# io.github.kaditang/agent-wallet-mcp (npm · @kaditang/agent-wallet-mcp)

Non-custodial Solana MCP: compare yields, buy tokenized US stocks (xStocks) & Ondo USDY. You sign.

- Trust score: 65/100 (medium)
- Change this week: +60
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-07

## Components

- npm · `@kaditang/agent-wallet-mcp`: 65/100 (this document), [markdown](https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp.md), [page](https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp)

## Channel facts

- Registry: `npm`
- Package: `@kaditang/agent-wallet-mcp`
- Version: `0.3.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-07.

- **Supply Chain Security**: 90/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known high-severity CVE affects uuid 8.3.2, reached via @solana/web3.js > jayson > uuid. A fixed version is available.
  - No install/post-install scripts declared.
  - 65 of 248 dependencies flagged as unhealthy (2 deprecated).
- **Provenance & Transparency**: 48/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 46 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 68/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2157 tokens (~154/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add kaditang-agent-wallet-mcp -- npx -y @kaditang/agent-wallet-mcp
```

### Codex

```bash
codex mcp add kaditang-agent-wallet-mcp -- npx -y @kaditang/agent-wallet-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "kaditang-agent-wallet-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@kaditang/agent-wallet-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add kaditang-agent-wallet-mcp --command npx --arg -y --arg @kaditang/agent-wallet-mcp
```

### Hermes

```yaml
mcp_servers:
  kaditang-agent-wallet-mcp:
    command: "npx"
    args: ["-y", "@kaditang/agent-wallet-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "kaditang-agent-wallet-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@kaditang/agent-wallet-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-07 (score 65, +4)

- [functional improvement] Security disclosure: fail → pass
- [functional] Dependency health: partial → 0.87

### 2026-08-06 (score 61, +28)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 100

### 2026-08-05 (score 33, 0)

- [security improvement] CVE-2026-69207 no longer affects this package

### 2026-08-04 (score 33, 0)

- [security regression] CVE-2026-69207 affects this package: high

### 2026-08-02 (score 33, +28)

- [security regression] CVE-2026-54285 affects this package: high
- [security regression] CVE-2026-41907 affects this package: high
- [security regression] Provenance: unverified → fail
- [security regression] Known CVEs: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional improvement] License: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional] Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional] Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.
- [functional] Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.
- [functional] Licence: MIT

### 2026-07-31 (score 5, −1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 6, −18)

- [security regression] Malware scan: pass → unverified

### 2026-07-27 (score 24)

First indexed and scored.

## MCP tools (14)

### `compare_yields` (~291 tokens)

Rank USDC lending + tokenized-treasury yields across major chains (Solana, Ethereum, Base, Arbitrum) via DefiLlama, RISK-ADJUSTED. Results are ranked by riskAdjustedApy (not headline APY): each pool's APY is discounted by volatility (sigma), TVL depth, protocol risk, DefiLlama's stability prediction, reward-emission dependence, and IL exposure. Each entry includes riskScore (0-100), riskFactors breakdown, and riskNotes explaining the discount — surface these so the user understands WHY a lower headline APY may be the better pick. Solana protocols (Kamino, MarginFi, Drift, JLP) are executable=true; other chains read-only in V1. Returns BOTH topExecutable (best risk-adjusted pool the user can act on today — recommend this for action) AND topByRiskAdjustedOverall (best across ALL chains, may be read-only in V1 — surface it so the user sees the true market-best, e.g. 'the global best is X% on Ethereum but the best you can execute now is Y% on Solana'). topByRiskAdjusted is a deprecated alias of topExecutable.

Input parameters:

- `amountUsdc` (number): Optional intended deposit size for impact estimation
- `minTvlUsd` (number): Minimum pool TVL filter (default 100000)

### `list_yield_tokens` (~72 tokens)

List supported tokenized treasury / yield-bearing tokens (USDY by Ondo Finance, more coming). These are SEC-registered securities under non-US prospectus, NOT stablecoins — unaffected by GENIUS/CLARITY Acts that ban stablecoin-issuer interest. Each share appreciates as interest accrues.

### `list_xstocks` (~124 tokens)

List supported tokenized US equities (Backed xStocks). 16 tickers across mega-cap-tech (NVDA/AAPL/TSLA/MSFT/GOOGL/AMZN/META), crypto-equity (COIN/MSTR/HOOD/CRCL), broad-market-etf (SPY/QQQ), commodity-etf (GLD), consumer (MCD), ai-defense (PLTR). Includes live Jupiter liquidity + USD price. For non-US holders only.

Input parameters:

- `category` (string): Optional category filter; omit to return all 16

### `quote_tokenized_stock` (~149 tokens)

Live Jupiter quote for buying a Backed xStock with USDC on Solana. Returns expected output, price impact, route, AND a best-entry timing signal (live premium vs the underlying NYSE price, z-scored against a same-market-regime trailing baseline: good-entry / fair / rich-wait). Surface the timing note to the user. READ ONLY — no on-chain action.

Input parameters:

- `amountUsdc` (string, required): USDC to spend, e.g. '5'
- `slippageBps` (number): Slippage tolerance in bps (default 50)
- `ticker` (string, required): US ticker like NVDA, AAPL, TSLA, SPY

### `get_portfolio` (~54 tokens)

Snapshot a Solana wallet: SOL, USDC, every held xStock or yield token priced via Jupiter. Returns total USD value. Read-only.

Input parameters:

- `wallet` (string, required): Solana wallet pubkey (base58)

### `portfolio_health` (~189 tokens)

Stateless 'should I do anything?' check for a wallet — the periodic re-engagement tool. Returns holdings (via get_portfolio), compares held yield to the best RISK-ADJUSTED executable yield available right now, and for each held xStock computes its live premium/discount vs the underlying + an entry/exit timing signal (from accumulated microstructure data). Emits actionable `notes` the AI should surface conversationally: e.g. 'your USDY is still the best risk-adjusted option', 'Kamino now offers more', 'the NVDAx you hold is at a +2% premium — rich if you're thinking of selling', 'you have idle USDC earning nothing'. Read-only, no signing. Run it when a user checks in to give them a reason to act (or reassurance to hold).

Input parameters:

- `wallet` (string, required): Solana wallet pubkey (base58)

### `suggest_rebalance` (~262 tokens)

Discipline tool: given a TARGET allocation, compute the trades that move a wallet toward it. READ-ONLY — it suggests buy/sell USD amounts per asset; the user executes via build_buy_xstock_tx / build_sell_xstock_tx / build_deposit_yield_tx and signs in their own wallet. Allocation base = USDC + held xStocks + held yield tokens (SOL is excluded as gas reserve). Each asset gets current% / target% / drift / deltaUsd (+buy / −sell) / action. Holds assets already within the drift threshold (no churn on noise); flags held assets not in the target (sold to 0). Surface the actions conversationally so the user can approve each trade.

Input parameters:

- `driftThresholdPct` (number): Only suggest a trade if drift exceeds this (default 3%).
- `minTradeUsd` (number): Suppress trades smaller than this USD amount (default 1).
- `targets` (array, required): Target allocation. Each item: { asset, percent }. asset is a ticker (NVDA, SPY), a yield-token symbol (USDY), or 'USDC' for cash. Percents should sum to ~100.
- `wallet` (string, required): Solana wallet pubkey (base58)

### `export_history` (~162 tokens)

Errand tool: export a wallet's tokenized-equity + yield-token TRADE HISTORY (a record for the user's accountant — NOT tax advice / not a tax calculation). Reconstructs USDC↔xStock and USDC↔yield-token swaps from on-chain history; execution price is derived from each tx's own balance deltas (no external price feed). Returns structured trades (date, buy/sell, asset, amount, USDC, price, Solscan link) + a CSV string. Capped at the last N signatures (default 100). Read-only.

Input parameters:

- `limit` (number): How many recent signatures to scan (default 100, max 200)
- `wallet` (string, required): Solana wallet pubkey (base58)

### `check_xstock_safety` (~271 tokens)

Pre-trade SAFETY check for a tokenized US stock — verify it's the REAL token (not a copycat) and OK to buy right now, BEFORE building a buy tx. Works for any issuer (Backed/xStocks, Ondo, Remora) and any Solana mint or EVM address. Pass `ticker` (e.g. NVDA → checks the canonical xStock) OR `token` (a symbol like AAPLx / AAPLon, or a raw mint/0x address) → returns decision (ok/review/avoid), issuer + whether it's verified against the issuer's own registry, and why. Catches copycats/fakes (the #1 risk — agents buy impersonator tokens), depeg, thin liquidity, off-hours mispricing, trading halts. FREE, read-only. STRONGLY recommended before build_buy_xstock_tx, and essential before buying any token NOT in list_xstocks.

Input parameters:

- `ticker` (string): US ticker (e.g. NVDA, AAPL) — checks the canonical Backed xStock for it
- `token` (string): OR a specific token: a symbol (AAPLx/AAPLon/TSLAr) or a raw Solana mint / 0x EVM address

### `track_tx` (~43 tokens)

Check a Solana transaction's on-chain status. Returns confirmation, success/fail, Solscan URL.

Input parameters:

- `signature` (string, required): Solana tx signature (base58)

### `build_deposit_yield_tx` (~124 tokens)

Build (do NOT send) an unsigned Solana transaction that swaps USDC for a yield-bearing tokenized treasury (USDY for non-US users). Returns base64 versioned tx + a one-click sign URL. SERVICE only — user signs in their wallet.

Input parameters:

- `amountUsdc` (string, required): USDC amount to deposit
- `asset` (string, required): Yield token slug
- `slippageBps` (number): Slippage in bps (default 50)
- `wallet` (string, required): User's Solana wallet pubkey (base58)

### `build_buy_xstock_tx` (~126 tokens)

Build (do NOT send) an unsigned Solana transaction that swaps USDC for a Backed xStock via Jupiter. Returns base64 versioned tx + sign URL. SERVICE only — user signs in their wallet.

Input parameters:

- `amountUsdc` (string, required): USDC to spend
- `slippageBps` (number): Slippage in bps (default 50)
- `ticker` (string, required): US ticker e.g. NVDA, AAPL, TSLA, SPY
- `wallet` (string, required): User's Solana wallet pubkey (base58)

### `build_sell_xstock_tx` (~150 tokens)

Build (do NOT send) an unsigned Solana transaction that sells a Backed xStock back to USDC via Jupiter. Returns base64 versioned tx + sign URL. SERVICE only.

Input parameters:

- `amountShares` (string, required): Number of xStock shares to sell, e.g. '0.02' — or 'max' to sell the entire balance (reads exact on-chain amount; avoids the rounding error that breaks selling the displayed balance)
- `slippageBps` (number): Slippage in bps (default 50)
- `ticker` (string, required): Stock ticker to sell, e.g. NVDA
- `wallet` (string, required): User's Solana wallet pubkey

### `build_withdraw_yield_tx` (~140 tokens)

Build (do NOT send) an unsigned Solana transaction that swaps a yield-bearing token (e.g. USDY) back to USDC via Jupiter. Returns base64 versioned tx + sign URL.

Input parameters:

- `amount` (string, required): Amount of the yield token to redeem (token units, e.g. '8.5' USDY) — or 'max' to redeem the entire balance (exact on-chain amount)
- `asset` (string, required): Yield token slug
- `slippageBps` (number): Slippage in bps (default 50)
- `wallet` (string, required): User's Solana wallet pubkey

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp#diagnostics

## Score history

- 2026-08-07: 65
- 2026-08-06: 61
- 2026-08-05: 33
- 2026-08-04: 33
- 2026-08-03: 33
- 2026-08-02: 33
- 2026-08-01: 5
- 2026-07-31: 5
- 2026-07-30: 6
- 2026-07-28: 24
- 2026-07-27: 24

## Links

- npm package: https://www.npmjs.com/package/@kaditang/agent-wallet-mcp
- Socket report: https://socket.dev/npm/package/@kaditang/agent-wallet-mcp
- Repository: https://github.com/kaditang/agent-wallet-mcp
- Website: https://autoyield.org/
- Changelog RSS feed: https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp.json
- HTML version of this page: https://verifymcp.io/servers/kaditang-agent-wallet-mcp/kaditang-agent-wallet-mcp
