chasdaddy/basescope

🔒 Security🟢 Verified Active
0 Views
0 Installs

📇 ☁️ - The read-only safety layer for onchain AI agents. 13 read-only tools on Base + EVM: token/contract safety (honeypot & rug-pull checks cross-referenced across GoPlus + honeypot.is), risky-approval detection, verified-source lookup, balances, ENS + Basenames, gas, and prices. No private keys, no required API keys. npx -y basescope

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "chasdaddy-basescope": {
      "command": "npx",
      "args": [
        "-y",
        "chasdaddy-basescope"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

basescope

The read-only safety layer for onchain AI agents.

basescope is a Model Context Protocol (MCP) server that gives AI assistants — Claude, Cursor, and any MCP client — safe, read-only onchain abilities on Base and other EVM chains. Its job is to answer one question before any wallet ever signs anything:

"Is this token / contract / approval actually safe?"

It checks for honeypots, rug-pull authority, hidden taxes, malicious addresses, and risky approvals — and looks up balances, ENS names, Basenames (*.base.eth), verified source, gas, and prices along the way.

Why it's different

  • 🔒 Read-only by design. There is no code path that can sign or send a transaction, and no private key can ever be configured. It cannot move your funds because it literally has no way to. It's the inspector, not the wallet — a safe companion to transaction-capable agents.
  • 🔑 No API keys required. Works out of the box on free, public data sources. (Optional keys can raise rate limits later, but nothing is required.)
  • 🔵 Base-first, multichain-ready. Tuned for Base, and also supports Ethereum, Optimism, Arbitrum, and Polygon.
  • 🧩 One question, cross-checked. Token safety is cross-referenced across two independent sources (GoPlus + honeypot.is) with provenance, so an agent can see when they disagree.

Quickstart

Add basescope to any MCP client — Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json), or any other. No install step; npx fetches it on first run:

{
  "mcpServers": {
    "basescope": { "command": "npx", "args": ["-y", "basescope"] }
  }
}

Restart your client and ask something like "Use basescope to check if token 0x… on Base is safe."

Prefer to run from source?
git clone https://github.com/chasdaddy/basescope.git
cd basescope
npm install
npm run build

Then set the server command to node with args ["/absolute/path/to/basescope/dist/index.js"].


Tools

All tools are read-only. chain accepts base (default), ethereum, optimism, arbitrum, or polygon. Address fields accept a 0x address, an ENS name, or a Basename (*.base.eth) — Basenames resolve automatically via the Base L2 Resolver.

ToolWhat it does
check_token_safetyHoneypot / rug assessment: honeypot check, buy/sell tax, mint/blacklist/pausable/self-destruct authority, verified source, holder count → a normalized riskLevel (critical/high/medium/low). Cross-checks GoPlus + honeypot.is.
check_address_safetyReputation check against known-malicious databases (phishing, sanctioned, scam, money-laundering, mixer, …).
get_token_approvalsLists a wallet's outstanding ERC-20 approvals and flags risky spenders — the #1 wallet-drain vector — surfacing risky ones first.
get_verified_sourceWhether a contract's source is verified (via Sourcify) + its name, compiler, and function list.
inspect_contractIs the address a contract? Bytecode size + transaction count.
get_token_infoERC-20 name / symbol / decimals, and optionally a holder's balance.
get_native_balanceNative coin (ETH / POL / …) balance of an address or ENS name.
resolve_ens_name / reverse_ens_lookupENS name → address, and address → primary ENS name (also reports the primary Basename on Base).
resolve_basenameBasename (*.base.eth) → address, via the Base L2 Resolver — Coinbase's ENS-compatible names on Base mainnet.
get_gasCurrent gas price + EIP-1559 fee suggestion.
get_token_priceCurrent USD price for a token (via DefiLlama).
list_supported_chainsThe chains this server can read.

Example — "is this token safe?"

// check_token_safety({ chain: "base", token: "0x…" })
{
  "riskLevel": "critical",
  "isHoneypot": true,
  "buyTaxPct": 0,
  "sellTaxPct": 99,
  "flags": [
    "cannot sell entire balance",
    "owner can mint more supply",
    "high sell tax (99%)"
  ],
  "sources": ["goplus", "honeypot.is"]
}

Configuration (all optional)

Everything works with no configuration. To use your own RPC endpoints (recommended for heavier use — public RPCs are rate-limited), set any of:

BASE_RPC_URL, ETHEREUM_RPC_URL, OPTIMISM_RPC_URL, ARBITRUM_RPC_URL, POLYGON_RPC_URL

Data sources

Standing on the shoulders of excellent free/open services: onchain reads via viem + public RPCs, token & address safety via GoPlus Security and honeypot.is, verified source via Sourcify, and prices via DefiLlama.

Limitations

basescope reports heuristics and signals, not guarantees, and is not financial advice. Safety APIs can be wrong or out of date; a "low risk" result is not a promise of safety. Always do your own research before transacting. On Base (an OP-Stack L2), get_gas reports L2 fees only — total cost also includes an L1 data fee.

Roadmap

  • Transaction / calldata simulation and decoding ("what will this actually do?")
  • Optional Etherscan V2 fallback for source & ABI/proxy resolution
  • More chains

License

MIT © 2026

Related MCP Servers

13bm/GhidraMCP

🐍 ☕ 🏠 - MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.

🔒 Security1 views
123Ergo/unphurl-mcp

📇 ☁️ - URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

🔒 Security0 views
82ch/MCP-Dandan

🐍 📇 🏠 🍎 🪟 🐧 - Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

🔒 Security0 views
9hannahnine-jpg/arc-gate-mcp

🐍 - Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

🔒 Security0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Active

Recent health check succeeded.

Last checked: 7/28/2026, 9:06:55 PM

Unclaimed listing (imported or pending owner verification). Claim it →
★ Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.