mcp-token-risk
OfficialProvides rug-pull and honeypot risk screening for EVM tokens on Ethereum, detecting red flags such as sell restrictions, buy/sell taxes, mintable supply, owner controls, proxy code, and holder concentration.
Supports risk screening for EVM tokens on Optimism, checking for honeypot behavior, token taxes, mintability, ownership and blacklist controls, and holder concentration.
Supports risk screening for EVM tokens on Polygon, detecting common scam indicators like honeypots, transfer taxes, mintable supply, owner privileges, unverified code, and concentrated holders.
Provides rug-pull and scam risk screening for Solana SPL tokens by mint address, flagging active mint or freeze authority, mutable metadata, transfer fees/hooks, and holder or LP concentration.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-token-riskIs 0x7a250d5630B4cF539739dF2C5dAcb4c659F2488D a honeypot on Ethereum?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-token-risk
Token Risk — rug-pull / honeypot screening for crypto tokens.
Part of Pipeworx — an MCP gateway connecting AI agents to 1576+ live data sources.
Tools
Tool | Description |
| Rug-pull / honeypot / scam RISK SCREENING for an EVM token (Ethereum, BSC, Base, Arbitrum, Polygon, Optimism, Avalanche, and more). Pass the token CONTRACT ADDRESS and the chain. Detects honeypots (can you actually sell?), buy/sell tax, mintable supply, hidden/renounceable owner, owner-can-change-balances, blacklist/whitelist controls, proxy/upgradeable code, unverified source, and holder concentration — the standard rug-pull red flags. Returns a computed red_flags[] list plus the raw GoPlus Security facts. Keyless, live on-chain. Use before buying/interacting with any token, or for "is $TOKEN a scam / honeypot / safe?". |
| Rug-pull / scam RISK SCREENING for a Solana SPL token. Pass the token MINT address. Detects active mint authority (supply can be inflated), freeze authority (your balance can be frozen), closable/mutable-metadata flags, transfer fees/hooks, and holder + LP concentration. Returns a computed red_flags[] list plus the raw GoPlus Security facts. Keyless, live on-chain. Use for "is this Solana token safe / a rug?". |
Related MCP server: hive-mcp-address-screen
Quick Start
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
{
"mcpServers": {
"token-risk": {
"url": "https://gateway.pipeworx.io/token-risk/mcp"
}
}
}What this endpoint actually serves
tools/list at https://gateway.pipeworx.io/token-risk/mcp returns the tools in the table
above plus the shared Pipeworx meta-tools — ask_pipeworx,
discover_tools, search_within, remember/recall and the rest of the
gateway-wide set. So the tool count you see is larger than this table: a
single-pack endpoint currently lists roughly 30 shared tools alongside the
pack's own. The connection's initialize response states its exact scope, and
is the authoritative answer for a given day.
This is deliberate, not multiplexing by accident. The meta-tools are what let a
scoped connection answer a question this pack does not cover — via
ask_pipeworx, which routes across the whole catalog — without you adding a
second MCP server. There is currently no way to mount a pack endpoint without
them; if the extra schemas cost you more context than the routing is worth,
connect to the full gateway once rather than to several pack endpoints.
Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:
{
"mcpServers": {
"pipeworx": {
"url": "https://gateway.pipeworx.io/mcp"
}
}
}Both URLs reach the same gateway and the same 1576+ data sources. The
only difference is which pack's tools are listed directly; ask_pipeworx
reaches all of them from either one.
No MCP client? Call it over HTTP
curl -X POST https://gateway.pipeworx.io/v1/tools/token_risk_evm \
-H 'Content-Type: application/json' \
-d '{"contract_address":"0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48","chain":"ethereum"}'No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/token_risk_evm. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.
Standalone (no gateway account)
This package also runs as a local stdio MCP server — no Pipeworx account, no gateway round-trip:
{
"mcpServers": {
"token-risk": {
"command": "npx",
"args": ["-y", "@pipeworx/mcp-token-risk"]
}
}
}Or run it directly to confirm it starts:
npx -y @pipeworx/mcp-token-riskIt speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call
for only this pack's tools — none of the shared meta-tools the gateway
connection above adds. Same source, same tools, no ask_pipeworx routing.
Using with ask_pipeworx
Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:
ask_pipeworx({ question: "your question about Token Risk data" })The gateway picks the right tool and fills the arguments automatically.
More
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Instant rug-check for any EVM or Solana token, distilled to one clear 0-10 risk verdict.
Solana wallet & token reputation lookup. Risk verdict, score, DefiLlama TVL, Rugcheck.
Rug pull risk and on-chain forensics for tokens on Solana, Ethereum, Base and Robinhood.
Crypto security, honeypot detection, wallet analysis, and token risk scoring across 31 blockchains.
Related MCP Servers
- FlicenseNot gradedqualityNot gradedmaintenanceEnables blockchain security analysis using GoPlus Security API, providing rug pull detection, phishing site detection, NFT security analysis, and token security assessment across 14+ blockchain networks. Supports comprehensive security analysis for addresses, tokens, and smart contracts through natural language queries.2-
- AlicenseNot gradedqualityCmaintenancePre-settlement on-chain address risk screening for autonomous agents, using GoPlus 17-vector analysis and returning Ed25519-signed attestation receipts.MIT
- AlicenseAqualityBmaintenanceQuick-scan a smart contract for rug, honeypot, or centralization risk before sending funds. It combines verified source, live on-chain state, and heuristic Solidity analysis to return a SAFE/CAUTION/HIGH-RISK verdict.1MIT
- AlicenseAqualityBmaintenanceOn-chain rug-pull & honeypot risk screen for ERC-20 tokens, providing a SAFE / CAUTION / HIGH-RISK verdict based on live public RPC reads.2MIT