MCP Server for tip.md - provides tools for crypto tipping, wallet management, and blockchain transactions on Ethereum, Base, and Solana networks
This server has significant structural and security issues that prevent it from meeting production quality standards. While 8 tools are defined with schemas and descriptions, the implementation exhibits critical problems: (1) SECURITY: Three tools (export_tipping_wallet, tip_on_base, tip_on_solana, withdraw_tipping_funds) handle private keys and irreversible financial transactions without documented confirmation mechanisms or dry-run patterns. The check_tipping_balance tool returns private keys to users, which is extremely sensitive. (2) NAMING: Tool names lack consistent verb_noun patterns, 'check_tipping_balance' and 'crypto_tipping' are weak; 'get_user_wallet_types' is better. (3) DESCRIPTIONS: Most descriptions are present but lack guidance for agent selection. The crypto_tipping tool description is generic ('Provides details') without clarity on whether it actually executes or just provides information. (4) PARAMETERS: Parameters are typed (good) but lack range constraints for numeric amounts. The 'amount' field in tip_on_base and tip_on_solana accepts numbers with only a minimum (0.01) noted in description, no maximum or decimal precision documented. (5) ERROR HANDLING: No visible recovery guidance, no handling of blockchain transaction failures, no partial-success patterns for multi-step operations. (6) SCHEMAS: Input schemas are present and properly typed with descriptions, meeting the basic rubric, but output schemas are not documented in the tool definitions themselves.
Check balance and wallet information for tipping. Creates new wallet for new users or retrieves existing wallet. Supports both Ethereum (Base) and Solana networks. Returns wallet addresses, balances, and private keys for new wallets.
Provides details for crypto tipping a tip.md user via blockchain. Supporting Ethereum, Base and Solana.
Export your tipping wallet private key for full control (SECURITY SENSITIVE). Returns structured JSON with wallet data and security warnings. Requires your tip.md user ID. Base network only.
Retrieves a tip.md user's configured wallet types from the database.
Responds with pong, useful for health checks.
Send USDC tips on Base from your personal tip.md wallet using the x402 payment protocol. Returns structured JSON with transaction details. Pays from your dedicated wallet to recipient via x402 protocol and distributed using CDP Wallet API. IMPORTANT: When successful, always show the user the transaction hashes as clickable links using the format: https://basescan.org/tx/{transactionHash} for both recipient and platform transactions.
CRITICAL SECURITY: Private keys returned in check_tipping_balance and export_tipping_wallet responses. Private keys must never be exposed in tool responses, they enter LLM context and logs. Use server-side secret injection or hardware wallet signing instead.
CRITICAL: Irreversible financial operations (tip_on_base, tip_on_solana, withdraw_tipping_funds) lack confirmation/dry-run pattern. Agents can accidentally send funds without user approval. Implement confirmation_request pattern with explicit user sign-off before executing blockchain transactions.
Numeric parameters (amount in tip_on_base, tip_on_solana, withdraw_tipping_funds) lack maximum bounds and precision constraints. No documented decimal places or safeguards against $1000+ accidental tips. Add explicit min/max and precision to descriptions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 48 | 2026-07-28+ | v2 |
Send USDC tips on Solana from your personal tip.md wallet using the x402 payment protocol. Returns structured JSON with transaction details. IMPORTANT: When successful, always show the user the transaction hashes as clickable links using the format: https://solscan.io/tx/{transactionHash} for both recipient and platform transactions.
Withdraw USDC from your tipping wallet to any Ethereum address. Returns structured JSON with transaction details. Requires your tip.md user ID. Base network only.
crypto_tipping description is vague ('Provides details for crypto tipping'), unclear whether it executes a transaction or only returns information. Does not state what the tool returns or when to use it vs. tip_on_base/tip_on_solana. Rewrite to be explicit: 'Get transaction details and fees for tipping a user via blockchain. Does NOT execute the transaction, use tip_on_base or tip_on_solana to send.'
Output schemas not documented for any tool. LLMs cannot plan downstream calls or extract fields without knowing response structure. Add explicit 'Returns' documentation (JSON schema) to every tool description.
No error handling guidance. Tools do not document what happens on blockchain failure, insufficient balance, invalid recipient, or network timeouts. Add recovery guidance: 'If transaction fails, call check_tipping_balance to verify funds, then retry.'
Weak naming: 'crypto_tipping' and 'check_tipping_balance' lack verb_noun clarity. Better: 'get_tipping_details' and 'get_wallet_balance'. 'check_tipping_balance' reads like a read-only lookup but can create wallets, rename to 'get_or_create_wallet' to signal side effects.
destinationAddress parameter in withdraw_tipping_funds lacks format validation guidance. Description should state: 'Valid Ethereum address (0x..., 42 hex characters)'. No regex or pattern constraint documented.
withdraw_tipping_funds accepts amount as 'number' but description mentions 'or "all" for full balance'. Type mismatch, either use a union (number | string 'all') or two separate parameters. Current schema will reject the string 'all'.
No documented permission/scope model. Tools like export_tipping_wallet and tip_on_base should declare required permissions (e.g., 'write:wallet', 'read:wallet'). This enables least-privilege agent configuration and audit trails.