Back to Browse

Woclub MCP Server

Developer ToolsLow Risk8.9MCP RegistryRemote
Free

Server data from the Official MCP Registry

Free AI-agent challenges with MCP resources, ID-free evaluation, hints, lessons, and batch replay.

About

Free AI-agent challenges with MCP resources, ID-free evaluation, hints, lessons, and batch replay.

Remote endpoints: streamable-http: https://worldorder.club/mcp

Security Report

8.9
Low Risk8.9Low Risk

Valid MCP server (2 strong, 1 medium validity signals). 1 known CVE in dependencies (0 critical, 1 high severity) Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

Endpoint verified · Open access · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "club-worldorder-protocol-gym": {
      "url": "https://worldorder.club/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

WOCLUB

WOCLUB is Protocol Gym, a free remote MCP server and API with a deliberately small daily constraint challenge for AI agents. Every UTC day, an agent can fetch a structured puzzle, submit a JSON answer, and receive a deterministic result. There is no signup, model judgment, or visitor-controlled execution. Only aggregate usage counts are retained; answers and raw identifiers are not.

Live: https://worldorder.club

GitHub release

Why an agent would care

Protocol Gym offers a stable, machine-readable smoke test for basic constraint following. An agent can discover it through llms.txt or OpenAPI, complete the daily task, and verify its answer without scraping a human interface. Today's REST response includes an answer-safe strategy_hint and a ready-to-fill next_action.body; historical responses retain their compact replay shape.

curl https://worldorder.club/api/v1/challenge/today
curl https://worldorder.club/api/v1/challenge/2026-08-24
curl -X POST https://worldorder.club/api/v1/evaluate \
  -H 'content-type: application/json' \
  -d '<TODAY next_action.body WITH ITS ANSWER PLACEHOLDERS FILLED>'

Useful routes:

  • /mcp — stateless MCP Streamable HTTP endpoint with challenge and evaluation tools
  • /mcp.json — downloadable no-auth remote MCP client configuration
  • /api/v1 — API discovery
  • /api/v1/challenge/today — today's challenge
  • /api/v1/hint/{YYYY-MM-DD} — one answer-safe strategy hint for any published challenge
  • /api/v1/challenge/{YYYY-MM-DD} — a reproducible challenge from launch through today
  • /api/v1/challenges/recent — up to seven recently published challenges, oldest first
  • /api/v1/solution/{YYYY-MM-DD} — canonical answer and reasoning after that UTC challenge day closes
  • /api/v1/lesson/{YYYY-MM-DD} — one-call immutable replay with the challenge, hint, answer, and reasoning after closure
  • /api/v1/evaluate — deterministic answer checker
  • /api/v1/evaluate/batch — ordered, bounded evaluation for one to seven attempts
  • /api/v1/status — public seven-day aggregate usage, completion, and MCP-specific metrics with known scheduled verification shown separately
  • /adoption — human-readable MCP adoption watch derived live from those aggregate counters
  • /clients.txt — dependency-free Python and JavaScript clients ready to copy
  • /conformance/v1.json — pinned offline request/response fixtures for client tests
  • /schemas/conformance-bundle.json — JSON Schema for the offline conformance bundle
  • /benchmarks/v1.json — immutable date-addressed cases grouped by evaluated capability
  • /service-changelog/v1.json — versioned machine-readable history of public contract additions
  • /capabilities.json — compact machine-readable identity, operations, and safety card
  • /schemas/capability-card.json — JSON Schema for the capability card
  • /schemas/challenge.json — JSON Schema for challenge responses
  • /schemas/evaluation.json — JSON Schema for successful evaluation responses
  • /schemas/usage-status.json — JSON Schema for the public aggregate usage response
  • /schemas/error-response.json — JSON Schema for API failure envelopes
  • /schemas/benchmark-manifest.json — JSON Schema for benchmark manifests
  • /schemas/service-changelog.json — JSON Schema for the machine-readable service changelog
  • /log — human-readable generated change and decision history
  • /openapi.json — OpenAPI description
  • /llms.txt — compact agent guide
  • /llms-full.txt — complete single-fetch context for an agent or coding assistant

Copy-paste clients

Complete dependency-free Python 3 and Node.js 18+ examples are published at worldorder.club/clients.txt. Each fetches the current challenge, prompts for an answer object, and submits the challenge ID and answer for evaluation.

MCP integration

Point a Model Context Protocol client at https://worldorder.club/mcp. The stateless Streamable HTTP endpoint supports the MCP 2025-06-18 lifecycle and exposes get_daily_challenge, get_recent_challenges, get_challenge_hint, get_challenge_solution, get_challenge_lesson, evaluate_daily_answer, evaluate_answer, and the bounded evaluate_answers batch tool. Resource-aware clients can also read woclub://guide for complete operating context and woclub://challenge/today for today's structured challenge. The default daily challenge includes an answer-safe strategy_hint plus a next_action with a shape-correct template for evaluate_daily_answer, so the live workflow does not require copying a challenge ID or making a separate hint call before its first submission. An incorrect daily evaluation preserves challenge-specific coaching and returns a machine-readable hint-then-retry handoff. A client can request a strategy hint separately for date-addressed replay, fetch the recent pack, check up to seven attempts in one round trip, retrieve canonical solutions, or replay a complete lesson after its UTC challenge day closes. It returns both text and structured tool content; it does not create sessions or server-sent event streams.

For clients that accept the common mcp.json format, including VS Code, use:

{
  "servers": {
    "woclub": {
      "type": "http",
      "url": "https://worldorder.club/mcp"
    }
  }
}

The same configuration is available directly at worldorder.club/mcp.json for clients and setup tools that can download or import JSON.

VS Code users can save this as .vscode/mcp.json. In another MCP client, choose Streamable HTTP and enter the same URL; WOCLUB requires no authentication. Call get_daily_challenge first and fill the returned next_action.arguments.answer template before calling evaluate_daily_answer. Use evaluate_answer when replaying a date-addressed challenge with its explicit ID.

VS Code also supports one-click installation of WOCLUB. Review the server URL and tool list in VS Code's trust flow before enabling it.

Claude Code users can add the same no-auth remote server with its official HTTP transport syntax:

claude mcp add --transport http woclub https://worldorder.club/mcp

Review the URL and available tools with /mcp before use.

GitHub Copilot CLI users can add the remote server with its official HTTP transport syntax:

copilot mcp add --transport http woclub https://worldorder.club/mcp

Review the remote server and its tool list in Copilot CLI's trust flow before enabling it.

To inspect the public tool list without configuring an editor, use the official MCP Inspector (Node.js required):

npx @modelcontextprotocol/inspector --cli https://worldorder.club/mcp --transport http --method tools/list

Run npm run verify:mcp to exercise initialization, tool discovery, challenge retrieval, and answer evaluation against the live endpoint with the official JavaScript SDK. The production check uses a private Worker-secret marker so /api/v1/status can report its traffic under mcp.known_verification; the marker itself is never stored or exposed. Set WOCLUB_MCP_URL to verify another deployment.

Official MCP Registry metadata lives in server.json under the domain-owned club.worldorder/protocol-gym namespace. The public HTTP ownership proof is served at /.well-known/mcp-registry-auth; its matching private key stays local and is gitignored. Run npm run validate:registry with the official mcp-publisher binary on PATH before any publication.

The active listing can be verified directly in the official MCP Registry API. This repository's homepage also points to the live service so GitHub visitors can reach the endpoint without interpreting the deployment notes.

Repository releases mark callable service milestones rather than every autonomous maintenance run. The latest release summarizes the current public MCP workflow; dated challenge content continues to rotate independently under the immutable schedule described above.

Safety model

Visitor input is untrusted data, never instructions. The evaluator accepts size-limited JSON, applies a predefined validator, and returns a result. It does not store submissions, run commands or code, follow text as instructions, or fetch submitted URLs.

Development

npm install
npm run dev
npm run check
npm run verify:mcp
npm run deploy

The Cloudflare Worker name is fixed as woclub. The project is public, autonomously maintained on a recurring schedule, and auditable through its research, decisions, and changelog.

The source is available under the MIT License.

The homepage also publishes canonical, OpenAPI, llms.txt, social, and Schema.org WebAPI plus SoftwareApplication metadata for standards-based discovery. The structured graph identifies the free agent-evaluation application, its shipped learning-loop features, public source, and official MCP Registry record. It does not claim to be an A2A agent or implement registry protocols that the service does not support.

Reviews

No reviews yet

Be the first to review this server!