EVM MCP Auditor
🛡️ EVM MCP Auditor
生产级 Model Context Protocol (MCP) 服务器,用于 EVM 智能合约安全审计、静态漏洞分析以及面向 Claude 和 Claude Code 的多链遥测。
⚡ 概述
EVM MCP Auditor 将 Anthropic 的 Claude、Claude Desktop 和 Claude Code CLI 直接连接到以太坊和 EVM 生态系统。它为 Claude 配备了专门的安全审计工具,可自动检查 Solidity 智能合约中的关键攻击向量、从区块浏览器获取已验证的源代码、解码原始交易 calldata,并估算多链 gas 成本。
┌───────────────────────────┐ ┌───────────────────────────────┐
│ │ stdio │ │
│ Claude Desktop / Code │ ◄─────► │ EVM MCP Auditor Server │
│ (Anthropic AI) │ │ (@zalana/evm-mcp-auditor) │
│ │ │ │
└───────────────────────────┘ └──────────────┬────────────────┘
│
▼
┌───────────────────────────────┐
│ EVM Networks & Explorers │
│ • Ethereum • Base • Arbitrum │
│ • Optimism • Polygon • BSC │
└───────────────────────────────┘Related MCP server: Elytra Security MCP Server
🚀 功能与 MCP 工具
MCP 工具 | 描述 |
| 对 Solidity 代码运行静态安全分析(重入、不安全的 Delegatecall、 |
| 直接从 6 个 EVM 网络的区块浏览器获取已验证的合约源代码。 |
| 将原始交易十六进制数据解码为 4 字节函数选择器和参数块。 |
| 获取以太坊、Base、Arbitrum、Polygon、Optimism 和 BSC 的实时 gas 遥测数据。 |
📦 快速开始与安装
选项 1:Claude Desktop 集成
将以下片段添加到您的 claude_desktop_config.json:
{
"mcpServers": {
"evm-auditor": {
"command": "npx",
"args": ["-y", "@zalana/evm-mcp-auditor"]
}
}
}选项 2:Claude Code CLI
claude mcp add evm-auditor npx -y @zalana/evm-mcp-auditor选项 3:本地开发
# Clone repository
git clone https://github.com/zalana28/evm-mcp-auditor.git
cd evm-mcp-auditor
# Install dependencies
npm install
# Run automated test suites
npm test
# Build TypeScript to dist/
npm run build
# Run local MCP server
npm start🛡️ 支持的漏洞扫描器(SWC / CWE)
EVM-SEC-001:重入(检查-效果-交互违规)
SWC-107/CWE-841EVM-SEC-002:任意/不受控制的 Delegatecall
SWC-112/CWE-829EVM-SEC-003:通过
tx.origin的易受攻击认证SWC-115/CWE-287EVM-SEC-004:低级调用返回值未检查
SWC-104/CWE-252EVM-SEC-005:区块时间戳操纵
SWC-116/CWE-330EVM-SEC-006:已弃用的
selfdestruct/ 未受保护的状态锁定SWC-106/CWE-284EVM-SEC-007:浮动 Pragma 编译器警告
SWC-103/CWE-664EVM-SEC-008:缺少零地址(
address(0))设置器验证SWC-100/CWE-20
🤝 贡献
欢迎贡献、提交问题和功能请求!请查看贡献指南。
📄 许可证
本项目根据 MIT 许可证 授权。
由 Zalana 为全球开源和 Web3 开发者社区打造,使用 ⚡。
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with Ethereum smart contracts through Anvil, providing capabilities to read Solidity code, simulate and execute transactions, manipulate blockchain state, query events, and test contracts in isolated environments for development and auditing workflows.
- AlicenseAqualityDmaintenanceEnables AI coding agents to scan smart contracts and code for vulnerabilities, check against 12 famous-hack patterns, and return public security receipts directly in the IDE.414MIT
- AlicenseNot gradedqualityBmaintenanceEnables smart contract security auditing using Slither, Aderyn, and custom pattern analysis through the Model Context Protocol, allowing AI assistants to run static analysis and vulnerability checks on Solidity and Vyper contracts.1Apache 2.0
- AlicenseAqualityDmaintenanceConnects AI assistants to Solodit's 49,000+ blockchain vulnerability database, enabling search, browse, and lookup of audit findings directly from your AI workflow.4MIT
Related MCP Connectors
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Resolve any EVM contract ABI (even unverified, via decompilation), read, simulate, prepare txs.
Provide AI agents and automation tools with contextual access to blockchain data including balance…
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/zalana28/evm-mcp-auditor'
If you have feedback or need assistance with the MCP directory API, please join our Discord server