io.github.choaticpixels/wicked-mcp

Wicked MCP

The whole Wicked suite for agents: trading, DeFi/token risk, identity, reputation, memory. x402.

1.3.0
Version
remote + npm
Transport
75
Tools

Security review

Partly reviewed

Reviewed 31m ago.

  • tools: 75 tools scanned
  • metadata: scanned
  • packages: 1 checked
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    registry_search_tools, registry_tool_detail, registry_onboarding_message

Tools (75)

  • kalshi_probability

    [Trading Data API] Free, no signup required — Free, no signup required. Kalshi prediction-market probabilities. Query by category (returns the most active open markets) or a specific market ticker. **Example:** `/v1/kalshi-probability?category=crypto`

  • kalshi_market

    [Trading Data API] Single Kalshi market depth: orderbook (yes/no levels) + recent trades for a specific ticker. — Single Kalshi market depth: orderbook (yes/no levels) + recent trades for a specific ticker. **Example:** `/v1/kalshi-market?ticker=KXBTCD-26JUN1315-T64099.99`

  • funding_oi

    [Trading Data API] Aggregated perpetual-futures funding rate & open interest from Binance + Bybit, with 7-day average funding, 24h OI change, and a long/short bias signal. — Aggregated perpetual-futures funding rate & open interest from Binance + Bybit, with 7-day average funding, 24h OI change, and a long/short bias signal. **Example:** `/v1/funding-oi?symbol=BTC`

  • long_short_ratio

    [Trading Data API] Binance long/short ratios: global account, top-trader account, top-trader position, and taker buy/sell — Binance long/short ratios: global account, top-trader account, top-trader position, and taker buy/sell. Companion to funding-oi. **Example:** `/v1/long-short-ratio?symbol=BTC&period=1h`

  • orderbook

    [Trading Data API] Top-of-book depth + spread (bps) from Binance, Bybit, or Hyperliquid. — Top-of-book depth + spread (bps) from Binance, Bybit, or Hyperliquid. **Example:** `/v1/orderbook?symbol=BTC&exchange=binance&depth=10`

  • basis

    [Trading Data API] Spot-vs-perp basis (premium %) with funding-implied annualized carry — Spot-vs-perp basis (premium %) with funding-implied annualized carry. Spot from Coinbase; perp marks from Binance + Bybit. **Example:** `/v1/basis?symbol=BTC`

  • hyperliquid

    [Trading Data API] Hyperliquid perpetual context: funding (hourly), open interest, mark/oracle/mid price, premium, 24h volume — Hyperliquid perpetual context: funding (hourly), open interest, mark/oracle/mid price, premium, 24h volume. Not geo-blocked. **Example:** `/v1/hyperliquid?symbol=BTC`

  • volatility

    [Trading Data API] Deribit volatility: DVOL implied-vol index (30d forward) + latest realized volatility, for BTC or ETH. — Deribit volatility: DVOL implied-vol index (30d forward) + latest realized volatility, for BTC or ETH. **Example:** `/v1/volatility?currency=BTC`

  • sentiment

    [Trading Data API] Free, no signup required — Free, no signup required. Crypto Fear & Greed Index (alternative.me), current reading + optional history. **Example:** `/v1/sentiment?limit=7`

  • defi_tvl

    [Trading Data API] DefiLlama data: TVL by chain, stablecoin circulating supply, or yield pools. — DefiLlama data: TVL by chain, stablecoin circulating supply, or yield pools. **Example:** `/v1/defi-tvl?view=chains`

  • price

    [Trading Data API] Current spot price for crypto (Coinbase) or US equities/ETFs (Alpaca SIP), via the shared routing layer. — Current spot price for crypto (Coinbase) or US equities/ETFs (Alpaca SIP), via the shared routing layer. **Example:** `/v1/price?symbol=BTC`

  • ohlcv

    [Trading Data API] OHLCV candles (oldest-first) for crypto or stocks — OHLCV candles (oldest-first) for crypto or stocks. Routes to Alpaca SIP / Alpaca-crypto / Coinbase. **Example:** `/v1/ohlcv?symbol=NVDA&timeframe=1h&limit=100`

  • atr

    [Trading Data API] Average True Range (Wilder's) + volatility-regime classification (low/normal/high/extreme by historical percentile) — Average True Range (Wilder's) + volatility-regime classification (low/normal/high/extreme by historical percentile). Crypto or stocks. **Example:** `/v1/atr?symbol=BTC&timeframe=1h&period=14`

  • rates

    [Trading Data API] US Treasury yield curve (1M–30Y) + recession-indicator spreads (10y-2y, 10y-3m), from FRED. — US Treasury yield curve (1M–30Y) + recession-indicator spreads (10y-2y, 10y-3m), from FRED. **Example:** `/v1/rates`

  • market_clock

    [Trading Data API] US equities market clock (is_open, next_open/close) + upcoming sessions, via Alpaca — US equities market clock (is_open, next_open/close) + upcoming sessions, via Alpaca. Crypto endpoints are 24/7 and unaffected. **Example:** `/v1/market-clock`

  • market_overview

    [Trading Data API] Free, no signup required — Free, no signup required. CoinGecko global crypto stats (total market cap, 24h volume, BTC/ETH dominance) or top coins by market cap. **Example:** `/v1/market-overview`

  • gas

    [Trading Data API] Free, no signup required — Free, no signup required. Ethereum gas oracle (safe/propose/fast gas prices + base fee, in gwei), via Etherscan. **Example:** `/v1/gas`

  • fvg

    [Trading Data API] Fair Value Gap zones (standard ICT/LuxAlgo) with CE (50%), gap size, age, fill status, distance from price — Fair Value Gap zones (standard ICT/LuxAlgo) with CE (50%), gap size, age, fill status, distance from price. Standard timeframes match TradingView candles. Crypto or stocks. **Example:** `/v1/fvg?symbol=BTC&timeframe=1h`

  • liquidity_levels

    [Trading Data API] ICT liquidity levels: buy-side liquidity (above swing highs) & sell-side (below swing lows), sweep/taken status, relative-equal pools, and nearest untaken targets — ICT liquidity levels: buy-side liquidity (above swing highs) & sell-side (below swing lows), sweep/taken status, relative-equal pools, and nearest untaken targets. Crypto or stocks. **Example:** `/v1/liquidity-levels?symbol=TQQQ&timeframe=1h`

  • macro_calendar

    [Trading Data API] Free, no signup required — Free, no signup required. Upcoming US macro events (FOMC rate decisions, CPI, jobs report) with verified Fed/BLS dates, days-until, and Kalshi rate-decision odds (cut/hold/hike) for FOMC meetings. **Example:** `/v1/macro-calendar`

  • earnings_calendar

    [Trading Data API] US equity earnings announcement calendar: report date, before/after-market timing, analyst EPS estimate + count, market cap, and prior-year actual EPS — US equity earnings announcement calendar: report date, before/after-market timing, analyst EPS estimate + count, market cap, and prior-year actual EPS. Sourced live from Nasdaq's public calendar. **Example:** `/v1/earnings-calendar?date=2026-07-14&days=3`

  • momentum_score

    [Trading Data API] Multi-asset momentum verdict (bias, confidence, thesis, entry/invalidation/targets, signal readings) from the oracle.py pipeline, run on a separate Python service — Multi-asset momentum verdict (bias, confidence, thesis, entry/invalidation/targets, signal readings) from the oracle.py pipeline, run on a separate Python service. Scoped to 10 assets. **Example:** `/v1/momentum-score?symbol=BTC&timeframe=1h`

  • protocol_health_scoreboard

    [Protocol Health Oracle] Public teaser: protocol name, score, and verdict only (no components/history) across the full tracked universe — auto-ingested from DefiLlama (TVL > $1M) plus curated protocols. — Public teaser: protocol name, score, and verdict only (no components/history) across the full tracked universe — auto-ingested from DefiLlama (TVL > $1M) plus curated protocols.

  • protocol_health_list_protocols

    [Protocol Health Oracle] All tracked protocols with their latest health score and verdict. — All tracked protocols with their latest health score and verdict.

  • protocol_health_track_protocol

    [Protocol Health Oracle] Track a new protocol — Track a new protocol. Scored immediately from live GitHub + DeFiLlama data.

  • protocol_health_score

    [Protocol Health Oracle] Latest health score for one protocol: components (GitHub activity, TVL trend, treasury), source details, and score history. — Latest health score for one protocol: components (GitHub activity, TVL trend, treasury), source details, and score history.

  • protocol_health_refresh_all

    [Protocol Health Oracle] Force an immediate live re-score of all tracked protocols. — Force an immediate live re-score of all tracked protocols.

  • protocol_health_sync_universe

    [Protocol Health Oracle] Force an immediate sync of the tracked-protocol universe from DefiLlama (TVL > $1M) — Force an immediate sync of the tracked-protocol universe from DefiLlama (TVL > $1M). Runs automatically once/day; use this to trigger it on demand.

  • token_risk

    [Token Risk Oracle] Free, public, no signup — Free, public, no signup. Aggregates real on-chain risk signals from GoPlus Security for a token contract — honeypot detection, mint/ownership authority, holder & LP concentration, buy/sell tax, trust-list status — into one transparent risk score. Never a bare safe/unsafe claim: every flag GoPlus didn't return data for stays null, and the raw source data ships alongside the score.

  • broker_sync_register_user

    [Broker Sync API] Register a user with SnapTrade and get a brokerage connection-portal URL. — Register a user with SnapTrade and get a brokerage connection-portal URL.

  • broker_sync_connections

    [Broker Sync API] List a user's connected brokerage accounts (normalized). — List a user's connected brokerage accounts (normalized).

  • broker_sync_positions

    [Broker Sync API] Real positions across all of a user's connected brokerages, one normalized schema, stamped as_of. — Real positions across all of a user's connected brokerages, one normalized schema, stamped as_of.

  • broker_sync_balances

    [Broker Sync API] Cash & buying power per connected account (normalized). — Cash & buying power per connected account (normalized).

  • broker_sync_transactions

    [Broker Sync API] Transaction/activity history across brokerages. — Transaction/activity history across brokerages.

  • broker_sync_prop_firms

    [Broker Sync API] Prop-firm platform integration registry — live-verified methods (Topstep ProjectX API, FTMO MatchTrader bridge) and connection status. — Prop-firm platform integration registry — live-verified methods (Topstep ProjectX API, FTMO MatchTrader bridge) and connection status.

  • reputation_status

    [Wicked Reputation] An agent's current reputation: tier, active/unbonding stake, score, slash count, founding-member badge. http_status 404 means the wallet never registered — treat as tier 'unranked'.

  • reputation_statement

    [Wicked Reputation] An agent's full position plus real event ledger (stakes, unstakes, withdrawals, slashes). Does not include WickedAPI call volume or fees — see the `note` field.

  • reputation_query

    [Wicked Reputation] Search/rank registered agents by tier, stake, reputation or slash history. Every filter is a typed query param.

  • reputation_tiers

    [Wicked Reputation] Live tier thresholds and benefits (min stake, rate-limit multiplier, fee discount). Read at call time — thresholds are admin-configurable.

  • reputation_transparency

    [Wicked Reputation] Live transparency numbers: treasury address, custody model, unbonding cooldown, total stake, agents, slash events, founding-slot counts.

  • registry_search_tools

    [Wicked Registry] Search x402/MCP tools by real reliability data (uptime, latency, schema conformance). Works via x402 (402 carries payment instructions) or a free API key (pass api_key, or set REGISTRY_API_KEY). No key yet? Call registry_onboarding_message then registry_create_api_key to get one yourself. For a quick free check of a known tool, use registry_lookup.

  • registry_tool_detail

    [Wicked Registry] One tool's full score breakdown, component history and recent real health checks. x402 or a free API key.

  • registry_lookup

    [Wicked Registry] Free lookup: find a tool's id and headline reliability score by name or URL fragment (q), exact endpoint URL (endpoint) or category. No key or payment. Use it to check a tool before your agent pays it; follow with registry_tool_badge or registry_tool_detail.

  • registry_onboarding_message

    [Wicked Registry] Step 1 of self-onboarding. Returns the exact message YOU must sign (EIP-191 personal_sign) plus its timestamp, valid for about an hour. action=api_key (needs wallet) for a free API key, or action=register (needs name and endpoint_url) to list your own tool. This tool never signs anything.

  • registry_create_api_key

    [Wicked Registry] Step 2 of getting a free API key. Submit the wallet, the timestamp and YOUR signature over the message from registry_onboarding_message(action=api_key). The key (wr_...) is returned once - store it and pass it as api_key to registry_search_tools / registry_tool_detail. Up to 3 active keys per wallet; past the daily cap calls fall back to x402.

  • registry_featured_tools

    [Wicked Registry] Top scored active tools. Public and free.

  • registry_tool_badge

    [Wicked Registry] A tool's current composite reliability score. Public and free.

  • registry_report_tool

    [Wicked Registry] File a complaint about a tool's reliability or behaviour. Public, rate-limited; reviewed manually, never auto-suspends.

  • registry_register_tool

    [Wicked Registry] Register a tool you own so it gets real synthetic checks and a live score. Get the exact message to sign from registry_onboarding_message(action=register), sign it with owner_wallet, then call this. This tool never signs.

  • identity_sandbox_register

    [Wicked Identity] START HERE if you have no wallet or cannot sign messages. Returns a sandbox wallet + sandbox_token (no signing, no body). Then call identity_get_challenge and identity_submit_response with wallet + sandbox_token. Sandbox results are for trying the service: signed with a separate key (identity_jwks sandbox=true) and never reported as verified. Use a real wallet for an accountable identity. Limit: 10 per IP per hour.

  • identity_get_test_key

    [Wicked Identity] Get a free self-serve test API key (7-day expiry, 20 requests/min) to use as api_key on identity_status instead of paying via x402. Limit: 5 per IP per day.

  • identity_get_nonce

    [Wicked Identity] Real-wallet path, step 1: a one-time nonce + message to sign. Every signed identity call needs a fresh nonce (single-use, 5-minute TTL). Not needed for sandbox identities.

  • identity_register

    [Wicked Identity] Register a REAL wallet (no stake required). Needs your signature over identity_get_nonce's message; this tool never signs. Sandbox identities are registered by identity_sandbox_register instead.

  • identity_get_challenge

    [Wicked Identity] Request a real time-boxed liveness challenge (constrained-generation task, 30s budget). The clock starts when this returns: answer in ONE pass via identity_submit_response before `expires_at`. Real wallet: needs a fresh signed nonce (fetch + sign the nonce for the NEXT call before calling this). Sandbox: just wallet + sandbox_token.

  • identity_submit_response

    [Wicked Identity] Submit your answer to a challenge; scored pass / fail / inconclusive. A pass returns a short-lived signed assertion_token (JWT) verifiable via identity_jwks. Real wallet: needs a DIFFERENT fresh nonce than identity_get_challenge used. Sandbox: wallet + sandbox_token.

  • identity_status

    [Wicked Identity] Does a wallet currently hold a valid, unexpired assertion? No signature needed. Pays via x402, or pass api_key (get one free from identity_get_test_key) / set IDENTITY_API_KEY. Sandbox wallets are never `verified`; they report sandbox: true and sandbox_verified instead.

  • identity_jwks

    [Wicked Identity] Public RS256 keys to verify an assertion_token locally. Free. Set sandbox=true for the separate key set that signs sandbox assertions.

  • sanity_check

    [Wicked Sanity] Verify one claim before acting on it. Verdicts: supported | contradicted | unsupported | insufficient_evidence (see `data`). confidence_score is raw consistency (a "contradicted" verdict scores near 0). Policy: act on supported; treat unsupported/insufficient_evidence as unverified; reject contradicted. x402 or SANITY_API_KEY; 429 means a rate limit — see retry_after.

  • sanity_check_batch

    [Wicked Sanity] Verify up to 50 claims against one shared context in a single call — prefer this over one sanity_check per sentence. `data` is a list in the same order as `claims`.

  • memory_prepare

    Wicked Memory step 1 of every call: returns the exact `message_to_sign`. Sign it with your own wallet (EIP-191 personal_sign), then call the matching memory_* tool with the SAME arguments plus the returned timestamp, nonce and your signature. Timestamp must be within 5 minutes; nonce is single-use, so prepare again for every call.

  • memory_store

    [Wicked Memory] Store a memory (free, fair-use rate limited). A real embedding is computed at write time. Run memory_prepare with operation 'store' and these same arguments first.

  • memory_search

    [Wicked Memory] Semantic search over YOUR memories only, ranked by real cosine similarity. The one metered call: free with MEMORY_API_KEY, otherwise http_status 402 with x402 v2 instructions under `payment_required` (0.001 USDC on Base) — pay, then call again with the SAME arguments (a 402 does not consume the nonce) plus payment_signature.

  • memory_get

    [Wicked Memory] Fetch one of your memories by id (another wallet's or a deleted id returns the same 404).

  • memory_update

    [Wicked Memory] Update without overwriting: creates a new version and closes the old one (valid_until / superseded_by). Omitted fields carry over; only the current version can be updated (409 otherwise).

  • memory_history

    [Wicked Memory] Full version chain for a memory, oldest first, with valid_from / valid_until / superseded_by. Works from any version's id.

  • memory_delete

    [Wicked Memory] PERMANENTLY hard-delete a memory (right-to-be-forgotten). Default scope "chain" removes every version; "version" only this one. Only an audit row (no content) is kept.

  • memory_deletions

    [Wicked Memory] Your deletion audit log (ids, times, reasons; never content).

  • paywall_signup

    [x402 Paywall] Create a tenant account. Returns a Bearer apiKey ONCE — store it and set PAYWALL_API_KEY. Rate-limited to 5/hour per IP.

  • paywall_get_tenant

    [x402 Paywall] Your tenant record (needs PAYWALL_API_KEY).

  • paywall_list_routes

    [x402 Paywall] List your paywalled routes (needs PAYWALL_API_KEY).

  • paywall_create_route

    [x402 Paywall] Paywall a new endpoint with x402 pay-per-call, settled in USDC straight to payTo. With upstreamUrl, paid requests are proxied to your backend. Applies live within ~20s (needs PAYWALL_API_KEY).

  • paywall_import_routes

    [x402 Paywall] Bulk upsert routes keyed on (method, path) — paywall a whole API in one call (needs PAYWALL_API_KEY).

  • paywall_update_route

    [x402 Paywall] Partial update of a route (e.g. change price or payout wallet); applies live within ~20s (needs PAYWALL_API_KEY).

  • paywall_delete_route

    [x402 Paywall] Remove a paywalled route; applies within ~20s (needs PAYWALL_API_KEY).

  • paywall_list_settlements

    [x402 Paywall] Your real on-chain USDC settlements (earnings) (needs PAYWALL_API_KEY).