@celorodrigues/token-safety-mcp

MCPcommunautéen ligne
v2.0.2io.github.baianomarceloeduardo-jpgMITMis à jour il y a 2 jnpmGitHub

MCP server for Base L2 token safety: bytecode scans, swap simulations, approval and liquidity risk, and the live new-pool channel — six paid x402 surfaces plus x402 infrastructure tools, with payment handled server-side.

État de l’endpointen ligne
vérifié il y a 2 jours · 1664 ms
100 % des 1 vérification a atteint cet endpoint
Fonctionne dans
ClaudeCursorCopilotChatGPTGemini

Déduit des transports déclarés par cette annonce (stdio, streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
457Téléch./sem.
il y a 2 jDernière mise à jour
Lit ces identifiants
  • AUTOMATON_MCP_PAYER_KEYClé d’APIfacultatif

    Private key of the wallet that pays for calls. The server only SIGNS an EIP-3009 authorisation; it never sends a transaction. Also required: ALLOW_OUTBOUND_SPEND=1, and this key is not loaded into…

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
Auteurio.github.baianomarceloeduardo-jpg
LicenceMIT
Version2.0.2
Sourcenpm+mcp-registry
Statut de confiance
B
60/100Bon
✓Listé dans l’index Forge+10/10
—Identité de l’éditeur vérifiée+0/20
→ Éditeur : exécutez `forge publish` depuis le dépôt du paquet pour revendiquer la propriété
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publiez depuis GitHub Actions avec --provenance pour que l’attestation lie ce paquet à ce dépôt
—Correspondance de mainteneur npm+0/5
→ Acquis dès que votre identité est vérifiée ci-dessus et que ce login est mainteneur npm de ce paquet
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance—
Dépendances✓ 0 résolues · aucune vulnérable
Surface d’outils13 outils · aucun privilégié
Analyse de sécurité✓ Proprev2.0.2 · aujourd’huiQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé28 sept. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

13 outils · aucun privilégié
Extrait statiquement du paquet publiév2.0.2 · 10h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

x402_healthCheck that the x402 Value API is live and read its advertised payment terms (network, chainId, asset, payTo, schemes).

Check that the x402 Value API is live and read its advertised payment terms (network, chainId, asset, payTo, schemes).

Aucun schéma d’entrée n’a été publié pour cet outil.

x402_pricingRead per-route pricing for the Value API (USDC amounts per route, the six surfaces, the free trial).

Read per-route pricing for the Value API (USDC amounts per route, the six surfaces, the free trial).

Aucun schéma d’entrée n’a été publié pour cet outil.

x402_conformanceAudit ANY x402 service: fetches its 402 challenge and returns a pass/fail conformance verdict (scheme, network, chainId, asset, payTo, amount).

Audit ANY x402 service: fetches its 402 challenge and returns a pass/fail conformance verdict (scheme, network, chainId, asset, payTo, amount).

Aucun schéma d’entrée n’a été publié pour cet outil.

verify_paymentVerify an on-chain ERC-20/USDC transfer on Base (free). Confirms the tx is real and confirmed, paid the right recipient, and met a minimum amount.

Verify an on-chain ERC-20/USDC transfer on Base (free). Confirms the tx is real and confirmed, paid the right recipient, and met a minimum amount.

Aucun schéma d’entrée n’a été publié pour cet outil.

x402_indexRead the live x402 service leaderboard (objectively scored by the conformance engine).

Read the live x402 service leaderboard (objectively scored by the conformance engine).

Aucun schéma d’entrée n’a été publié pour cet outil.

x402_submitFree self-submission: add your own x402 service to the public leaderboard. Returns the queued entry.

Free self-submission: add your own x402 service to the public leaderboard. Returns the queued entry.

Aucun schéma d’entrée n’a été publié pour cet outil.

x402_paid_uuidPAID call (0.001 USDC on Base) that returns a settled UUID, proving the whole x402 loop end to end. Settled by this server on your behalf when a payer is configured.

PAID call (0.001 USDC on Base) that returns a settled UUID, proving the whole x402 loop end to end. Settled by this server on your behalf when a payer is configured.

Aucun schéma d’entrée n’a été publié pour cet outil.

token_scanBytecode security scan of a Base token contract (PAID, 0.001 USDC). Reports honeypot opcodes, mint/blacklist/pause/tax capabilities, a risk score and a verdict. Read-only: no transaction is sent.

Bytecode security scan of a Base token contract (PAID, 0.001 USDC). Reports honeypot opcodes, mint/blacklist/pause/tax capabilities, a risk score and a verdict. Read-only: no transaction is sent.

Aucun schéma d’entrée n’a été publié pour cet outil.

tx_simulateRead-only buy/sell simulation of a Base token through the Uniswap V2 WETH pool (PAID, 0.01 USDC). Returns reverts, the measured transfer tax and a honeypot verdict. No transaction is sent.

Read-only buy/sell simulation of a Base token through the Uniswap V2 WETH pool (PAID, 0.01 USDC). Returns reverts, the measured transfer tax and a honeypot verdict. No transaction is sent.

Aucun schéma d’entrée n’a été publié pour cet outil.

approval_riskRead-only audit of the ERC-20 approvals an owner granted for a token (PAID, 0.01 USDC): spender, allowance, contract vs EOA, verified flag, drainable amount and a drain-risk verdict.

Read-only audit of the ERC-20 approvals an owner granted for a token (PAID, 0.01 USDC): spender, allowance, contract vs EOA, verified flag, drainable amount and a drain-risk verdict.

Aucun schéma d’entrée n’a été publié pour cet outil.

liquidity_riskOne-block liquidity audit of a Base token (PAID, 0.01 USDC): Uniswap V3 / Aerodrome pools, USD needed to move the price 1/2/5/10%, concentration, LP burn evidence and explicit coverage gaps.

One-block liquidity audit of a Base token (PAID, 0.01 USDC): Uniswap V3 / Aerodrome pools, USD needed to move the price 1/2/5/10%, concentration, LP burn evidence and explicit coverage gaps.

Aucun schéma d’entrée n’a été publié pour cet outil.

sentinel_latestNewest liquidity pools created on Base (Uniswap v3/v4, Aerodrome) with a bytecode risk score per new token (PAID, 0.001 USDC). Filters are optional.

Newest liquidity pools created on Base (Uniswap v3/v4, Aerodrome) with a bytecode risk score per new token (PAID, 0.001 USDC). Filters are optional.

Aucun schéma d’entrée n’a été publié pour cet outil.

sentinel_streamSubscribe to the live Base pool channel (/v2/sentinel/stream, SSE, 0.01 USDC). Unlike the other five this is a CONTINUOUS channel, not a discrete RPC action: this tool opens it, collects events for a bounded window and returns what arrived, saying so plainly. Reading again is another call. The serv…

Subscribe to the live Base pool channel (/v2/sentinel/stream, SSE, 0.01 USDC). Unlike the other five this is a CONTINUOUS channel, not a discrete RPC action: this tool opens it, collects events for a bounded window and returns what arrived, saying so plainly. Reading again is another call. The serv…

Aucun schéma d’entrée n’a été publié pour cet outil.

13 outils sur 13 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

MCP server for Base L2 token safety: bytecode scans, swap simulations, approval and liquidity risk, and the live new-pool channel — six paid x402 surfaces plus x402 infrastructure tools, with payment handled server-side.

Mots-clés
mcpmodel-context-protocolx402basetoken-securityhoneypotrug-pullagentusdc
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-09-30 — résolution observée, et non une déclaration de l'éditeur.

0 paquets résolus · 0 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

Ce paquet ne déclare aucune dépendance d'exécution.

Thèmes

Apparentés dans security