Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.
xahau_server_infoHealth, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.Health, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_infoAccount root: balance, sequence, flags, regular key. Read-only.Account root: balance, sequence, flags, regular key. Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_objectsLedger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.Ledger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_hooksThe Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.The Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_hook_definitionFetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.Fetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_hook_stateRead Hook State entries for an account namespace (32-byte key→value map). Read-only.Read Hook State entries for an account namespace (32-byte key→value map). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_transactionA validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.A validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_ledgerHeader/summary of a ledger (default the latest validated). Read-only.Header/summary of a ledger (default the latest validated). Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_feeCurrent network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.Current network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_linesTrustlines (issued-currency balances) held by an account. Read-only.Trustlines (issued-currency balances) held by an account. Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_offersOpen DEX offers placed by an account. Read-only.Open DEX offers placed by an account. Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
explain_accountOne-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).One-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).
Aucun schéma d’entrée n’a été publié pour cet outil.
get_account_uritokensURITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.URITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_hook_onDecode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.Decode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
encode_hook_onBuild a canonical HookOn hex from a list of transaction types to fire on. Offline.Build a canonical HookOn hex from a list of transaction types to fire on. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_hook_can_emitDecode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…Decode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…
Aucun schéma d’entrée n’a été publié pour cet outil.
encode_hook_can_emitBuild a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.Build a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
estimate_hook_state_costCompute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…Compute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…
Aucun schéma d’entrée n’a été publié pour cet outil.
simulate_hook_triggerStatically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…Statically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_sethookDecode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.Decode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_tx_blobDecode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.Decode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
encode_tx_blobEncode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.Encode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_uritoken_idValidate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.Validate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
xah_amountConvert between XAH and drops (1 XAH = 1,000,000 drops). Offline.Convert between XAH and drops (1 XAH = 1,000,000 drops). Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
validate_addressValidate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.Validate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
xaddressEncode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.Encode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
currency_codeConvert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.Convert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_resultDecode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.Decode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
ripple_timeConvert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.Convert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_xpopDecode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…Decode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…
Aucun schéma d’entrée n’a été publié pour cet outil.
inspect_emitted_txDecode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.Decode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_lease_uriDecode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…Decode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_amountDecode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.Decode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
decode_sign_requestDecode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.Decode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.
Aucun schéma d’entrée n’a été publié pour cet outil.
scam_checkAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
inspect_hook_wasmParse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.Parse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.
Aucun schéma d’entrée n’a été publié pour cet outil.
analyze_hookRun the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.Run the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
audit_account_hooksFetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.Fetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.
Aucun schéma d’entrée n’a été publié pour cet outil.
list_rulesEnumerate the Hook analyzer rule registry (id, severity, title, category). Offline.Enumerate the Hook analyzer rule registry (id, severity, title, category). Offline.
Aucun schéma d’entrée n’a été publié pour cet outil.
hook_dry_runAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
38 outils sur 40 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.
36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)
112 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.
+100 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.
Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.