contract-auditor
Quick-scan a smart contract for rug, honeypot, or centralization risk before sending funds. It combines verified source, live on-chain state, and heuristic Solidity analysis to return a SAFE/CAUTION/HIGH-RISK verdict.
README
contract-auditor 🛡️
Quick-scan a smart contract for rug / honeypot / centralization risk before you approve or send funds.
contract-auditor is an MCP server and a pay-per-call x402 HTTP API. Give it a deployed contract address + chain (or raw Solidity source) and it returns a SAFE / CAUTION / HIGH-RISK verdict with an explained risk score.
It combines three things an AI agent can't gather on its own from a chat:
- Verified source from Sourcify (key-less, multi-chain) — or the absence of it (a strong red flag).
- Live on-chain state via public RPC — is there code at all? Is it an upgradeable proxy (owner can swap the code)? Who is the owner, and is it a single EOA, a multisig, or renounced?
- Heuristic Solidity scan for the real ways a contract takes or freezes your funds.
⚠️ Heuristic quick-scan, not a formal audit. Absence of findings is not proof of safety. Always do your own research before sending funds.
What it catches
| 🔁 Upgradeable proxy | EIP-1967 / 1167 / beacon — the owner can replace the audited code |
| 👑 Owner powers | mint, pause, blacklist, owner-adjustable fees/tax, max-tx limits, trading on/off, withdraw/sweep |
| 💀 Dangerous primitives | selfdestruct, delegatecall, tx.origin auth, arbitrary external calls, inline assembly |
| 🍯 Honeypot signals | can't-sell patterns: blacklist + uncapped tax + trading switch + wallet/tx caps |
| 🔓 Owner status | live on-chain: renounced, single EOA (one key), or multisig/timelock? |
| ❓ Unverified | no verified source on Sourcify = you can't read what you're trusting |
Use as an MCP server (free)
{
"mcpServers": {
"contract-auditor": { "command": "npx", "args": ["-y", "contract-auditor-mcp"] }
}
}
Tool: audit_contract — params: address, chain (alias or chainId), source (optional raw Solidity), deep (boolean).
Or connect over HTTP at POST /mcp.
Free HTTP API
GET https://contract-auditor-ivory.vercel.app/audit?address=0xdAC17F958D2ee523a2206206994597C13D831ec7&chain=ethereum
GET https://contract-auditor-ivory.vercel.app/audit?address=0x...&chain=base
Supported chains: ethereum, base, optimism, arbitrum, polygon, bsc, avalanche, gnosis, celo (or a numeric chainId). Free tier is rate-limited to 30 requests/hour/IP.
Pay-per-call (x402)
The /pro/audit route is gated by x402. Your agent pays $0.25 USDC per call automatically — no sign-up, no API key — settling on-chain (USDC on Base) to the operator wallet.
GET /pro/audit?address=0x...&chain=ethereum # 402 → pay → result
How it works (honest about the limits)
- Source is fetched from Sourcify by
(chainId, address). If a contract is only verified on a native explorer and not mirrored to Sourcify, it shows as unverified here — pass thesourcedirectly to scan it. - On-chain checks use public RPCs (best-effort, community endpoints). If a chain's RPC is briefly down the audit degrades to a source-only verdict.
- The Solidity scan is static pattern/heuristic analysis with comment-stripping and owner-gating context. It is tuned for low false-alarm on well-known patterns, but it is not symbolic execution or a formal verifier.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
mcp-server-qdrant
这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器