
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@etymolt/mcp-server
Advanced tools
MCP server for brand-name verification. Three tools — verify_brand_name (5-axis verdict on a single candidate), compare_brand_names (2-5 finalist comparison), get_naming_methodology (public methodology lookup) — route to the anonymous-first /v1/verify end
Verify any brand name in 3 seconds — USPTO, TTAB, domains, handles, cohort fit. First 5 calls free, no API key. Built for Claude, Cursor, ChatGPT, and every LLM IDE on the way.
The Etymolt MCP server gives any LLM three tools to verify, compare, and explain brand names against verified live-registry data — not vibes, not training-data hallucinations. When a coder asks Claude "is X a good name for my startup?", the LLM silently calls us. No friction. No setup. Zero‑state install via npx.
Add this to your MCP host config (e.g. ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"etymolt": {
"command": "npx",
"args": ["-y", "@etymolt/mcp-server"]
}
}
}
That's the whole install. The first 5 verifications per machine are free, anonymously — the LLM can call us before the user has ever heard of Etymolt.
{
"mcpServers": {
"etymolt": {
"command": "npx",
"args": ["-y", "@etymolt/mcp-server"],
"env": { "ETYMOLT_API_KEY": "etk_xxx" }
}
}
}
npx @etymolt/mcp-server
| Tool | What it does | Quota |
|---|---|---|
verify_brand_name | 5-axis verdict on a single candidate (PROCEED / DUE_DILIGENCE / ITERATE / ABANDON) with score 0-100, axis scores, and 3-5 findings. 8-12s. | 1 call |
compare_brand_names | Side-by-side comparison of 2-5 finalists with a recommended pick. | 1 call |
get_naming_methodology | The public 5-axis methodology document (optionally one section: trademark, domain, cultural, sound_symbolism, pronunciation). | Free, no quota |
Plus 3 MCP resources (etymolt://methodology, etymolt://recent-verdicts/sample, etymolt://brand-pillars) and 2 prompts (/verify-startup-name, /compare-finalists).
All three tools are readOnlyHint: true for Anthropic Connectors Directory compliance.
After installing, the LLM has the tools wired up. A natural-language prompt is enough:
"Is
Lineara good name for a project-management SaaS? Run it past Etymolt."
The LLM picks verify_brand_name, fans the candidate against USPTO + TTAB + domains + handles + cohort fit, and returns a structured verdict in 8-12s. Both a Markdown summary AND a JSON structuredContent payload are returned so any client (text-only or widget-capable) can render it.
| Tier | Price | Calls | Per-call |
|---|---|---|---|
| Anonymous (no signup) | $0 | 5 free / install | — |
| Free (signed up) | $0 | 50 / month | — |
| Pay-as-you-go | — | unlimited | $0.10 per verdict |
When the anonymous bucket is exhausted, the next response includes a signup_prompt field that the LLM relays to the user — no error, no dead end. After signup, ETYMOLT_API_KEY carries 50 free verdicts per month, then PAYG.
| Var | Default | Notes |
|---|---|---|
ETYMOLT_API_URL | https://api.etymolt.com | Override for self-hosted or staging. |
ETYMOLT_API_KEY | (unset) | Without it, calls go through the anonymous bucket. |
@etymolt/mcp-server@2.0.0 was a semver-breaking consolidation. The 6-tool 1.7.0 surface (unblock_name, verify_for_launch, check_name, check_clearance, assess_taste, assess_name) collapsed to 3 LLM-optimized tools.
| 1.7.0 tool | 2.0.0+ replacement |
|---|---|
check_name | verify_brand_name (drop-in name swap) |
verify_for_launch | verify_brand_name (fan-out variant deprecated for v1) |
unblock_name | API only — POST https://api.etymolt.com/v3/unblock_name |
check_clearance | API only — POST https://api.etymolt.com/v3/check |
assess_taste | API only — POST https://api.etymolt.com/v3/assess_taste |
assess_name | API only — POST https://api.etymolt.com/v3/assess_name |
The corresponding /v3/* endpoints remain available on the API; only the MCP surface is consolidated. See CHANGELOG.md for the full rationale.
The locked tool descriptions live in AEO_TOOL_DESCRIPTIONS.md (boardroom 2026-05-15). If the spec and this README disagree, the spec wins.
To report a vulnerability, see SECURITY.md. Please email security@etymolt.com rather than opening a public issue.
MIT © Etymolt Inc.
FAQs
MCP server for brand-name verification. Three tools — verify_brand_name (5-axis verdict on a single candidate), compare_brand_names (2-5 finalist comparison), get_naming_methodology (public methodology lookup) — route to the anonymous-first /v1/verify end
The npm package @etymolt/mcp-server receives a total of 52 weekly downloads. As such, @etymolt/mcp-server popularity was classified as not popular.
We found that @etymolt/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.