ProfitCollector
22 pay-per-call developer, security, network and data utilities using x402 on Base.
我该使用它吗
质量与安全性
发现(9)
- LOW在 post_security_repo_risk_report_standard 中
- LOW在 post_security_repo_risk_report_deep 中
- LOW在 post_json_pretty 中
- LOW在 post_base64_encode 中
- LOW在 post_base64_decode 中
- LOW在 post_security_repo_risk_report_standard 中
- LOW在 post_security_repo_risk_report_deep 中
- LOW在 post_security_repo_risk_report_due_diligence 中
- LOW在 post_quebec_invoice_compliance_check 中
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"profitcollector": {
"url": "https://mcp.bakhour.ca/mcp"
}
}
}远程端点
https://mcp.bakhour.ca/mcpstreamable-http它能做什么
工具清单
工具(31)
🟢get_dns_lookup(domain, record_type)
Resolve ONE DNS record type for a domain. For all record types at once use /domain/intelligence; for a bundled DNS+TLS+headers audit use /web/audit or /security/posture; for mail-security plus a scored verdict use /domain/due-diligence.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"title": "Domain"
},
"record_type": {
"type": "string",
"default": "A",
"title": "Record Type"
}
},
"required": [
"domain"
],
"additionalProperties": false
}🟢get_jwt_decode(token)
Decode a JWT payload without signature verification.
输入模式
{
"type": "object",
"properties": {
"token": {
"type": "string",
"title": "Token"
}
},
"required": [
"token"
],
"additionalProperties": false
}🟢get_subnet_calculate(cidr)
Calculate subnet information from CIDR notation.
输入模式
{
"type": "object",
"properties": {
"cidr": {
"type": "string",
"title": "Cidr"
}
},
"required": [
"cidr"
],
"additionalProperties": false
}🟡post_json_repair(text)
Repair common malformed JSON formatting issues.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_media_image_convert
Convert an image between common formats (e.g. PNG/JPEG/WebP) from a URL or base64 payload.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟡post_security_repo_risk_report_standard(repo_url, ref)
SBOM inventory plus real OSV.dev dependency-vulnerability matches and dependency-freshness signals for a public Git repository. One-shot alternative to a per-seat secret-scanning subscription.
输入模式
{
"type": "object",
"properties": {
"repo_url": {
"type": "string",
"description": "Public https://github.com/... or https://gitlab.com/... repository URL."
},
"ref": {
"type": "string",
"description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
}
},
"required": [
"repo_url"
],
"additionalProperties": false
}🟡post_security_repo_risk_report_deep(repo_url, ref)
Everything in the standard report, plus a repo-wide secret/credential exposure scan (matched values are never returned).
输入模式
{
"type": "object",
"properties": {
"repo_url": {
"type": "string",
"description": "Public https://github.com/... or https://gitlab.com/... repository URL."
},
"ref": {
"type": "string",
"description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
}
},
"required": [
"repo_url"
],
"additionalProperties": false
}🟡post_security_repo_risk_report_due_diligence(repo_url, ref)
Everything in the deep report, plus real OpenSSF Scorecard maintainer/governance signals and a prioritized recommendation. An automated baseline positioned against $5,000-$95,000 human technical due diligence.
输入模式
{
"type": "object",
"properties": {
"repo_url": {
"type": "string",
"description": "Public https://github.com/... or https://gitlab.com/... repository URL."
},
"ref": {
"type": "string",
"description": "Optional branch/tag to analyze. Defaults to the repository's default branch."
}
},
"required": [
"repo_url"
],
"additionalProperties": false
}🟡post_x402_service_trust_report(target_url, target_method)
Live, on-demand check of ONE x402-protected endpoint before you pay it: payment-requirements structure, TLS certificate, payTo on-chain balance, known-asset recognition, resource/host consistency, and discovery-manifest cross-check -- not a cached aggregate reputation score.
输入模式
{
"type": "object",
"properties": {
"target_url": {
"type": "string",
"description": "The full https:// URL of the x402-protected endpoint to evaluate."
},
"target_method": {
"type": "string",
"enum": [
"GET",
"POST"
],
"description": "HTTP method to request target_url with. Defaults to GET; use POST for action-style endpoints that only 402-challenge on POST."
}
},
"required": [
"target_url"
],
"additionalProperties": false
}🟡post_freshdep_scan(repo_url, ref, threshold_days)
Flags pinned dependencies in a repository's requirements.txt, package-lock.json, or uv.lock published more recently than a freshness threshold -- a supply-chain-compromise tripwire. Free CLI (requirements.txt/package-lock.json only, uv.lock support pending there): github.com/sbakhour/freshdep.
输入模式
{
"type": "object",
"properties": {
"repo_url": {
"type": "string",
"description": "Full https://github.com/<owner>/<repo> URL to scan."
},
"ref": {
"type": "string",
"description": "Optional branch/tag to check out instead of the default branch."
},
"threshold_days": {
"type": "number",
"description": "Flag anything published more recently than this many days ago. Defaults to 7."
}
},
"required": [
"repo_url"
],
"additionalProperties": false
}🟡post_quebec_invoice_compliance_check(subtotal, gst_amount, qst_amount, english_text, french_text)
Verifies GST/QST were calculated correctly per Revenu Quebec's current (non-compounded) formula, and flags whether a French invoice version is present per Charter of the French Language s.57/89/91. Pure arithmetic + text check; not legal or tax advice.
输入模式
{
"type": "object",
"properties": {
"subtotal": {
"type": "number",
"description": "Pre-tax subtotal in CAD."
},
"gst_amount": {
"type": "number",
"description": "GST amount as shown on the invoice."
},
"qst_amount": {
"type": "number",
"description": "QST amount as shown on the invoice."
},
"english_text": {
"type": "string",
"description": "The invoice's primary/other-language text (optional but needed for the language check)."
},
"french_text": {
"type": "string",
"description": "The invoice's French text, if any (optional -- its absence is itself flagged)."
}
},
"required": [
"subtotal",
"gst_amount",
"qst_amount"
],
"additionalProperties": false
}🟡post_quebec_invoice_generate(invoice_number, seller_name, seller_gst_number, seller_qst_number, line_items)
Assembles a bilingual (French/English) Quebec invoice document with GST/QST computed exactly per Revenu Quebec's current formula -- you supply both languages' line-item text, this does not translate. Not legal or tax advice.
输入模式
{
"type": "object",
"properties": {
"invoice_number": {
"type": "string",
"description": "Your own invoice number/reference."
},
"seller_name": {
"type": "string",
"description": "Seller/business name to display."
},
"seller_gst_number": {
"type": "string",
"description": "GST registration number, optional."
},
"seller_qst_number": {
"type": "string",
"description": "QST registration number, optional."
},
"line_items": {
"type": "array",
"description": "Each item needs description_en, description_fr (both required -- this assembles, it does not translate), and amount.",
"items": {
"type": "object",
"properties": {
"description_en": {
"type": "string"
},
"description_fr": {
"type": "string"
},
"amount": {
"type": "number"
}
},
"required": [
"description_en",
"description_fr",
"amount"
]
}
}
},
"required": [
"invoice_number",
"seller_name",
"line_items"
],
"additionalProperties": false
}🟡post_json_validate(text)
Validate JSON text and return parsing details.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_json_pretty(text)
Pretty-print valid JSON text.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_json_minify(text)
Minify valid JSON text.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_base64_encode(text)
Encode UTF-8 text using Base64.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_base64_decode(text)
Decode Base64 to UTF-8 text.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_hash_sha256(text)
Generate SHA-256 digest from text.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟡post_hash_sha512(text)
Generate SHA-512 digest from text.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟢get_uuid_generate(count)
Generate a random UUID version 4.
输入模式
{
"type": "object",
"properties": {
"count": {
"type": "integer",
"default": 1,
"title": "Count"
}
},
"additionalProperties": false
}🟢get_url_parse(url)
Parse a URL into structured components.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"title": "Url"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟡post_text_stats(text)
Calculate character, word, line and byte statistics.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🔴post_text_dedupe_lines(text)
Remove duplicate lines while preserving original order.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟢get_timestamp_convert(timestamp)
Convert a Unix timestamp to UTC ISO-8601.
输入模式
{
"type": "object",
"properties": {
"timestamp": {
"type": "number",
"title": "Timestamp"
}
},
"required": [
"timestamp"
],
"additionalProperties": false
}🟡post_domain_due_diligence(domain)
The most comprehensive domain assessment: DNS + mail security (SPF/DKIM/DMARC) + TLS + HTTP headers, scored. The only endpoint in this group that adds mail-security analysis. Use for a one-shot decision-grade verdict on an unfamiliar domain; use /dns/lookup, /ssl/check, /security/headers, /web/audit or /security/posture instead for a single fact or a cheaper signal.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"minLength": 1,
"title": "Domain",
"description": "Public domain name to assess",
"examples": [
"example.com"
]
}
},
"required": [
"domain"
],
"additionalProperties": false
}🟢get_domain_intelligence(domain)
Collect ALL common DNS record types (A/AAAA/MX/NS/TXT/CAA) for a domain in one call -- the multi-record bundle version of /dns/lookup.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"title": "Domain"
}
},
"required": [
"domain"
],
"additionalProperties": false
}🟢get_web_audit(url)
Consolidated DNS, TLS and HTTP security audit for a public HTTPS website, returned as RAW findings (no score) -- the bundled version of /dns/lookup + /ssl/check + /security/headers. Use /security/posture instead for a 0-100 score/grade.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"title": "Url"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟢get_security_posture(url)
Assess TLS and HTTP security posture for a public HTTPS website -- the SAME inspection as /web/audit, but returns a 0-100 score/grade and findings instead of raw fields.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"title": "Url"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟡post_data_transform(text, operation)
Normalize and transform common structured text automatically.
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string"
},
"operation": {
"type": "string",
"enum": [
"auto",
"json_pretty",
"json_minify",
"base64_encode",
"base64_decode",
"dedupe_lines"
],
"default": "auto"
}
},
"required": [
"text"
],
"additionalProperties": false
}🟢get_security_headers(url)
Inspect HTTP security headers for ONE URL only. For headers combined with TLS and DNS, use /web/audit (raw) or /security/posture (scored).
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"title": "Url"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟢get_ssl_check(hostname)
Inspect the TLS certificate for ONE hostname only. For TLS combined with HTTP headers and DNS, use /web/audit (raw) or /security/posture (scored).
输入模式
{
"type": "object",
"properties": {
"hostname": {
"type": "string",
"title": "Hostname"
}
},
"required": [
"hostname"
],
"additionalProperties": false
}推荐提示词
get_dns_lookupget_dns_lookup社区
证据