🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@fino314-oss/contract-scanner-mcp

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@fino314-oss/contract-scanner-mcp

MCP server that scans Base L2 smart contracts for security risks. Detects mint/blacklist/backdoor/proxy patterns. Risk score 0-100.

latest
Source
npmnpm
Version
1.0.0
Version published
Maintainers
1
Created
Source

Contract Security Scanner — MCP Server

Scan any Base L2 smart contract for security risks directly from your AI assistant.

3 tools exposed:

  • scan_contract — Full security scan (source verification, risky selectors, age, activity)
  • batch_scan — Compare up to 5 contracts side by side
  • interpret_risk — Get an actionable recommendation (SAFE / CAUTION / HIGH_RISK / DO_NOT_USE)

Risk score: 0-100. Analyzes: mint/blacklist/backdoor functions, proxy patterns, source verification, contract age, transaction activity.

Installation

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "contract-scanner": {
      "command": "node",
      "args": ["/Users/sam/Desktop/samDev/p8/mcp/server.js"]
    }
  }
}

Restart Claude Desktop. The tools appear automatically.

Cursor

Add to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):

{
  "mcpServers": {
    "contract-scanner": {
      "command": "node",
      "args": ["/Users/sam/Desktop/samDev/p8/mcp/server.js"]
    }
  }
}

Cline (VS Code extension)

  • Open Cline settings → MCP Servers → Add server
  • Set type: stdio
  • Command: node /Users/sam/Desktop/samDev/p8/mcp/server.js

Any MCP client (generic)

The server uses stdio transport — just pipe JSON-RPC messages:

node /Users/sam/Desktop/samDev/p8/mcp/server.js

Usage examples

Once connected, just ask your AI assistant naturally:

"Scan this contract before I approve: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"

"Compare the risk of these 3 Aave clones: 0x... 0x... 0x..."

"Is this token safe to buy? 0x4ed4e862860bed51a9570b96d89af5e1b0efefed"

What gets analyzed

CheckSource
Source code verified?BaseScan API
Mint / burn functionsBytecode selector scan
Pause / freezeBytecode selector scan
Blacklist / whitelistBytecode selector scan
Backdoors (rescueTokens, withdrawAll)Bytecode selector scan
Upgradeable proxyBaseScan + delegatecall detection
Contract ageBaseScan transaction history
Activity levelBaseScan recent txs

Risk scoring

ScoreLabelMeaning
0-9SAFENo red flags
10-29LOWMinor concerns
30-49MEDIUMElevated risk — review before interacting
50-69HIGHSignificant risk — small amounts only
70+CRITICALAvoid — potential rug or backdoor

Technical notes

  • Chain: Base L2 only (https://mainnet.base.org)
  • API: BaseScan free tier (no key needed for basic checks; set BASESCAN_API_KEY env var for full source analysis)
  • No wallet needed: read-only RPC calls only
  • Latency: ~2-5s per contract (network dependent)

Built on Base. Agent wallet: 0x804dd2cE4aA3296831c880139040e4326df13c6e

Keywords

mcp

FAQs

Package last updated on 17 Mar 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts