basescope
basescope
The read-only safety layer for onchain AI agents.
basescope is a Model Context Protocol (MCP) server that gives AI assistants — Claude, Cursor, and any MCP client — safe, read-only onchain abilities on Base and other EVM chains. Its job is to answer one question before any wallet ever signs anything:
"Is this token / contract / approval actually safe?"
It checks for honeypots, rug-pull authority, hidden taxes, malicious addresses, and risky approvals — and looks up balances, ENS names, Basenames (*.base.eth), verified source, gas, and prices along the way.
Why it's different
🔒 Read-only by design. There is no code path that can sign or send a transaction, and no private key can ever be configured. It cannot move your funds because it literally has no way to. It's the inspector, not the wallet — a safe companion to transaction-capable agents.
🔑 No API keys required. Works out of the box on free, public data sources. (Optional keys can raise rate limits later, but nothing is required.)
🔵 Base-first, multichain-ready. Tuned for Base, and also supports Ethereum, Optimism, Arbitrum, and Polygon.
🧩 One question, cross-checked. Token safety is cross-referenced across two independent sources (GoPlus + honeypot.is) with provenance, so an agent can see when they disagree.
Quickstart
Add basescope to any MCP client — Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json), or any other. No install step; npx fetches it on first run:
{
"mcpServers": {
"basescope": { "command": "npx", "args": ["-y", "basescope"] }
}
}Restart your client and ask something like "Use basescope to check if token 0x… on Base is safe."
git clone https://github.com/chasdaddy/basescope.git
cd basescope
npm install
npm run buildThen set the server command to node with args ["/absolute/path/to/basescope/dist/index.js"].
Related MCP server: BlueAgent x402 Services
Tools
All tools are read-only. chain accepts base (default), ethereum, optimism, arbitrum, or polygon. Address fields accept a 0x address, an ENS name, or a Basename (*.base.eth) — Basenames resolve automatically via the Base L2 Resolver.
Tool | What it does |
check_token_safety | Honeypot / rug assessment: honeypot check, buy/sell tax, mint/blacklist/pausable/self-destruct authority, verified source, holder count → a normalized |
check_address_safety | Reputation check against known-malicious databases (phishing, sanctioned, scam, money-laundering, mixer, …). |
get_token_approvals | Lists a wallet's outstanding ERC-20 approvals and flags risky spenders — the #1 wallet-drain vector — surfacing risky ones first. |
get_verified_source | Whether a contract's source is verified (via Sourcify) + its name, compiler, and function list. |
inspect_contract | Is the address a contract? Bytecode size + transaction count. |
get_token_info | ERC-20 name / symbol / decimals, and optionally a holder's balance. |
get_native_balance | Native coin (ETH / POL / …) balance of an address or ENS name. |
resolve_ens_name / reverse_ens_lookup | ENS name → address, and address → primary ENS name (also reports the primary Basename on Base). |
resolve_basename | Basename ( |
get_gas | Current gas price + EIP-1559 fee suggestion. |
get_token_price | Current USD price for a token (via DefiLlama). |
list_supported_chains | The chains this server can read. |
Example — "is this token safe?"
// check_token_safety({ chain: "base", token: "0x…" })
{
"riskLevel": "critical",
"isHoneypot": true,
"buyTaxPct": 0,
"sellTaxPct": 99,
"flags": [
"cannot sell entire balance",
"owner can mint more supply",
"high sell tax (99%)"
],
"sources": ["goplus", "honeypot.is"]
}Configuration (all optional)
Everything works with no configuration. To use your own RPC endpoints (recommended for heavier use — public RPCs are rate-limited), set any of:
BASE_RPC_URL, ETHEREUM_RPC_URL, OPTIMISM_RPC_URL, ARBITRUM_RPC_URL, POLYGON_RPC_URLData sources
Standing on the shoulders of excellent free/open services: onchain reads via viem + public RPCs, token & address safety via GoPlus Security and honeypot.is, verified source via Sourcify, and prices via DefiLlama.
Limitations
basescope reports heuristics and signals, not guarantees, and is not financial advice. Safety APIs can be wrong or out of date; a "low risk" result is not a promise of safety. Always do your own research before transacting. On Base (an OP-Stack L2), get_gas reports L2 fees only — total cost also includes an L1 data fee.
Roadmap
Transaction / calldata simulation and decoding ("what will this actually do?")
Optional Etherscan V2 fallback for source & ABI/proxy resolution
More chains
License
MIT © 2026
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceToken safety oracle for AI agents. Honeypot detection, 17 scam pattern checks, LP lock verification across 6 EVM chains. Score 0-100 with risk flags. ERC Token Safety Score standard.1MIT
- Flicense-qualityDmaintenancePay-per-use AI security and research tools for autonomous agents on Base, enabling honeypot detection, risk assessment, wallet analysis, and yield optimization via the x402 protocol.
- Alicense-qualityCmaintenanceEnables agents to assess counterparty risk, token danger, and wallet creditworthiness on Base by analyzing contract powers and controlling wallet reputation.MIT
- FlicenseAqualityCmaintenanceAgent-Level Transaction Safety Oracle. Before an AI agent signs a blockchain transaction, it returns a SAFE/UNSAFE verdict with a SENTINEL Score (AAA-D) and risk flags. Pay-per-call $0.005 USDC via x402 on Base.1
Related MCP Connectors
Read-only on-chain intelligence for AI agents on Base: balances, tokens, gas, tx status.
Read-only on-chain intel for AI agents on Base: balances, tokens, gas, tx status. No API keys.
Check a Base contract, transaction or web page before you act. Free pricing, paid per call in USDC.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/chasdaddy/basescope'
If you have feedback or need assistance with the MCP directory API, please join our Discord server