Skip to main content
Glama
README.md
# FabTally Safe — MCP server

Read-only crypto **safety + "what am I signing"** verification for AI agents and
wallets. Fronts the FabTally Safe HTTP API (https://safe.fabtally.com).

- **Read-only.** Never holds, moves, signs for, or broadcasts funds. No private
  key. Outputs are descriptive facts from public sources — **not financial advice**.
- **8 tools**: 4 free teasers + 4 paid (x402, USDC on Base).

## Tools

| Tool | Tier | What it does |
|------|------|--------------|
| `token_safety` | paid $0.02 | Multi-chain token honeypot/rug check — aggregates GoPlus + honeypot.is into a 0-100 risk score with explainable reasons. |
| `decode_signature` | paid $0.01 | "What am I signing" — decode EIP-712 / Permit / Permit2 / Seaport typed-data into plain English + risk flags (unlimited approval, malicious spender, expiry, NFT-drain). |
| `approvals` | paid $0.01 | Wallet approval-risk scan ranked by exposure + address-poisoning "revoke bait" detection + the revoke calldata you execute yourself. |
| `simulate` | paid $0.02 | Keyless pre-sign transaction analysis: eth_call revert check + static delta prediction + risk flags. |
| `token_safety_free` · `decode_signature_free` · `approvals_free` · `simulate_free` | free | Real teaser results, no wallet. |

Chains: ethereum, base, bsc, polygon, arbitrum, optimism (honeypot.is signals on
ethereum/base/bsc).

## Payment

Paid tools use **x402** (USDC on Base, `eip155:8453`). Call a paid tool with no
`x_payment` to receive the decoded 402 challenge (price, network, asset, payTo);
build an x402 authorization and call again with the token in `x_payment`. Humans
can instead prepay by card and use an `X-FabTally-Key` credit header on the HTTP API.

## Transports

- **stdio** (default): `node index.js` — for Claude Desktop and local MCP clients.
- **streamable-http**: `MCP_HTTP_PORT=8113 node http.js` — hosted at
  `https://safe.fabtally.com/mcp`.

## Config

- `FABTALLY_SAFE_BASE` — API base (default `https://safe.fabtally.com`).

Operator: Sunstone Soft · https://fabtally.com · Not financial advice · read-only.

TDQS

A3.9/5.0

Scored across 8 tools

Disambiguation3/5

The four core domains (token safety, signature decode, approvals, simulate) are distinct, but each has a paid and free pair with overlapping purpose. The descriptions clarify that free versions are teasers, but agents may still struggle to pick between them based on the level of detail needed.

Naming Consistency3/5

All names use snake_case and the _free suffix is consistent, but base names mix grammatical patterns: token_safety (noun_noun), decode_signature (verb_noun), approvals (plural noun), and simulate (bare verb). No uniform verb_noun convention is present.

Tool Count4/5

Eight tools is within the well-scoped 3-15 range, but since the set is really four features each with a paid and free variant, the count feels slightly inflated. Still, the free teasers provide a useful way to test functionality without payment.

Completeness4/5

The server covers token risk, signature decoding, approval scanning, and transaction simulation, forming a solid wallet-safety toolkit. Minor gaps exist (e.g., no address profiling or historical trend analysis), but core workflows are covered.

Maintenance

ActivityStale
ResponsivenessNo issues