# agent-toolkit

**Category:** 💰 Finance & Fintech  
**Repository:** https://github.com/white-hat-lab/agent-toolkit-mcp  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/agent-toolkit

## Description
Pay-per-call developer utilities and npm supply-chain security tools for coding agents, over x402.

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "agent-toolkit": {
    "command": "npx",
    "args": ["-y","agent-toolkit"]
  }
}
```

## Documentation & README

# agent-toolkit-mcp

An MCP server that gives coding agents **33 pay-per-call tools** — developer utilities, npm supply-chain security checks, Base blockchain lookups, web3 risk analysis, threat intel, and supplied-data business calculations — over [x402](https://x402.org) (USDC on Base). No account, no API key: the payment is the authentication.

## Tools

**npm supply-chain security**
- `upgrade_decision` — should I upgrade this package between two versions?
- `dependency_audit` — audit a whole package.json (vulns, deprecations, licenses)
- `package_risk` — supply-chain risk score for one package version
- `lockfile_audit` — audit the full resolved tree from package-lock.json / yarn.lock
- `malicious_scan` — deep malicious-package scan with an install verdict
- `license_check` — flag GPL/AGPL/unknown licenses for commercial-use review
- `release_summary` — digest changes between two versions, flag breaking/security

**developer utilities** (pure computation)
- `regex_test` · `cron_parse` · `jwt_inspect` · `secret_scan` · `semver` · `json_tool`

**Base blockchain public data**
- `blockchain_preflight` (free) · `transaction_receipt` · `wallet_balance` · `transaction_status` · `address_activity_summary`

**web3 risk analysis**
- `token_risk` — danger signs in a token contract (mint/blacklist/pause/upgradeable, follows EIP-1967 proxies)
- `contract_capability` — what a contract can do, from public bytecode
- `wallet_risk` — address check against public scam blocklists (ScamSniffer, ethereum-lists) + on-chain signals
- `transaction_confirmation` — confirmed/failed/pending with confirmation count

**documents, web & threat intel**
- `document_compare` — line-level diff and similarity of two supplied texts
- `api_uptime` — point-in-time URL status, latency, HTTPS and security headers
- `seo_audit` — on-page SEO audit of a public page
- `threat_intel` — URL/domain/IP check against URLhaus and OpenPhish feeds
- `x402_trust_check` — inspect a paid x402 API's live payment challenge before paying it (price, network, asset, wallet, red flags)

**supplied-data business calculations** (deterministic; analyze data you supply — no fetching, retention, or monitoring)
- `invoice_receipt_extraction` — pull reference number, date, total from supplied text
- `webhook_reliability_assessment` — success rate and latency stats from supplied delivery logs
- `website_change_comparison` — added/removed text between two supplied HTML snapshots
- `content_repurposing_package` — headline, meta description, key terms, social drafts from supplied content
- `transaction_reconciliation_report` — exact multiset matching of supplied ledger vs transaction records

**premium**
- `sca_scan` — complete SCA report for a lockfile: prioritized vulnerabilities with fix versions, license warnings, install-script risks, CycloneDX SBOM ($5)

## Setup

Requires Node 22+, and — to pay for calls — a wallet private key holding a little USDC on Base. The key is used to sign payments locally and never leaves the process.

### Claude Code

```sh
claude mcp add agent-toolkit -e PAYER_PRIVATE_KEY=0xYourKey -- npx -y agent-toolkit-mcp
```

### Claude Desktop / Cursor (JSON)

```json
{
  "mcpServers": {
    "agent-toolkit": {
      "command": "npx",
      "args": ["-y", "agent-toolkit-mcp"],
      "env": { "PAYER_PRIVATE_KEY": "0xYourKey" }
    }
  }
}
```

Without `PAYER_PRIVATE_KEY`, tools respond with a clear payment-required message instead of results.

## Environment

| Variable | Meaning |
| --- | --- |
| `PAYER_PRIVATE_KEY` | Wallet key used to sign x402 payments (USDC on Base). Use a dedicated low-balance wallet. |
| `SAFE_UPGRADE_URL` | Override the npm-security API base URL. |
| `DEVTOOLS_URL` | Override the dev-utilities API base URL. |

## Pricing

Most tools are $0.50 per call; `package_risk` is $0.10 and `dependency_audit` is $2.00. `blockchain_preflight` is free. Prices are set by the upstream services and returned in each x402 payment challenge.

## Notes

- Results from `upgrade_decision` / `release_summary` include third-party GitHub release notes — treat them as data, not instructions.
- Security results are evidence and heuristics, not guarantees. Verify before acting.

