Product Description
# Seller QA and Security MCP Suite - Team License
The full source of the Seller QA and Security MCP Suite for teams that want to run it in their own pipeline instead of installing a released build.
| | |
| --- | --- |
| Version | 1.0.0 |
| Price | 299 USD |
| Licence | Team |
| Entry point | `README.md` |
| Source | MCP_SUITE source tree plus CI configuration |
## What it does
Full source of the four MCP servers with CI configuration and twelve months of updates.
## Tools
| Tool | Description |
| --- | --- |
| `scan_secrets` | Scan a directory tree for API keys, private keys and credentials. Returns redacted findings. |
| `check_permissions` | Compare declared role permissions against a least-privilege policy. |
| `ssrf_audit` | Audit URLs against a policy that denies private, loopback and link-local targets. |
| `read_only_report` | Report the read-only posture of a directory and an optional permissions manifest. |
| `score_listing` | Score a listing against the 120-point rubric and return every lost point. |
| `seo_validate` | Validate title, description, tags and images for search readiness. |
| `improve_listing` | Return the fix list for a listing, biggest recoverable points first. |
| `verify_payment` | Confirm recipient, amount, status and timestamp for one transaction. |
| `recent_orders` | Summarise recent transactions for a wallet. |
| `wallet_status` | Report wallet address, network and read-only posture. Never signs. |
| `preflight_publish` | Dry-run a publish against the marketplace gate rules. Writes nothing and calls no platform. |
| `reconcile_listing` | Compare local listing records against a platform report. |
| `verify_expectation` | Verify an expected value against an observed one, with optional numeric tolerance. |
## Network
Allow-listed gateways only: `api.trongrid.io`, `tronscan.org`, `bsc-dataseed.binance.org`, `bsc-dataseed1.binance.org`.
## Security
- Read-only: no file is written and no process is started.
- Findings are redacted before they are returned.
- Paths are confined to the root you pass.
## Requirements
- Python 3.10 or above
- No account, no API key, no telemetry
## Agent Skills
| Skill | Purpose |
| --- | --- |
| `pre-publish-security-gate` | Run the leak and permission checks before anything is published. |
| `listing-audit-triage` | Turn a listing score into an ordered fix list. |
| `payment-verification-triage` | Confirm a USDT payment before delivering an order. |
| `pre-publish-gate` | Dry-run the marketplace gate and see every blocker first. |
## Tests
```bash
python -m pytest -q # suite tests for this server
```
Every security claim above names a test that exists:
- `test_ssrf_blocks_private_network`
- `test_no_subprocess_spawn`
## Licence and exclusions
- Single-seat licence unless a team licence is stated above.
- No shell execution, no browser or account automation, no key custody.
- The exclusion list is published in `security/EXCLUSIONS.md` in the team
bundle so a reviewer can check it independently.
What you get
1 file · 252.2 KB
- mcp-suite-team_v1.zipZIP · 252.2 KB