EVM MCP Auditor
# š”ļø EVM MCP Auditor
[](https://github.com/zalana28/evm-mcp-auditor/actions/workflows/ci.yml)
[](https://m8ven.ai/mcp/zalana28-evm-mcp-auditor-1w5o9p)
[](https://glama.ai/mcp/servers/d80plnk6uh)
[](https://opensource.org/licenses/MIT)
[](https://modelcontextprotocol.io)
[](https://www.typescriptlang.org)
> **Production-grade Model Context Protocol (MCP) server for EVM Smart Contract security auditing, static vulnerability analysis, and multi-chain telemetry for Claude & Claude Code.**
---
## ā” Overview
**EVM MCP Auditor** connects Anthropic's **Claude**, **Claude Desktop**, and **Claude Code CLI** directly to Ethereum and EVM ecosystems. It equips Claude with specialized security auditing tools to automatically inspect Solidity smart contracts for critical attack vectors, fetch verified source code from block explorers, decode raw transaction calldata, and estimate multi-chain gas costs.
```
āāāāāāāāāāāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā ā stdio ā ā
ā Claude Desktop / Code ā āāāāāāāŗ ā EVM MCP Auditor Server ā
ā (Anthropic AI) ā ā (@zalana/evm-mcp-auditor) ā
ā ā ā ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāā
ā
ā¼
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā EVM Networks & Explorers ā
ā ⢠Ethereum ⢠Base ⢠Arbitrum ā
ā ⢠Optimism ⢠Polygon ⢠BSC ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
```
---
## š Features & MCP Tools
| MCP Tool | Description |
| :--- | :--- |
| `evm_audit_contract` | Run static security analysis on Solidity code (Reentrancy, Unsafe Delegatecall, `tx.origin` auth, Unchecked Calls, Timestamp Dependency, Selfdestruct). |
| `evm_fetch_source` | Pull verified contract source code directly from block explorers across 6 EVM networks. |
| `evm_decode_calldata` | Decode raw transaction hex data into 4-byte function selectors and parameter chunks. |
| `evm_estimate_gas` | Fetch real-time gas telemetry across Ethereum, Base, Arbitrum, Polygon, Optimism, and BSC. |
---
## š¦ Quickstart & Installation
### Option 1: Claude Desktop Integration
Add the following snippet to your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"evm-auditor": {
"command": "npx",
"args": ["-y", "@zalana/evm-mcp-auditor"]
}
}
}
```
### Option 2: Claude Code CLI
```bash
claude mcp add evm-auditor npx -y @zalana/evm-mcp-auditor
```
### Option 3: Local Development
```bash
# Clone repository
git clone https://github.com/zalana28/evm-mcp-auditor.git
cd evm-mcp-auditor
# Install dependencies
npm install
# Run automated test suites
npm test
# Build TypeScript to dist/
npm run build
# Run local MCP server
npm start
```
---
## š”ļø Supported Vulnerability Scanners (SWC / CWE)
- **EVM-SEC-001**: Reentrancy (Checks-Effects-Interactions violation) `SWC-107` / `CWE-841`
- **EVM-SEC-002**: Arbitrary / Uncontrolled Delegatecall `SWC-112` / `CWE-829`
- **EVM-SEC-003**: Vulnerable Authentication via `tx.origin` `SWC-115` / `CWE-287`
- **EVM-SEC-004**: Unchecked Return Value of Low-Level Call `SWC-104` / `CWE-252`
- **EVM-SEC-005**: Block Timestamp Manipulation `SWC-116` / `CWE-330`
- **EVM-SEC-006**: Deprecated `selfdestruct` / Unprotected State Lock `SWC-106` / `CWE-284`
- **EVM-SEC-007**: Floating Pragma Compiler Warning `SWC-103` / `CWE-664`
- **EVM-SEC-008**: Missing Zero-Address (`address(0)`) Setter Validation `SWC-100` / `CWE-20`
---
## š¤ Contributing
Contributions, issues, and feature requests are welcome! Please check the [Contributing Guide](CONTRIBUTING.md).
## š License
This project is licensed under the [MIT License](LICENSE).
---
<sub>Built with ā” by [Zalana](https://github.com/zalana28) for the global Open-Source and Web3 developer community.</sub>
TDQS
Scored across 4 tools
Each tool occupies a completely distinct role: estimating gas, auditing source, fetching source, and decoding calldata. There is zero functional overlap between the four, eliminating any chance of an agent selecting the wrong tool for a given intent.
All tools follow a flawless 'evm_verb_noun' snake_case convention with no exceptions. The consistent prefix plus action word makes the API predictable and easy to reason about.
Four focused tools is perfectly scoped for a specialized auditing server covering the key audit workflow without bloat. It hits the sweet spot of being comprehensive for its domain without unnecessary features.
The core fetch-source-and-audit workflow is well covered, with useful supporting utilities for gas analysis and calldata decoding. However, there's no way to list past audits, compare versions, or interact with the broader transaction context, which are minor gaps for a full auditing lifecycle.