The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Contract Security Scanner listing page.
Scan any Base L2 smart contract for security risks directly from your AI assistant.
3 tools exposed:
scan_contract — Full security scan (source verification, risky selectors, age, activity)batch_scan — Compare up to 5 contracts side by sideinterpret_risk — Get an actionable recommendation (SAFE / CAUTION / HIGH_RISK / DO_NOT_USE)Risk score: 0-100. Analyzes: mint/blacklist/backdoor functions, proxy patterns, source verification, contract age, transaction activity.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
Restart Claude Desktop. The tools appear automatically.
Add to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):
stdionode /Users/sam/Desktop/samDev/p8/mcp/server.jsThe server uses stdio transport — just pipe JSON-RPC messages:
Once connected, just ask your AI assistant naturally:
| Check | Source |
|---|---|
| Source code verified? | BaseScan API |
| Mint / burn functions | Bytecode selector scan |
| Pause / freeze | Bytecode selector scan |
| Blacklist / whitelist | Bytecode selector scan |
| Backdoors (rescueTokens, withdrawAll) | Bytecode selector scan |
| Upgradeable proxy | BaseScan + delegatecall detection |
| Contract age | BaseScan transaction history |
| Activity level | BaseScan recent txs |
| Score | Label | Meaning |
|---|---|---|
| 0-9 | SAFE | No red flags |
| 10-29 | LOW | Minor concerns |
| 30-49 | MEDIUM | Elevated risk — review before interacting |
| 50-69 | HIGH | Significant risk — small amounts only |
| 70+ | CRITICAL | Avoid — potential rug or backdoor |
https://mainnet.base.org)BASESCAN_API_KEY env var for full source analysis)Built on Base. Agent wallet: 0x804dd2cE4aA3296831c880139040e4326df13c6e