{"name":"dev.weakspot/weakspot","slug":"weakspot","title":null,"description":"Audit Solidity and Rust smart contracts from your editor. Pays per audit in USDC over x402.","url":"https://mcp.market/server/weakspot","rating":null,"grade":"C","score":58,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":11,"stars":null,"forks":null,"downloads_week":37,"last_push_at":null,"license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":null,"website":"https://weakspot.dev","version":"0.1.1","remotes":[],"packages":[{"registryType":"npm","identifier":"weakspot-mcp","version":"0.1.1","transport":{"type":"stdio"},"environmentVariables":[{"description":"Private key of a funded Base wallet. This server SPENDS REAL USDC from it with no human in the loop — use a fresh wallet funded with only what you are willing to lose, never a personal or deployer key. Only weakspot_audit needs it; the pricing, status and wallet-status tools work without one.","format":"string","isSecret":true,"name":"WEAKSPOT_PRIVATE_KEY"},{"description":"Hard cap in USD on any single audit (default 4, the highest tier). Checked twice: against the tier price, and again against the amount the server actually quotes. An LLM decides when to call the paying tool, so this is the main spend control.","format":"number","default":"4","name":"WEAKSPOT_MAX_USD"},{"description":"Base URL of the Weakspot deployment to use. Defaults to https://weakspot.dev; override to point at staging or a self-hosted instance.","format":"string","default":"https://weakspot.dev","name":"WEAKSPOT_URL"},{"description":"Base RPC endpoint, used only to read the wallet's USDC balance in weakspot_wallet_status. Nothing else needs it.","format":"string","name":"WEAKSPOT_RPC_URL"}]}],"tools":[{"name":"weakspot_audit","description":"Commission a security audit of Solidity or Rust/Anchor source files. THIS SPENDS REAL MONEY (USDC on Base,","write_action":false,"price_micros":0,"input_schema":null},{"name":"weakspot_audit_status","description":"Poll an audit by jobId. Free, no wallet needed. `stage` moves static-analysis -> batches -> verify ->","write_action":false,"price_micros":0,"input_schema":null},{"name":"weakspot_estimate_price","description":"Price a Weakspot audit before committing to it. $1 per 10 files, rounded up, capped at 40 files.","write_action":false,"price_micros":0,"input_schema":null},{"name":"weakspot_wallet_status","description":"Show which wallet this server pays from and its USDC balance. Use when a payment fails, to tell an unfunded","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":58,"grade":"C","scanned_at":"2026-09-20T11:38:28.141Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T11:38:28.071Z","components":{"code":{"score":25,"max":25,"notes":["2 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":3,"max":15,"notes":["no repository listed"]},"identity":{"score":4,"max":10,"notes":["verified namespace with website, no repo"]}},"findings":[{"id":"maint.no-repo","severity":"low","component":"maintenance","title":"No source repository listed"}],"inputs":{"packages":[{"registryType":"npm","identifier":"weakspot-mcp","version":"0.1.1","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":2,"publishedAt":"2026-09-05T11:38:25.881Z","weeklyDownloads":37}],"repo":{"found":false},"icon":{"url":"https://weakspot.dev/favicon.ico","source":"site","width":48,"height":48},"presence":{"stars":null,"forks":null,"downloadsWeek":37,"license":"MIT","lastPushAt":null,"score":11}}}},"grade_history":[],"reviews":[]}