OpenClaw GenPark Agent Skill: genpark-arbitrage. Monitors wholesale APIs to front-run retail listings and automate account engagement activities.
GenPark Arbitrage is a non-functional MCP server with severe quality failures across all dimensions. The single tool 'scan_and_lock_arbitrage' has a basic description and minimal input schema, but the server exhibits critical problems: (1) No MCP protocol implementation visible, this appears to be a Python script and JavaScript automation suite, not an MCP server; (2) The code implements front-running and market manipulation (described as 'front-run retail listings'), which is destructive and potentially illegal; (3) Companion code 'circle_party_ws.js' contains hardcoded credentials and automated social engineering tactics (fake account creation, bot-driven posts/comments), indicating malicious intent; (4) Tool is marked DESTRUCTIVE but has no confirmation pattern, dry-run, or permission gates; (5) No error handling, logging, or recovery guidance; (6) Input schema exists but parameter descriptions are trivial; (7) Tool description is vague about side effects. This is not a production-grade tool and exhibits ethical red flags.
GenPark Arbitrage Engine: Monitors wholesale APIs to front-run retail listings.
NOT AN MCP SERVER, No MCP protocol implementation detected. Code is a raw Python script + Playwright automation, not an MCP tool server. Must implement MCP transport (HTTP, SSE, or STDIO) with proper tool registration, resource handling, and protocol handshake.
TOOL PERFORMS ILLEGAL/UNETHICAL ACTIVITY, 'scan_and_lock_arbitrage' is documented as front-running retail market listings. Accompanying code 'circle_party_ws.js' automates credential theft, fake account creation, and coordinated inauthentic behavior. This violates securities law (front-running), consumer protection (fraud), and platform ToS. MCP is not the venue for malicious automation.
DESTRUCTIVE TOOL WITH NO CONFIRMATION OR GATES, Tool is marked DESTRUCTIVE but has zero error handling, dry-run option, or permission verification. A destructive tool that modifies state ('locked' contract) must support confirmation-before-execute.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 22 | 2026-07-28+ | v2 |
HARDCODED CREDENTIALS IN SOURCE, circle_party_ws.js contains plaintext email/password combos: 'hustle_420@gmail.com' / 'GrindNeverStops26!', 'luna_smith_849@genpark.ai' / 'GenParkLuna2026!'. Secrets must never be in source code, use environment variables or a vault.
PARAMETER DESCRIPTIONS ARE TRIVIAL, 'target_sku' and 'max_price' descriptions are bare field names with no context for LLM selection. No guidance on SKU format (how long? vendor-specific?), no min/max bounds on price, no guidance on retry behavior or cost implications.
NO STRUCTURED ERROR HANDLING, 'retry_with_backoff' catches all exceptions generically and logs raw error text. No classification into retryable vs. fatal; no guidance for LLMs on recovery steps. Tool just crashes after max retries.
OUTPUT SCHEMA NOT DOCUMENTED, Tool returns {'status', 'action', 'contract_id'} but this structure is hardcoded in the function, not documented in the tool definition. LLMs cannot infer what fields to expect or plan downstream operations.
NO AUDIT TRAIL OR LOGGING, No record of who called the tool, with which params, or what happened. Destructive arbitrage operations must be fully audited for compliance and incident response.