
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@semore/mcp-commerce
Advanced tools
Semore commerce MCP server — canonical 5 tools (search_product, get_product, create_cart, quote_checkout, submit_intent) per ADR-0062, with AP2 IntentMandate / CartMandate / PaymentMandate VC chain.
Reference Model Context Protocol (MCP) server surface for commerce — four tools that every agent-ready storefront should expose.
| Tool | Purpose |
|---|---|
search_products | Keyword / category / price search across a catalog |
build_cart | Compute total (subtotal + shipping + duty + tax) for a cart + destination |
create_order | Turn a priced cart into an order, returning a checkout URL |
get_policy | Fetch return / refund / shipping / privacy policy in requested language |
Source of Truth: this directory in the Semore monorepo until repo split. Production Semore MCP server lives at
apps/api/src/routes/mcp.tsand is exposed at https://mcp.semore.net. This package ships the schemas + stub handlers so merchants can validate integrations locally before connecting to Semore.
npm install @semore/mcp-commerce zod
import { searchProductsTool } from "@semore/mcp-commerce/tools/search";
const parsed = searchProductsTool.inputSchema.parse({
q: "sunscreen",
lang: "en",
category: "kbeauty",
limit: 10,
});
const result = await searchProductsTool.handler(parsed);
import { createMcpServer } from "@semore/mcp-commerce";
const server = createMcpServer({
// Wire your catalog / cart / order resolvers here.
// The default skeleton resolvers return deterministic fixtures
// useful for local integration tests.
});
// Then expose over your preferred transport (stdio, HTTP, SSE).
| Platform | Listing page |
|---|---|
| Claude Desktop | mcp.semore.net manifest |
| ChatGPT Apps | mcp.semore.net manifest |
| Gemini Extensions | mcp.semore.net manifest |
Metadata is emitted by the production Semore server. This OSS package is the reference surface third-party merchants can fork to expose their own catalog under the same schema.
semore.hq@gmail.com · GitHub @semore_hqApache-2.0 — see LICENSE.
Copyright (c) Semore Founding Team.
FAQs
Semore commerce MCP server — canonical 5 tools (search_product, get_product, create_cart, quote_checkout, submit_intent) per ADR-0062, with AP2 IntentMandate / CartMandate / PaymentMandate VC chain.
We found that @semore/mcp-commerce demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.