ProfitCollector

22 pay-per-call developer, security, network and data utilities using x402 on Base.

Should I use this

Quality & Safety

A
Description quality
91%
Schema completeness
83%
Naming quality
85%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (9)

  • LOWTool 'post_security_repo_risk_report_standard' description lacks action verbin post_security_repo_risk_report_standard
  • LOWTool 'post_security_repo_risk_report_deep' description lacks action verbin post_security_repo_risk_report_deep
  • LOWTool 'post_json_pretty' description lacks action verbin post_json_pretty
  • LOWTool 'post_base64_encode' description lacks action verbin post_base64_encode
  • LOWTool 'post_base64_decode' description lacks action verbin post_base64_decode
  • LOWTool 'post_security_repo_risk_report_standard' name length outside 3-30 rangein post_security_repo_risk_report_standard
  • LOWTool 'post_security_repo_risk_report_deep' name length outside 3-30 rangein post_security_repo_risk_report_deep
  • LOWTool 'post_security_repo_risk_report_due_diligence' name length outside 3-30 rangein post_security_repo_risk_report_due_diligence
  • LOWTool 'post_quebec_invoice_compliance_check' name length outside 3-30 rangein post_quebec_invoice_compliance_check

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,689Tokens (tool definitions)
~600 BTypical response size
Significant attention impact (2.10% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "profitcollector": {
      "url": "https://mcp.bakhour.ca/mcp"
    }
  }
}

Remote endpoints

https://mcp.bakhour.ca/mcpstreamable-http

What it can do

Tool inventory

Tools (31)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢get_dns_lookup(domain, record_type)

Resolve ONE DNS record type for a domain. For all record types at once use /domain/intelligence; for a bundled DNS+TLS+headers audit use /web/audit or /security/posture; for mail-security plus a scored verdict use /domain/due-diligence.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "title": "Domain"
    },
    "record_type": {
      "type": "string",
      "default": "A",
      "title": "Record Type"
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}
🟢get_jwt_decode(token)

Decode a JWT payload without signature verification.

Input Schema

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string",
      "title": "Token"
    }
  },
  "required": [
    "token"
  ],
  "additionalProperties": false
}
🟢get_subnet_calculate(cidr)

Calculate subnet information from CIDR notation.

Input Schema

{
  "type": "object",
  "properties": {
    "cidr": {
      "type": "string",
      "title": "Cidr"
    }
  },
  "required": [
    "cidr"
  ],
  "additionalProperties": false
}
🟡post_json_repair(text)

Repair common malformed JSON formatting issues.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_media_image_convert

Convert an image between common formats (e.g. PNG/JPEG/WebP) from a URL or base64 payload.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡post_security_repo_risk_report_standard(repo_url, ref)

SBOM inventory plus real OSV.dev dependency-vulnerability matches and dependency-freshness signals for a public Git repository. One-shot alternative to a per-seat secret-scanning subscription.

Input Schema

{
  "type": "object",
  "properties": {
    "repo_url": {
      "type": "string",
      "description": "Public https://github.com/... or https://gitlab.com/... repository URL."
    },
    "ref": {
      "type": "string",
      "description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
    }
  },
  "required": [
    "repo_url"
  ],
  "additionalProperties": false
}
🟡post_security_repo_risk_report_deep(repo_url, ref)

Everything in the standard report, plus a repo-wide secret/credential exposure scan (matched values are never returned).

Input Schema

{
  "type": "object",
  "properties": {
    "repo_url": {
      "type": "string",
      "description": "Public https://github.com/... or https://gitlab.com/... repository URL."
    },
    "ref": {
      "type": "string",
      "description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
    }
  },
  "required": [
    "repo_url"
  ],
  "additionalProperties": false
}
🟡post_security_repo_risk_report_due_diligence(repo_url, ref)

Everything in the deep report, plus real OpenSSF Scorecard maintainer/governance signals and a prioritized recommendation. An automated baseline positioned against $5,000-$95,000 human technical due diligence.

Input Schema

{
  "type": "object",
  "properties": {
    "repo_url": {
      "type": "string",
      "description": "Public https://github.com/... or https://gitlab.com/... repository URL."
    },
    "ref": {
      "type": "string",
      "description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
    }
  },
  "required": [
    "repo_url"
  ],
  "additionalProperties": false
}
🟡post_x402_service_trust_report(target_url, target_method)

Live, on-demand check of ONE x402-protected endpoint before you pay it: payment-requirements structure, TLS certificate, payTo on-chain balance, known-asset recognition, resource/host consistency, and discovery-manifest cross-check -- not a cached aggregate reputation score.

Input Schema

{
  "type": "object",
  "properties": {
    "target_url": {
      "type": "string",
      "description": "The full https:// URL of the x402-protected endpoint to evaluate."
    },
    "target_method": {
      "type": "string",
      "enum": [
        "GET",
        "POST"
      ],
      "description": "HTTP method to request target_url with. Defaults to GET; use POST for action-style endpoints that only 402-challenge on POST."
    }
  },
  "required": [
    "target_url"
  ],
  "additionalProperties": false
}
🟡post_freshdep_scan(repo_url, ref, threshold_days)

Flags pinned dependencies in a repository's requirements.txt, package-lock.json, or uv.lock published more recently than a freshness threshold -- a supply-chain-compromise tripwire. Free CLI (requirements.txt/package-lock.json only, uv.lock support pending there): github.com/sbakhour/freshdep.

Input Schema

{
  "type": "object",
  "properties": {
    "repo_url": {
      "type": "string",
      "description": "Full https://github.com/<owner>/<repo> URL to scan."
    },
    "ref": {
      "type": "string",
      "description": "Optional branch/tag to check out instead of the default branch."
    },
    "threshold_days": {
      "type": "number",
      "description": "Flag anything published more recently than this many days ago. Defaults to 7."
    }
  },
  "required": [
    "repo_url"
  ],
  "additionalProperties": false
}
🟡post_quebec_invoice_compliance_check(subtotal, gst_amount, qst_amount, english_text, french_text)

Verifies GST/QST were calculated correctly per Revenu Quebec's current (non-compounded) formula, and flags whether a French invoice version is present per Charter of the French Language s.57/89/91. Pure arithmetic + text check; not legal or tax advice.

Input Schema

{
  "type": "object",
  "properties": {
    "subtotal": {
      "type": "number",
      "description": "Pre-tax subtotal in CAD."
    },
    "gst_amount": {
      "type": "number",
      "description": "GST amount as shown on the invoice."
    },
    "qst_amount": {
      "type": "number",
      "description": "QST amount as shown on the invoice."
    },
    "english_text": {
      "type": "string",
      "description": "The invoice's primary/other-language text (optional but needed for the language check)."
    },
    "french_text": {
      "type": "string",
      "description": "The invoice's French text, if any (optional -- its absence is itself flagged)."
    }
  },
  "required": [
    "subtotal",
    "gst_amount",
    "qst_amount"
  ],
  "additionalProperties": false
}
🟡post_quebec_invoice_generate(invoice_number, seller_name, seller_gst_number, seller_qst_number, line_items)

Assembles a bilingual (French/English) Quebec invoice document with GST/QST computed exactly per Revenu Quebec's current formula -- you supply both languages' line-item text, this does not translate. Not legal or tax advice.

Input Schema

{
  "type": "object",
  "properties": {
    "invoice_number": {
      "type": "string",
      "description": "Your own invoice number/reference."
    },
    "seller_name": {
      "type": "string",
      "description": "Seller/business name to display."
    },
    "seller_gst_number": {
      "type": "string",
      "description": "GST registration number, optional."
    },
    "seller_qst_number": {
      "type": "string",
      "description": "QST registration number, optional."
    },
    "line_items": {
      "type": "array",
      "description": "Each item needs description_en, description_fr (both required -- this assembles, it does not translate), and amount.",
      "items": {
        "type": "object",
        "properties": {
          "description_en": {
            "type": "string"
          },
          "description_fr": {
            "type": "string"
          },
          "amount": {
            "type": "number"
          }
        },
        "required": [
          "description_en",
          "description_fr",
          "amount"
        ]
      }
    }
  },
  "required": [
    "invoice_number",
    "seller_name",
    "line_items"
  ],
  "additionalProperties": false
}
🟡post_json_validate(text)

Validate JSON text and return parsing details.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_json_pretty(text)

Pretty-print valid JSON text.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_json_minify(text)

Minify valid JSON text.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_base64_encode(text)

Encode UTF-8 text using Base64.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_base64_decode(text)

Decode Base64 to UTF-8 text.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_hash_sha256(text)

Generate SHA-256 digest from text.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟡post_hash_sha512(text)

Generate SHA-512 digest from text.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟢get_uuid_generate(count)

Generate a random UUID version 4.

Input Schema

{
  "type": "object",
  "properties": {
    "count": {
      "type": "integer",
      "default": 1,
      "title": "Count"
    }
  },
  "additionalProperties": false
}
🟢get_url_parse(url)

Parse a URL into structured components.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "title": "Url"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟡post_text_stats(text)

Calculate character, word, line and byte statistics.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🔴post_text_dedupe_lines(text)

Remove duplicate lines while preserving original order.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟢get_timestamp_convert(timestamp)

Convert a Unix timestamp to UTC ISO-8601.

Input Schema

{
  "type": "object",
  "properties": {
    "timestamp": {
      "type": "number",
      "title": "Timestamp"
    }
  },
  "required": [
    "timestamp"
  ],
  "additionalProperties": false
}
🟡post_domain_due_diligence(domain)

The most comprehensive domain assessment: DNS + mail security (SPF/DKIM/DMARC) + TLS + HTTP headers, scored. The only endpoint in this group that adds mail-security analysis. Use for a one-shot decision-grade verdict on an unfamiliar domain; use /dns/lookup, /ssl/check, /security/headers, /web/audit or /security/posture instead for a single fact or a cheaper signal.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1,
      "title": "Domain",
      "description": "Public domain name to assess",
      "examples": [
        "example.com"
      ]
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}
🟢get_domain_intelligence(domain)

Collect ALL common DNS record types (A/AAAA/MX/NS/TXT/CAA) for a domain in one call -- the multi-record bundle version of /dns/lookup.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "title": "Domain"
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}
🟢get_web_audit(url)

Consolidated DNS, TLS and HTTP security audit for a public HTTPS website, returned as RAW findings (no score) -- the bundled version of /dns/lookup + /ssl/check + /security/headers. Use /security/posture instead for a 0-100 score/grade.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "title": "Url"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟢get_security_posture(url)

Assess TLS and HTTP security posture for a public HTTPS website -- the SAME inspection as /web/audit, but returns a 0-100 score/grade and findings instead of raw fields.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "title": "Url"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟡post_data_transform(text, operation)

Normalize and transform common structured text automatically.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string"
    },
    "operation": {
      "type": "string",
      "enum": [
        "auto",
        "json_pretty",
        "json_minify",
        "base64_encode",
        "base64_decode",
        "dedupe_lines"
      ],
      "default": "auto"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
🟢get_security_headers(url)

Inspect HTTP security headers for ONE URL only. For headers combined with TLS and DNS, use /web/audit (raw) or /security/posture (scored).

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "title": "Url"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟢get_ssl_check(hostname)

Inspect the TLS certificate for ONE hostname only. For TLS combined with HTTP headers and DNS, use /web/audit (raw) or /security/posture (scored).

Input Schema

{
  "type": "object",
  "properties": {
    "hostname": {
      "type": "string",
      "title": "Hostname"
    }
  },
  "required": [
    "hostname"
  ],
  "additionalProperties": false
}

Recommended Prompts

retrieve_data
Get details about [item] from ProfitCollector
Expected tools: get_dns_lookup
fetch_info
Fetch [information type] using ProfitCollector
Expected tools: get_dns_lookup

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded31 tools
verifiedversion not recorded31 tools
verifiedversion not recorded31 tools