solidit-mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@solidit-mcp-serverSearch for reentrancy vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
solidit-mcp-server
Give AI assistants instant access to Solodit's 49,000+ blockchain vulnerability database.
An MCP server that connects Claude (and other MCP clients) to the Solodit audit findings API -- search vulnerabilities, browse recent discoveries, and look up specific findings directly from your AI workflow.
Runs via npx solidit-mcp-server with zero global installation required.
Quick Start
Get an API key at solodit.cyfrin.io (Profile > API Keys)
Add the MCP config (see Claude Code or Claude Desktop below)
Start using it -- ask Claude something like:
"Search for reentrancy vulnerabilities in DeFi protocols"
Related MCP server: Elytra Security MCP Server
Claude Code
Add to your .mcp.json (project-level) or ~/.claude/mcp.json (global):
{
"mcpServers": {
"solodit": {
"command": "npx",
"args": ["-y", "solidit-mcp-server"],
"env": { "SOLODIT_API_KEY": "your-api-key-here" }
}
}
}Claude Desktop
Add to your Claude Desktop config file:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"solodit": {
"command": "npx",
"args": ["-y", "solidit-mcp-server"],
"env": { "SOLODIT_API_KEY": "your-api-key-here" }
}
}
}Docker
Build and run locally:
docker build -t solidit-mcp-server .
docker run -i -e SOLODIT_API_KEY=your-api-key-here solidit-mcp-serverOr use docker-compose with a .env file:
# .env
SOLODIT_API_KEY=your-api-key-heredocker compose upTools
search_findings
Full-featured search across Solodit's database with 14+ filters. All parameters are optional -- a bare call returns recent findings.
Parameter | Type | Description |
| string | Free-text search across titles and content |
| string[] | Severity filter: |
| string[] | Vulnerability type: |
| string[] | Audit firm: |
| string[] | Protocol type: |
| string[] | Language: |
| string | Protocol name (partial match) |
| string | Auditor handle (partial match) |
| number | Minimum quality score (0-5) |
| number | Minimum rarity score (0-5) |
| string | Preset: |
| string | Custom date cutoff (ISO format, e.g. |
| string |
|
| string |
|
| number | Page number (default: 1) |
| number | Results per page (default: 20, max: 100) |
| number | Content preview length (default: 500, max: 5000) |
Example: "Find high-impact reentrancy findings in DeFi protocols audited by Cyfrin"
get_finding_detail
Retrieve the full content and metadata of a single finding by ID or slug. Use after seeing a result in search_findings to get the complete writeup.
Parameter | Type | Description |
| string | The finding ID (UUID) or slug from search results or Solodit URLs |
Example: "Get the full details of finding abc-123-def"
search_by_tag
Search by vulnerability tags, sorted by quality score (best examples first). Ideal for finding high-quality writeups about a specific vulnerability class.
Parameter | Type | Description |
| string[] | Required. One or more vulnerability tags |
| string[] | Severity filter: |
| string[] | Language filter |
| string[] | Protocol category filter |
| number | Page number (default: 1) |
| number | Results per page (default: 10, max: 100) |
Example: "Find the best oracle manipulation examples in Solidity"
recent_findings
Browse the latest findings from the last N days, sorted by recency (newest first).
Parameter | Type | Description |
| number | Days to look back (default: 30) |
| string[] | Severity filter: |
| string[] | Language filter |
| string[] | Protocol category filter |
| number | Page number (default: 1) |
| number | Results per page (default: 10, max: 100) |
Example: "Show me high-impact findings from the last 7 days"
API Key
This server requires a Solodit API key. Get yours at solodit.cyfrin.io under Profile > API Keys.
The key is passed via the SOLODIT_API_KEY environment variable in your MCP configuration (see setup sections above).
License
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityDmaintenanceIntegrates the Exploit-DB database with AI assistants to enable searching for exploits, shellcodes, and proof-of-concept code during penetration testing workflows. It allows users to perform keyword searches and direct CVE-to-exploit mappings to retrieve technical security data.Last updated
- AlicenseAqualityCmaintenanceEnables AI coding agents to scan smart contracts and code for vulnerabilities, check against 12 famous-hack patterns, and return public security receipts directly in the IDE.Last updated439MIT
- AlicenseAqualityBmaintenanceEnables AI assistants to search and analyze vulnerabilities and exploits from multiple intelligence sources, including NVD, CISA KEV, ExploitDB, Metasploit, and more, with tools for CVE research, exploit analysis, and report generation.Last updated17MIT
- AlicenseAqualityDmaintenanceEnables searching over 20,000+ smart contract audit findings from Solodit, with filters for severity, firm, tags, and more. Designed for use with AI coding agents like Claude Code and Codex CLI.Last updated456155MIT
Related MCP Connectors
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Connect AI assistants to your GitHub-hosted Obsidian vault to seamlessly access, search, and analy…
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/HBlackfoxx/solidit-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server