Skip to main content
Glama
README.md
# Solana Agent Audit MCP

An autonomous security audit MCP server and CLI utility designed for Solana programs, Anchor frameworks, and AI Agent Wallets.

Supports automated **x402 payment headers** and micropayments in USDC for pay-per-audit AI workflows.

## Features

- **Program Vulnerability Scanner**: Static analysis detecting missing `Signer` checks on authority accounts, unconstrained PDA derivations in `invoke_signed`, unverified external CPI program targets, and unsafe account closure resurrect vectors.
- **x402 Micropayment Protocol**: Built-in paywall invoice generator that creates standardized x402 payment memos for automated agent-to-agent transactions.
- **Standard MCP Protocol**: Implements Model Context Protocol tools (`audit_solana_code` and `get_payment_invoice`) compatible with Claude Code, Cursor, Codex, and OpenClaw.

## Payout Recipient Configuration

All generated audit invoices route payments directly to the designated Solana recipient address:
```
FCGFGq1WRawg4oQ8zicwt3qX3FdsJPBZzAoC1ZSfp7oD
```

## Quickstart

### 1. Install & Build

```bash
npm install
npm run build
npm test
```

### 2. Configure with MCP Client (Claude Code / Cursor / Codex)

Add to your MCP configuration:

```json
{
  "mcpServers": {
    "solana-auditor": {
      "command": "node",
      "args": ["dist/index.js"]
    }
  }
}
```

### 3. Available Tools

- `audit_solana_code({ sourceCode, programName })`: Performs static security audit returning structured findings, severity, recommendations, and security score (0-100).
- `get_payment_invoice({ serviceName, amountUsdc })`: Generates an x402 payment request invoice with recipient address and unique transaction memo.

## License

MIT

TDQS

A3.7/5.0

Scored across 2 tools

Disambiguation5/5

The two tools have completely distinct purposes: one audits Solana code, the other generates payment invoices. There is no overlap or ambiguity between them.

Naming Consistency5/5

Both tools follow a consistent verb_noun pattern (audit_solana_code, get_payment_invoice), making the naming predictable and clear.

Tool Count3/5

With only two tools, the server feels thin. The payment invoice tool is tangential to the core auditing purpose, making the tool count borderline for the stated domain.

Completeness3/5

The audit surface is minimal with only a single audit operation, lacking supporting features like audit history or status retrieval. The inclusion of payment invoicing is odd and doesn't fill functional gaps in the auditing workflow.

Maintenance

ActivityMaintained
ResponsivenessNo issues