Back to Browse

Base Security Scanner MCP Server

SecurityModerate7.5MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.

About

MCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.

Security Report

7.5
Moderate7.5Low Risk

Valid MCP server (2 strong, 4 medium validity signals). 3 known CVEs in dependencies (0 critical, 2 high severity) Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

3 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Base mainnet RPC URL (defaults to https://mainnet.base.org)Optional

Environment variable: RPC_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-lordbasilaiassistant-sudo-base-security-scanner-mcp": {
      "env": {
        "RPC_URL": "your-rpc-url-here"
      },
      "args": [
        "-y",
        "base-security-scanner-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

base-security-scanner-mcp

MCP server for AI agents to scan smart contracts on Base mainnet for security vulnerabilities. Detect honeypots, rug pulls, hidden mints, proxy patterns, and generate full audit reports -- all read-only, no private key needed.

Install

npx -y base-security-scanner-mcp

Configure (Claude Desktop / Cursor)

{
  "mcpServers": {
    "base-security-scanner": {
      "command": "npx",
      "args": ["-y", "base-security-scanner-mcp"]
    }
  }
}

Tools (8)

ToolDescription
scan_contractAnalyze a contract for security issues (reentrancy, access control, hidden mints, proxy patterns)
check_honeypotCheck if a token is a honeypot by simulating buy+sell via Uniswap V2
detect_rug_riskScore rug pull risk 0-100 based on ownership, liquidity, permissions, honeypot status
analyze_bytecodeDisassemble bytecode, identify contract type (proxy, AMM, ERC-20, diamond, etc.)
check_token_permissionsCheck owner permissions: mint, pause, blacklist, change fees, disable trading
get_contract_infoBasic contract metadata: verified status, bytecode size, ETH balance, token info
compare_bytecodeClone detection -- check if two contracts share the same bytecode
audit_reportFull security audit combining all checks into one comprehensive report

Environment Variables

VariableDefaultDescription
RPC_URLhttps://mainnet.base.orgBase mainnet RPC endpoint

How It Works

  • Bytecode Analysis: Extracts PUSH4 opcodes to find function selectors, matches against 30+ known dangerous patterns
  • Opcode Scanning: Detects DELEGATECALL, SELFDESTRUCT, CREATE, CREATE2
  • Honeypot Detection: Simulates ETH->Token->ETH round-trip via Uniswap V2 router getAmountsOut
  • Rug Scoring: Weighted algorithm combining ownership, liquidity depth, dangerous permissions, honeypot status
  • Clone Detection: Jaccard similarity on function selector sets

Related MCP Servers

PackageToolsWhat it does
obsd-launchpad-mcp14Deploy tokens, trade, earn OBSD
base-security-scanner-mcp8Scan contracts for vulnerabilities
base-price-oracle-mcp7On-chain price feeds from DEX pools
base-multi-wallet-mcp8Coordinated multi-wallet trading
base-gasless-deploy-mcp5Gasless ERC-20 token deployment
base-flash-arb-mcp7Detect arbitrage opportunities
base-token-sniper-mcp5Discover & trade new launches
base-wallet-toolkit-mcp7Wallet balances, gas, tokens
base-contract-reader-mcp6Read any smart contract (free)
create-mcp-server-cli-Scaffold a new MCP server

License

MIT

Reviews

No reviews yet

Be the first to review this server!