Back to Browse

Shopify 16 Tools for Ecommerce MCP Server

Business ToolsModerate7.2LocalRemoteNew
Free

16 Shopify commerce tools for MCP agents, from product discovery to checkout.

About

Grandmaster MCP is a remote MCP server running on a Cloudflare Worker. It exposes 16 tools for Shopify product discovery, merchant storefront catalogs, carts, checkouts, and store policies and FAQs. Global catalog tools call Shopify's global catalog; merchant-specific tools forward requests to the domain supplied for that merchant. The server passes the upstream response back to the MCP client.

The tools are grouped into global catalog (3), storefront catalog (3), cart (4), checkout (5), and policies/FAQs (1). Cart and checkout actions operate on the merchant specified in each call. Completing a checkout can place an order and requires the buyer's authorization.

Security Report

7.2
Moderate7.2Low Risk

This is a Shopify UCP MCP server that provides tools for catalog search, cart management, and checkout operations. The server properly delegates to Shopify-hosted APIs and uses Zod for input validation. However, there are moderate-severity concerns around error handling (broad exception catching, potential information disclosure), input validation (passthrough schemas allowing arbitrary data), and unauthenticated access to sensitive operations. Permissions align with the server's commerce purpose, but defensive coding practices could be improved.

2 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Getting Started

Once installed, try these example prompts and explore these capabilities:

  • 11. Add `https://grand-master-mcp.anigok.com/mcp` as a remote MCP server in your client.
  • 22. For global discovery, ask: "Search the global Shopify catalog for trail running shoes." This uses `global_search_catalog` and does not require a merchant domain.
  • 33. For a particular store, provide its `shop_domain` and a UCP agent profile URL, then ask: "Search this store for a blue jacket." This uses `search_catalog`. If you do not have your own profile, use `https://ucp-agent-profile.facetimefy.com/ucp/agent-profiles/2026-08-25/valid-with-capabilities.json` for `_meta["ucp-agent"].profile`.
  • 44. Review cart and checkout results before changing them. Use `complete_checkout` only after the buyer authorizes the purchase and payment.

Reviews

No reviews yet

Be the first to review this server!