Server data from the Official MCP Registry
Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding
Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding
Set these up before or after installing:
Environment variable: RPC_URL
Environment variable: THRYX_API_KEY
Environment variable: BASESCAN_API_KEY
Environment variable: ETHERSCAN_API_KEY
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-lordbasilaiassistant-sudo-contract-scanner": {
"env": {
"RPC_URL": "your-rpc-url-here",
"THRYX_API_KEY": "your-thryx-api-key-here",
"BASESCAN_API_KEY": "your-basescan-api-key-here",
"ETHERSCAN_API_KEY": "your-etherscan-api-key-here"
},
"args": [
"-y",
"@thryx/contract-scanner-mcp-server"
],
"command": "npx"
}
}
}This monorepo contains multiple cryptocurrency/DeFi MCP servers with serious security vulnerabilities. Critical findings include direct shell command execution via subprocess, hardcoded secrets in configuration files, and overly broad permissions that enable arbitrary blockchain operations and financial transactions without sufficient safeguards. Supply chain analysis found 4 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.
Scanned 5 files · 11 findings
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Be the first to review this server!
by Toleno
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace
Create, build, and publish Python MCP servers to PyPI — conversationally.
by mcp-marketplace
Scaffold, build, and publish TypeScript MCP servers to npm — conversationally