contract-auditor

contract-auditor

Quick-scan a smart contract for rug, honeypot, or centralization risk before sending funds. It combines verified source, live on-chain state, and heuristic Solidity analysis to return a SAFE/CAUTION/HIGH-RISK verdict.

Category
访问服务器

README

contract-auditor 🛡️

Quick-scan a smart contract for rug / honeypot / centralization risk before you approve or send funds.

contract-auditor is an MCP server and a pay-per-call x402 HTTP API. Give it a deployed contract address + chain (or raw Solidity source) and it returns a SAFE / CAUTION / HIGH-RISK verdict with an explained risk score.

It combines three things an AI agent can't gather on its own from a chat:

  1. Verified source from Sourcify (key-less, multi-chain) — or the absence of it (a strong red flag).
  2. Live on-chain state via public RPC — is there code at all? Is it an upgradeable proxy (owner can swap the code)? Who is the owner, and is it a single EOA, a multisig, or renounced?
  3. Heuristic Solidity scan for the real ways a contract takes or freezes your funds.

⚠️ Heuristic quick-scan, not a formal audit. Absence of findings is not proof of safety. Always do your own research before sending funds.

What it catches

🔁 Upgradeable proxy EIP-1967 / 1167 / beacon — the owner can replace the audited code
👑 Owner powers mint, pause, blacklist, owner-adjustable fees/tax, max-tx limits, trading on/off, withdraw/sweep
💀 Dangerous primitives selfdestruct, delegatecall, tx.origin auth, arbitrary external calls, inline assembly
🍯 Honeypot signals can't-sell patterns: blacklist + uncapped tax + trading switch + wallet/tx caps
🔓 Owner status live on-chain: renounced, single EOA (one key), or multisig/timelock?
Unverified no verified source on Sourcify = you can't read what you're trusting

Use as an MCP server (free)

{
  "mcpServers": {
    "contract-auditor": { "command": "npx", "args": ["-y", "contract-auditor-mcp"] }
  }
}

Tool: audit_contract — params: address, chain (alias or chainId), source (optional raw Solidity), deep (boolean).

Or connect over HTTP at POST /mcp.

Free HTTP API

GET https://contract-auditor-ivory.vercel.app/audit?address=0xdAC17F958D2ee523a2206206994597C13D831ec7&chain=ethereum
GET https://contract-auditor-ivory.vercel.app/audit?address=0x...&chain=base

Supported chains: ethereum, base, optimism, arbitrum, polygon, bsc, avalanche, gnosis, celo (or a numeric chainId). Free tier is rate-limited to 30 requests/hour/IP.

Pay-per-call (x402)

The /pro/audit route is gated by x402. Your agent pays $0.25 USDC per call automatically — no sign-up, no API key — settling on-chain (USDC on Base) to the operator wallet.

GET /pro/audit?address=0x...&chain=ethereum   # 402 → pay → result

How it works (honest about the limits)

  • Source is fetched from Sourcify by (chainId, address). If a contract is only verified on a native explorer and not mirrored to Sourcify, it shows as unverified here — pass the source directly to scan it.
  • On-chain checks use public RPCs (best-effort, community endpoints). If a chain's RPC is briefly down the audit degrades to a source-only verdict.
  • The Solidity scan is static pattern/heuristic analysis with comment-stripping and owner-gating context. It is tuned for low false-alarm on well-known patterns, but it is not symbolic execution or a formal verifier.

License

MIT

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
mcp-server-qdrant

mcp-server-qdrant

这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。

官方
精选
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选