mcp-contract-security
mcp-contract-security
MCP-сервер для сканирования безопасности смарт-контрактов.
Реализует необходимые инструменты:
scan_contractcompare_security_modelsaudit_checklist
Поддерживает языки:
solidityrusttypescript
Что он проверяет
scan_contract в настоящее время обнаруживает эвристические паттерны для:
Повторный вход
Риск переполнения/недополнения целых чисел
Проблемы контроля доступа
Подверженность фронт-раннингу
Риск манипуляции оракулом
Вывод включает:
список уязвимостей с серьезностью/типом/строкой
security_scorenear_equivalent_scoreNEAR-специфичные заметки по безопасности и рекомендации
Related MCP server: meok-mcp-injection-scan-mcp
Установка
npm install -g mcp-contract-securityОпубликованный пакет:
MCP Registry: https://registry.modelcontextprotocol.io/v0/servers/io.github.mastrophot%2Fcontract-security-scanner/versions/0.1.1
Конфигурация MCP (Claude Desktop)
{
"mcpServers": {
"contract-security": {
"command": "mcp-contract-security"
}
}
}Использование инструментов
scan_contract
Входные данные:
{
"code": "contract source code here",
"language": "solidity"
}compare_security_models
Входные данные (необязательно):
{
"language": "solidity"
}audit_checklist
Входные данные (необязательно):
{
"language": "rust"
}Локальная разработка
npm install
npm run checkПоставляемые артефакты
Дополнительные публикационные артефакты подготовлены в deliverables/:
deliverables/mcp-registry-submission.mddeliverables/security-subreddit-posts.mddeliverables/blog-why-near-contracts-safer.mdserver.json(метаданные MCP Registry, проверено по схеме)
Лицензия
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.482MIT
- AlicenseAqualityCmaintenanceScans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.5MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that statically audits Solidity smart contracts for common vulnerabilities like reentrancy and access control, enabling developers to identify and fix security issues via natural language.
- FlicenseNot gradedqualityDmaintenanceEnables scanning Solidity smart contracts for 13 vulnerability classes using pattern-based analysis; provides full audit, quick scan, gas analysis, and detector catalog through MCP tools.
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mastrophot/near-mcp-contract-security'
If you have feedback or need assistance with the MCP directory API, please join our Discord server