xahau-mcp

MCPcommunity
v2.3.0Dane BrownMITUpdated 7d agonpmGitHub

Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
240Downloads/wk
6GitHub stars
2Forks
7d agoLast update
Package
AuthorDane Brown
LicenseMIT
Version2.3.0
Sourcenpm+mcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
Dependencies60 resolved · 2 with advisories
Tool surface40 tools · none privileged
Security scan⚠ Warnings (2)v2.3.0 · todayHow well does this scan work?
EvalsNone
IndexedOct 10, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · none privileged
Statically extracted from the published packagev2.3.0 · 19h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

xahau_server_infoHealth, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.

Health, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.

No input schema was published for this tool.

get_account_infoAccount root: balance, sequence, flags, regular key. Read-only.

Account root: balance, sequence, flags, regular key. Read-only.

No input schema was published for this tool.

get_account_objectsLedger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.

Ledger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.

No input schema was published for this tool.

get_account_hooksThe Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.

The Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transactions carrying the matching HookName). Read-only.

No input schema was published for this tool.

get_hook_definitionFetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.

Fetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.

No input schema was published for this tool.

get_hook_stateRead Hook State entries for an account namespace (32-byte key→value map). Read-only.

Read Hook State entries for an account namespace (32-byte key→value map). Read-only.

No input schema was published for this tool.

get_transactionA validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.

A validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.

No input schema was published for this tool.

get_ledgerHeader/summary of a ledger (default the latest validated). Read-only.

Header/summary of a ledger (default the latest validated). Read-only.

No input schema was published for this tool.

get_feeCurrent network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.

Current network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.

No input schema was published for this tool.

get_account_linesTrustlines (issued-currency balances) held by an account. Read-only.

Trustlines (issued-currency balances) held by an account. Read-only.

No input schema was published for this tool.

get_account_offersOpen DEX offers placed by an account. Read-only.

Open DEX offers placed by an account. Read-only.

No input schema was published for this tool.

explain_accountOne-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).

One-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode leases auto-decoded), and recent activity — plus warnings and notes. Read-only; exactly 5 serial RPC reads (>=1100ms apart).

No input schema was published for this tool.

get_account_uritokensURITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.

URITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.

No input schema was published for this tool.

decode_hook_onDecode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.

Decode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Offline.

No input schema was published for this tool.

encode_hook_onBuild a canonical HookOn hex from a list of transaction types to fire on. Offline.

Build a canonical HookOn hex from a list of transaction types to fire on. Offline.

No input schema was published for this tool.

decode_hook_can_emitDecode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…

Decode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/active-low, active-high SetHook bit). NOTE: an ABSENT HookCanEmit field means the hook may emit ANY transaction (including SetHook) — this too…

No input schema was published for this tool.

encode_hook_can_emitBuild a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.

Build a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the field entirely on the SetHook to allow emitting anything. Offline.

No input schema was published for this tool.

estimate_hook_state_costCompute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…

Compute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-entry capacity (256×scale bytes), per-entry reserve units (= scale, charged even for 1 byte), total reserve units, overflow warnings, and t…

No input schema was published for this tool.

simulate_hook_triggerStatically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…

Statically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) roles — from the tx fields alone, no bytecode run and no ledger read. For tx types whose stakeholders require ledger-object lookups it returns…

No input schema was published for this tool.

decode_sethookDecode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.

Decode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.

No input schema was published for this tool.

decode_tx_blobDecode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.

Decode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.

No input schema was published for this tool.

encode_tx_blobEncode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.

Encode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.

No input schema was published for this tool.

decode_uritoken_idValidate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.

Validate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.

No input schema was published for this tool.

xah_amountConvert between XAH and drops (1 XAH = 1,000,000 drops). Offline.

Convert between XAH and drops (1 XAH = 1,000,000 drops). Offline.

No input schema was published for this tool.

validate_addressValidate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.

Validate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.

No input schema was published for this tool.

xaddressEncode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.

Encode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.

No input schema was published for this tool.

currency_codeConvert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.

Convert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.

No input schema was published for this tool.

decode_resultDecode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.

Decode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.

No input schema was published for this tool.

ripple_timeConvert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.

Convert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.

No input schema was published for this tool.

decode_xpopDecode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…

Decode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itself. Returns the source ledger header, the decoded inner BURN transaction (type, burned drops = its Fee, target network), and the UNL valida…

No input schema was published for this tool.

inspect_emitted_txDecode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.

Decode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tries to send' summary + danger score (scam rules). Closes the loop on emitter hooks. Offline.

No input schema was published for this tool.

decode_lease_uriDecode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…

Decode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP. Accepts the on-chain URI hex, the base64 text, or raw buffer hex. Verified against the canonical evernode-js-client encoder + real mainnet…

No input schema was published for this tool.

decode_amountDecode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.

Decode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → normalized value/currency/issuer. Offline.

No input schema was published for this tool.

decode_sign_requestDecode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.

Decode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary and safety warnings (SetHook, AccountDelete, key changes, no-expiry, already-signed). Offline — understand before you sign.

No input schema was published for this tool.

scam_checkNo description published

This tool published no description. Forge does not invent one.

inspect_hook_wasmParse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.

Parse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, never executes the module.

No input schema was published for this tool.

analyze_hookRun the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.

Run the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.

No input schema was published for this tool.

audit_account_hooksFetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.

Fetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.

No input schema was published for this tool.

list_rulesEnumerate the Hook analyzer rule registry (id, severity, title, category). Offline.

Enumerate the Hook analyzer rule registry (id, severity, title, category). Offline.

No input schema was published for this tool.

hook_dry_runNo description published

This tool published no description. Forge does not invent one.

38 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.

Keywords
xahauhooksxrplmcpmodel-context-protocolsmart-contractswasmstatic-analysisblockchain
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-10 — observed resolution, not a publisher declaration.

60 packages resolved · 3 direct · 2 carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

112 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+100 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in crypto & web3