Skip to main content
Glama
cyberwareX

CyberWareX MCP Servers

Official
README.md
# CyberWareX MCP Servers

MCP (Model Context Protocol) servers for the [CyberWareX](https://cyberwarex.com) suite —
pay-per-call APIs built for AI agents. Every backing API is **live**, speaks
[x402](https://docs.x402.org) (HTTP 402 → pay USDC on Base → result), and needs
**no account and no API key**: the first paid call is the entire onboarding.

| Server | Tools | What it does | Price |
|---|---|---|---|
| [`web-access`](web-access/) | `web_fetch` `web_extract` `web_screenshot` `web_pdf` | Live web pages as LLM-ready markdown, CSS extraction, screenshots, PDFs | $0.005–$0.01 |
| [`defi-oracle`](defi-oracle/) | `token_safety` `honeypot_check` `contract_risk` | "Is this token safe to trade?" — live buy/sell simulation, contract powers, A–F grade with evidence (Base + BSC). **3 free calls/day** with header `X-Free-Trial: 1` — try before funding a wallet | $0.02–$0.06 |
| [`chain-data`](chain-data/) | `chain_wallet` `chain_token` `chain_price` `chain_gas` `chain_tx` `chain_ens` | EVM data across Base, Ethereum, Arbitrum, Optimism, Polygon — no RPC keys, no node | $0.002–$0.004 |
| [`voice-stt`](voice-stt/) | `voice_transcribe` | Voice messages → text, per 10-second block | $0.015 |
| [`wallet-safety`](wallet-safety/) | `simulate_transaction` `decode_calldata` `decode_signature_request` `address_risk` `contract_abi` `url_safety` | Pre-sign safety for wallet/trading agents: simulate a tx before signing, decode EIP-712/personal_sign requests (drainer flags), sanctions + scam-ledger address screening, verified ABI, URL phishing score. 6 chains. **3 free calls/day** per service | $0.002–$0.01 |
| [`council`](council/) | `council` `council_deep` `council_grounded` | A second opinion before your agent acts on one model's unearned confidence: 3-4 DIFFERENT models answer the same question independently, then a chair returns one verdict with `confidence`, the consensus and the `dissent` that held. The grounded tier buys the evidence first (honeypot sim, sanctions screen, page content, SEC profile, web) and itemises what it spent for you. Gate irreversible steps on confidence, not certainty. **1 free call/day** | $0.01 / $0.03 / $0.05-0.12 |

## Install

```bash
pip install mcp requests
```

Each server is a single self-contained file speaking MCP over stdio:

```bash
python web-access/mcp_server.py
```

### Claude Desktop / Claude Code config

```json
{
  "mcpServers": {
    "cyberwarex-web":    { "command": "python", "args": ["/path/to/cyberwarex-mcp/web-access/mcp_server.py"] },
    "cyberwarex-oracle": { "command": "python", "args": ["/path/to/cyberwarex-mcp/defi-oracle/mcp_server.py"] },
    "cyberwarex-chain":  { "command": "python", "args": ["/path/to/cyberwarex-mcp/chain-data/mcp_server.py"] },
    "cyberwarex-voice":  { "command": "python", "args": ["/path/to/cyberwarex-mcp/voice-stt/mcp_server.py"] }
  }
}
```

## How payment works

These servers **never hold keys and never pay**. An unpaid tool call returns the x402
invoice (`x402_payment_required: true` with the full `accepts` block) so the *calling
agent's* x402 client can sign the gasless EIP-3009 USDC authorization and retry —
either through the agent's own payment stack, or by setting the `*_X_PAYMENT` env var
with a pre-signed payment header.

Machine-readable catalog of everything: **https://cyberwarex.com/.well-known/x402**
(LLM-readable summary at [/llms.txt](https://cyberwarex.com/llms.txt)).

## Configuration (env vars)

| Server | Base URL override | Payment header | Timeout |
|---|---|---|---|
| web-access | `AWA_BASE_URL` | `AWA_X_PAYMENT` | `AWA_TIMEOUT` |
| defi-oracle | `DSO_BASE_URL` | `DSO_X_PAYMENT` | `DSO_TIMEOUT` |
| chain-data | `CHAIN_BASE_URL` | `CHAIN_X_PAYMENT` | `CHAIN_TIMEOUT` |
| voice-stt | `VOICE_BASE_URL` | `VOICE_X_PAYMENT` | `VOICE_TIMEOUT` |

Defaults point at the live public services — they work out of the box.

## License

MIT — see [LICENSE](LICENSE). Contact: x402@cyberwarex.com

TDQS

A4.4/5.0

Scored across 3 tools

Disambiguation4/5

token_safety is the full-report umbrella and naturally overlaps with both honeypot_check and contract_risk, but the focused tools have clearly distinct single-purpose roles: sellability only vs. contract governance only. Descriptions make the separation actionable, though an agent might overuse token_safety when a lighter check would suffice.

Naming Consistency5/5

All three tool names use lowercase snake_case and follow a consistent target_aspect pattern: token_safety, honeypot_check, contract_risk. There is no mixed casing or style drift, and each name clearly reflects its focused purpose.

Tool Count5/5

Three tools is a well-scoped size for a token-security domain: one comprehensive vetting tool plus two dedicated focused checks. Each tool earns its place and there is no bloat or trivial filler.

Completeness4/5

The surface covers the core token-vetting workflow: full tradeability verdict, isolated honeypot detection, and contract-power/ownership risk. Minor gaps exist such as explicit liquidity-lock or approval-specific checks, but they are largely covered indirectly through the GoPlus and contract analysis layers.

Maintenance

ActivityMaintained
ResponsivenessUnresponsive