Skip to main content
Glama
traql

traql MCP server

Official

traql MCP server

npm CI License: MIT

암호화폐 주소와 거래에 대한 AML 및 규정 준수 위험 점수를 산출하고, Model Context Protocol을 통해 AI 에이전트에 제공합니다.

에이전트에게 *"이 주소로 보내도 안전한가요?"*라고 물어보면, 0–100 위험 점수, 위험 밴드(구간), 그 뒤에 있는 위험 범주, 그리고 API 키가 있는 경우에는 각 개별 신호와 그 출처 및 신뢰도까지 반환합니다.

ethereum address 0x8589427373d6d84e98730d7795d8f6f8731fda16
RISK 100/100 — CRITICAL
Flags: sanctions, mixer, scam

Signals (21):
  +80  [sanctions/eth_labels] direct.sanctions — sanctions label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
  +68  [mixer/eth_labels] direct.mixer — mixer label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
  +10  [mixer] behavior.mixer_contact — direct contact with mixer 0xdd4c48c0b24039969fc16d1cdf626eab821d3384
  +9   [sanctions/ofac_sdn] indirect.sanctions — sent to Semenov Roman (sanctions, 18% of USDC volume) [entity Semenov Roman, confidence 1.00]
  ... and 17 more

Computed at 2026-08-23T11:42:49Z.

traql 기반: OFAC SDN, 영국 OFSI, EU 및 UN 제재 명단, Tether/Circle 동결 이벤트, 선별된 해킹·믹서 귀속 정보, 그리고 Ethereum, BSC, TRON, TON, Bitcoin에 걸친 거래 상대방 노출 분석입니다.

빠른 시작

Node.js 18+가 필요합니다.

npx -y @traql/mcp

이 서버는 stdio를 통해 MCP를 사용하므로, 일반적으로 직접 실행하기보다는 클라이언트가 이 서버를 가리키도록 설정합니다.

Claude Code

claude mcp add traql --env TRAQL_API_KEY=your_key -- npx -y @traql/mcp

Claude Desktop

claude_desktop_config.json에 추가하세요:

{
  "mcpServers": {
    "traql": {
      "command": "npx",
      "args": ["-y", "@traql/mcp"],
      "env": { "TRAQL_API_KEY": "your_key" }
    }
  }
}

Cursor

~/.cursor/mcp.json(또는 프로젝트의 .cursor/mcp.json)에 위와 동일한 mcpServers 블록을 추가하세요.

VS Code

.vscode/mcp.json에 추가하세요:

{
  "servers": {
    "traql": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@traql/mcp"],
      "env": { "TRAQL_API_KEY": "your_key" }
    }
  }
}

Related MCP server: zarq-risk-intelligence

API 키 받기

app.traql.io에서 가입하고 이메일을 확인하세요. 무료 확인이 포함되어 있습니다. API 키 아래에서 키를 발급하세요. 비밀 키는 한 번만 표시되며, 언제든 교체하거나 폐기할 수 있습니다.

키가 없는 경우에도 서버는 실행되지만, keyless 등급에서는 항목별 신호 대신 하나의 간단한 사유 문구만 제공되고, 요청 한도가 엄격합니다. 그리고 호스팅 API에서는 호출당 x402 결제 요구가 붙습니다. 에이전트에서 사용하려면 키를 설정하세요.

구성

변수

필수

기본값

설명

TRAQL_API_KEY

권장

—

traql 대시보드에서 발급한 API 키입니다. X-API-Key로 전송되며, 항목별 신호와 높은 호출 한도를 사용할 수 있게 해 줍니다.

TRAQL_API_URL

아니

https://api.traql.io

API의 기본 URL입니다. traql을 자체 호스팅할 때는 배포 주소로 지정하세요.

TRAQL_TIMEOUT_MS

아니

30000

요청당 타임아웃(밀리초)입니다.

도구

check_address

단일 주소의 위험 점수를 반환합니다.

인자

타입

필수

설명

chain

ethereum | bsc | tron | ton | bitcoin

예

주소가 속한 네트워크입니다.

address

string

예

해당 체인의 고유한 형식으로 된 주소입니다.

screen_transaction

양쪽이 포함된 거래 전송을 다음 두 가지 모드 중 하나로 평가합니다:

  • Pre-flight — from과 to(선택적으로 amount와 asset)를 전달하여 브로드캐스트 전에 거래를 검사합니다. 지원되는 모든 체인에서 작동합니다.

  • By hash — tx_hash만 전달해 이미 온체인에 있는 거래를 조회합니다. Ethereum, BSC, TRON 및 TON에서 지원됩니다.

인자

타입

필수

설명

chain

chain enum

예

거래가 속한 네트워크입니다.

from

string

pre-flight

보내는 주소입니다.

to

string

pre-flight

받는 주소입니다.

amount

string

아니요

자산의 기준 단위로 표시된 정수 금액입니다(예: 1 USDT는 1000000).

asset

string

아니요

자산 또는 토큰 심볼입니다(예: USDT).

tx_hash

string

by-hash

브로드캐스트한 거래의 해시입니다. from/to와 함께 사용할 수 없습니다.

응답

두 도구 모두 사람이 읽을 수 있는 텍스트와 structuredContent를 반환합니다:

{
  "subject": { "type": "address", "chain": "ethereum", "address": "0x…" },
  "result": {
    "score": 100,
    "band": "critical",
    "flags": ["sanctions", "mixer", "scam"],
    "partial": false,
    "computed_at": "2026-08-23T11:42:49Z",
    "reasons": [
      {
        "code": "direct.sanctions",
        "message": "sanctions label \"Tornado.Cash: Donate\" from eth_labels (severity 100 × confidence 0.80 = 80.0)",
        "contribution": 80,
        "category": "sanctions",
        "source": "eth_labels",
        "entity": "Tornado.Cash: Donate",
        "severity": 100,
        "confidence": 0.8,
        "eff": 80.0
      }
    ]
  }
}

점수 구간: clean 0–9, low 10–39, elevated 40–69, high 70–89, critical 90–100.

partial: true는 결과를 계산하는 동안 상위 데이터 소스가 정상적으로 응답하지 않았거나 다소 저하되었음을 의미합니다. 따라서 해당 점수는 최종 결론이 아니라 하한선으로 읽어야 합니다.

성공한 호출은 설정된 계정의 체크 1회를 사용합니다. 잘못된 입력은 가능한 한 로컬에서 거부되므로 비용이 들지 않습니다.

개발

npm install
npm run build
npm test

참고

점수는 트라이지(triage) 및 자동화를 위한 참고 신호입니다. 이 점수는 불법 행위에 대한 법적 판단이 아니며, 그 자체로 어떤 규제 의무를 충족시키거나 면제해 주지 않습니다.

링크

라이선스

MIT

Available Tools

2 tools
check_addressCheck address riskA
Read-only

Score a single crypto address for AML and compliance risk.

Returns a risk score from 0 (clean) to 100 (critical), the band it falls into, and the risk categories that drove it — sanctions, mixer, scam, darknet, stolen_funds, ransomware, high_risk_exchange and others. With an API key configured, the response also itemizes every contributing signal with its data source, severity and confidence, so the verdict can be explained rather than just asserted.

Use it before sending funds to an unfamiliar address, to triage an address a user pasted, to check a counterparty in an investigation, or to vet a deposit address. Covers Ethereum, BSC, TRON, TON and Bitcoin. Each call consumes one check from the configured traql account.

ParametersJSON Schema
NameRequiredDescriptionDefault
chainYesBlockchain network the subject belongs to.
addressYesAddress in the chain's native format: 0x-hex for ethereum and bsc, base58 starting with T for tron, EQ/UQ for ton, and legacy or bech32 for bitcoin.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes
subjectYesEcho of the canonical subject that was scored.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already indicate readOnlyHint and non-destructive, and the description adds meaningful behavioral detail beyond that: the exact return semantics (risk score 0-100, bands, categories), conditional verbosity with an API key, and the resource cost ('Each call consumes one check'). It doesn't contradict annotations, and the additional consumption caveat is valuable.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the purpose and returns, then use cases, then chains and consumption. It is concise at four sentences, with no fluff. It could be slightly tighter (the chain list is redundant with the schema enum), but it remains efficiently structured and readable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the presence of an output schema, the description need not detail return types, but it still explains the risk score range, band concept, and categories. It also covers supported chains, use cases, and the API-key enhancement. Everything an agent needs to invoke and interpret the result is present, so it is fully complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already provides full descriptions for both parameters (chain enum and address format), so the baseline is 3. The description adds no extra parameter semantics—it only references the chain coverage implicitly, which the schema already communicates. No additional meaning is introduced beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description begins with a clear verb-resource pair ('Score a single crypto address for AML and compliance risk') that precisely states the tool's function. It also differentiates from the sibling tool screen_transaction by focusing on address-level vetting rather than transaction screening.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description lists concrete use cases ('before sending funds', 'triage a pasted address', 'vet a deposit address'), giving clear context for when to use it. It does not explicitly exclude transaction screening, but the single sibling tool makes the distinction evident; mentioning that tool as an alternative would make this a perfect 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

screen_transactionScreen transaction riskA
Read-only

Screen a transaction for AML and compliance risk by scoring both sides of the transfer.

Two modes, chosen by which arguments are given:

  • Pre-flight — pass from and to (optionally amount and asset) to screen a transfer before it is broadcast. Works on every supported chain.

  • By hash — pass only tx_hash to look up a transaction that is already on-chain. Supported on ethereum, bsc, tron and ton.

Returns the same score, band, flags and itemized signals as an address check, with each signal marked as applying to the sending or receiving side. Use it as a pre-send safety gate, or to review a payment that already went out. Each call consumes one check from the configured traql account.

ParametersJSON Schema
NameRequiredDescriptionDefault
toNoRecipient address, for screening a transfer that has not been broadcast yet.
fromNoSender address, for screening a transfer that has not been broadcast yet.
assetNoOptional asset or token symbol being transferred, for example USDT.
chainYesBlockchain network the subject belongs to.
amountNoOptional transfer amount as an integer string in the asset's base units (for example 1000000 for 1 USDT, which has 6 decimals). Never a decimal fraction.
tx_hashNoHash of an already-broadcast transaction. Mutually exclusive with `from`/`to`. Supported on ethereum, bsc, tron and ton only.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes
subjectYesEcho of the canonical subject that was scored.

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false. The description adds valuable behavioral context beyond annotations: 'Each call consumes one check from the configured traql account' (a quota side effect) and describes the return structure ('score, band, flags and itemized signals'). This is consistent with annotations and provides useful operational detail.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well-structured with a clear opening statement followed by a bulleted breakdown of modes. The information is front-loaded and each sentence serves a purpose—no filler or redundancy. It is slightly long but contains only necessary details, earning a 4 rather than 5 due to the length.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (two modes, six parameters, chain restrictions, and an existing output schema), the description covers all essential usage context: modes, which chains support which mode, use cases, and the quota side effect. Nothing critical is missing for an agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds meaning by explaining the two modes and how parameters relate (pre-flight: from/to, optional amount/asset; by-hash: tx_hash only, mutually exclusive). It also gives an example for the amount format, reinforcing the schema description. This is helpful clarification beyond the schema's individual parameter descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a clear verb+resource: 'Screen a transaction for AML and compliance risk by scoring both sides.' It explicitly differentiates from the sibling address-check tool by focusing on transactions and even references the shared return format ('same score, band, flags and itemized signals as an address check'). This leaves no ambiguity about what the tool does and how it differs from check_address.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clearly states when to use it: 'Use it as a pre-send safety gate, or to review a payment that already went out.' It also details two explicit modes with the exact parameters to pass ('pass from and to...' vs 'pass only tx_hash') and lists chain support for each. While it doesn't explicitly name check_address as an alternative, the mention of 'same... as an address check' implies routing, so guidance is strong but not exhaustive.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 2 tool updatesv0.1.0
    • First observedcheck_address
    • First observedscreen_transaction

TDQS

A4.4/5.0

Scored across 2 tools

Disambiguation5/5

The two tools target distinctly different entities: check_address evaluates a single address, while screen_transaction evaluates a transaction by scoring both sides. They are clearly separated by purpose and input requirements, with no overlapping functionality.

Naming Consistency5/5

Both tool names follow a consistent verb_noun pattern: check_address and screen_transaction. The verbs ('check' vs 'screen') are semantically appropriate and the noun targets (address, transaction) are clear, maintaining a uniform naming style.

Tool Count4/5

With only two tools, the server is compact but well-scoped for its narrow AML screening purpose. Each tool covers a fundamental operation (address check and transaction screening), so the count feels appropriate rather than insufficient, though it is below the typical 3-15 range.

Completeness4/5

The tool surface covers the primary use cases for AML risk assessment: pre-transaction screening and single-address checks. Minor gaps exist, such as lack of batch processing or historical investigation features, but these are not essential for the stated purpose and do not create dead ends in common workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    Provides blockchain address risk scoring and asset information through the BICScan API, allowing users to assess risks for crypto addresses, domains, and dApps on a scale of 0-100.
    2
    16
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to access real-time crypto risk intelligence with two tools: Flare for precursor detection and Core for overall risk environment assessment.
    4
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Crypto compliance tools for AI-agent payments: screen any address for sanctions, frozen-stablecoin and hacker/mixer exposure across 8+ chains, trace fund taint, and get an allow/review/decline decision before settlement. Free keyless address checks; deeper endpoints are x402-payable.
    314 npm
    MIT