Back to Browse

M2m Sentinel Sdk MCP Server

SecurityLow Risk10.0MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Base bytecode capability observations, proxy resolution, gas, DEX, and transfer telemetry.

About

Base bytecode capability observations, proxy resolution, gas, DEX, and transfer telemetry.

Remote endpoints: streamable-http: https://api.m2msentinel.com/mcp sse: https://api.m2msentinel.com/sse

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

6 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Optional M2M Sentinel API key for prepaid access.Required

Environment variable: M2M_SENTINEL_API_KEY

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

M2M Sentinel SDK & MCP Server

Official multi-language client library, Model Context Protocol (MCP) server, and Coinbase AgentKit ActionProvider for M2M Sentinel — deterministic EVM bytecode capability observations and common-proxy resolution for autonomous applications operating on Base. Callers own transaction policy.

This export labels npm 1.2.8 as a local release candidate, not a verified published artifact. This candidate version does not establish registry publication or installability. The install commands below use the last-verified npm release 1.2.7.

npm version PyPI version License: MIT Smithery


Try Base USDC without a wallet or API key

This quickstart uses Base USDC, a published allowlisted sample at 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913. The response contains factual capability evidence and limitations, not a safety guarantee or transaction advice. The live demo can be rate limited (HTTP 429 with Retry-After) or unavailable when upstream evidence sources fail (HTTP 503).

curl --fail-with-body https://api.m2msentinel.com/v1/demo/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
npm install m2m-sentinel-sdk@1.2.7
const { M2MSentinelClient } = require('m2m-sentinel-sdk');
(async () => {
  const client = new M2MSentinelClient();
  const result = await client.demoAudit('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
  console.log(JSON.stringify(result, null, 2));
})().catch((error) => { console.error(error.message); process.exitCode = 1; });
pip install m2m-sentinel==1.2.7
from m2m_sentinel import M2MSentinelClient

client = M2MSentinelClient()
result = client.demo_audit("0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913")
print(result)

Other addresses receive only the public preview. Full /v1/audit/:address analysis remains protected by an API key or an explicitly authorized x402 payment; the demo never pays silently. The client does not automatically retry or fall back to a protected route after a demo error. The source SDK export includes a runnable no-credential JavaScript example at examples/try_public_demo.js; it is not included in the last-verified npm 1.2.7 artifact.


⚡ 1. Model Context Protocol (MCP) Server

Connect M2M Sentinel directly to Claude Desktop, Cursor, Windsurf, or any MCP-compliant LLM agent.

Option A: 1-Click via Smithery

npx -y @smithery/cli mcp add M2M-Sentinel/m2m-sentinel-sdk --client claude

Option B: Local Stdio (claude_desktop_config.json)

{
  "mcpServers": {
    "m2m-sentinel": {
      "command": "npx",
      "args": ["-y", "m2m-sentinel-sdk@1.2.7"],
      "env": {
        "M2M_SENTINEL_API_KEY": ""
      }
    }
  }
}

Option C: Remote Streamable HTTP

  • Current MCP endpoint: https://api.m2msentinel.com/mcp
  • Legacy HTTP+SSE compatibility: https://api.m2msentinel.com/sse with messages at https://api.m2msentinel.com/messages

🤖 2. Coinbase AgentKit Integration

import { AgentKit } from "@coinbase/agentkit";
import { m2mSentinelActionProvider } from "m2m-sentinel-sdk";

const agentKit = await AgentKit.from({
  walletProvider,
  actionProviders: [
    m2mSentinelActionProvider({
      apiKey: process.env.M2M_SENTINEL_API_KEY
    })
  ]
});

📦 3. JavaScript / TypeScript Client

Authenticated SDK quickstart

npm install m2m-sentinel-sdk@1.2.7
const { M2MSentinelClient } = require('m2m-sentinel-sdk');

const client = new M2MSentinelClient({ apiKey: process.env.M2M_SENTINEL_API_KEY });

async function main() {
const audit = await client.auditContract('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
console.log('Proxy Detected:', audit.audit.proxyResolution.isProxy);
console.log('Proxy Target:', audit.audit.proxyResolution.targetAddress);
console.log('Capabilities:', audit.audit.verdict.executableCapabilities);
console.log('Evidence:', audit.audit.dissection.capabilities);
}

main().catch(console.error);

🛡️ Base Account wallet_sendCalls Guard

The public SDK includes guardWalletSendCalls, a customer-side execution-identity boundary for Base Account / EIP-5792 batches. It preflights the anchor call and evaluates its caller policy before scheduling any remaining call, then pins remaining calls to the first trusted block identity in waves of at most four. Each settled wave is validated and policy-checked in ascending request-index order before a later wave starts; a failure or rejection stops later scheduling. The original detached request is forwarded only after all checks pass. It does not sign, broadcast, custody funds, infer inner UserOperation semantics, or make a safety claim. See examples/base_account_paymaster_guard.js for a no-network fixture.


🐍 4. Python Client

pip install m2m-sentinel==1.2.7
from m2m_sentinel import M2MSentinelClient

client = M2MSentinelClient()
result = client.demo_audit("0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913")
print(result)

Transaction-specific preflight example

The public repository includes a standalone, mock-only transaction boundary example at examples/transaction_preflight.js. From this repository root, run:

node examples/transaction_preflight.js

It observes one caller-supplied Base transaction, passes the observation to a caller-owned policy, and reaches only a mock signing/send callback. It refuses to continue on unverified evidence, unresolved execution, an observation mismatch, or a missing Diamond selector mapping. It never signs or sends a transaction; optional live mode uses only a caller-supplied API-key header and remains the caller's responsibility.


💳 5. Autonomous x402 Micropayments (Headless M2M)

import { x402SignerClient } from "m2m-sentinel-sdk";

const client = new x402SignerClient({
  walletSigner: myAgentWallet,
  baseUrl: "https://api.m2msentinel.com"
});

const result = await client.request("/v1/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913");

📜 License

MIT License. Copyright (c) 2026 M2M Sentinel.

Reviews

No reviews yet

Be the first to review this server!