Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.github.hypeprinter007-stack/anchor-x402

NPM · ANCHOR-X402-MCP · 2 COMPONENTS · SCANNED AUG 3

x402-paid agent tools: 18 over HTTP, 14 over stdio. USDC per call, no API key.

+51 this week 75 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security87
  • No malware found by supply-chain analysis.Pass
  • Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to hypeprinter007-stack/anchor-x402-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 74 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1817 tokens (~129/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · anchor-x402-mcp

# add to Claude Code
claude mcp add hypeprinter007-stack-anchor-x402 -- npx -y anchor-x402-mcp
# add to Codex CLI
codex mcp add hypeprinter007-stack-anchor-x402 -- npx -y anchor-x402-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "hypeprinter007-stack-anchor-x402": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "anchor-x402-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add hypeprinter007-stack-anchor-x402 --command npx --arg -y --arg anchor-x402-mcp
# ~/.hermes/config.yaml
mcp_servers:
  hypeprinter007-stack-anchor-x402:
    command: "npx"
    args: ["-y", "anchor-x402-mcp"]
// mcp.json
{
  "mcpServers": {
    "hypeprinter007-stack-anchor-x402": {
      "command": "npx",
      "args": [
        "-y",
        "anchor-x402-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Aug 26 +70
    • Provenance: unverified → pass security
    • Known CVEs: unverified → partial security
    • Install scripts: unverified → pass security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • The attested source repository moved: hypeprinter007-stack/anchor-x402-mcp security
    • Security disclosure: fail → unverified functional
    • Tool coverage: unverified → 100 functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Maintenance: unverified → pass functional
    • MCP protocol: unverified → pass functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 97 functional
    • First check of Schema quality: excellent functional
    • First check of Schema quality: fail functional
    • Licence: MIT functional
  • 1 Aug 26 −2
    • First check of Stability: unverified security
    • Dependency health: partial → unverified functional
    • First check of Capabilities: unverified functional
    • Package version: 0.2.0 → 0.2.1 functional
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −17
    • Malware scan: pass → unverified security
    • Dependency health: unverified → partial functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
  • 27 Jul 26 24

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
hypeprinter007-stack/anchor-x402-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/hypeprinter007-stack/anchor-x402-mcp/.github/workflows/publish.yml@refs/tags/v0.2.1
Rekor log index:
1582845743
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:7b455dde36dae8da417d5706a97fa3460ddb5170ad2fc217fe0e347813c5070ccb131d97796bc252c0e4449f7e517f0a1e1306ad807fd3d1f4bbc32b8
Discovery method:
attestation_endpoint
Dependencies 113 packages

113 packages in the resolved dependency tree · 112 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 14 exposed · ~1,817 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
anchor_hash ~178

Anchor a 32-byte hash to BOTH Base mainnet (as EIP-1559 calldata) and Solana mainnet (via the Memo program) in a single call. Returns both transaction hashes plus block-explorer URLs as cryptographic proof of when the hash existed. Pure infrastructure — no opinions about content. Use for DAO vote receipts, AI decision attestations, contract notarization, scientific data integrity, audit trails. $0.005 USDC.

NameTypeReqDescription
dataArbitrary JSON to be canonicalized + SHA-256'd by the server. Mutually exclusive with `hash`.
hashstringPre-computed 32-byte hex hash (64 chars, no 0x prefix). Mutually exclusive with `data`.
notestringOptional 200-char note included in the response (NOT on-chain).

No output schema declared.

No examples provided.

attest_decision ~231

Verify a wallet signature over (input_hash, output_hash, decision) with domain separation, then dual-chain anchor the resulting Merkle root on Base and Solana mainnet. Returns the verified signer plus on-chain proof URLs. Use when an AI agent's decision needs a cryptographic, auditable receipt — autonomous trade approvals, AI-assisted contract decisions, model-output attestation for liability records. $0.010 USDC.

NameTypeReqDescription
decisionstringyesFree-form short label, e.g. "APPROVED", "REJECTED", "CONFIDENCE=0.93" (max 64 chars).
input_hashstringyes64-char hex SHA-256 of the agent's input.
output_hashstringyes64-char hex SHA-256 of the agent's output / decision payload.
schemestringyesSignature scheme.
signaturestringyes0x-prefixed hex (eip191) or base58 (ed25519).
signer_pubkeystringRequired for ed25519 (Solana base58 pubkey).

No output schema declared.

No examples provided.

aura ~110

Aura read of any target — returns color (free-form e.g. 'molten gold with copper veins'), tier (S/A/B/C/D/F), score (0-9999), and a 2-3 sentence punchy description. Universal input — wallet, tweet, project, person, idea, meme. Use for viral / shareable content, brand vibes, social. $0.01 USDC.

NameTypeReqDescription
targetstringyesAnything to read the aura of (max 4000 chars).

No output schema declared.

No examples provided.

decode_calldata ~148

Decode raw EVM calldata into a human-readable function name, canonical signature, and typed parameter values. Resolves the 4-byte selector against openchain.xyz's signature directory, then ABI-decodes the args. Use for tx inspection before signing, mempool analysis, debug. EVM-only (chain='ethereum'); 'solana' returns 400. $0.001 USDC.

NameTypeReqDescription
calldata_hexstringyesRaw EVM calldata (>=4 byte selector), with or without 0x prefix.
chainstringyesEVM-only; 'solana' returns 400.
contract_addressstringOptional. Reserved for future on-chain ABI lookups.

No output schema declared.

No examples provided.

decode_tx ~122

Structured decode of any mainnet transaction by hash. Supply chain ('base' | 'ethereum' | 'solana') and tx_hash. Returns from/to/value/gas/status/calldata for EVM, or slot/fee/signers/program_calls for Solana. Mined txs cached in-process. Use for tx inspection, audit, agent UX (rendering tx summaries to users). $0.001 USDC.

NameTypeReqDescription
chainstringyes
tx_hashstringyesEVM 0x+64hex or Solana base58 signature.

No output schema declared.

No examples provided.

grade ~91

Academic letter grade (A+ to F) with 3-7 red-pen marginalia one-liners and a one-paragraph teacher summary. Universal input — code, pitch deck, tweet, wallet, idea. Use for sharp feedback at low cost, prompt engineering eval, pre-investment screen. $0.01 USDC.

NameTypeReqDescription
targetstringyesAnything to grade (max 6000 chars).

No output schema declared.

No examples provided.

intel_wallet ~117

Unified wallet intelligence bundle. ONE call returns balances on Base + Ethereum + Solana, USDC across chains, transaction count, ENS/SNS reverse lookup, and sanctions verdict — all aggregated from 8–10 parallel free public sources. Replaces a wallet-investigation script with a single $0.005 call. Use for KYB pre-flight, counterparty research, fraud detection. $0.005 USDC.

NameTypeReqDescription
walletstringyesEVM 0x… address (40 hex) or Solana base58 pubkey.

No output schema declared.

No examples provided.

oracle ~102

Yes/no oracle with dual-chain anchored verdict. LLM answers YES / NO / MAYBE with one-sentence reason, then anchors sha256(question|answer|timestamp) to Base + Solana mainnet so anyone can prove the question was asked at a specific time. Use for prediction-market commits, conditional contracts, time-stamped opinions, settling bets. $0.05 USDC.

NameTypeReqDescription
questionstringyesA yes/no question (max 1000 chars).

No output schema declared.

No examples provided.

parse_datetime ~149

Parse any freeform datetime string ('tomorrow at noon', 'yesterday', '2026-05-13T15:30Z', 'in 2 hours') into a fully structured normalized form: ISO 8601, unix epoch, components (year/month/day/hour/min/sec/weekday), relative seconds + human form, confidence score. Saves agent LLM tokens on date parsing. $0.001 USDC.

NameTypeReqDescription
base_timestringOptional ISO 8601 reference; defaults to now UTC.
inputstringyesFreeform datetime string.
timezonestringOptional IANA tz name (e.g. 'America/New_York'); defaults to UTC.

No output schema declared.

No examples provided.

resolve_name ~97

Cross-chain name resolution. Pass a name like 'vitalik.eth' or 'bonfida.sol' and get back the resolved address(es) across supported registries. Currently supports ENS (.eth) and Bonfida SNS (.sol). Cached 1h server-side. $0.001 USDC.

NameTypeReqDescription
namestringyesHuman-readable name, e.g. 'vitalik.eth' or 'bonfida.sol'.

No output schema declared.

No examples provided.

roast ~98

Witty, observational roast of any target — a wallet address, tweet, code snippet, startup idea, person, meme, anything. Returns a 3-5 paragraph LLM roast and a one-sentence neutral summary of the target. Clever, not mean-spirited. Use for entertainment, demo content, social. $0.05 USDC.

NameTypeReqDescription
targetstringyesAnything to roast — free text up to 8000 chars.

No output schema declared.

No examples provided.

screen_wallet ~127

Sanctions + AML screening for any EVM or Solana wallet address. Returns sanctions match (boolean), specific OFAC SDN programs flagged (Tornado Cash, Lazarus Group, Hydra Market, Garantex, Blender.io etc.), inferred chain, and a low/medium/high risk verdict. Use for AML pre-flight checks before any treasury transfer, KYC onboarding, vendor diligence, payroll wallet verification, marketplace counterparty checks. $0.001 USDC.

NameTypeReqDescription
walletstringyesEVM 0x… address (40 hex) or Solana base58 pubkey.

No output schema declared.

No examples provided.

tldr ~112

Summarize a URL or pasted text into 3-5 concise bullets. Fetches up to 500KB on the URL path, strips HTML with BeautifulSoup. Use for research distillation, link-rot insurance, agent reading lists. Exactly one of `text` or `url`. $0.01 USDC.

NameTypeReqDescription
textstringPasted text to summarize. Omit if providing `url`.
urlstringURL to fetch + summarize. Omit if providing `text`.

No output schema declared.

No examples provided.

token_price ~135

USD spot price for any major token. Pass either `symbol` (BTC, ETH, SOL, USDC, etc.) OR (chain + contract). Returns USD price, 24h change percent, market cap, fetched-at timestamp. CoinGecko-backed, cached 60s. $0.001 USDC.

NameTypeReqDescription
chainstringChain slug: base, ethereum, solana, polygon, arbitrum, optimism, bsc, avalanche.
contractstringToken contract address. Required with chain.
symbolstringToken symbol like 'ETH'. Mutually exclusive with chain+contract.

No output schema declared.

No examples provided.