Integrates with the Kash.click French point-of-sale system to create sales transactions, manage product catalogs and customer data, and configure shop settings including departments, payment methods, and delivery options.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The caisse-enregistreuse-api MCP server exposes 41 tools, focused primarily on general-purpose capabilities. Its published description reads: "Integrates with the Kash.click French point-of-sale system to create sales transactions, manage product catalogs and customer data, and configure shop settings including departmen…". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates caisse-enregistreuse-api F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Hidden instructions in a tool description". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check caisse-enregistreuse-api's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add caisse-enregistreuse-api to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.kash.click/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
List all Kash / free-cash-register.net accounts linked to an email address. Use this before account_create to check if the user already has an account. Returns an array of accounts, each with accountT
Create a new Kash / free-cash-register.net account. Requires an email address and a shop name (accountTitle). Optional: configType to pre-load a dataset matching your business type (e.g. 'Restaurant',
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: account_create
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
ed immediately. IMPORTANT: the user must validate their email via the linkRecommendationRemove model-directed instructions from tool descriptions.
tool: order_create
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
to pay online. IMPORTANT: before creating a validated invoice (payment ≠RecommendationRemove model-directed instructions from tool descriptions.
tool: account_list
A tool description tries to alter the model’s use of another tool.
Use this before account_create to check if the user already has an account. ReRecommendationDescriptions must describe only their own tool.
tool: auth_request_otp
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
p 1 of 2 for in-conversation authentication. Sends a one-time password (OTP)RecommendationRemove side-channel parameters; constrain tool inputs.
tool: auth_request_otp
A tool description tries to alter the model’s use of another tool.
(obtained from account_list) to target the right one. On success, an OTP coRecommendationDescriptions must describe only their own tool.
tool: auth_login_with_otp
A tool description tries to alter the model’s use of another tool.
mediately. Call auth_request_otp first to receive the OTP by email.RecommendationDescriptions must describe only their own tool.
tool: account_show_infos
A tool description tries to alter the model’s use of another tool.
ill them in via account_edit.RecommendationDescriptions must describe only their own tool.
tool: auth_logout
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
EY and SHOPID). After this, all tools requiring authentication will fail until a newRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: order_create
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: order_edit
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: plu_edit
A tool description tries to alter the model’s use of another tool.
ept the ID. Use data_list_products to find the article ID first.RecommendationDescriptions must describe only their own tool.
tool: dept_add
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: dept_edit
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: client_add
A tool description tries to alter the model’s use of another tool.
date, etc. Use data_list_clients to check if the customer already exists first.RecommendationDescriptions must describe only their own tool.
tool: client_edit
A tool description tries to alter the model’s use of another tool.
ept the ID. Use data_list_clients to find the customer ID first.RecommendationDescriptions must describe only their own tool.
tool: payment_mode_add
A tool description tries to alter the model’s use of another tool.
cashboxes). Use data_list_payments_modes to list existing methods.RecommendationDescriptions must describe only their own tool.
tool: payment_mode_delete
A tool description tries to alter the model’s use of another tool.
by its ID. Use data_list_payments_modes to find the ID.RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: account_create
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: auth_request_otp
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: vat_delete
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: plu_delete
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: dept_delete
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: client_delete
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: payment_mode_delete
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Step 1 of 2 for in-conversation authentication. Sends a one-time password (OTP) to the user's email address. If the user has multiple accounts, provide accountID (obtained from account_list) to target
Step 2 of 2 for in-conversation authentication. Exchange the OTP received by email for an APIKEY and SHOPID, and automatically initialize the session so all other tools work immediately. Call auth_req
Modify the settings of the authenticated shop account. All fields are optional. Covers: basic info (name, address, legal numbers), receipt display options, order requirements, feature flags (stock, ba
Retrieve all current settings of the authenticated shop account as a JSON object. Returns the full shop configuration: name, address, legal numbers, receipt options, order requirements, enabled featur
Clear the current authentication session (APIKEY and SHOPID). After this, all tools requiring authentication will fail until a new login is performed.
Download a synthetic HTML sales report for a given period. Period logic: omit all date fields to get yesterday's report; provide y only for a full-year report; y + m for a full-month report; y + m + d
Record a new order in the connected shop. Input includes paymentMode, and items[]. Each item can be of type 'catalog' (with productId), 'department' (with price and deptId) or 'free' (with title and p
Modify an existing order by its ID. Use the payment field to control the order state: -2 = keep as unvalidated quote (not paid); -1 = validate as invoice without payment; a payment method ID (from dat
Retrieve the list of articles (products) configured in the shop. Returns an array of products with fields like id, title, price, and departmentId. Optional parameter 'format' allows output as json, cs
Get all departments (product categories) defined in the shop, including their names and default tax rates. Supports format=json|csv|html.
Return the list of department groups, used to organize product categories. Each group may include multiple department IDs.
Get the list of clients registered in the shop, including contact info, loyalty points.
Retrieve product variations (declinaisons) such as size or color. Returns an array of variant definitions with value and optional price delta.
List all delivery methods available for the shop, such as in-store pickup, home delivery, or courier services.
tools.data.list.payments.description
List the registered cashboxes (physical or virtual) linked to the shop, including their current status and identifiers.
Return all configured delivery zones, including area names, postal codes, and applicable delivery fees or restrictions.
List all relay points where customers can pick up their orders, including address, city, and postal code.
Return all available discounts or promotions, including their names, types (percentage or fixed), values, and conditions.
List all users (cashiers, managers, etc.) associated with the shop, including their roles and identifiers.
Retrieve the list of tables configured in the app, used for restaurant mode or table management.
Retrieve the list of VAT rates configured in the shop, including their title, rate percentage, and optional accounting chapter.
Retrieve the list of unvalidated orders (that can still be modified)
List either: unvalidated orders (called quotes) with creation date between from_date_ISO8601 and to_date_ISO8601 OR validated orders (called orders, invoices) with date of value between from_date_ISO8
Retrieve full order information by its unique ID, including items, client data, payment mode, and total amount.
Add a new VAT rate to the shop configuration. Requires a title and a rate (e.g. 20 for 20%). Optional fields: accountingChapter, legal mention.
Modify an existing VAT rate by its ID. All fields are optional except the ID.
Permanently remove a VAT rate from the shop configuration by its ID.
Add a new item/article to the shop catalog. Requires a title. Optional fields include price, department (deptID), VAT rate (vatID), barcode, stock, variations, and many more.
Edit an existing item/article in the catalog by its ID. All fields are optional except the ID. Use data_list_products to find the article ID first.
Permanently remove an item/article from the catalog by its ID.
Add a new department (product category) to the catalog. Requires a title. Optional fields include VAT rate (vatID), price, discount, position, department group, and variations.
Edit an existing department/category by its ID. All fields are optional except the ID. Use data_list_departments to find the department ID first.
Permanently remove a department/category from the catalog by its ID.
Add a new customer to the shop's customer file. All fields are optional: name, surname, email, phone, address, company registration number, VAT number, barcode, private/public comment, blacklist statu
Edit an existing customer by their ID. All fields are optional except the ID. Use data_list_clients to find the customer ID first.
Permanently remove a customer from the shop's customer file by their ID.
Add a new payment method to the shop. Requires a title. Optional fields: type (Cash, Credit_Card, Check, Bank_Transfer, Meal_Voucher, Holiday_Voucher, and their refund equivalents), accountingChapter,
Permanently remove a payment method from the shop by its ID. Use data_list_payments_modes to find the ID.