base-security-scanner-mcp
MCP server for AI agents to scan smart contracts on Base mainnet for security vulnerabilities. Detect honeypots, rug pulls, hidden mints, proxy patterns, and generate full audit reports -- all read-only, no private key needed.
Install
npx -y base-security-scanner-mcpConfigure (Claude Desktop / Cursor)
{
"mcpServers": {
"base-security-scanner": {
"command": "npx",
"args": ["-y", "base-security-scanner-mcp"]
}
}
}Tools (8)
Tool | Description |
| Analyze a contract for security issues (reentrancy, access control, hidden mints, proxy patterns) |
| Check if a token is a honeypot by simulating buy+sell via Uniswap V2 |
| Score rug pull risk 0-100 based on ownership, liquidity, permissions, honeypot status |
| Disassemble bytecode, identify contract type (proxy, AMM, ERC-20, diamond, etc.) |
| Check owner permissions: mint, pause, blacklist, change fees, disable trading |
| Basic contract metadata: verified status, bytecode size, ETH balance, token info |
| Clone detection -- check if two contracts share the same bytecode |
| Full security audit combining all checks into one comprehensive report |
Environment Variables
Variable | Default | Description |
|
| Base mainnet RPC endpoint |
How It Works
Bytecode Analysis: Extracts PUSH4 opcodes to find function selectors, matches against 30+ known dangerous patterns
Opcode Scanning: Detects DELEGATECALL, SELFDESTRUCT, CREATE, CREATE2
Honeypot Detection: Simulates ETH->Token->ETH round-trip via Uniswap V2 router getAmountsOut
Rug Scoring: Weighted algorithm combining ownership, liquidity depth, dangerous permissions, honeypot status
Clone Detection: Jaccard similarity on function selector sets
Related MCP Servers
Package | Tools | What it does |
| 14 | Deploy tokens, trade, earn OBSD |
| 8 | Scan contracts for vulnerabilities |
| 7 | On-chain price feeds from DEX pools |
| 8 | Coordinated multi-wallet trading |
| 5 | Gasless ERC-20 token deployment |
| 7 | Detect arbitrage opportunities |
| 5 | Discover & trade new launches |
| 7 | Wallet balances, gas, tokens |
| 6 | Read any smart contract (free) |
| - | Scaffold a new MCP server |
License
MIT