@celorodrigues/token-safety-mcp

MCPcomunidaden línea
v2.0.2io.github.baianomarceloeduardo-jpgMITActualizado hace 2 dnpmGitHub

MCP server for Base L2 token safety: bytecode scans, swap simulations, approval and liquidity risk, and the live new-pool channel — six paid x402 surfaces plus x402 infrastructure tools, with payment handled server-side.

Estado del endpointen línea
comprobado hace 2 días · 1664 ms
100 % de las últimas 1 comprobación llegó a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (stdio, streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
457Descargas/sem.
hace 2 dÚltima actualización
Lee estas credenciales
  • AUTOMATON_MCP_PAYER_KEYClave de APIopcional

    Private key of the wallet that pays for calls. The server only SIGNS an EIP-3009 authorisation; it never sends a transaction. Also required: ALLOW_OUTBOUND_SPEND=1, and this key is not loaded into…

Declarado por el autor en el registro oficial de MCP. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquete
Autorio.github.baianomarceloeduardo-jpg
LicenciaMIT
Versión2.0.2
Fuentenpm+mcp-registry
Estado de confianza
B
60/100Bueno
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/20
→ Publicador: ejecuta `forge publish` desde el repo del paquete para reclamar la propiedad
—Firma de publicación Ed25519+0/5
→ Se incluye automáticamente cuando el publicador ejecuta `forge publish`
—Verificación de dominio+0/5
→ Publicador: aloja /.well-known/forge.json en la página del paquete con { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publica desde GitHub Actions con --provenance para que la attestation vincule este paquete a este repo
—Coincidencia de maintainer en npm+0/5
→ Se consigue cuando tu identidad esté verificada arriba y ese login sea maintainer de este paquete en npm
✓Análisis CVE · limpio+30/30
✓Análisis estático · limpio+20/20
Pégalo en Claude Code, Cursor o cualquier asistente de IA para corregir todas las carencias
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
Dependencias✓ 0 resueltas · ninguna vulnerable
Superficie de herramientas13 herramientas · ninguna privilegiada
Análisis de seguridad✓ Limpiov2.0.2 · hoy¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado28 sept 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

13 herramientas · ninguna privilegiada
Extraído estáticamente del paquete publicadov2.0.2 · 10h ago

Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.

x402_healthCheck that the x402 Value API is live and read its advertised payment terms (network, chainId, asset, payTo, schemes).

Check that the x402 Value API is live and read its advertised payment terms (network, chainId, asset, payTo, schemes).

No se publicó ningún esquema de entrada para esta herramienta.

x402_pricingRead per-route pricing for the Value API (USDC amounts per route, the six surfaces, the free trial).

Read per-route pricing for the Value API (USDC amounts per route, the six surfaces, the free trial).

No se publicó ningún esquema de entrada para esta herramienta.

x402_conformanceAudit ANY x402 service: fetches its 402 challenge and returns a pass/fail conformance verdict (scheme, network, chainId, asset, payTo, amount).

Audit ANY x402 service: fetches its 402 challenge and returns a pass/fail conformance verdict (scheme, network, chainId, asset, payTo, amount).

No se publicó ningún esquema de entrada para esta herramienta.

verify_paymentVerify an on-chain ERC-20/USDC transfer on Base (free). Confirms the tx is real and confirmed, paid the right recipient, and met a minimum amount.

Verify an on-chain ERC-20/USDC transfer on Base (free). Confirms the tx is real and confirmed, paid the right recipient, and met a minimum amount.

No se publicó ningún esquema de entrada para esta herramienta.

x402_indexRead the live x402 service leaderboard (objectively scored by the conformance engine).

Read the live x402 service leaderboard (objectively scored by the conformance engine).

No se publicó ningún esquema de entrada para esta herramienta.

x402_submitFree self-submission: add your own x402 service to the public leaderboard. Returns the queued entry.

Free self-submission: add your own x402 service to the public leaderboard. Returns the queued entry.

No se publicó ningún esquema de entrada para esta herramienta.

x402_paid_uuidPAID call (0.001 USDC on Base) that returns a settled UUID, proving the whole x402 loop end to end. Settled by this server on your behalf when a payer is configured.

PAID call (0.001 USDC on Base) that returns a settled UUID, proving the whole x402 loop end to end. Settled by this server on your behalf when a payer is configured.

No se publicó ningún esquema de entrada para esta herramienta.

token_scanBytecode security scan of a Base token contract (PAID, 0.001 USDC). Reports honeypot opcodes, mint/blacklist/pause/tax capabilities, a risk score and a verdict. Read-only: no transaction is sent.

Bytecode security scan of a Base token contract (PAID, 0.001 USDC). Reports honeypot opcodes, mint/blacklist/pause/tax capabilities, a risk score and a verdict. Read-only: no transaction is sent.

No se publicó ningún esquema de entrada para esta herramienta.

tx_simulateRead-only buy/sell simulation of a Base token through the Uniswap V2 WETH pool (PAID, 0.01 USDC). Returns reverts, the measured transfer tax and a honeypot verdict. No transaction is sent.

Read-only buy/sell simulation of a Base token through the Uniswap V2 WETH pool (PAID, 0.01 USDC). Returns reverts, the measured transfer tax and a honeypot verdict. No transaction is sent.

No se publicó ningún esquema de entrada para esta herramienta.

approval_riskRead-only audit of the ERC-20 approvals an owner granted for a token (PAID, 0.01 USDC): spender, allowance, contract vs EOA, verified flag, drainable amount and a drain-risk verdict.

Read-only audit of the ERC-20 approvals an owner granted for a token (PAID, 0.01 USDC): spender, allowance, contract vs EOA, verified flag, drainable amount and a drain-risk verdict.

No se publicó ningún esquema de entrada para esta herramienta.

liquidity_riskOne-block liquidity audit of a Base token (PAID, 0.01 USDC): Uniswap V3 / Aerodrome pools, USD needed to move the price 1/2/5/10%, concentration, LP burn evidence and explicit coverage gaps.

One-block liquidity audit of a Base token (PAID, 0.01 USDC): Uniswap V3 / Aerodrome pools, USD needed to move the price 1/2/5/10%, concentration, LP burn evidence and explicit coverage gaps.

No se publicó ningún esquema de entrada para esta herramienta.

sentinel_latestNewest liquidity pools created on Base (Uniswap v3/v4, Aerodrome) with a bytecode risk score per new token (PAID, 0.001 USDC). Filters are optional.

Newest liquidity pools created on Base (Uniswap v3/v4, Aerodrome) with a bytecode risk score per new token (PAID, 0.001 USDC). Filters are optional.

No se publicó ningún esquema de entrada para esta herramienta.

sentinel_streamSubscribe to the live Base pool channel (/v2/sentinel/stream, SSE, 0.01 USDC). Unlike the other five this is a CONTINUOUS channel, not a discrete RPC action: this tool opens it, collects events for a bounded window and returns what arrived, saying so plainly. Reading again is another call. The serv…

Subscribe to the live Base pool channel (/v2/sentinel/stream, SSE, 0.01 USDC). Unlike the other five this is a CONTINUOUS channel, not a discrete RPC action: this tool opens it, collects events for a bounded window and returns what arrived, saying so plainly. Reading again is another call. The serv…

No se publicó ningún esquema de entrada para esta herramienta.

13 de 13 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

MCP server for Base L2 token safety: bytecode scans, swap simulations, approval and liquidity risk, and the live new-pool channel — six paid x402 surfaces plus x402 infrastructure tools, with payment handled server-side.

Palabras clave
mcpmodel-context-protocolx402basetoken-securityhoneypotrug-pullagentusdc
Alternativas
Comparando superficies de herramientas…

Árbol de dependencias

Lo que un análisis de Forge resolvió a partir de los metadatos de npm el 2026-09-30: resolución observada, no una declaración del publicador.

0 paquetes resueltos · 0 directos · ninguno con avisos de seguridad La resolución se detiene en la profundidad 4 y en 60 paquetes.

Este paquete no declara dependencias en tiempo de ejecución.

Temas

Relacionados en security