Pre-sign check for agents: green/orange/red for EVM transactions, approvals and signatures via x402.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
A pre-sign risk check for AI agents. Before an agent signs a transaction, approval, or EIP-712 signature, it pays a few cents per call over x402 and gets back a green / orange / red verdict with machine-readable reason codes. Optionally, it also gets a plain-language explanation in Dutch or English.
Watch the 1-minute explainer: presign-guard.fizzl.eu/media/explainer.mp4
New: the token verdict in 45 seconds: presign-guard.fizzl.eu/media/token.mp4
Part of Klaartaal by FIZZL AI.
| Route | Price | Returns |
|---|---|---|
POST /v1/check | $0.01 USDC | Verdict, reason codes, decoded subject |
POST /v1/check/explain | $0.03 USDC | The same, plus a plain-language explanation (lang: "nl" or "en") |
GET /v1/token?chain=…&address=… | $0.01 USDC, Base or Solana | Token verdict: grade, reason codes, one-line summary, market data (see below) |
GET /v1/approvals?chain=…&address=… | $0.02 USDC, Base or Solana | Wallet approval audit: every open token approval, its spender, and which to revoke (see below) |
POST /mcp | free / paid | MCP server (Streamable HTTP): see below |
POST /feedback | free | Report a bug or a missing feature: see Feedback |
GET /health | free | Liveness |
GET /openapi.json | free | OpenAPI 3.1 spec with prices (x-payment-info) |
GET /.well-known/x402 | free | x402 discovery manifest |
Payment is x402 v2 with the exact scheme, in USDC on Base (the token verdict and the approval audit also on Solana). The 402 carries Bazaar discovery metadata (input example, input and output schema), and the challenge is mirrored into the JSON body for clients that don't read the PAYMENT-REQUIRED header. You are never charged for an error. Invalid requests (400) and upstream outages (503) cancel settlement, and they always return verdict: null, never a guessed verdict.
https://presign-guard.fizzl.eu/mcp is an MCP server (Streamable HTTP, stateless) for Claude, Cursor and agent frameworks, listed in the official MCP registry as io.github.Fizzl13/presign-guard.
| Tool | Price | Returns |
|---|---|---|
presign_quick_check | free, 10 calls/hour | The verdict only (green, orange or red) |
presign_check | $0.01 USDC via x402 | The full verdict and reason codes, as POST /v1/check |
presign_check_explain | $0.03 USDC via x402 | The same plus a plain-language explanation, as POST /v1/check/explain |
token_quick_verdict | free, shares the 10 calls/hour | The token verdict and grade only |
token_verdict | $0.01 USDC via x402 | The full token verdict, as GET /v1/token |
wallet_approvals | $0.02 USDC via x402 | The wallet approval audit, as GET /v1/approvals |
feedback | free | Report a bug or a missing feature, as POST /feedback |
The paid tools are paid inside the MCP call with the x402 MCP transport (_meta["x402/payment"]), on Base (token_verdict and wallet_approvals also on Solana), to the same payout wallets as the HTTP routes. Invalid input is refused before payment, and a failed check is not charged.
GET /v1/token?chain=solana&address=<mint> (or chain=base|ethereum|arbitrum|optimism|polygon|bsc with a 0x token contract) answers one question before an agent buys, holds or accepts a token: is the token itself a trap?
Grades: SAFE (green), CAUTION (one orange reason), RISKY (two or more), AVOID (red). The one-liner states facts only.
| Severity | Codes |
|---|---|
| red | RUGGED, NON_TRANSFERABLE, MALICIOUS_AUTHORITY; EVM: TOKEN_HONEYPOT, TOKEN_AIRDROP_SCAM, TOKEN_IMPERSONATION |
| orange | MINT_AUTHORITY_ACTIVE, FREEZE_AUTHORITY_ACTIVE, BALANCE_MUTABLE, CLOSABLE, TRANSFER_HOOK, TRANSFER_FEE, HIGH_TRANSFER_FEE (≥10%), TRANSFER_FEE_UPGRADABLE, LP_NOT_LOCKED (<50% locked, token younger than 30 days), LOW_LIQUIDITY (<$50k), NO_DEX_MARKET, NEW_TOKEN (<24 h), TOP_HOLDERS_CONCENTRATED (top holder >20% or top 10 >50%, pools and locked accounts excluded; on EVM only wallets count, not contracts); EVM: the GoPlus token codes of /v1/check (TOKEN_HIGH_TAX, TOKEN_UNVERIFIED, …), TOKEN_CANNOT_BUY and TOKEN_PAUSED (transfers are paused right now) |
| info | MUTABLE_METADATA, NO_SOCIALS, TOKEN_ON_TRUST_LIST, NO_SECURITY_DATA, RUGCHECK_DANGER, RUGCHECK_UNAVAILABLE, LP_NOT_LOCKED on older tokens, on trust-list tokens (USDC, USDT, WETH): the issuer's powers, LP_NOT_LOCKED, LOW_LIQUIDITY and NO_DEX_MARKET (DexScreener undercounts quote assets); EVM: TOKEN_PAUSABLE and TOKEN_BLACKLIST (the issuer can pause transfers or blacklist holders; a green one-liner says so) |
For a proxy token (USDC, cbBTC, EURC on Base) GoPlus reports no pause or blacklist fields, so the verdict asks the token itself with eth_call on the standard getters (paused, pauser, PAUSER_ROLE, blacklister, isBlacklisted, isBlackListed); those reasons carry source: "onchain" and the role address, and sources includes chain. If the chain RPC is down they are left out and the verdict still answers.
On a token on the GoPlus trust list (USDC, USDT), the issuer's powers (mint, freeze, change balances) are info: the issuer keeps them on purpose. Missing data never makes a token red. If GoPlus or DexScreener is down there is no verdict (503, not charged); if RugCheck is down the verdict comes without it and says so.
GET /v1/approvals?chain=base&address=<wallet> (or chain=ethereum|arbitrum|optimism|polygon|bsc) is the follow-up to /v1/check: that one asks "should I sign this approval?", this one asks "which approvals did I already give, and which should I revoke?". Agents with their own wallet can run it as a periodic check.
| Severity | Codes (per approval; the wallet-level reasons count them) |
|---|---|
| red | SPENDER_MALICIOUS (the spender is flagged by GoPlus) |
| orange | APPROVAL_TO_WALLET (the spender is a plain wallet, not a contract), SPENDER_SUSPICIOUS (GoPlus doubt list), SPENDER_UNVERIFIED (contract source not verified), UNLIMITED_APPROVAL (to a spender not on the GoPlus trust list) |
| info | UNLIMITED_APPROVAL_TRUSTED (e.g. Permit2), STALE_APPROVAL (older than a year), TOKEN_FLAGGED (the approved token itself), NO_APPROVALS |
Every approval with an orange or red code has revoke: true. The grades are the same as the token verdict. Source: GoPlus token_approval_security (ERC-20 allowances); NFT approvals are not covered. If GoPlus is down there is no verdict (503, not charged).
Supported chains: 1, 10, 56, 137, 8453, 42161.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/presign-guard)<a href="https://allmcps.com/mcp/presign-guard"><img src="https://allmcps.com/api/badge/presign-guard?style=directory" alt="Presign Guard on AllMCPs" /></a>