Atlas / MCP servers / pwh-pwh / Coin

CoinSAFE

mcp/pwh-pwh/coin

use Bitget’s API to get cryptocurrency info

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
MIT
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Welcome to the Coin MCP Server – your one-stop shop for snagging the latest cryptocurrency prices faster than you can say "To the moon!" 🌙 Built with FastMCP and spiced up with zod for validation, this little server is here to fetch token prices from Bitget’s API like a trusty crypto butler. 🧑💼

中文文档 | English

What Does It Do? 🤔

This project spins up a server that lets you query the current price of any cryptocurrency (paired with USDT) using Bitget’s slick API. Want to know how much your favorite token is worth right now? Just ask, and boom – the price is yours! 💸

  • Tool: getTokenPrice
  • Mission: Fetch the latest price of a token (e.g., BGB, BTC, ETH).
  • Superpower: It’s fast, it’s simple, and it’s powered by FastMCP! ⚡
  • Tool: getAnnoucements
  • Mission: get annoucements
  • Tool: getCoinInfo
  • Mission: Get detailed information about a specified token.
  • Superpower: Provides detailed information such as token transferability, supported chain list, chain network status, etc.

Features 🌟

  • 🎯 Dead-Simple API: Pass a token symbol, get a price. No fuss, no muss.
  • 🛡️ Zod Validation: Parameters are checked tighter than a vault door.
  • 📡 Bitget Integration: Pulls live data straight from Bitget’s market ticker API.
  • 🧠 Error Handling: Catches hiccups like a pro and logs them for you to giggle at later.

Getting Started 🏁

Ready to dive into the crypto price pool? Here’s how to get this baby running:

Prerequisites

  • Deno: You’ll need Deno installed because we’re fancy and modern. Grab it here.
  • Bitget API Access: No API key needed – we’re hitting the public endpoint like champs! But if you’ve got a custom BGURL, set it as an environment variable.

Installation

  1. Clone this repo like it’s hot:
git clone https://github.com/pwh-pwh/coin-mcp-server.git
cd coin-mcp-server
  1. Inst
Read from source at commit 73dff4c77362OBSERVED · 2026-10-09
02

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
getAnnoucementsreadSearch for cryptocurrency announcements within one month .parameter anType is announcement type\nAnnouncement type\n
getCoinInforeadGet spot coin information。Parameter:coin - Coin name\nResponse Parameters \n
getTokenPricereadget the current price of cryptocurrency
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:41
- **Bitget API Access**: No API key needed – we’re hitting the public endpoint like champs! But if you’ve got a custom `BGURL`, set it as an environment variable.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 73dff4c77362full audit observations/trust-audit/mcp-server/pwh-pwh__coin.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0973dff4c77362SAFEB89first audit
05

Questions

What is the Coin MCP server?

use Bitget’s API to get cryptocurrency info

What tools does Coin expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Coin safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Coin need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (73dff4c77362), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement