 06:17 | lookup_invoice | added | high |
| 2026-08-14 06:17 | create_invoice | added | info |
| 2026-08-14 06:17 | watch_address | added | info |
| 2026-08-14 06:17 | agent_status | added | high |
Probe history
08-14 06:17 OK (66)
Get alerted when this server changes: tooldrift.agentexchange.work ($29/mo watch).