MCPLow riskUnclaimed
storefront-guard
Verifies a merchant storefront is legitimate before an AI agent commits payment.
maxigirl123maxigirl123/storefront-guard
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.maxigirl123/storefront-guard",
"description": "Verifies a merchant storefront is legitimate before an AI agent commits payment.",
"repository": {
"url": "https://github.com/maxigirl123/Fortik",
"source": "github"
},
"version": "0.3.2",
"packages": [
{
"registryType": "npm",
"identifier": "storefront-guard-mcp-server",
"version": "0.3.2",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Google Safe Browsing API key for scam domain checks. Optional — degrades gracefully if not set.",
"format": "string",
"isSecret": true,
"name": "GOOGLE_SAFE_BROWSING_API_KEY"
},
{
"description": "SAM.gov API key for US federal exclusions check. Optional — skipped if not set.",
"format": "string",
"isSecret": true,
"name": "SAM_GOV_API_KEY"
},
{
"description": "URLhaus Auth-Key for malware URL lookups. Optional — degrades gracefully if not set.",
"format": "string",
"isSecret": true,
"name": "URLHAUS_AUTH_KEY"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:storefront-guard-mcp-server@0.3.2Runs install scripts—None
NetworkNoneNone
Needs credentials
GOOGLE_SAFE_BROWSING_API_KEYSAM_GOV_API_KEYURLHAUS_AUTH_KEYGOOGLE_SAFE_BROWSING_API_KEYSAM_GOV_API_KEYURLHAUS_AUTH_KEYOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.3.2latestOct 7, 2026
storefront-guardOpen in Codeg