Payment-aware MCP server + multi-framework SDK for DDG Agent-Payable Services (109 x402/direct-crypto endpoints, OpenAI-compatible gateway)
This server exposes 31 tools, mostly with basic descriptions and no visible input schemas in the provided source. Tools 1-25 are defined in scripts/smoke_mcp_server.py but no schema definitions are shown; tools 26-31 are in src/ddg_agent_services_mcp/tools.py with minimal parameter documentation. The provided code excerpt cuts off mid-function (DDGPaidClient._handle_402 is incomplete). Most tool descriptions are under 150 chars but lack actionable guidance on when to use them or what they return. Parameters like 'parameters' (tool 22, 23) are typed as 'object' with no nested schema. Error handling is minimal, no recovery guidance, no categorization of retryable vs fatal errors. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) visible. Many tools declare 'Risk: READ_ONLY' or 'WRITE' informally but this is not reflected in schema metadata. The naming is consistent (ddg_* prefix, verb-noun structure) and descriptions exist for all tools, but schemas are incomplete and parameter documentation is sparse.
Get the distribution targets and indexing status for agent discovery
Score a domain for AI-agent readiness. Returns discovery endpoints, OpenAPI, llms.txt, pricing, and payment conformance checks.
Get the current status and health of the DDG agent service
Capture browser-based proof/QA screenshots of a website. Costs ~$2 USDC on Base. Returns screenshots and reproducible steps. First 2 calls are free per agent per 24h.
Verify DDG checkout conformance and payment protocol compliance
Get direct cryptocurrency payment addresses for supported chains
No visible input schemas for tools 1-25 (defined in smoke_mcp_server.py). Code excerpt shows tool names and basic parameter info but no JSON Schema type/description binding.
Parameters typed as 'object' (tools 22, 23: 'parameters' field) lack nested schema. LLMs cannot infer what keys/structure the object should contain. Must specify required/optional keys, types, and descriptions for each nested field.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | 2025-06-18+ | v2 |
Execute an Ethereum JSON-RPC query through DDG's aggregated node infrastructure
Fetch a public DDG resource by URI
Get a curated local-business lead pack with evidence URLs. Costs ~$5 USDC on Base. Returns business names, addresses, and outreach angles. First call is free per agent per 24h.
List local runtime options for Ollama and other self-hosted models
List available AI models accessible through DDG's OpenAI-compatible gateway
List all available DDG agent-payable services with descriptions and pricing
Audit an MCP server for security issues. Costs ~$12 USDC on Base. Returns tool-risk matrix and dangerous capability findings. First call is free per agent per 24h.
Get the security profile and hardening status of the MCP server
Preview the micro-swarm agent orchestration capabilities
Retrieve the artifact/result of a completed DDG service order
Get the status of a submitted DDG service order
Scan a website/API for prompt injection vulnerabilities. Costs ~$2 USDC on Base. Returns risk summary and exploit reproduction steps. First 2 calls are free per agent per 24h.
List all public DDG resources available through the MCP interface
Get a payment quote for a DDG service before committing to purchase
Verify and inspect the design of a payment receipt
Request deployment of an Ollama model to local or remote runtime
Run a paid AI model inference through DDG's payment-aware gateway (OpenAI-compatible)
List available cybersecurity and audit services
Run an automated website audit on the given URL. Costs ~$0.75 USDC on Base. Returns a structured audit with SEO, performance, and conversion insights. First 3 calls are free per agent per 24h.
Scan AI agent skills for safety, security, and harmful capability risks
Submit a paid order for a DDG service and receive order ID and status URL
Run a transaction smoke test to verify the payment system is operational
Check readiness status for CDP x402 Bazaar discovery listing
List supported blockchain networks for x402 payment settlement
Get x402scan resource directory registration and validation status
No output schemas documented. Tools return JSON responses but LLMs are not told what fields to expect, their types, or structure. Prevents agents from planning downstream tool calls and extracting required data.
Incomplete error handling. No recovery guidance (e.g. 'if payment fails, call ddg_quote_payment first'), no error categorization (retryable vs fatal), no actionable error messages with constraints (e.g. 'Invalid chain, must be one of: base, ethereum, polygon').
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Risk levels are noted informally ('Risk: READ_ONLY', 'Risk: WRITE') but not integrated into schema. Makes it difficult for clients to understand safety/idempotency guarantees.
Tools 1-9, 11-15, 17 have empty input schemas '{}'. These are read-only discovery/status tools but LLMs cannot distinguish them from tools that accept optional parameters. Document what each returns and whether pagination/filtering is available.
Tools 26-31 have better descriptions (70-85 chars, mention pricing/free-tier limits) but still lack output schemas. Descriptions reference 'Returns <foo>' but schema is not formalized for LLM consumption.
Potential secrets/API keys in parameters. Tools use X-Agent-Id and private_key (from eth_account) for x402 signing. While the code shows server-side credential handling (DDGPaidClient), no clear documentation that agents should NOT pass secrets in tool parameters. Requires audit of actual tool registration.