Back to Browse

Attester MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.

About

Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.

Remote endpoints: streamable-http: https://attester.dev/mcp/

Security Report

4.8
Use Caution4.8High Risk

This MCP server wraps attester.dev's verification and oracle APIs with proper authentication mechanisms, clear permission scoping, and good code quality. Authentication is well-designed with support for prepaid credits (ATTESTER_API_KEY) and x402 wallet payments (BUYER_PRIVATE_KEY), both handled securely via environment variables. The codebase has appropriate input validation, no hardcoded secrets, and follows safe patterns for external API calls. Minor quality observations around error handling and logging do not materially impact security. Supply chain analysis found 6 known vulnerabilities in dependencies (1 critical, 3 high severity).

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

attester-mcp

MCP server for attester.dev: verification and API-existence oracle tools for AI agents, callable from any MCP client (Claude Code, Cursor, Windsurf, LangChain, CrewAI).

Every result ships with a wallet-signed attestation you can verify without trusting us: POST https://attester.dev/receipts/verify is free.

Quickstart: free oracle tools, no keys

No install needed. Point your MCP client at the hosted endpoint:

{
  "mcpServers": {
    "attester": {
      "url": "https://attester.dev/mcp/"
    }
  }
}

Four oracle tools work immediately: no account, no API key, no wallet. You get 25 free calls per day per client IP, shared across the four tools, resetting 00:00 UTC. (This config block works for Claude Code, Claude Desktop, and Cursor; any MCP client that speaks streamable HTTP.)

ToolWhat it doesPrice per call
attester_package_existsDoes this PyPI/npm package name really exist? Typosquat-adjacency flags on misses.Free (25/day keyless); $0.002 paid
attester_symbol_existsDoes this function, class, or constant exist in the package? Closest-match suggestions on misses.Free (25/day keyless); $0.005 paid
attester_symbol_signatureExact signature, structured params, docstring, deprecation status, resolved at a pinned version.Free (25/day keyless); $0.01 paid
attester_version_diffSymbol-level diff between two pinned versions: added, removed, changed, breaking/additive/neutral.Free (25/day keyless); $0.02 paid

Run it locally instead (stdio): install from source with pip install git+https://github.com/maminihds/attester-mcp.git, then use "command": "attester-mcp" in the config above. A zero-install uvx attester-mcp command lands once the package is published to PyPI.

Steer your agent: CLAUDE.md / Cursor Rules snippet

- Before installing or importing a package, call attester_package_exists (and attester_symbol_exists for specific functions) to confirm the name exists. Never import a name the oracle says does not exist.

Paid tools

ToolWhat it doesPrice per call
oracle_verify_workCheck another agent's work: citation support, code correctness, data/schema validation. Verdict plus signed attestation.$0.15 USDC
oracle_code_researchCited coding research; citations are re-checked and the proof attached.$0.10 USDC
oracle_judgeGrade an output against your rubric; signed score with per-criterion evidence.$0.10 USDC
oracle_watchtower_reportSigned 24h report on whether an x402 service honors its advertised prices.$0.05 USDC
oracle_spend_checkPre-payment counterparty check: should your agent pay this address?$0.005 USDC

Payment works two ways:

  • Prepaid credits (humans, no crypto): buy a $5 pack at this Stripe link, claim the att_live_... key once at https://attester.dev/credits/claim?session_id=cs_..., and set ATTESTER_API_KEY=att_live_... in the server env. Every paid call deducts from the balance. Check it at GET https://attester.dev/credits/balance with the key. (CREDITS_API_KEY still works as an alias.) The free oracle tools honor the key too: the demo routes skip the daily quota for it and never charge.
  • x402 (agents with wallets): set BUYER_PRIVATE_KEY to a Base wallet with USDC. The wrapper pays per call automatically (402, sign, retry) and sends the wallet address as X-Payer, which keys the paid endpoints' free quotas.

Without any key, the paid endpoints answer HTTP 402 with payment terms in the body.

Agent skill bundle (skills/attester)

The same API, packaged as an Agent Skill so agent configs load it as a default tool: when-to-use rules, exact curl per endpoint (the keyless /demo/v1/* free path for oracle checks, X-Payer free quotas for the rest), verdict reading, and receipt verification.

Install paths:

# Claude Code
/plugin marketplace add maminihds/attester-mcp

# skills.sh CLI (Claude Code, Cursor, Codex, 30+ agents)
npx skills add maminihds/attester-mcp

# OpenClaw (manifestless Claude bundle)
openclaw plugins install https://github.com/maminihds/attester-mcp

Or copy skills/attester/ into ~/.claude/skills/ manually. The bundle has a helper (skills/attester/scripts/call.py, stdlib + httpx) and two worked transcripts in skills/attester/examples/.

Install from source

pip install -r requirements.txt
python server.py            # stdio (default, for agents)
python server.py --http     # streamable-http on :8100

Environment variables:

  • SERVER_URL: API base URL, defaults to https://attester.dev.
  • ATTESTER_API_KEY: prepaid credits key (att_live_...), optional.
  • BUYER_PRIVATE_KEY: Base wallet for x402 payment, optional.

Example clients

examples/plain_python.py: direct x402-paid call with the official SDK. examples/langchain_example.py: LangChain tool wrapper.

Links

Reviews

No reviews yet

Be the first to review this server!