{
 "server": "exchange.merx/mcp",
 "url": "https://merx.exchange/mcp/sse",
 "verdict": "high-severity findings present",
 "current_tool_count": 66,
 "tools_ever_seen": 66,
 "drift_events": 51,
 "findings_by_severity": {
  "high": 28
 },
 "last_probe": {
  "status": "OK",
  "n_tools": 66,
  "ran_at": "2026-08-14T06:17:15.856Z"
 },
 "current_tools": [
  "agent_status",
  "analyze_prices",
  "approve_trc20",
  "calculate_savings",
  "call_contract",
  "cancel_monitor",
  "cancel_standing_order",
  "check_address_resources",
  "compare_providers",
  "compile_policy",
  "convert_address",
  "create_account",
  "create_invoice",
  "create_monitor",
  "create_order",
  "create_paid_order",
  "create_standing_order",
  "deposit_trx",
  "enable_auto_deposit",
  "ensure_resources",
  "estimate_contract_call",
  "estimate_transaction_cost",
  "execute_intent",
  "execute_swap",
  "explain_concept",
  "get_account_info",
  "get_balance",
  "get_best_price",
  "get_block",
  "get_chain_parameters",
  "get_contract_info",
  "get_deposit_info",
  "get_order",
  "get_price_history",
  "get_prices",
  "get_standing_order",
  "get_swap_quote",
  "get_token_info",
  "get_token_price",
  "get_transaction",
  "get_transaction_history",
  "get_trc20_balance",
  "get_trx_balance",
  "get_trx_price",
  "list_monitors",
  "list_orders",
  "list_providers",
  "list_standing_orders",
  "login",
  "lookup_invoice",
  "pay_invoice",
  "read_contract",
  "register_agent",
  "request_payment",
  "resource_broadcast",
  "search_transaction_history",
  "set_api_key",
  "set_private_key",
  "simulate",
  "suggest_duration",
  "transfer_trc20",
  "transfer_trx",
  "validate_address",
  "wait_for_delegation",
  "watch_address",
  "withdraw"
 ],
 "drift": [
  {
   "tool": "explain_concept",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "suggest_duration",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "calculate_savings",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "list_providers",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_account_info",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_trx_balance",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_trc20_balance",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_transaction",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_block",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_chain_parameters",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "convert_address",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_trx_price",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "validate_address",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "search_transaction_history",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "transfer_trx",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "transfer_trc20",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "approve_trc20",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_token_info",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "read_contract",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "estimate_contract_call",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "call_contract",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_contract_info",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_swap_quote",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "execute_swap",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_token_price",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_account",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "login",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "set_api_key",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "set_private_key",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "deposit_trx",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "enable_auto_deposit",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "pay_invoice",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_paid_order",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "execute_intent",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "simulate",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_standing_order",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "list_standing_orders",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_standing_order",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "cancel_standing_order",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_monitor",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "list_monitors",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "cancel_monitor",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "withdraw",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "compile_policy",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "resource_broadcast",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "register_agent",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "request_payment",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "lookup_invoice",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_invoice",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "watch_address",
   "kind": "added",
   "severity": "info",
   "detected_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "agent_status",
   "kind": "added",
   "severity": "high",
   "detected_at": "2026-08-14T06:17:15.856Z"
  }
 ],
 "findings": [
  {
   "tool": "get_account_info",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "nspect any TRON wallet. No auth required, no API key needed.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "read_contract",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "unction on a TRON smart contract. No auth or private key required.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_contract_info",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'get_token_info'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_account",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "Create a new Merx account, generate an API key, and get deposit info. No auth needed.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "login",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "Log in to an existing Merx account. No MERX_API_KEY needed.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "set_api_key",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "name",
   "evidence": "set_api_key",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "set_private_key",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "Set your TRON private key for this session. Address is derived automatically. Enables writ",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "set_private_key",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'transfer_trx'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "deposit_trx",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "osit TRX to your Merx account. Requires MERX_API_KEY + TRON_PRIVATE_KEY.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "pay_invoice",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ponse. The transfer is signed locally — your private key never leaves the MCP process.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "pay_invoice",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'set_private_key'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "execute_intent",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'create_order'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_standing_order",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "executions count, and status. Auth required (API key).",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "get_standing_order",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'list_standing_orders'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "cancel_standing_order",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ted actions are NOT reversed. Auth required (API key).",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "create_monitor",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "s to webhook=true if omitted. Auth required (API key).",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "list_monitors",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ert and balance_threshold (when watching the API key holder rather than a third-party address). For delegation_expiry",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "list_monitors",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'create_monitor'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "cancel_monitor",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "r stops firing notifications. Auth required (API key).",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "withdraw",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "prefer \"amount\" in new code.) Requires MERX_API_KEY.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "resource_broadcast",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "it for delegation, broadcast. Requires MERX_API_KEY with the \"broadcast\" scope, and a pre-signed transaction. Return",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "resource_broadcast",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'ensure_resources'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "register_agent",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ant to use as the on-chain identity for this API key. Idempotent — calling twice with the same key returns the existi",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "register_agent",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'request_payment'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "request_payment",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'register_agent'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "lookup_invoice",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'create_invoice'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "agent_status",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "ight activity your agent has. Auth required (API key) and agent must be registered first via register_agent.",
   "seen_at": "2026-08-14T06:17:15.856Z"
  },
  {
   "tool": "agent_status",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'register_agent'",
   "seen_at": "2026-08-14T06:17:15.856Z"
  }
 ],
 "probes": [
  {
   "status": "OK",
   "n_tools": 66,
   "ran_at": "2026-08-14T06:17:15.856Z"
  }
 ]
}