pathguard-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@pathguard-mcpCan you check this crypto address for scam risks before I send: 0x1a2b3c4d5e6f7890"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
pathguard-mcp
PathGuard MCP lets MCP-compatible AI agents check crypto transactions for scams and mistakes directly in conversation. It supports local MCP clients such as Claude Desktop, Claude Code, Gemini CLI, Grok CLI, Cursor, and Codex, plus remote Streamable HTTP deployments.
Listed on the official MCP Registry as
org.cieltech.pathguard/pathguard.
The production MCP server is a thin, authenticated interface to PathGuard's transaction-safety API. PathGuard analyzes transactions before a send; it does not sign, broadcast, or transfer funds.
Production MCP
Remote Streamable HTTP endpoint:
https://pathguard-v2.up.railway.app/mcp/Remote clients use OAuth to connect an existing PathGuard account. During authorization, PathGuard verifies the user's existing API key. The API key is not exposed to the AI client or returned through MCP.
For local/stdio use, the API key is supplied to the local server process through PATHGUARD_API_KEY.
Related MCP server: contract-guard-mcp
Install
The package is currently installed directly from this public repository and is not published to PyPI yet.
git clone https://github.com/Utee/pathguard-mcp.git
cd pathguard-mcp
python -m pip install .For development, use an editable install:
python -m pip install -e .Requires Python 3.10+ and mcp >= 2.0.
Get an API key
Create a PathGuard account and API key from the PathGuard API documentation.
Keep your API key private. Do not commit it to GitHub or expose it in browser-side code.
Local MCP clients
For local clients, the server uses stdio and authenticates to the PathGuard API with PATHGUARD_API_KEY.
Claude Desktop
Add this to your Claude Desktop config:
{
"mcpServers": {
"pathguard": {
"command": "pathguard-mcp",
"env": {
"PATHGUARD_API_KEY": "pg_your_key_here"
}
}
}
}Claude Code
claude mcp add --transport stdio pathguard -- pathguard-mcpSet PATHGUARD_API_KEY in the environment that starts Claude Code.
Gemini CLI
{
"mcpServers": {
"pathguard": {
"command": "pathguard-mcp",
"env": {
"PATHGUARD_API_KEY": "pg_your_key_here"
}
}
}
}Grok CLI
export PATHGUARD_API_KEY=pg_your_key_here
grok mcp add pathguard -- pathguard-mcpCodex, Cursor, VS Code, and other local MCP clients
Use the same stdio server definition as the Claude Desktop example. The exact configuration location varies by client.
Remote clients
For remote clients, use the production OAuth-protected Streamable HTTP endpoint shown above. Never put a PathGuard API key in browser-side configuration.
ChatGPT
In a ChatGPT workspace with Developer Mode enabled, create a custom MCP app and provide:
https://pathguard-v2.up.railway.app/mcp/Choose OAuth authentication. ChatGPT will use the PathGuard authorization flow to connect an existing PathGuard account.
The authorization flow verifies the user's PathGuard API key, then issues OAuth credentials for the MCP connection. The raw PathGuard API key is not returned to ChatGPT.
Available tools
Tool | What it does |
| Inspect one crypto destination and optional amount for PathGuard risk signals. |
| Run the full pre-send check and return |
| Check up to 1,000 transactions and return a compact risk summary or full results. |
| Record a suspected scam address when the user explicitly asks to report it. |
| View the connected account's plan and monthly scan usage. |
| Identify the PathGuard account represented by the OAuth connection. |
Tool safety boundary
PathGuard MCP is analysis-only. Its tools do not:
sign transactions;
broadcast transactions;
transfer funds;
request private keys or seed phrases;
replace your application's authorization controls.
A BLOCK result is a PathGuard safety signal. The wallet, application, or agent remains responsible for authorization, signing, and final transaction execution.
Batch checking
check_transactions_batch supports up to 1,000 items.
By default it returns a compact summary containing:
total items;
processed items;
ALLOW / REVIEW / BLOCK counts;
maximum risk score;
flag counts;
a sample of flagged transactions.
Use detail_level="full" when individual results are required.
Security
Keep API keys server-side and private.
Use HTTPS for remote deployments.
OAuth protects the production remote MCP connection.
The production MCP server maps the authenticated OAuth subject to an existing PathGuard account.
Internal server-to-server authentication is not exposed as an MCP argument or model-visible credential.
Never commit API keys, production credentials, or local
.envfiles.
Full API reference
See the PathGuard API documentation for endpoint schemas, rate limits, pricing, and risk-flag information.
PathGuard MCP: https://pathguard.cieltech.org/mcp
Related MCP Connectors
Pay-per-call safety checks for AI agents: screen a crypto address or URL before you transact.
Scam and phishing detection for AI agents: safe/warn/danger verdicts for URLs and messages.
Crypto transaction firewall and risk tools for MCP agents.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Related MCP Servers
- AlicenseAqualityCmaintenanceScans suspicious messages, URLs, and text for scams inside any MCP-compatible AI assistant. No signup or API key needed for anonymous use.182 npmMIT
- AlicenseNot gradedqualityBmaintenanceMCP server for a pre-interaction risk check on any EVM contract/token, enabling agents to verify contracts before approving, swapping, or trusting an address.1MIT
- AlicenseAqualityAmaintenanceMCP server that enables AI signing agents to pre-flight transactions by checking ERC-7730 descriptor safety, explaining function semantics, and scanning contracts for danger primitives.4MIT
- AlicenseAqualityCmaintenanceRead-only crypto safety MCP server that helps AI agents and wallets verify token honeypot risks, decode EIP-712 signatures, scan approval risks, and simulate transactions before signing.8MIT