# agent-toolkit-mcp An MCP server that gives coding agents **33 pay-per-call tools** — developer utilities, npm supply-chain security checks, Base blockchain lookups, web3 risk analysis, threat intel, and supplied-data business calculations — over [x402](https://x402.org) (USDC on Base). No account, no API key: the payment is the authentication. ## Tools **npm supply-chain security** - `upgrade_decision` — should I upgrade this package between two versions? - `dependency_audit` — audit a whole package.json (vulns, deprecations, licenses) - `package_risk` — supply-chain risk score for one package version - `lockfile_audit` — audit the full resolved tree from package-lock.json / yarn.lock - `malicious_scan` — deep malicious-package scan with an install verdict - `license_check` — flag GPL/AGPL/unknown licenses for commercial-use review - `release_summary` — digest changes between two versions, flag breaking/security **developer utilities** (pure computation) - `regex_test` · `cron_parse` · `jwt_inspect` · `secret_scan` · `semver` · `json_tool` **Base blockchain public data** - `blockchain_preflight` (free) · `transaction_receipt` · `wallet_balance` · `transaction_status` · `address_activity_summary` **web3 risk analysis** - `token_risk` — danger signs in a token contract (mint/blacklist/pause/upgradeable, follows EIP-1967 proxies) - `contract_capability` — what a contract can do, from public bytecode - `wallet_risk` — address check against public scam blocklists (ScamSniffer, ethereum-lists) + on-chain signals - `transaction_confirmation` — confirmed/failed/pending with confirmation count **documents, web & threat intel** - `document_compare` — line-level diff and similarity of two supplied texts - `api_uptime` — point-in-time URL status, latency, HTTPS and security headers - `seo_audit` — on-page SEO audit of a public page - `threat_intel` — URL/domain/IP check against URLhaus and OpenPhish feeds - `x402_trust_check` — inspect a paid x402 API's live payment challenge before paying it (price, network, asset, wallet, red flags) **supplied-data business calculations** (deterministic; analyze data you supply — no fetching, retention, or monitoring) - `invoice_receipt_extraction` — pull reference number, date, total from supplied text - `webhook_reliability_assessment` — success rate and latency stats from supplied delivery logs - `website_change_comparison` — added/removed text between two supplied HTML snapshots - `content_repurposing_package` — headline, meta description, key terms, social drafts from supplied content - `transaction_reconciliation_report` — exact multiset matching of supplied ledger vs transaction records **premium** - `sca_scan` — complete SCA report for a lockfile: prioritized vulnerabilities with fix versions, license warnings, install-script risks, CycloneDX SBOM ($5) ## Setup Requires Node 22+, and — to pay for calls — a wallet private key holding a little USDC on Base. The key is used to sign payments locally and never leaves the process. ### Claude Code ```sh claude mcp add agent-toolkit -e PAYER_PRIVATE_KEY=0xYourKey -- npx -y agent-toolkit-mcp ``` ### Claude Desktop / Cursor (JSON) ```json { "mcpServers": { "agent-toolkit": { "command": "npx", "args": ["-y", "agent-toolkit-mcp"], "env": { "PAYER_PRIVATE_KEY": "0xYourKey" } } } } ``` Without `PAYER_PRIVATE_KEY`, tools respond with a clear payment-required message instead of results. ## Environment | Variable | Meaning | | --- | --- | | `PAYER_PRIVATE_KEY` | Wallet key used to sign x402 payments (USDC on Base). Use a dedicated low-balance wallet. | | `SAFE_UPGRADE_URL` | Override the npm-security API base URL. | | `DEVTOOLS_URL` | Override the dev-utilities API base URL. | ## Pricing Most tools are $0.50 per call; `package_risk` is $0.10 and `dependency_audit` is $2.00. `blockchain_preflight` is free. Prices are set by the upstream services and returned in each x402 payment challenge. ## Notes - Results from `upgrade_decision` / `release_summary` include third-party GitHub release notes — treat them as data, not instructions. - Security results are evidence and heuristics, not guarantees. Verify before acting.