Back to Browse

Pyresec Agent MCP Server

Developer ToolsScan in ProgressMCP RegistryRemote
Free

Server data from the Official MCP Registry

AI code security audits via x402 USDC: $0.01 scans, $0.50 audits, $5 auto-fixes. SAST/SCA.

About

AI code security audits via x402 USDC: $0.01 scans, $0.50 audits, $5 auto-fixes. SAST/SCA.

Remote endpoints: streamable-http: https://pyresec-agent-519576377065.us-central1.run.app/mcp

Security Report

0.0
Use Caution0.0Moderate Risk

5 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-renaat-s-pyresec-agent": {
      "url": "https://pyresec-agent-519576377065.us-central1.run.app/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

PYRESEC — AI Code Security Engine

Autonomous SAST/SCA security auditing via x402 USDC micropayments on Base. No subscriptions. No accounts. Just code in, findings out.

Network: Base Protocol: x402 MCP Compatible License: Proprietary

Live Instance


Quick Start

Option 1: x402 Python Client (Recommended)

pip install x402
import x402

client = x402.Client(wallet_key="your-base-private-key")
response = client.post(
    "https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan",
    json={"code": "def login(u,p): return db.query(f\"SELECT * FROM users WHERE name={u} AND pass={p}\")"}
)
print(response.json())

Option 2: curl (Manual x402 Flow)

# Step 1: Send request (returns 402 with payment requirements)
curl -X POST https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan \
  -H "Content-Type: application/json" \
  -d '{"code": "def login(u,p): return db.query(f\"SELECT * FROM users WHERE name={u} AND pass={p}\")"}'

# Step 2: Pay $0.01 USDC on Base using x402 protocol

# Step 3: Resubmit with X-PAYMENT header
curl -X POST https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan \
  -H "Content-Type: application/json" \
  -H "X-PAYMENT: <payment-proof>" \
  -d '{"code": "..."}'

Option 3: GitHub Action (CI/CD)

- name: PYRESEC Security Scan
  uses: nanoclone-ltd/pyresec-scan-action@main
  with:
    code-path: ./src
    tier: quick-scan
    x402-wallet-key: ${{ secrets.X402_WALLET_KEY }}

Option 4: MCP-Compatible Agent (Claude, Cursor, etc.)

PYRESEC is a registered MCP tool. Any MCP-compatible client discovers it automatically:

{
  "mcpServers": {
    "pyresec": {
      "url": "https://pyresec-agent-519576377065.us-central1.run.app/mcp"
    }
  }
}

Service Tiers

TierPriceEndpointDescriptionModel
Quick Scan$0.01POST /v1/audit/quick-scanTop 3 findings by severity, CWE IDs, line numbersqwen3.6-27b
Deep Audit$0.50POST /v1/audit/deep-repoOWASP Top 10, SCA dependency scanning, logic flaws, gas optimizationqwen3.8-27b
Remediation$5.00POST /v1/audit/remediateFull patched code with change explanations and security notesqwen3.8-27b

x402 Payment Flow

PYRESEC uses the x402 protocol for permissionless micropayments on Base. No accounts, no API keys, no subscriptions.

┌──────────┐     POST /v1/audit/quick-scan     ┌──────────┐
│  Client   │ ───────────────────────────────▶  │  PYRESEC │
│ (x402)    │ ◀──── 402 Payment Required ─────  │  Agent   │
│           │       { amount, network, to }     │          │
│           │                                   │          │
│           │ ──── X-PAYMENT (proof) ─────────▶ │          │
│           │ ◀──── 200 + Scan Results ──────── │          │
└──────────┘                                   └──────────┘

How it works:

  1. Client sends a POST request to any audit endpoint
  2. PYRESEC returns 402 Payment Required with payment details (amount, recipient address, network)
  3. Client signs and submits a USDC transfer on Base mainnet
  4. Client resubmits the original request with the X-PAYMENT header containing the payment proof
  5. PYRESEC verifies the payment on-chain and returns the scan results

No wallet? Use the x402 Python SDK or any x402-compatible client.


Architecture

                         ┌─────────────────────────────────┐
                         │          Client Layer            │
                         │  x402 SDK / curl / MCP Client    │
                         └──────────────┬──────────────────┘
                                        │
                              ┌─────────▼─────────┐
                              │   FastAPI Server   │
                              │   (Cloud Run)      │
                              │                    │
                              │  ┌──────────────┐  │
                              │  │ x402 Payment │  │
                              │  │  Middleware   │  │
                              │  └──────┬───────┘  │
                              └─────────┼──────────┘
                                        │
                    ┌───────────────────┼───────────────────┐
                    │                   │                   │
          ┌─────────▼─────────┐ ┌───────▼───────┐ ┌───────▼───────┐
          │  Agent Controller │ │  Population   │ │   Wallet      │
          │  (SAST + LLM)     │ │  Controller   │ │  Interface    │
          └─────────┬─────────┘ └───────────────┘ └───────────────┘
                    │
          ┌─────────▼─────────┐
          │   Groq LLM        │
          │   (qwen models)   │
          └─────────┬─────────┘
                    │
          ┌─────────▼─────────┐
          │  Security Findings │
          │  JSON Response     │
          └───────────────────┘

Supported Vulnerability Types

#TypeCWESeverity
1SQL InjectionCWE-89HIGH
2Cross-Site Scripting (XSS)CWE-79HIGH
3Command InjectionCWE-78CRITICAL
4Path TraversalCWE-22MEDIUM
5Hardcoded SecretsCWE-798CRITICAL
6Weak CryptographyCWE-327MEDIUM
7SSRFCWE-918HIGH
8Insecure DeserializationCWE-502HIGH
9Authentication BypassCWE-287CRITICAL
10Improper Input ValidationCWE-20MEDIUM

For AI Agents (MCP Integration)

PYRESEC is discoverable by any MCP-compatible agent. When an agent needs to audit code, it can find PYRESEC automatically through:

  • MCP Registry: registry.modelcontextprotocol.io
  • Smithery.ai: smithery.ai/server/@renaat-s/pyresec-agent
  • Direct manifest: /mcp/manifest.json

Tool Definitions

ToolDescriptionCost
quick_scanFast SAST scan, top 3 findings by severity with CWE IDs$0.01 USDC
deep_auditFull OWASP Top 10, SCA, logic flaws, gas optimization$0.50 USDC
remediate_codeAuto-patched code with change explanations, ready for PR$5.00 USDC

Agent Discovery Flow

1. Agent queries MCP Registry for "security audit" tools
2. PYRESEC appears in results with tool schemas
3. Agent calls quick_scan with source code
4. PYRESEC returns 402 with x402 payment requirements
5. Agent's x402 wallet pays USDC on Base
6. Agent resubmits with payment proof
7. PYRESEC returns findings as structured JSON

Self-Sustaining Agent

PYRESEC runs as an autonomous agent on Base Mainnet:

  • Heartbeat every 30 min — checks balance, reports health
  • Death — shuts down if balance < $0.05
  • Replication — sends 50% surplus to dev wallet when balance > $20
  • Kill switch — admin can halt all instances remotely

Deployment

Docker

docker build -t pyresec-agent .
docker run -p 8080:8080 --env-file .env pyresec-agent

Google Cloud Run

gcloud run deploy pyresec-agent \
  --source . \
  --platform managed \
  --region us-central1 \
  --allow-unauthenticated \
  --set-env-vars "CDP_WALLET_SECRET=$CDP_WALLET_SECRET,GROQ_API_KEY=$GROQ_API_KEY"

Company

NanoClone Life Sciences Ltd. (UK) Website: nanoclonesystems.com

License

Proprietary. See LICENSE for details.

Reviews

No reviews yet

Be the first to review this server!