Back to Directory/Security & Auth

Contract Security Scanner

Scans Base L2 smart contracts for security risks. Risk score 0-100, detects backdoors & proxies.

Security & AuthJavaScriptv1.0.0

Contract Security Scanner — MCP Server

contract-scanner-mcp MCP server

Scan any Base L2 smart contract for security risks directly from your AI assistant.

3 tools exposed:

  • scan_contract — Full security scan (source verification, risky selectors, age, activity)
  • batch_scan — Compare up to 5 contracts side by side
  • interpret_risk — Get an actionable recommendation (SAFE / CAUTION / HIGH_RISK / DO_NOT_USE)

Risk score: 0-100. Analyzes: mint/blacklist/backdoor functions, proxy patterns, source verification, contract age, transaction activity.


Installation

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "contract-scanner": {
      "command": "node",
      "args": ["/Users/sam/Desktop/samDev/p8/mcp/server.js"]
    }
  }
}

Restart Claude Desktop. The tools appear automatically.


Cursor

Add to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):

{
  "mcpServers": {
    "contract-scanner": {
      "command": "node",
      "args": ["/Users/sam/Desktop/samDev/p8/mcp/server.js"]
    }
  }
}

Cline (VS Code extension)

  1. Open Cline settings → MCP Servers → Add server
  2. Set type: stdio
  3. Command: node /Users/sam/Desktop/samDev/p8/mcp/server.js

Any MCP client (generic)

The server uses stdio transport — just pipe JSON-RPC messages:

node /Users/sam/Desktop/samDev/p8/mcp/server.js

Usage examples

Once connected, just ask your AI assistant naturally:

"Scan this contract before I approve: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"

"Compare the risk of these 3 Aave clones: 0x... 0x... 0x..."

"Is this token safe to buy? 0x4ed4e862860bed51a9570b96d89af5e1b0efefed"

What gets analyzed

CheckSource
Source code verified?BaseScan API
Mint / burn functionsBytecode selector scan
Pause / freezeBytecode selector scan
Blacklist / whitelistBytecode selector scan
Backdoors (rescueTokens, withdrawAll)Bytecode selector scan
Upgradeable proxyBaseScan + delegatecall detection
Contract ageBaseScan transaction history
Activity levelBaseScan recent txs

Risk scoring

ScoreLabelMeaning
0-9SAFENo red flags
10-29LOWMinor concerns
30-49MEDIUMElevated risk — review before interacting
50-69HIGHSignificant risk — small amounts only
70+CRITICALAvoid — potential rug or backdoor

Technical notes

  • Chain: Base L2 only (https://mainnet.base.org)
  • API: BaseScan free tier (no key needed for basic checks; set BASESCAN_API_KEY env var for full source analysis)
  • No wallet needed: read-only RPC calls only
  • Latency: ~2-5s per contract (network dependent)

Built on Base. Agent wallet: 0x804dd2cE4aA3296831c880139040e4326df13c6e

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @fino314-oss/contract-scanner-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-fino-oss-contract-scanner": {
      "command": "npx",
      "args": [
        "-y",
        "@fino314-oss/contract-scanner-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@fino314-oss/contract-scanner-mcpnpm

Compatible MCP Clients

Contract Security Scanner works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More