Back to Browse

Quiet Menders MCP Server

Developer ToolsModerate7.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Privacy clinic + pay-per-call data APIs for AI agents via x402. Never pays or touches keys.

About

Privacy clinic + pay-per-call data APIs for AI agents via x402. Never pays or touches keys.

Remote endpoints: streamable-http: https://mcp.brianbooms.com/mcp streamable-http: https://quiet-menders-mcp.brianbooms.workers.dev/mcp

Security Report

7.2
Moderate7.2Low Risk

The Quiet Menders MCP server is a well-intentioned privacy-focused tool with proper architecture and reasonable authentication patterns via x402 payment protocol. However, several code quality and security concerns exist: the server makes unauthenticated HTTP calls to upstream endpoints without request signing, lacks input validation on some parameters, uses broad exception handling, and does not implement rate limiting or request timeouts on all paths. These issues, combined with the server's role as a relay to multiple third-party APIs, warrant a moderate risk rating despite the absence of critical vulnerabilities.

2 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Quiet Menders — MCP Server

Privacy-preserving tools for AI agents, served over MCP Streamable HTTP. Real serves, no tracking.

Live endpoint: https://quiet-menders-mcp.brianbooms.workers.dev/mcp Waystation: brianbooms.com

Tools (34)

Free clinic / waystation tools (10)

ToolWhat it does
qm_scrubPrompt-injection scan + redacted copy
qm_validate_machine_filesCheck a site's llms.txt / agent.json / robots.txt
qm_probe_endpointURL liveness: status, latency, redirects, content-type
qm_attestMint a portable sanity attestation (HMAC token)
qm_attest_verifyVerify an attestation token
qm_second_opinionAdvisory risk-pattern scan of a planned action
qm_clinic_diagnoseRestore Clinic structured read (anonymous)
qm_clinic_checkupRestore Clinic wellness checkup: 10-question self-report screening (stateless)
qm_clinic_statsAnonymous aggregate clinic counts (≥10 threshold)
qm_helpedThe Quiet Menders helped counter

Commerce tools (2)

ToolWhat it does
qm_catalogPurchasable catalog: 24 music SKUs ($0.05–$299.00), 22 data/lane items, voluntary tip routes. Read-only.
qm_buyLive 402 payment challenge for any purchasable item (products, tips, data). Challenge relay only.

Data lane tools (22) — two-phase x402

Call without the payment argument to receive the live 402 payment requirements (payment_required). Sign the payment in your own wallet / x402 client, then re-call with payment set to the base64 x402 payload — the data comes back in the tool result. The server only forwards the caller-supplied payment header to the rail: it never signs, never pays, never touches private keys, never holds funds. Prices are USDC on Base; the live 402 challenge is authoritative.

ToolPriceWhat it does
qm_data_weather$0.01Current weather + 7-day forecast for a lat/lon
qm_data_time$0.01Current local time in any IANA time zone
qm_data_geocode$0.01Place name ↔ coordinates (forward/reverse)
qm_data_crypto$0.01Live crypto spot price in fiat
qm_data_wiki$0.01Wikipedia summary + link
qm_data_dns$0.01DNS records (A/AAAA/MX/TXT/CNAME/NS/SOA/SRV)
qm_data_astronomy$0.01Sunrise/sunset/moon phase for a location + date
qm_data_holidays$0.01Public holidays by country + year
qm_data_country$0.01Country reference data (capital, region, income, coords)
qm_data_cert$0.01TLS certificate check: issuer, validity, days left
qm_data_httpcheck$0.01HTTP endpoint liveness: status, redirects, headers, timing
qm_data_iss_pass$0.01Next visible ISS flyovers for a lat/lon
qm_data_summarize$0.01Webpage summary (honors robots.txt)
qm_data_readability$0.01Clean article text extraction
qm_data_fx$0.01Fiat currency conversion at current rates
qm_data_feed$0.01RSS/Atom feed parsed to clean JSON
qm_data_sleep_tip$0.01Sleep-hygiene tip from the rotating collection
qm_data_lyric_quote$0.01Original lyric line (no third-party lyrics, no royalty issues)
qm_sleep_recommend$0.05Curated sleep-track picks by mood + minutes
qm_sleep_queue$0.10Ordered sleep queue filling the requested hours
qm_lyrics_get$0.05Full lyric text + metadata for one track
qm_playlist_build$0.10Playlist for a mood + minutes, with sync-license quotes

Resale permitted: you may resell data outputs at your own price.

Use

Point any MCP client at the live endpoint above (Streamable HTTP). server.mjs is the Cloudflare Worker source; server.json is the registry manifest.

Cline

CLI (no VS Code needed):

npm install -g cline
cline mcp add quiet-menders https://quiet-menders-mcp.brianbooms.workers.dev/mcp --transport streamableHttp

Or paste this into Cline's MCP settings (cline_mcp_settings.json):

{
  "mcpServers": {
    "quiet-menders": {
      "transport": {
        "type": "streamableHttp",
        "url": "https://quiet-menders-mcp.brianbooms.workers.dev/mcp"
      }
    }
  }
}

Restart Cline — the 34 qm_* tools show up in the MCP servers panel, ready to call.

License

MIT — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!