Security & Testing
fingersai.co
Provides tools for verifying entities, checking payee legitimacy, and assessing merchant trust scores.
ENDPOINT 1
https://fingersai.co/mcp
MCP server metadata
- Name
- fingers
- Version
- 1.0.0
Call `verify` before acting on anything you can't be sure of. Branch on recommended_action; anything other than 'proceed' means do not act yet.
Known tools 50
x402_leaderboardThe honest x402 trust index: merchants ranked by real unique payers (facilitator-verified), not raw volume.
Inferred read-onlyx402_profileFull free trust profile for one x402 merchant: identity/origin, demand, reputation, safety flags, and what could not be verified.
Inferred read-onlyresolve_entityFIRST STOP for a name/entity question: 'what is X', 'when did X come out / launch', 'is X legit / a rug', 'who is X', or a bare proper noun / ticker.
Inferred read-onlyonchain_lookupBasic onchain picture of an address on any supported EVM chain: contract or not, code size, native balance, and whether it's an EIP-1967 upgradeable proxy (and its implementation).
Inferred read-onlyread_contractCall a view/pure function to resolve an exact fact on any supported EVM chain.
Inferred read-onlyetherscan_lookupEtherscan verified-source metadata for a contract: its ACTUAL name (e.g.
Inferred read-onlynft_floor_priceLIVE floor price of an NFT collection, fetched right now from Alchemy (OpenSea + LooksRare).
Inferred read-onlynft_infoNFT COLLECTION info (name, standard, total supply, holder count) for a chain that has NO marketplace floor source, ESPECIALLY ROBINHOOD CHAIN.
Inferred read-onlyfind_collectionsResolve a collection NAME to the right CONTRACT via CoinGecko's curated NFT index.
Inferred read-onlytoken_priceLIVE price + market snapshot for a crypto TOKEN/coin (not an NFT) from CoinGecko: current USD price, 24h and 7d change, market cap, 24h volume, all-time high and how far below it is.
Inferred read-onlyprice_historyRecent price MOVEMENT of a crypto token over the last N days: price path, high/low, net change, range, how many intervals moved down, biggest drawdown, and a sparkline.
Inferred read-onlynft_floor_historyHistorical NFT FLOOR over the last N days from CoinGecko, for one collection or a COMPARISON of two.
Inferred read-onlydex_tokenLIVE price, 24h change, volume and liquidity for ANY token trading on a DEX, across ~all chains INCLUDING SOLANA and ROBINHOOD CHAIN (ethereum, base, arbitrum, optimism, polygon, bsc, solana, robinhood), by contract address or by name/ticker.
Inferred read-onlyproject_linksFind and VERIFY a project's WEBSITE, SOCIALS, and CODE REPOS from every free source (DexScreener + GeckoTerminal + CoinGecko) and check each repo's liveness (GitHub / GitLab / Bitbucket: stars, last push, archived).
Inferred read-onlymarket_moversScan and RANK a whole chain's most-traded tokens by 24h price move — the biggest GAINERS or LOSERS right now.
Inferred read-onlyprediction_marketLIVE prediction-market data from Polymarket (the biggest prediction market).
Inferred read-onlytoken_securityLIVE token SAFETY/rug-risk profile from GoPlus for a fungible token: honeypot, buy/sell tax, open-source, proxy, mintable, can-take-back-ownership, hidden owner, transfer-pausable, blacklist power, owner/creator holdings %, holder count, top-10 holder concentration, total liquidity, and how much of the LP is locked or burned (the #1 rug signal).
Potential side effectsstock_quoteLIVE US stock/equity quote from Financial Modeling Prep, by ticker OR company name (e.g.
Inferred read-onlytokenized_stockVerify a TOKENIZED STOCK on ROBINHOOD CHAIN against Robinhood's OWN issuer registry: is this the GENUINE Robinhood-issued token (matched to the exact contract in api.robinhood.com/rhj) or a same-name COPYCAT/impersonator, is it TRACKING the real equity (healthy peg, multiplier-aware) or DE-PEGGED, and the disclosure that these are tokenized DEBT not equity.
Inferred read-onlyrobinhood_token_safetyFull safety scan for a ROBINHOOD-CHAIN token by 0x address, reconciling THREE sources: GoPlus (HONEYPOT, buy/sell tax, can't-sell-all, blacklist, pausable, mintable -- the sellability verdict), Blockscout (verified source, holders, top-holder CONCENTRATION, creator), and the DEX (liquidity).
Inferred read-onlyrobinhood_honeypot_simREAL-TIME honeypot check for a ROBINHOOD-CHAIN token: SIMULATES an actual buy then sell against the token's own V3 pool (no funds move) and reports whether SELLING REVERTS (a honeypot) plus the round-trip tax.
Inferred read-onlyrobinhood_moversLIVE Robinhood-chain token discovery -- what's moving on Robinhood right now.
Inferred read-onlyrobinhood_clonesFind COPYCAT tokens on Robinhood Chain that share a name/symbol -- the 'runner' problem where a hit token or stock ticker gets cloned many times so buyers hit an imposter (we've seen 19 tokens named 'GP').
Inferred read-onlyrobinhood_authenticityReal-vs-FAKE checker for Robinhood Chain: is a DOMAIN the official explorer/docs or a phishing lookalike, and is a 'Robinhood Chain token / airdrop / snapshot / claim' real?
Inferred read-onlyrobinhood_nft_checkSafety check for a ROBINHOOD-CHAIN NFT collection (Anvil marketplace, Howl Street, etc).
Inferred read-onlyrobinhood_nft_valueValue the ASSETS HELD INSIDE a Robinhood-chain NFT (ERC-6551 token-bound account).
Inferred read-onlystock_safetyStock RISK/safety profile from Financial Modeling Prep: actively trading vs delisted, exchange (OTC/pink-sheet = risk), penny-stock and micro-cap flags, Altman-Z bankruptcy score (<1.8 = distress, >3 = safe) and Piotroski fundamental-health score (0-9).
Inferred read-onlystock_moversLIVE top stock movers for the current/most-recent US session from Financial Modeling Prep: biggest gainers, biggest losers, or most-active by volume.
Inferred read-onlyaddress_securityWallet/address REPUTATION from GoPlus threat feeds (SlowMist/BlockSec etc.): flags phishing, drainer/stealing attacks, money laundering, mixer use, sanctions, fake-KYC, honeypot deployment, and how many malicious contracts the address has created.
Inferred read-onlydeployer_checkDue diligence on the WALLET/DEPLOYER behind a token, NFT, or mint: how many contracts it has deployed before and when (its TRACK RECORD), how old the wallet is, plus its scam/abuse reputation.
Inferred read-onlywallet_nftsWhat NFTs a WALLET holds / has minted or collected across the main OpenSea chains (ethereum, polygon, base, arbitrum, optimism), and how active it is.
Inferred read-onlywallet_fundsFOLLOW THE MONEY: a wallet's balance and WHERE its funds moved -- the top addresses it WITHDREW to and was funded by (native ETH + internal txs + ERC-20).
Inferred read-onlycollection_teamWHO is behind an OpenSea collection / mint: the creator-owner wallet, the PAYOUT recipient wallet(s) where mint + royalty money goes, the contract, verification status, and socials.
Inferred read-onlyrug_checkOne-call MARKETPLACE RUG-RISK scorecard for an NFT mint / collection: resolves the team, vets the creator/payout wallet (scam flags, wallet age, prior deployed-contract track record), follows the mint proceeds, checks contract safety, and flags the classic launchpad-scam patterns.
Inferred read-onlytx_checkSIMULATE a transaction BEFORE signing it: what does it ACTUALLY do to your funds?
Inferred read-onlyrugcheckSOLANA rug analysis from RugCheck.xyz (the Solana-native tool traders actually use): risk flags, LP lock %, mint/freeze authority revoked, top-holder concentration, a rugged flag, AND BUNDLE / INSIDER detection (insider_holdings_pct = share held by coordinated insider/bundled wallets, insider_networks, creator_balance) -- the memecoin rug tell traders check on every buy.
Inferred read-onlypump_statuspump.fun GRADUATION + bonding-curve status for a SOLANA token: has it graduated to a real Raydium market (graduated), how far along its bonding curve (bonding_curve_progress_pct), market cap, creator.
Inferred read-onlydefillamaDeFi protocol due-diligence from DeFiLlama (keyless): TVL, category, chains, and a check against DeFiLlama's HACKS database of known past exploits (amount lost, technique, date).
Inferred read-onlysec_filingsSEC EDGAR filings for a US-listed STOCK (keyless, official primary source): recent 10-K (annual), 10-Q (quarterly), 8-K (material events), S-1, proxy filings, plus recent insider Form-4 trades.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.fingers]
url = "https://fingersai.co/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"fingers": {
"type": "http",
"url": "https://fingersai.co/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: fingers
Remote MCP URL: https://fingersai.co/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"fingers": {
"url": "https://fingersai.co/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"fingers": {
"type": "http",
"url": "https://fingersai.co/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "fingers",
"transport": "streamable-http",
"url": "https://fingersai.co/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Trust Data Available
BuiltWith Trust API v2 evidence for fingersai.co was fetched 2026-08-29T14:06:05.496Z.
fingersai.co is assessed as Neutral: No suspicious signals found, but no strong positive signal either
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.