
Security News
OpenClaw Skill Marketplace Emerges as Active Malware Vector
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
merchant-categories-mcp
Advanced tools
It is generated with Stainless.
Because it's not published yet, clone the repo and build it:
git clone git@github.com:jamalla/merchant-categories-sdk.git
cd merchant-categories-sdk
./scripts/bootstrap
./scripts/build
# set env vars as needed
export MERCHANT_CATEGORIES_API_KEY="My API Key"
node ./packages/mcp-server/dist/index.js
[!NOTE] Once this package is published to npm, this will become:
npx -y merchant-categories-mcp
Build the project as mentioned above.
There is a partial list of existing clients at modelcontextprotocol.io. If you already have a client, consult their documentation to install the MCP server.
For clients with a configuration JSON, it might look something like this:
{
"mcpServers": {
"merchant_categories_api": {
"command": "node",
"args": [
"/path/to/local/merchant-categories-sdk/packages/mcp-server",
"--client=claude",
"--tools=all"
],
"env": {
"MERCHANT_CATEGORIES_API_KEY": "My API Key"
}
}
}
}
There are two ways to expose endpoints as tools in the MCP server:
You can run the package on the command line to discover and filter the set of tools that are exposed by the MCP Server. This can be helpful for large APIs where including all endpoints at once is too much for your AI's context window.
You can filter by multiple aspects:
--tool includes a specific tool by name--resource includes all tools under a specific resource, and can have wildcards, e.g. my.resource*--operation includes just read (get/list) or just write operationsIf you specify --tools=dynamic to the MCP server, instead of exposing one tool per endpoint in the API, it will
expose the following tools:
list_api_endpoints - Discovers available endpoints, with optional filtering by search queryget_api_endpoint_schema - Gets detailed schema information for a specific endpointinvoke_api_endpoint - Executes any endpoint with the appropriate parametersThis allows you to have the full set of API endpoints available to your MCP Client, while not requiring that all of their schemas be loaded into context at once. Instead, the LLM will automatically use these tools together to search for, look up, and invoke endpoints dynamically. However, due to the indirect nature of the schemas, it can struggle to provide the correct properties a bit more than when tools are imported explicitly. Therefore, you can opt-in to explicit tools, the dynamic tools, or both.
See more information with --help.
All of these command-line options can be repeated, combined together, and have corresponding exclusion versions (e.g. --no-tool).
Use --list to see the list of available tools, or see below.
Different clients have varying abilities to handle arbitrary tools and schemas.
You can specify the client you are using with the --client argument, and the MCP server will automatically
serve tools and schemas that are more compatible with that client.
--client=<type>: Set all capabilities based on a known MCP client
openai-agents, claude, claude-code, cursor--client=cursorAdditionally, if you have a client not on the above list, or the client has gotten better over time, you can manually enable or disable certain capabilities:
--capability=<name>: Specify individual client capabilities
top-level-unions: Enable support for top-level unions in tool schemasvalid-json: Enable JSON string parsing for argumentsrefs: Enable support for $ref pointers in schemasunions: Enable support for union types (anyOf) in schemasformats: Enable support for format validations in schemas (e.g. date-time, email)tool-name-length=N: Set maximum tool name length to N characters--capability=top-level-unions --capability=tool-name-length=40--capability=top-level-unions,tool-name-length=40--resource=cards --operation=read
--resource=cards --no-tool=create_cards
--client=cursor --capability=tool-name-length=40
--resource=cards,accounts --operation=read --tag=kyc --no-tool=create_cards
// Import the server, generated endpoints, or the init function
import { server, endpoints, init } from "merchant-categories-mcp/server";
// import a specific tool
import createCategories from "merchant-categories-mcp/tools/categories/create-categories";
// initialize the server and all endpoints
init({ server, endpoints });
// manually start server
const transport = new StdioServerTransport();
await server.connect(transport);
// or initialize your own server with specific tools
const myServer = new McpServer(...);
// define your own endpoint
const myCustomEndpoint = {
tool: {
name: 'my_custom_tool',
description: 'My custom tool',
inputSchema: zodToJsonSchema(z.object({ a_property: z.string() })),
},
handler: async (client: client, args: any) => {
return { myResponse: 'Hello world!' };
})
};
// initialize the server with your custom endpoints
init({ server: myServer, endpoints: [createCategories, myCustomEndpoint] });
The following tools are available in this MCP server.
categories:create_categories (write): This endpoint allows you to create a new category and return the category ID and its details.
retrieve_categories (read): This endpoint allows you to return the complete details for a specific category by passing the category as a path parameter.
update_categories (write): This endpoint allows you to update category details by passing the category as a path parameter.
list_categories (read): This endpoint allows you to list all categories related to your store directly from this endpoint. Also, it allows you to filter them using a keyword, the endpoint would return any category which name matches this keyword.
delete_categories (write): This endpoint allows you to delete a specific category by passing the category as a path parameter.
list_children_categories (read): This endpoint allows you to return specific category children by passing the category as a path parameter.
list_products_categories (read): This endpoint allows you to list all the products and their sort order that are related in a specified category by passing the id as a path parameter..
search_categories (read): This endpoint allows you to search through existing categories using keywords (a.k.a name of the category) as well as an array of Category IDs
FAQs
The official MCP Server for the Merchant Categories API
We found that merchant-categories-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.