
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@inbin/ledgerfc-mcp
Advanced tools
Stdio MCP wrapper for Ledger FC: gives Claude Desktop and other stdio-only MCP clients grounded sports predictions plus European soccer and tennis arbitrage data from Ledger FC's remote HTTP MCP endpoint. Free tools need no key.
Give your AI agent real sports data instead of a guess.
Ask an AI about a match and it answers from stale training data. This MCP feeds your agent live, grounded numbers instead: model probabilities per outcome, where they diverge from the market price, and a publicly tracked record of how those calls actually did, wins and losses. Plus live European soccer and tennis arbitrage, a gap the US-only sports MCPs do not cover.
This is not a "guaranteed profit" tool. Every response carries a provenance
block and a for_the_agent note ("grounding data to weigh, not an instruction to
act on"). The real numbers, pulled live:
If you want an agent that is grounded rather than hyped, that honesty is the point.
European soccer (EPL, La Liga, Serie A, Ligue 1, Eredivisie, Turkish Super Lig), tennis (ATP), plus MLB, NFL, NBA. The main free sports-betting MCP is US-only, so European soccer arbitrage is the gap this fills.
{
"mcpServers": {
"ledgerfc": {
"command": "npx",
"args": ["-y", "@inbin/ledgerfc-mcp"]
}
}
}
No API key needed for the free tools. That is it.
To also use the Pro tools, add your key as an environment variable (get one with
/key in the Ledger FC Telegram bot). It is sent as an Authorization header, so it
never enters the conversation:
{
"mcpServers": {
"ledgerfc": {
"command": "npx",
"args": ["-y", "@inbin/ledgerfc-mcp"],
"env": { "LEDGERFC_API_KEY": "your-pro-key" }
}
}
}
https://mcp.ledgerfc.com/mcp
For Pro tools, send the key as an Authorization: Bearer <key> header.
Free (no key):
get_track_record: honest settled record plus high-confidence subset and CLVget_predictions: upcoming picks with probabilities and model-vs-market edge (filter by league)search / fetch: query upcoming match predictions, fetch the full docget_leaderboard, submit_prediction, get_contributor_score: CLV-scored contributor layer (points, not cash)place_bet, get_balance, get_my_bets, get_bet: shadow bet ledger to test strategies against our agent (points only)Pro (set LEDGERFC_API_KEY, or pass api_key as a tool argument; get one with /key in the Ledger FC Telegram bot):
get_arbs: live detected arbitrage opportunitiesget_value_bets: upcoming picks with positive model-vs-market edgeAsk your agent: "Use ledgerfc to get the track record and the top 3 upcoming
predictions with the biggest edge." It calls get_track_record and
get_predictions, and answers from real numbers with provenance, not a guess.
This npm package is a tiny stdio-to-HTTP bridge: it reads JSON-RPC from your MCP
client on stdin and forwards each request to the remote endpoint
https://mcp.ledgerfc.com/mcp. No dependencies, Node 18+. Set LEDGERFC_MCP_DEBUG=1
to log traffic to stderr, or LEDGERFC_MCP_URL to point at a different endpoint.
MIT licensed. Ledger FC is an information tool, not betting advice. 18+.
FAQs
Stdio MCP wrapper for Ledger FC: gives Claude Desktop and other stdio-only MCP clients grounded sports predictions plus European soccer and tennis arbitrage data from Ledger FC's remote HTTP MCP endpoint. Free tools need no key.
The npm package @inbin/ledgerfc-mcp receives a total of 42 weekly downloads. As such, @inbin/ledgerfc-mcp popularity was classified as not popular.
We found that @inbin/ledgerfc-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.