Elytra Security MCP Server
OfficialThe Elytra Security MCP Server provides AI coding agents with security scanning tools for code and smart contracts, exploit pattern testing, and agent identity verification.
Scan code snippets for vulnerabilities (
elytra_scan): Analyze source code in Solidity, Vyper, JS/TS, Python, Go, Rust, Java, Ruby, PHP, or IaC formats (Terraform, Kubernetes, Dockerfile, GitHub Actions) for security issues. Returns findings with severity ratings, fix suggestions, and a 0–100 security score.Scan deployed smart contracts by address (
elytra_scan_address): Fetch and analyze the verified source code of a live onchain contract using its0x...address across Ethereum, Base, Arbitrum, Optimism, and Polygon.Replay famous exploit patterns (
elytra_replay_hacks): Test code against 12 historically significant exploit patterns representing $3.04B+ in combined losses (Bybit, Ronin, Euler, Beanstalk, Multichain, Curve, Radiant, zkSync, Cream, Wormhole, Nomad, Mango) to check if your code is vulnerable to similar mistakes.Retrieve Elytra's agent identity (
elytra_agent_identity): Access Elytra's onchain ERC-8004 agent card, including capabilities, pricing on Base and Solana, attestation count, and discovery endpoints — useful for programmatic integration or agent verification.
Allows scanning deployed contracts on Ethereum by address, using Elytra's security tools to detect vulnerabilities and check exploit patterns.
Allows scanning deployed contracts on Optimism by address, using Elytra's security tools to detect vulnerabilities and check exploit patterns.
Allows scanning deployed contracts on Polygon by address, using Elytra's security tools to detect vulnerabilities and check exploit patterns.
Allows scanning deployed contracts on Solana by address, using Elytra's security tools to detect vulnerabilities and check exploit patterns.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Elytra Security MCP ServerScan this Solidity contract for vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@elytrasec/mcp
Elytra Security as a Model Context Protocol server. Give your AI coding agent (Claude Desktop, Cursor, Cline, Zed) the ability to scan smart contracts and code, check 12 famous-hack patterns, and return public Elytra security receipts — without leaving the IDE.
173 detection rules. ERC-8004 verified agent. x402 pay-per-call in USDC on Base + Solana.
Install
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"elytra": {
"command": "npx",
"args": ["-y", "@elytrasec/mcp@latest"]
}
}
}Restart Claude Desktop. The 4 Elytra tools appear in the MCP indicator.
Cursor
Settings → MCP → Add server:
{ "command": "npx", "args": ["-y", "@elytrasec/mcp@latest"] }Cline / Continue / any MCP-compatible client
Same one-liner — install as a stdio server with the npx command above.
Related MCP server: Cybrium MCP Server
Tools
Tool | What it does |
| Scan a code snippet for security vulnerabilities |
| Scan a deployed contract by 0x address (Ethereum / Base / Arbitrum / Optimism / Polygon) |
| Test code against 12 famous-exploit patterns ($3.04B combined losses): Bybit, Ronin, Euler, Beanstalk, Multichain, Curve, Radiant, zkSync, Cream, Wormhole, Nomad, Mango |
| Return Elytra's onchain agent card (ERC-8004, pricing, capabilities) |
Privacy & safety
This MCP server is a thin, read-only client over Elytra's public HTTP API. Specifically:
No shell execution. The server never spawns child processes or executes shell commands.
No file writes. The server reads nothing from disk and writes nothing to disk.
No private keys. The server never reads, requests, generates, or stores private keys.
No wallet signing. The server never signs transactions or messages. Any onchain payments (x402) are settled by Elytra's facilitators, not by this server.
Sends only what you ask it to. Each tool call forwards exactly the code, address, or query the AI agent passed in — nothing more. No telemetry, no ambient file reads, no background uploads.
May return public receipt URLs. Depending on Elytra's API mode, a scan can produce a public receipt page at
https://elytrasec.io/r/<id>. The URL is returned to you; you decide whether to share it.
Optional env vars
ELYTRA_API_KEY— Bearer key for the paid/api/v1/scanendpoint (bypasses x402 micropayment for higher throughput). Contact hello@elytrasec.io.ELYTRA_BASE_URL— Override the defaulthttps://elytrasec.io(for self-hosting).
Pricing
All tools above hit Elytra's free public endpoints. For higher rate limits or AI-powered deep review, the underlying API supports x402 pay-per-call in USDC on Base or Solana (1¢ per scan, 2¢ per review).
Other Elytra packages
@elytrasec/cli— same detectors, command-line.npx -y @elytrasec/cli scan .ElytraSec/elytra-action— drop into a GitHub Actions workflow.@elytrasec/engine— the underlying analysis library.
Links
Website: https://elytrasec.io
Playground (interactive): https://elytrasec.io/playground
Hack Replay Library: https://elytrasec.io/hacks
Agent card: https://elytrasec.io/.well-known/agent-card.json
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceProvides real-time OWASP ASVS security guidance and vulnerability scanning for AI coding agents. Enables proactive security during code generation by checking security requirements, scanning code for vulnerabilities, and suggesting secure code fixes.3MIT

Cybrium MCP Serverofficial
Alicense-qualityBmaintenanceProvides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.159Apache 2.0- Flicense-qualityCmaintenanceEnables IDE integration with a multi-agent AI pipeline for solving, reviewing, and optimizing code through adversarial peer review and security filtering.
- Alicense-qualityAmaintenanceEnables AI agents to scan code for security and quality issues and receive machine-readable reports with suggested fixes and verification criteria.892MIT
Related MCP Connectors
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ElytraSec/mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server