Start with Provider Trust.
Use it before connecting to or spending with an unfamiliar provider. It should report what is observed, what is missing, and what remains unverified rather than converting incomplete evidence into a safety claim.
Machines should not have to guess. Each primary MCP has one obvious reason to call it, a clear evidence boundary, and a canonical machine endpoint. Start with the buyer's actual question rather than a product name.
Verify a source or provider before an AI agent trusts it. Use it for identity, runtime status, payment-surface evidence and explicit uncertainty. Missing evidence stays unknown.
Delegate narrowly scoped actions into a browser the user authenticated themselves. Sessions are short-lived, origin-scoped and revocable; cookies, passwords and session tokens are not exported, CAPTCHA is not automated, and GhostKey does not autonomously spend.
Find the right API or tool for a task, including web scraping, URL to Markdown, fact verification, stock data, currency conversion and web research. It is the main general-purpose capability router.
Discover x402-paid APIs and inspect fresh payment requirements before calling them. It exposes terms; the caller still decides whether, when and how much to spend.
Get read-only tokenized-stock and real-world-asset intelligence with source boundaries. Metadata is not proof of tradability, ownership, current price or settlement.
Get current software package docs, metadata, dependency context and vulnerability evidence. Absence of observed vulnerability evidence is not proof that a package is safe.
The stack is deliberately separated so a machine buyer can call the narrowest useful capability and preserve the evidence boundary around the answer.
Use it before connecting to or spending with an unfamiliar provider. It should report what is observed, what is missing, and what remains unverified rather than converting incomplete evidence into a safety claim.
Use GhostKey when an agent needs narrowly scoped actions inside a browser session that the user authenticated. The user retains authentication; the bridge does not export credentials, bypass access controls, automate CAPTCHA, or authorize spend.
Inspect the current payment requirement as close to execution as possible. Cached marketing prices are planning information only; the fresh target PAYMENT-REQUIRED challenge controls the actual terms.
ScriptDocs handles software-package evidence. Robinhood RWA Intelligence handles tokenized-asset metadata and related read-only evidence. Neither should be treated as a substitute for evidence outside its declared scope.