PALISADE MCP Server
Officialby palisadescan
README.md
# PALISADE MCP Server
Onchain security scanner for DeFi traders on Robinhood Chain. Protect against rugpulls, honeypots, and dangerous token approvals. Read-only by design — no keys, no signing, no custody.
Live MCP endpoint: **https://mcp.palisadescan.com**
Site: **https://palisadescan.com**
## Quick test (no install, no API key)
Verify PALISADE is live and returns a real verdict in one call:
```bash
curl -s https://mcp.palisadescan.com/health
# -> {"status":"ok","service":"palisade-mcp","tools":18}
curl -s -X POST https://mcp.palisadescan.com/tools/call \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call",
"params":{"name":"palisade_safety_score",
"arguments":{"contract":"0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48","chain":"ethereum"}}}'
# -> {"jsonrpc":"2.0","id":1,"result":{"score":92,"risk_level":"safe",...}}
```
All scans are read-only and need no API key. Calls go to `POST /tools/call` (JSON-RPC 2.0);
`GET /tools/list` enumerates all tools. There is no REST API — use these.
## Network
PALISADE ships Robinhood-Chain-first. The scanners (approvals, token, honeypot, safety score) target Robinhood Chain (`chainid=4663`) over its native Blockscout RPC. EVM majors and Solana are supported for cross-chain scanning; a small set of Ethereum stablecoins are kept in the verified registry so multichain wallets get correct labels.
| Chain | Approvals | Token Scan | Honeypot |
|----------------|-----------|------------|----------|
| Robinhood Chain| Yes | Yes | Yes |
| Ethereum | Yes | Yes | Yes (GoPlus) |
| Polygon | Yes | Yes | Yes (GoPlus) |
| Arbitrum | Yes | Yes | Yes (GoPlus) |
| Solana | — | Yes (GoPlus) | Yes (GoPlus) |
## Features
- **Approval Scanner** — list all ERC-20/ERC-721 approvals, flag unlimited approvals, identify risky spenders
- **Token Scanner** — analyze contracts for rugpull indicators: hidden mint, proxy patterns, tax manipulation, blacklist functions
- **Honeypot Detector** — simulate buy/sell to detect tokens that block selling
- **Safety Score** — 0-100 rating based on bytecode analysis, ownership, registry match, complexity
- **Wallet Report** — full security posture assessment
- **Wallet Monitor** — alerts for new approvals, risky interactions, and balance changes
- **Token Market** — price, liquidity, 24h volume, and pool age via DexScreener (no API key)
- **Deployer Check** — contract verification, name, and deployer reputation via Blockscout
- **Batch Scan** — score multiple tokens in one call, ranked by risk
- **Consensus** — multi-source verdict: 6 independent signals vote; risk only escalates to high/critical when multiple sources agree (false-positive guard)
- **Liquidity Lock** — detect whether DEX liquidity is locked, burned, or freely withdrawable (rug-pull vector); missing data returns `unknown`, never `safe`
- **Approval Simulator** — risk-assess a spender *before* you sign: contract vs EOA, known-safe, scam-flagged, unlimited amount
- **Clone Detector** — bytecode fingerprinting flags copy-paste scam clones, cross-checked against the scam DB
- **Tax Scanner** — flags punishing or owner-modifiable buy/sell/transfer tax (the "0% now, 99% later" trap); missing data returns `unknown`, never `safe`
- **Ownership Scanner** — who controls the contract and what they can do: mint, pause, blacklist, reclaim ownership, modify balances, selfdestruct; a renounced owner neutralizes these powers
- **Holder Concentration** — whale-dump risk: top-holder concentration over the *sellable* float, excluding LP pools, burns, and locked holders; one wallet over half the float is flagged even with a clean contract
Every tool is read-only. PALISADE reads the chain and reports — it never requests a signature, holds keys, or moves funds.
## Install
```bash
pip install -e .
# With dev dependencies
pip install -e ".[dev]"
```
## Run
```bash
# Stdio transport (default)
make run
# SSE transport on port 3100
make run-sse
```
## Configuration
Set environment variables:
```bash
export ROBINHOOD_RPC=https://rpc.mainnet.chain.robinhood.com # Custom RPC (optional)
export ETHERSCAN_API_KEY=your_key_here # Optional — deployer checks on EVM majors
```
## MCP Client Config
### Claude Desktop
```json
{
"mcpServers": {
"palisade": {
"command": "python3",
"args": ["-m", "palisade_mcp.server"],
"cwd": "/path/to/palisade/src",
"env": {
"ROBINHOOD_RPC": "https://rpc.mainnet.chain.robinhood.com"
}
}
}
}
```
### Cursor
Same format — see `config/cursor.json`.
## CLI Scripts
```bash
# Scan approvals
./scripts/palisade-approvals.sh <wallet> [chain]
# Scan token safety
./scripts/palisade-token.sh <token> [chain]
# Detect honeypot
./scripts/palisade-honeypot.sh <token> [chain]
# Get safety score
./scripts/palisade-score.sh <contract> [chain]
# Full wallet report
./scripts/palisade-report.sh <wallet> [chain]
# Check a token against the community scam DB
./scripts/palisade-check-scam.sh <token> [chain]
# Report a scam
./scripts/palisade-report-scam.sh <token> <type> <description> [chain]
```
## Development
```bash
make test # Run tests
make lint # Check code style
make format # Auto-format code
```
## License
MIT
This server cannot be deployed
Maintenance
ActivityStale
ResponsivenessNo issues