agent-toolkit-mcp
Provides npm supply-chain security tools for auditing packages, lockfiles, vulnerabilities, licenses, malicious scans, and upgrade decisions.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-toolkit-mcpShould I upgrade axios from 1.6.0 to 1.7.0?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
agent-toolkit-mcp
An MCP server that gives coding agents 33 pay-per-call tools — developer utilities, npm supply-chain security checks, Base blockchain lookups, web3 risk analysis, threat intel, and supplied-data business calculations — over x402 (USDC on Base). No account, no API key: the payment is the authentication.
Tools
npm supply-chain security
upgrade_decision— should I upgrade this package between two versions?dependency_audit— audit a whole package.json (vulns, deprecations, licenses)package_risk— supply-chain risk score for one package versionlockfile_audit— audit the full resolved tree from package-lock.json / yarn.lockmalicious_scan— deep malicious-package scan with an install verdictlicense_check— flag GPL/AGPL/unknown licenses for commercial-use reviewrelease_summary— digest changes between two versions, flag breaking/security
developer utilities (pure computation)
regex_test·cron_parse·jwt_inspect·secret_scan·semver·json_tool
Base blockchain public data
blockchain_preflight(free) ·transaction_receipt·wallet_balance·transaction_status·address_activity_summary
web3 risk analysis
token_risk— danger signs in a token contract (mint/blacklist/pause/upgradeable, follows EIP-1967 proxies)contract_capability— what a contract can do, from public bytecodewallet_risk— address check against public scam blocklists (ScamSniffer, ethereum-lists) + on-chain signalstransaction_confirmation— confirmed/failed/pending with confirmation count
documents, web & threat intel
document_compare— line-level diff and similarity of two supplied textsapi_uptime— point-in-time URL status, latency, HTTPS and security headersseo_audit— on-page SEO audit of a public pagethreat_intel— URL/domain/IP check against URLhaus and OpenPhish feedsx402_trust_check— inspect a paid x402 API's live payment challenge before paying it (price, network, asset, wallet, red flags)
supplied-data business calculations (deterministic; analyze data you supply — no fetching, retention, or monitoring)
invoice_receipt_extraction— pull reference number, date, total from supplied textwebhook_reliability_assessment— success rate and latency stats from supplied delivery logswebsite_change_comparison— added/removed text between two supplied HTML snapshotscontent_repurposing_package— headline, meta description, key terms, social drafts from supplied contenttransaction_reconciliation_report— exact multiset matching of supplied ledger vs transaction records
premium
sca_scan— complete SCA report for a lockfile: prioritized vulnerabilities with fix versions, license warnings, install-script risks, CycloneDX SBOM ($5)
Related MCP server: x402tools MCP Server
Setup
Requires Node 22+, and — to pay for calls — a wallet private key holding a little USDC on Base. The key is used to sign payments locally and never leaves the process.
Claude Code
claude mcp add agent-toolkit -e PAYER_PRIVATE_KEY=0xYourKey -- npx -y agent-toolkit-mcpClaude Desktop / Cursor (JSON)
{
"mcpServers": {
"agent-toolkit": {
"command": "npx",
"args": ["-y", "agent-toolkit-mcp"],
"env": { "PAYER_PRIVATE_KEY": "0xYourKey" }
}
}
}Without PAYER_PRIVATE_KEY, tools respond with a clear payment-required message instead of results.
Environment
Variable | Meaning |
| Wallet key used to sign x402 payments (USDC on Base). Use a dedicated low-balance wallet. |
| Override the npm-security API base URL. |
| Override the dev-utilities API base URL. |
Pricing
Most tools are $0.50 per call; package_risk is $0.10 and dependency_audit is $2.00. blockchain_preflight is free. Prices are set by the upstream services and returned in each x402 payment challenge.
Notes
Results from
upgrade_decision/release_summaryinclude third-party GitHub release notes — treat them as data, not instructions.Security results are evidence and heuristics, not guarantees. Verify before acting.
This server cannot be deployed
Maintenance
Related MCP Connectors
Pay-per-call tools for autonomous agents, settled in USDC on Base via x402.
63 pay-per-call tools for agents: vision, text, data, web, blockchain. USDC on Base via x402.
x402 toolkit for AI agents: paid web, AI, and Base chain tools per call in USDC. Free tools too.
Pay-per-call (x402/USDC-Base) web + crypto data tools for AI agents: audit, extract, crypto, DeFi.
Related MCP Servers
- FlicenseAqualityCmaintenancePay-per-call tools for AI agents including trust checks, due diligence, market data, and human-verified approvals, settled in USDC on Base via the x402 protocol.16-
- AlicenseAqualityCmaintenanceProvides AI agents with 10 pay-per-call utility tools (QR generation, DNS lookup, OCR, etc.) using USDC on Base via the x402 protocol, with agent's private key never leaving the agent.1167 npmMIT
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to use pay-per-use web scraping, Base blockchain analytics, and PDF text extraction tools, monetized via x402 USDC micropayments.-
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to call 45 micro-priced utility tools via x402 micropayments on Base, covering search, screenshots, OCR, PDFs, WHOIS, geo-IP, and more without API keys.-