Non-custodial Solana swap & limit order engine for AI agents.
A Model Context Protocol server for TradeRouter.ai — non-custodial Solana swap, limit, trailing, DCA, TWAP, and combo-order engine for AI agents. Yes, and here's exactly why. The private key is read once from , used for local signing with + , and never transmitted, logged, or persisted. Only signed transactions leave your machine. Server messages are Ed25519-verified against a hard-coded trust…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
get_wallet_addressNo description publishedThis tool published no description. Forge does not invent one.
build_swapNo description publishedThis tool published no description. Forge does not invent one.
submit_signed_swapNo description publishedThis tool published no description. Forge does not invent one.
auto_swapNo description publishedThis tool published no description. Forge does not invent one.
get_holdingsNo description publishedThis tool published no description. Forge does not invent one.
get_mcapNo description publishedThis tool published no description. Forge does not invent one.
get_flex_cardNo description publishedThis tool published no description. Forge does not invent one.
connect_websocketNo description publishedThis tool published no description. Forge does not invent one.
connection_statusNo description publishedThis tool published no description. Forge does not invent one.
get_fill_logNo description publishedThis tool published no description. Forge does not invent one.
place_limit_orderNo description publishedThis tool published no description. Forge does not invent one.
place_trailing_orderNo description publishedThis tool published no description. Forge does not invent one.
place_twap_orderNo description publishedThis tool published no description. Forge does not invent one.
place_limit_twap_orderNo description publishedThis tool published no description. Forge does not invent one.
place_trailing_twap_orderNo description publishedThis tool published no description. Forge does not invent one.
place_limit_trailing_orderNo description publishedThis tool published no description. Forge does not invent one.
place_limit_trailing_twap_orderNo description publishedThis tool published no description. Forge does not invent one.
list_ordersNo description publishedThis tool published no description. Forge does not invent one.
check_orderNo description publishedThis tool published no description. Forge does not invent one.
cancel_orderNo description publishedThis tool published no description. Forge does not invent one.
extend_orderNo description publishedThis tool published no description. Forge does not invent one.
0 of 21 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
A Model Context Protocol server for TradeRouter.ai — non-custodial Solana swap, limit, trailing, DCA, TWAP, and combo-order engine for AI agents. Yes, and here's exactly why. The private key is read once from , used for local signing with + , and never transmitted, logged, or persisted. Only signed transactions leave your machine. Server messages are Ed25519-verified against a hard-coded trust anchor. See SECURITY.md for the full threat model, data-flow diagram, and permissions manifest. 1.…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.