← MCP servers · vladimir-human

ru-marketplace-mcp

BLOCKgrade F · trust 57/100

Одиннадцать маркетплейсов и недвижимость Циан как MCP-серверы: Wildberries, Ozon, Яндекс Маркет, Детский мир, Авито, AliExpress, Taobao, Мегамаркет, Lamoda, DNS, Ситилинк, Циан. Плюс сравнение цен по всем товарным источникам одним вызовом. Только чтение, ключи не нужны.

aliexpressavitociancitilinkdetsky mirdnsdsh pluginlamoda

Overview

From the repository's own README, as read at the audited commit.

# ru-marketplace-mcp[![CI](https://github.com/Vladimir-Human/ru-marketplace-mcp/actions/workflows/ci.yml/badge.svg)](https://github.com/Vladimir-Human/ru-marketplace-mcp/actions/workflows/ci.yml)[![Python 3.12+](https://img.shields.io/badge/python-3.12%2B-blue.svg)](https://www.python.org/downloads/)[![License: MIT](https://img.shields.io/badge/license-MIT-green.svg)](LICENSE)[![MCP](https://img.shields.io/badge/MCP-stdio%20%7C%20http-orange.svg)](https://modelcontextprotocol.io)**MCP-серверы для российских и китайских маркетплейсов.** Цены, наличие,рейтинги, отзывы и реквизиты продавцов с Wildberries, Ozon, Яндекс Маркета,Детского мира, Авито, AliExpress, Taobao, Мегамаркета, Lamoda, DNS и Ситилинка.Плюс недвижимость с Циана исравнение цен по всем товарным источникам одним вызовом.Только чтение. Ключи API, токены и регистрация не нужны — площадки с жёсткиманти-ботом читаются через ваш собственный Chrome. Одно исключение по желанию:опциональный MPStats берёт платный токен (`MPSTATS_MP_AUTH`) — без него всёостальное работает как прежде.[English version below](#english-version) · [Архитектура](docs/ARCHITECTURE.md) ·[Как добавить источник](docs/ADDING_A_SOURCE.md) · [Про анти-бот](docs/ANTI_BOT.md)Для проверок в браузере добавлен опциональный режим сохранения вкладки:`CHROME_CHALLENGE_HANDOFF_S=120`. После завершения проверки повтор того жезапроса в той же MCP-сессии продолжает чтение этой вкладки. Поддержка и ограниченияописаны в [настройке Chrome](docs/CDP_SETUP.md#optional-challenge-handoff).---## Что внутри| Сервер            | Инструментов | Что нужно, чтобы читалось                                                  | Что умеет                                                                                 || ----------------- | ------------ | -------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- || **Wildberries**   | 8            | анонимный HTTP     

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (oci)
claude mcp add ru-marketplace-mcp:2.3.0 -- docker run -i --rm ghcr.io/vladimir-human/ru-marketplace-mcp:2.3.0:None

Exposed tools (1) 1 read · 0 write · 0 destructive

ToolRiskDescription
namedreadReturn a named thing.

Details

Source
Vladimir-Human/ru-marketplace-mcp
npm
ru-marketplace-mcp@1.6.0
PyPI
ru-marketplace-mcp
Transports
stdio · streamable-http
License
MIT
Stars
106 · pushed 0d ago

Trust audit

Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (7 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/ozon-connector/src/ozon_connector/server.py:225
kind, payload = pickle.loads(out)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
work/v2-research/security.md:87
Product titles, seller names, and reviews are untrusted seller/buyer-authored text. Existing `SECURITY.md` and skill docs warn the consuming agent, but this is guidance rather than an enforceable prot
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packages/marketplace-connector/src/marketplace_connector/cli.py:291
module = __import__(module_path, fromlist=[tool_name])
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packages/marketplace-connector/src/marketplace_connector/server.py:181
module = __import__(module_path, fromlist=["mcp"])
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile.stdio:112
# naive `curl -f http://127.0.0.1:8000/mcp` would flap. A truthful healthcheck
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/mcp-core/src/mcp_core/resilience.py:106
if re.search(r"[A-Za-zА-Яа-я]", s):  # any letter → unit/suffix → ambiguous
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/mcp-core/src/mcp_core/resilience.py:238
if re.search(r"[A-Za-zА-Яа-я]", s) and re.search(r"\d[ ,]\d{3}\b", s):
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mpstats-connector/tests/test_call_envelope.py:218
secret = "synthetic-session-secret"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/detmir-connector/tests/test_server.py:255
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/wb-connector/tests/test_helpers.py:1731
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/yandex-connector/tests/test_server.py:242
["../../etc/passwd", "123?foo=bar", "abc", "12 34", "1/2", "-5"],
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
work/v2-research/security.md:92
2. **OWASP Server-Side Request Forgery Prevention Cheat Sheet / SSRF overview** — <https://owasp.org/www-community/attacks/Server_Side_Request_Forgery> (retrieved 2026-09-09). The page describes attac
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CDP_SETUP.md:109
curl -s http://127.0.0.1:9222/json/version
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/DEPLOYMENT.md:83
The endpoint is `http://127.0.0.1:8000/mcp`. Configure the client to send these
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/DEPLOYMENT.md:153
# -> http://127.0.0.1:8000/mcp on the host
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/citilink-connector/tests/test_server.py:232
"http://127.0.0.1:9222/product/5f4dcc3b5aa764d61d8327de/",
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/lamoda-connector/tests/fixtures/search_grid_live.html:10
<div class="_gridItem_1l7ym_11"><div id="RTLAEQ981601" class="x-product-card__card x-product-card__card_catalog _card_1l7ym_31 ui-catalog-product-card"><div class="x-product-card__link x-product-card_
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/lamoda-connector/tests/fixtures/search_grid_live.html:12
</span></span> <!----> <!----> <!----></div></div> <div class="_extra_opwis_2 _extraHoveredWithoutShadow_opwis_24" font-color="#000"><div class="_extraInner_opwis_32 _extraInnerWithoutShadow_opwis_44"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/mcp-core/src/mcp_core/transport/chrome_cdp.py:703
data = base64.b64decode(encoded, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/mcp-core/tests/test_chrome_cdp_snapshot.py:245
base64.b64decode(jpeg(0, 400)),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/mcp-core/tests/test_chrome_cdp_snapshot.py:246
base64.b64decode(jpeg(500, 0)),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/mcp-core/tests/test_chrome_cdp_snapshot.py:255
raw = base64.b64decode(jpeg(601, 399))
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/avito-connector/tests/test_server.py:339
url = server._build_search_url("ноутбук сsd", 2, "637640", "4")
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/mcp-core/tests/test_resilience_properties.py:126
if not re.search(r"[A-Za-zА-Яа-я]", s):

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-09-18 · audit v0.4.0 · source sha cc3923dc268b · full audit: observations/trust-audit/mcp-server/vladimir-human__ru-marketplace-mcp.json · Report an issue or request a re-scan

Audit history

DateSourceVerdictGradeScoreChange
2026-09-18cc3923dc268bBLOCKF57first audit

Alternatives

Other servers in the same categories, safer ones first.

Questions

What is the ru-marketplace-mcp MCP server?

Одиннадцать маркетплейсов и недвижимость Циан как MCP-серверы: Wildberries, Ozon, Яндекс Маркет, Детский мир, Авито, AliExpress, Taobao, Мегамаркет, Lamoda, DNS, Ситилинк, Циан. Плюс сравнение цен по всем товарным источникам одним вызовом. Только чтение, ключи не нужны.

What tools does ru-marketplace-mcp expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ru-marketplace-mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (57/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does ru-marketplace-mcp need?

No credential environment variables were found in its source, so it appears to need none.

How does ru-marketplace-mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as ru-marketplace-mcp at 1.6.0.

How current is this page?

The grade is for one exact copy of the source (cc3923dc268b), read on 2026-09-18. The repository is watched and re-audited when it changes.

Provenance: OBSERVED · read 2026-09-18 · job trust-audit-2026-09-18