Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.
xahau_server_infoHealth, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.Health, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_infoAccount root: balance, sequence, flags, regular key. Read-only.Account root: balance, sequence, flags, regular key. Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_objectsLedger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.Ledger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_hooksThe Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.The Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_hook_definitionFetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.Fetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_hook_stateRead Hook State entries for an account namespace (32-byte key→value map). Read-only.Read Hook State entries for an account namespace (32-byte key→value map). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_transactionA validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.A validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_ledgerHeader/summary of a ledger (default the latest validated). Read-only.Header/summary of a ledger (default the latest validated). Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_feeCurrent network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.Current network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_linesTrustlines (issued-currency balances) held by an account. Read-only.Trustlines (issued-currency balances) held by an account. Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_offersOpen DEX offers placed by an account. Read-only.Open DEX offers placed by an account. Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
explain_accountOne-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).One-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).
Per questo strumento non è stato pubblicato alcuno schema di input.
get_account_uritokensURITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.URITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_hook_onDecode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.Decode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
encode_hook_onBuild a canonical HookOn hex from a list of transaction types to fire on. Offline.Build a canonical HookOn hex from a list of transaction types to fire on. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_hook_can_emitDecode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…Decode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…
Per questo strumento non è stato pubblicato alcuno schema di input.
encode_hook_can_emitBuild a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.Build a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
estimate_hook_state_costCompute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…Compute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…
Per questo strumento non è stato pubblicato alcuno schema di input.
simulate_hook_triggerStatically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…Statically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_sethookDecode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.Decode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_tx_blobDecode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.Decode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
encode_tx_blobEncode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.Encode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_uritoken_idValidate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.Validate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
xah_amountConvert between XAH and drops (1 XAH = 1,000,000 drops). Offline.Convert between XAH and drops (1 XAH = 1,000,000 drops). Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
validate_addressValidate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.Validate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
xaddressEncode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.Encode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
currency_codeConvert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.Convert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_resultDecode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.Decode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
ripple_timeConvert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.Convert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_xpopDecode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…Decode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…
Per questo strumento non è stato pubblicato alcuno schema di input.
inspect_emitted_txDecode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.Decode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_lease_uriDecode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…Decode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_amountDecode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.Decode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
decode_sign_requestDecode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.Decode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.
Per questo strumento non è stato pubblicato alcuno schema di input.
scam_checkNessuna descrizione pubblicataQuesto strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.
inspect_hook_wasmParse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.Parse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.
Per questo strumento non è stato pubblicato alcuno schema di input.
analyze_hookRun the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.Run the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
audit_account_hooksFetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.Fetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.
Per questo strumento non è stato pubblicato alcuno schema di input.
list_rulesEnumerate the Hook analyzer rule registry (id, severity, title, category). Offline.Enumerate the Hook analyzer rule registry (id, severity, title, category). Offline.
Per questo strumento non è stato pubblicato alcuno schema di input.
hook_dry_runNessuna descrizione pubblicataQuesto strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.
38 strumenti su 40 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.
Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)
112 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.
+100 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.
Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.