Atlas / MCP servers / fewsats / Amazon Shopping

Amazon ShoppingSAFE

mcp/fewsats/amazon-shopping

Amazon MCP server to search & buy products using the L402

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
6 3r · 3w · 0d
Transport
streamable-http
License
—
Stars
81
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ This project has been discontinued and is no longer maintained. No further updates, bug fixes, or support will be provided. The repository is archived for reference only.

This integration allows you to search and buy Amazon products directly through your AI assistant. Shop Amazon's vast catalog by simply chatting with Claude!

What You Need

  1. Claude Desktop App - Your AI shopping assistant
  2. Fewsats Account - Required for secure payments (takes 2 minutes to set up)

Quick Setup Guide

Step 1: Install Claude Desktop App

  1. Download Claude from claude.ai/download
  2. Install and open the app

Step 2: Set Up Fewsats

  1. Go to fewsats.com and create an account
  2. Add a payment method (credit card, Apple Pay, or Google Pay)
  3. Get your API key from app.fewsats.com/api-keys

Step 3: Configure Claude

  1. Find your Claude config file:
  2. Mac: Open Terminal and paste: open ~/Library/Application\ Support/Claude/claude_desktop_config.json
  3. Windows: Press Win+R, type %APPDATA%/Claude, and open claude_desktop_config.json
  1. Add this configuration (replace YOURFEWSATSAPI_KEY with your actual key):
{
"mcpServers": {
"Amazon": {
"command": "uvx",
"args": [
"amazon-mcp"
]
},
"Fewsats": {
"command": "env",
"args": [
"FEWSATS_API_KEY=YOUR_FEWSATS_API_KEY",
"uvx",
"fewsats-mcp"
]
}
}
}

Step 4: Install UV

UV is a small tool needed to run the Amazon integration:

  • Mac: Open Terminal and run:
curl -LsSf https://astral.sh/uv/install.sh | sh
  • Windows: Open PowerShell as Administrator and run:
irm https://astral.sh/uv/install.ps1 | iex

Start Shopping!

That's it! Now you can chat with Claude about Amazon products. Try these:

  • "Find me a c
Read from source at commit 87c64f497434OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add amazon-mcp -- uvx amazon-mcp
claude-desktop
{
  "mcpServers": {
    "amazon-mcp": {
      "command": "uvx",
      "args": [
        "amazon-mcp"
      ]
    }
  }
}
03

Exposed tools (6)

3 read · 3 write · 0 destructive.

ToolRiskDescription
amazon_get_payment_offersread
amazon_searchread
get_order_by_external_idwrite
get_order_by_payment_tokenwrite
get_user_ordersread
pay_with_x402write
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:58
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 87c64f497434full audit observations/trust-audit/mcp-server/fewsats__amazon-shopping.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0787c64f497434SAFEB88first audit
06

Questions

What is the Amazon Shopping MCP server?

Amazon MCP server to search & buy products using the L402

What tools does Amazon Shopping expose?

6 in total: 3 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Amazon Shopping safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Amazon Shopping need?

No credential environment variables were found in its source, so it appears to need none.

How does Amazon Shopping run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as amazon-mcp.

How current is this page?

The grade is for one exact copy of the source (87c64f497434), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement