# M2M Sentinel [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/M2M-Sentinel/m2m-sentinel-sdk  
**GitHub Stars:** 2  
**npm Downloads (last month):** 319  
**Views:** 1  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/m2m-sentinel

## Description
Base bytecode capability observations, proxy resolution, gas, DEX, and transfer telemetry.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "m2m-sentinel": {
    "command": "npx",
    "args": ["-y","m2m-sentinel-sdk"],
    "env": {
      "M2M_SENTINEL_API_KEY": ""
    }
  }
}
```

**Requires environment variables:** `M2M_SENTINEL_API_KEY` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What M2M Sentinel MCP server does

The M2M Sentinel MCP server connects MCP-compatible agents to M2M Sentinel’s Base-focused contract analysis service. Its documented audit flow accepts a contract address and returns structured results covering proxy resolution, executable capabilities, and capability evidence derived from bytecode observations. The repository description also identifies gas, DEX, and transfer telemetry as part of the service’s scope, but the provided examples specifically demonstrate contract auditing and capability output.

The server is intended for autonomous applications that need observations before deciding whether or how to act. Callers retain transaction policy: the audit result does not replace an application’s approval rules or execution controls.

## How it works

An MCP client starts the package locally with npx and communicates over stdio, or connects to the published Streamable HTTP endpoint at `https://api.m2msentinel.com/mcp`. Legacy HTTP+SSE clients can use the documented SSE endpoint and its messages URL. Requests require the configured M2M Sentinel API key where applicable.

The JavaScript and Python examples call an `auditContract` operation with a Base address. The returned structure includes `audit.proxyResolution.isProxy`, an optional target address, `audit.verdict.executableCapabilities`, and `audit.dissection.capabilities`. This gives an agent structured observations it can pass to a separate, caller-owned policy layer.

## Setup and configuration

For a local MCP installation, configure the package as an MCP server with the `npx -y m2m-sentinel-sdk` command and set `M2M_SENTINEL_API_KEY` in the server environment. Smithery provides a command-based installation path for Claude. Remote deployments can use the current Streamable HTTP URL instead of launching the local package.

The repository also publishes `m2m-sentinel-sdk` for JavaScript or TypeScript and `m2m-sentinel` for Python. Coinbase AgentKit users can add the supplied action provider and pass the same API key through their application configuration. An x402 signer client is available for headless requests to the service’s API.

## Tools and capabilities

The M2M Sentinel MCP server supports the documented contract-audit workflow for Base addresses, including:

- Observing deterministic EVM bytecode capabilities.
- Resolving common proxy implementations and reporting a target address when found.
- Returning executable-capability verdicts and capability evidence.
- Exposing the service through MCP, JavaScript or TypeScript, Python, and Coinbase AgentKit interfaces.
- Supporting remote requests through Streamable HTTP and legacy HTTP+SSE compatibility endpoints.

The repository additionally includes a Base Account `wallet_sendCalls` guard and mock-only transaction-preflight examples. These are SDK examples and execution boundaries, not evidence that the MCP server signs or broadcasts transactions.

## Limitations and notes

M2M Sentinel does not own transaction policy. The wallet guard does not sign, broadcast, custody funds, infer inner UserOperation semantics, or make a safety claim. The transaction-preflight example similarly stops at a mock signing or sending callback and requires the caller to supply policy and, in live mode, the API-key header.

Treat returned observations as inputs to application controls rather than automatic authorization. The provided material documents Base-oriented behavior and does not establish support for other networks. It also does not enumerate individual MCP tool names beyond the demonstrated audit workflow, so integrations should verify the exposed tool schema during setup.

_Full upstream README: https://allmcps.com/mcp/m2m-sentinel/readme_

