mcpbeat Sign in

Contract Security Scanner MCP Server

local only

Contract Security Scanner runs on your own machine — the client starts it, so there is no endpoint to ping. 25 installs a week from npm. Last commit 17 Mar 2026.

Scans Base L2 smart contracts for security risks. Risk score 0-100, detects backdoors & proxies.

Installs per day peak 10 · avg 4 · +108% w/w
a month agotoday
25
Installs / week
npm · @fino314-oss/contract-scanner-mcp
0
Stars
0 open issues
17 Mar 2026
Last commit
0 releases in 90 days
License
JavaScript

Nothing serious here today

Today is the operative word: we check Contract Security Scanner every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add contract-scanner -- npx -y @fino314-oss/contract-scanner-mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "contract-scanner": {
      "args": [
        "-y",
        "@fino314-oss/contract-scanner-mcp"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.contract-scanner]
command = "npx"
args = ["-y", "@fino314-oss/contract-scanner-mcp"]
.cursor/mcp.json
{
  "mcpServers": {
    "contract-scanner": {
      "args": [
        "-y",
        "@fino314-oss/contract-scanner-mcp"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "contract-scanner": {
      "args": [
        "-y",
        "@fino314-oss/contract-scanner-mcp"
      ],
      "command": "npx"
    }
  }
}

This one needs environment variables set before it will start: BASESCAN_API_KEY (BaseScan API key for source code analysis (optional — basic bytecode scan works without it)). The author declared them in the registry entry; get the values from the project itself.

Alternatives to Contract Security Scanner

same job, measured the same way
Contract Scanner
by lordbasilaiassistant-sudo

Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding

25 installs/wk local only
Aikido MCP
by bajuzjefe

Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.

45 installs/wk local only
Contract Security Scanner
by mastrophot

MCP smart contract scanner with NEAR-focused security context.

32 installs/wk local only
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

176 installs/wk local only
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

local only
HexScan Token Security
by hexscan

Honeypot detection & token risk scan for ERC-20s. Risk score 0-100, tax, source verification.

2 tools answering
Agent Security Scanner MCP
by sinewaveai

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

728 installs/wk local only
QuantumScan PQC Scanner
by gaiabio12-design

PQC scanner for GitHub repos and smart contracts. Detects quantum-vulnerable ECDSA/RSA.

4 tools answering

Contract Security Scanner — questions

Answers built from our own checks of this server.

Why is there no uptime for Contract Security Scanner?
Contract Security Scanner runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package @fino314-oss/contract-scanner-mcp was installed 25 times last week.
How do I connect Contract Security Scanner?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls @fino314-oss/contract-scanner-mcp straight from npm; nothing to host, nothing to sign up for.
How many people use Contract Security Scanner?
The npm package @fino314-oss/contract-scanner-mcp was installed 25 times in the last week. Week over week that is +108%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is Contract Security Scanner open source?
We cannot say either way: written in JavaScript and 0 stars on GitHub, but we could not determine the licence, and without one the code is not open source by default.