Back to Browse

Frisk MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Screen the counterparty of an x402 payment before an agent pays it. Runs offline by default.

About

Screen the counterparty of an x402 payment before an agent pays it. Runs offline by default.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: 3 highly-trusted packages.

16 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Hosted API key. Without it the server screens entirely offline.Required

Environment variable: FRISK_API_KEY

Override the hosted endpoint. Defaults to https://api.tryfrisk.dev.Optional

Environment variable: FRISK_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "dev-tryfrisk-frisk": {
      "env": {
        "FRISK_API_KEY": "your-frisk-api-key-here",
        "FRISK_BASE_URL": "your-frisk-base-url-here"
      },
      "args": [
        "-y",
        "frisk-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Frisk

CI npm PyPI npm License: MIT

Pre-transaction risk screening for autonomous AI agents.

Before your agent pays an x402 seller or calls an unfamiliar tool, ask Frisk whether the counterparty is trustworthy and whether the transaction fits your policy. Frisk returns a verdict — allow, review, or block — with a trust score and human-readable reasons. It is advisory: your agent stays in control of the decision.

import { Client } from "frisk-screen";

const client = new Client(); // lite mode, no key required

const result = await client.screen("0x9a3f1b2c3d4e5f60718293a4b5c6d7e8f9a0bc12", {
  endpoint: "https://api.seller.x402/quote",
  amount: 2.5,
  asset: "USDC",
  policy: { maxPerCall: 5.0 },
});

if (!result.allowed) {
  console.log(result.verdict, result.trustScore, result.reasons);
}

Surfaces

SurfacePackageSource
TypeScript SDKfrisk-screen (npm)typescript/
Python SDKfrisk-screen (PyPI)python/
MCP serverfrisk-mcp (npm)mcp/

Both SDKs expose the same model: a Client with a screen() call, a lite mode that runs locally with zero dependencies, and an optional hosted mode for reputation history and live threat intelligence.

MCP server

For agents that cannot import a library, and for asking the question interactively, the same checks are available as an MCP server exposing one tool, screen_payment:

{
  "mcpServers": {
    "frisk": {
      "command": "npx",
      "args": ["-y", "frisk-mcp"]
    }
  }
}

No API key and no account: with no configuration it screens entirely on your machine. It is listed in the MCP registry as dev.tryfrisk/frisk.

An MCP tool runs only when a model chooses to call it, so a check the model can skip is a weaker guarantee than the same check on the code path that signs the payment. Where the money actually moves, prefer the SDK. Details in mcp/.

Lite mode vs. hosted

Lite (default)Hosted (API key)
RunsLocally, offlineFrisk API
SignalsPublic, structural checks onlyReputation graph, trained models, threat feed
ConfidenceAlways lowRises with coverage
CostFreeUsage-based

Lite mode catches obvious problems — malformed counterparties, payTo swaps, insecure endpoints, policy violations, and a small seed blocklist — without a network call. The hosted API (https://api.tryfrisk.dev) adds reputation history and continuously updated threat intelligence.

Design principles

  • Advisory, not in-path. Frisk never holds your funds or blocks a payment itself; it returns a verdict and your code decides.
  • Zero runtime dependencies. The TypeScript SDK is built on the platform fetch API (Node, Bun, Deno, Workers, browser); the Python SDK uses only the standard library.
  • Typed. Both SDKs ship with full type information.

Contributing

See CONTRIBUTING.md. Security disclosures: SECURITY.md.

License

MIT

The hosted API at api.tryfrisk.dev is additionally governed by the Terms of Service.

Reviews

No reviews yet

Be the first to review this server!