Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.
xahau_server_infoHealth, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.Health, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_account_infoAccount root: balance, sequence, flags, regular key. Read-only.Account root: balance, sequence, flags, regular key. Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_account_objectsLedger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.Ledger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_account_hooksThe Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.The Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_hook_definitionFetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.Fetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_hook_stateRead Hook State entries for an account namespace (32-byte key→value map). Read-only.Read Hook State entries for an account namespace (32-byte key→value map). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_transactionA validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.A validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_ledgerHeader/summary of a ledger (default the latest validated). Read-only.Header/summary of a ledger (default the latest validated). Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_feeCurrent network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.Current network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_account_linesTrustlines (issued-currency balances) held by an account. Read-only.Trustlines (issued-currency balances) held by an account. Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
get_account_offersOpen DEX offers placed by an account. Read-only.Open DEX offers placed by an account. Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
explain_accountOne-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).One-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).
No se publicó ningún esquema de entrada para esta herramienta.
get_account_uritokensURITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.URITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.
No se publicó ningún esquema de entrada para esta herramienta.
decode_hook_onDecode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.Decode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
encode_hook_onBuild a canonical HookOn hex from a list of transaction types to fire on. Offline.Build a canonical HookOn hex from a list of transaction types to fire on. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_hook_can_emitDecode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…Decode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…
No se publicó ningún esquema de entrada para esta herramienta.
encode_hook_can_emitBuild a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.Build a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
estimate_hook_state_costCompute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…Compute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…
No se publicó ningún esquema de entrada para esta herramienta.
simulate_hook_triggerStatically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…Statically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…
No se publicó ningún esquema de entrada para esta herramienta.
decode_sethookDecode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.Decode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_tx_blobDecode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.Decode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
encode_tx_blobEncode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.Encode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_uritoken_idValidate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.Validate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.
No se publicó ningún esquema de entrada para esta herramienta.
xah_amountConvert between XAH and drops (1 XAH = 1,000,000 drops). Offline.Convert between XAH and drops (1 XAH = 1,000,000 drops). Offline.
No se publicó ningún esquema de entrada para esta herramienta.
validate_addressValidate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.Validate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
xaddressEncode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.Encode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
currency_codeConvert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.Convert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_resultDecode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.Decode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
ripple_timeConvert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.Convert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_xpopDecode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…Decode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…
No se publicó ningún esquema de entrada para esta herramienta.
inspect_emitted_txDecode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.Decode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_lease_uriDecode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…Decode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…
No se publicó ningún esquema de entrada para esta herramienta.
decode_amountDecode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.Decode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
decode_sign_requestDecode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.Decode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.
No se publicó ningún esquema de entrada para esta herramienta.
scam_checkSin descripción publicadaEsta herramienta no publicó ninguna descripción. Forge no se la inventa.
inspect_hook_wasmParse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.Parse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.
No se publicó ningún esquema de entrada para esta herramienta.
analyze_hookRun the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.Run the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.
No se publicó ningún esquema de entrada para esta herramienta.
audit_account_hooksFetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.Fetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.
No se publicó ningún esquema de entrada para esta herramienta.
list_rulesEnumerate the Hook analyzer rule registry (id, severity, title, category). Offline.Enumerate the Hook analyzer rule registry (id, severity, title, category). Offline.
No se publicó ningún esquema de entrada para esta herramienta.
hook_dry_runSin descripción publicadaEsta herramienta no publicó ninguna descripción. Forge no se la inventa.
38 de 40 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
El rastreo se detuvo en el límite de 60 paquetes. El resto del árbol nunca se resolvió.
Hay 36 paquetes resueltos más que no se dibujan aquí (límite de visualización: 24). Toda dependencia con avisos de seguridad se dibuja aunque se supere el límite. Inventario completo (SBOM CycloneDX)
112 dependencias declaradas nunca llegaron al árbol. Faltan en la resolución de Forge, no en el paquete.
+100 más sin listar. Los recuentos por motivo de arriba las incluyen todas.
No se siguen: peerDependencies. Este árbol cubre solo dependencias en tiempo de ejecución, así que lo que estas arrastren nunca se resolvió.