Back to Browse

Agentrisk MCP Server

Developer ToolsUse Caution3.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Pre-trade token risk scoring API for Base tokens, paid via x402.

About

Pre-trade token risk scoring API for Base tokens, paid via x402.

Remote endpoints: streamable-http: https://agentrisk.dev/mcp/manifest

Security Report

3.2
Use Caution3.2High Risk

AgentRisk M2M is a token risk analysis API with reasonable architecture but contains several security concerns. The service makes external API calls (GoPlus, DexScreener) without strict validation, relies on environment variable configuration for RPC endpoints without fallback validation, and has incomplete error handling in critical paths. The x402 payment integration adds complexity without visible credential validation. While the core analysis logic is sound and permissions align with the DeFi security purpose, these issues warrant attention before production deployment. Supply chain analysis found 7 known vulnerabilities in dependencies (0 critical, 1 high severity).

6 files analyzed ยท 21 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

AgentRisk M2M ๐Ÿ›ก๏ธ

Pre-Trade Security Layer for Autonomous DeFi Agents on Base. Stop letting your autonomous trading bots get rekt by stealth honeypots, malicious taxes, and rugpulls.


โšก The Problem

Autonomous trading bots are fast, but they are completely blind. Every minute, new unvetted tokens launch on Base. A significant share are deliberately engineered traps designed to block sells, drain executing wallets, or alter transfer taxes at the worst possible moment. Static blocklists (like standard free APIs) are useless against freshly deployed, obfuscated contracts. By the time human-curated lists update, your bot's capital is already gone.

๐ŸŽฏ The Solution

AgentRisk is an isolated, machine-readable security API built specifically for AI agents and automated scripts. Before your bot executes a swap() on Uniswap or Aerodrome, it pings AgentRisk. We run a deep runtime simulation combining direct on-chain checks, GoPlus Security, and DexScreener liquidity data, and return a strict verdict:

{
  "riskScore": 20,
  "riskLevel": "CAUTION",
  "verdict": "PROCEED WITH CAUTION. Top 10 holders control 51.8% of supply.",
  "shouldExecute": true,
  "reasons": [
    "Top 10 holders control 51.8% of supply."
  ]
}

What Makes This Different

  • Deployer wallet freshness โ€” flags newly-created wallets used for one-off token launches
  • Brand impersonation detection โ€” flags tokens named after known companies (Apple, Google, Meta, etc.)
  • Data source disagreement โ€” flags cases where third-party APIs and our own on-chain checks disagree
  • Human-readable verdict โ€” one plain-English sentence, not just raw scores
  • Sub-millisecond cached responses โ€” repeat scans within 30 seconds return instantly, with a cached field so you know whether a result is fresh or reused

Quick Testing with MCP Inspector

Want to poke at the MCP server without writing any code? Run: npx @modelcontextprotocol/inspector

Then connect it to https://agentrisk.dev/mcp/manifest and call check_token_risk directly from the UI.

Cache Freshness Warning

Every response includes cached (boolean) and timestamp (unix seconds) fields. Cached results are served for up to 30 seconds โ€” long enough to speed up repeat lookups, short enough to catch a rug pull or a newly-enabled honeypot function in most cases. For the final safety check immediately before executing a trade, we recommend either calling with a fresh request or checking that cached is false / timestamp is very recent before trusting a shouldExecute: true result.

โš™๏ธ How It Works (M2M Architecture)

  1. Agent Discovers Token via mempool or DEX router event.
  2. Agent Calls AgentRisk MCP Tool (check_token_risk) or the direct /scan endpoint.
  3. Instant x402 Micropayment ($0.15 USDC instantly settled on Base โ€” no API keys, subscriptions, or credit cards; pure machine-to-machine payment).
  4. Binary Decision: The agent receives shouldExecute: true/false with a risk score and structured reasons.

๐Ÿ“ฆ Python SDK

pip install agentriskm2m
import asyncio
from agentrisk import AgentRisk

async def main():
    risk = AgentRisk(private_key="your_base_wallet_private_key")
    result = await risk.scan("0xTokenAddressHere")
    print(result["verdict"])

asyncio.run(main())

PyPI page

Or check a token instantly from the terminal, no code needed:

export AGENTRISK_PRIVATE_KEY=your_base_wallet_private_key
agentriskm2m check 0xTokenAddressHere

๐Ÿš€ Copy-Paste Integration (60 seconds)

Install the x402 SDK, then run this โ€” it handles payment automatically:

pip install x402 eth-account

import asyncio
from eth_account import Account
from x402 import x402Client
from x402.http.clients import x402HttpxClient
from x402.mechanisms.evm import EthAccountSigner
from x402.mechanisms.evm.exact.register import register_exact_evm_client

PRIVATE_KEY = "your_base_wallet_private_key"
TOKEN_ADDRESS = "0x..."  # the token you want to check

async def check_token():
    account = Account.from_key(PRIVATE_KEY)
    client = x402Client()
    register_exact_evm_client(client, EthAccountSigner(account))
    async with x402HttpxClient(client) as http:
        response = await http.get(f"https://agentrisk.dev/scan?token={TOKEN_ADDRESS}")
        print(response.json())

asyncio.run(check_token())

That's it. It pays 0.15 USDC automatically and prints the risk report. Your wallet needs a small amount of USDC and ETH (for gas) on Base.

Framework Integration Examples

Option 1: MCP (Claude, Cursor, any MCP-compatible agent)

No code needed โ€” just point your MCP client config at:

{
  "mcpServers": {
    "agentrisk": {
      "url": "https://agentrisk.dev/mcp/manifest"
    }
  }
}

Your agent will automatically discover check_token_risk as an available tool.

Option 2: LangChain

from langchain.tools import tool
from eth_account import Account
from x402 import x402Client
from x402.http.clients import x402HttpxClient
from x402.mechanisms.evm import EthAccountSigner
from x402.mechanisms.evm.exact.register import register_exact_evm_client

account = Account.from_key("your_base_wallet_private_key")
client = x402Client()
register_exact_evm_client(client, EthAccountSigner(account))

@tool
async def check_token_safety(token_address: str) -> dict:
    """Check if a Base token is a honeypot or scam before buying or swapping."""
    async with x402HttpxClient(client) as http:
        response = await http.get(f"https://agentrisk.dev/scan?token={token_address}")
        return response.json()

# Add check_token_safety to your agent's tools list

Option 3: Coinbase AgentKit

from coinbase_agentkit import action

@action(
    name="check_token_safety",
    description="Check if a Base token is safe to trade before executing a swap"
)
async def check_token_safety(token_address: str) -> dict:
    async with x402HttpxClient(client) as http:
        response = await http.get(f"https://agentrisk.dev/scan?token={token_address}")
        return response.json()

Option 4: Plain Python (any custom bot, no framework)

def buy_token(token_address, amount):
    risk = check_token_safety(token_address)  # your call to AgentRisk
    if not risk["shouldExecute"]:
        print(f"Blocked: {risk['verdict']}")
        return
    execute_swap(token_address, amount)

Option 5: Automatic discovery via x402 Bazaar

If your agent searches the x402 Bazaar for tools, AgentRisk is discoverable automatically โ€” no manual integration needed.

๐Ÿš€ Other Integration Options

Option 1: MCP Server (For Claude, Cursor & Custom Agents)

MCP manifest is live at: https://agentrisk.dev/mcp/manifest

Tool endpoint: POST https://agentrisk.dev/mcp/tools/check_token_risk (x402-gated, 0.15 USDC per call). ### Option 2: Direct HTTP Call

GET https://agentrisk.dev/scan?token=<CONTRACT_ADDRESS>

Returns HTTP 402 with payment instructions until a valid x402 payment (0.15 USDC on Base) is attached.

๐Ÿ’ฐ Economy

  • Model: Pay-per-scan via the x402 protocol on Base Mainnet.
  • Cost: 0.15 USDC per comprehensive scan.
  • Facilitator: Coinbase's official CDP facilitator โ€” verifies and settles payments directly on Base.

๐Ÿ”Ž Live Status

Built for autonomous systems that trust math, not hype.

Reviews

No reviews yet

Be the first to review this server!