mcp-contract-security
mcp-contract-security
MCP-Server für die Sicherheitsprüfung von Smart Contracts.
Implementiert die erforderlichen Tools:
scan_contractcompare_security_modelsaudit_checklist
Unterstützte Sprachen:
solidityrusttypescript
Was geprüft wird
scan_contract erkennt derzeit heuristische Muster für:
Reentrancy
Integer-Overflow/Underflow-Risiko
Zugriffskontrollprobleme
Front-Running-Exposition
Oracle-Manipulationsrisiko
Die Ausgabe umfasst:
Schwachstellenliste mit Schweregrad/Typ/Zeile
security_scorenear_equivalent_scoreNEAR-spezifische Sicherheitshinweise und Empfehlung
Related MCP server: meok-mcp-injection-scan-mcp
Installation
npm install -g mcp-contract-securityVeröffentlichtes Paket:
MCP-Registry: https://registry.modelcontextprotocol.io/v0/servers/io.github.mastrophot%2Fcontract-security-scanner/versions/0.1.1
MCP-Konfiguration (Claude Desktop)
{
"mcpServers": {
"contract-security": {
"command": "mcp-contract-security"
}
}
}Tool-Nutzung
scan_contract
Eingabe:
{
"code": "contract source code here",
"language": "solidity"
}compare_security_models
Eingabe (optional):
{
"language": "solidity"
}audit_checklist
Eingabe (optional):
{
"language": "rust"
}Lokale Entwicklung
npm install
npm run checkLieferbare Assets
Zusätzliche Veröffentlichungs-Assets sind in deliverables/ vorbereitet:
deliverables/mcp-registry-submission.mddeliverables/security-subreddit-posts.mddeliverables/blog-why-near-contracts-safer.mdserver.json(MCP-Registry-Metadaten, schema-validiert)
Lizenz
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.482MIT
- AlicenseAqualityCmaintenanceScans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.5MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that statically audits Solidity smart contracts for common vulnerabilities like reentrancy and access control, enabling developers to identify and fix security issues via natural language.
- FlicenseNot gradedqualityDmaintenanceEnables scanning Solidity smart contracts for 13 vulnerability classes using pattern-based analysis; provides full audit, quick scan, gas analysis, and detector catalog through MCP tools.
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mastrophot/near-mcp-contract-security'
If you have feedback or need assistance with the MCP directory API, please join our Discord server