# xahau-mcp

Model Context Protocol (stdio) server for the Xahau network: offline Hook WASM inspection, a Hooks-specific static-analysis rule engine, and read-only ledger, codec, governance and unsigned-transaction tooling. Never signs or submits.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.3.0
- **Author:** Dane Brown
- **License:** MIT
- **npm:** xahau-mcp
- **Source:** https://github.com/Hugegreencandle/xahau-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-10-10T18:32:25.771Z
- **Version scanned:** 2.3.0
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `xahau_server_info` — Health, version, amendments and ledger range of a Xahau node (mainnet or testnet). Read-only.
- `get_account_info` — Account root: balance, sequence, flags, regular key. Read-only.
- `get_account_objects` — Ledger objects owned by an account, optionally filtered by type (hook, hook_state, uri_token, etc.). Read-only.
- `get_account_hooks` — The Hooks installed on an account, with each HookOn bitmap decoded to the transaction types it fires on, and any HookName (a named hook fires only for transacti
- `get_hook_definition` — Fetch a HookDefinition ledger object by hash (CreateCode WASM, HookOn, fee, reference count). Read-only.
- `get_hook_state` — Read Hook State entries for an account namespace (32-byte key→value map). Read-only.
- `get_transaction` — A validated transaction by hash, including Xahau HookExecutions metadata (hook return codes/strings). Read-only.
- `get_ledger` — Header/summary of a ledger (default the latest validated). Read-only.
- `get_fee` — Current network transaction fee (base fee in drops + load/queue state) — for building a tx with the right Fee. Read-only.
- `get_account_lines` — Trustlines (issued-currency balances) held by an account. Read-only.
- `get_account_offers` — Open DEX offers placed by an account. Read-only.
- `explain_account` — One-call plain-English account snapshot: balance, key-safety read (master/regular key), installed Hooks (+what they fire on), trustlines, URITokens (Evernode le
- `get_account_uritokens` — URITokens (Xahau-native NFTs) owned by an account, with each token's URI decoded from hex to text. Read-only.
- `decode_hook_on` — Decode a HookOn 256-bit bitmap into the set of transaction types the hook fires on. Handles the inverted/active-low encoding and the active-high SetHook bit. Of
- `encode_hook_on` — Build a canonical HookOn hex from a list of transaction types to fire on. Offline.
- `decode_hook_can_emit` — Decode a HookCanEmit 256-bit bitmap into the set of transaction types a hook is permitted to EMIT (HookCanEmit amendment). Same encoding as HookOn (inverted/act
- `encode_hook_can_emit` — Build a canonical HookCanEmit hex from the list of transaction types a hook should be allowed to emit (HookCanEmit amendment; same encoding as HookOn). Omit the
- `estimate_hook_state_cost` — Compute the owner-reserve cost of Hook State entries under ExtendedHookState. Given each entry's value size in bytes and the HookStateScale (1–16), returns per-
- `simulate_hook_trigger` — Statically predict which accounts' hooks a transaction WOULD invoke (transactional stakeholders), with strong (can rollback) vs weak (runs, can't rollback) role
- `decode_sethook` — Decode a SetHook transaction (JSON or tx blob) into its hook definitions, each with HookOn decoded. Offline.
- `decode_tx_blob` — Decode a Xahau transaction blob (hex) into JSON via the Xahau-aware binary codec. Offline.
- `encode_tx_blob` — Encode a transaction JSON into an UNSIGNED Xahau binary blob (for inspection/round-trip; never signed). Offline.
- `decode_uritoken_id` — Validate a URIToken ID and explain its structure (SHA512-Half of issuer||URI; not reversible offline). Offline.
- `xah_amount` — Convert between XAH and drops (1 XAH = 1,000,000 drops). Offline.
- `validate_address` — Validate a Xahau/XRPL address (classic r-address or X-address) → type, account-id, embedded destination tag, network. Offline.
- `xaddress` — Encode a classic address + destination tag into an X-address, or decode an X-address back to classic + tag. Offline.
- `currency_code` — Convert a currency between 3-char ISO code (e.g. USD) and its 160-bit/40-hex form. Non-standard 160-bit codes pass through. Offline.
- `decode_result` — Decode a transaction engine result code (e.g. 0/tesSUCCESS, 153/tecHOOK_REJECTED) ⇄ its name. Accepts a number or the result-code name. Offline.
- `ripple_time` — Convert between Ripple time (seconds since 2000-01-01), Unix time, and ISO 8601. Xahau tx/ledger timestamps use Ripple time. Offline.
- `decode_xpop` — Decode an XPOP (Xahau Proof of Payment) — the proof blob inside an Import/Burn2Mint tx. Accepts the Import Blob hex (hex of the XPOP JSON) or the XPOP JSON itse
- `inspect_emitted_tx` — Decode what a hook's emit() actually built: pass the emitted[] blob hex(es) from an execute_hook result → each decoded to tx JSON + a plain-English 'what it tri
- `decode_lease_uri` — Decode an Evernode lease URIToken URI (the `evrlease`/LTV format) → lease index, lease amount in EVR (XFL-decoded), half ToS hash, mint identifier, outbound IP.
- `decode_amount` — Decode an amount: native drops (digits), a serialized 8-byte native or 48-byte issued STAmount (hex), or an issued amount object {currency,issuer,value} → norma
- `decode_sign_request` — Decode a sign request (a Xaman/Xumm payload's txjson, or a raw tx_blob hex) into the transaction plus a plain-English 'what you would be authorizing' summary an
- `scam_check`
- `inspect_hook_wasm` — Parse a Hook's CreateCode WASM (hex or base64): imports (Hook API functions), exports (hook/cbak), memory, custom sections, loop and guard(_g) counts. Offline, 
- `analyze_hook` — Run the Hook static-analysis / security rule engine over a CreateCode WASM (+ optional SetHook params) and return SARIF-lite findings. Offline.
- `audit_account_hooks` — Fetch every hook on an account, pull each HookDefinition's WASM, and run the analyzer over all of them. Read-only network + offline analysis.
- `list_rules` — Enumerate the Hook analyzer rule registry (id, severity, title, category). Offline.
- `hook_dry_run`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"xahau\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"xahau-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/xahau-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/xahau-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/xahau-mcp
- HTML page: https://forgeregistry.com/registry/xahau-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
