Mmcp.market

Chain Signer MCP server

by Kevthetech143·io.github.Kevthetech143/chain-signer·v0.5.31·1 stars

Security suite for AI agents: flag drains, permit-phishing & risky actions before signing.

A88/100grade A
What users say
No reviews yet
Be the first
Safety scan
A88/100

full report

Adoption
Growing

1 stars159 downloads/wk

Reviews

Write one

Nobody has reviewed Chain Signer yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Chain Signer tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan30 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 83 days ago12/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 88/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Chain Signer in Claude Code, Cursor or VS Code

claude mcp add chain-signer -- uvx chain-signer
Add to Cursor

What the publisher says

From the Chain Signer repository's README, as published. We do not edit it. Read it on GitHub

chain-signer

<!-- mcp-name: io.github.Kevthetech143/chain-signer -->

A security suite for AI agents — the seatbelt that catches the dangerous thing BEFORE it happens. Three guards, each callable on its own (and as MCP tools), pairing with any wallet or identity stack:

approval, approve-all, token & NFT transferFrom, proxy upgrade, on-chain permit, on-chain Permit2 approve/permit/transferFrom, approvals hidden in multicall incl. Uniswap router batches and Multicall3 aggregate/aggregate3/aggregate3Value (the batch helper on every EVM chain), approvals wrapped in ERC-4337/smart-account execute/executeBatch, Gnosis Safe multiSend/execTransaction and DSProxy execute, drains routed through the Uniswap Universal Router (Permit2 permit/transferFrom commands incl. sub-plans), 1inch AggregationRouter v5 swap() with redirected output or zero slippage, 0x ExchangeProxy transformERC20() with zero slippage, EIP-7702 account delegation, will-revert).

  • preflight(tx) — decode an unsigned transaction and flag drains before signing (unlimited/large

(ERC-2612, Uniswap Permit2 incl. SignatureTransfer + witness variants, DAI-style permits) and Seaport orders that give assets away — zero consideration, proceeds routed to a third party, or hidden in a BulkOrder tree.

  • inspecttypeddata(td) — catch permit-phishing in an EIP-712 message before the agent signs it
  • check_action(action, policy) — enforce allow/forbid + value/recipient limits before the agent acts.

All three fail safe and are guards, not guarantees. Also bundled: a non-custodial multi-chain wallet (burner, balance, send, swap) — the agent holds its own key and signs locally. No MetaMask, no account, no custody.

from chain_signer import assert_safe
assert_safe(tx)   # raises if the tx is a drain/unlimited-approval/revert — review before signing

Install

pip install chain-signer
export ETHERSCAN_API_KEY=...   # for live balance reads + broadcast (Etherscan v2)

Bitcoin/Solana support is optional: pip install "chain-signer[all]".

Quickstart (10 seconds — offline, no key, no funds, no network)

pip install chain-signer
from chain_signer import preflight
spender = "0x" + "22" * 20
tx = {"to": "0x" + "33" * 20, "data": "0x095ea7b3" + spender[2:].rjust(64, "0") + "f" * 64, "value": 0}
print(preflight(tx))   # ok=False — flags unlimited_approval before you'd ever sign

That's the wedge: the drain gets flagged before you'd ever sign it — no key, no funds, no network.

Bundled wallet (optional — the guards pair with any wallet)

from chain_signer import burner, send_ether
from chain_signer.balance import get_balance

w = burner()                          # fresh throwaway wallet; the agent owns w.private_key
print(w.address, get_balance(w))      # live on-chain balance
send_ether(w, "0x...recipient", 0.001)  # auto nonce+gas, signed locally, broadcast

Full runnable demos are in the repo: examples/agentsafetydemo.py (all three guards stop three real attacks) and examples/quickstart.py (wallet) — clone to run them, or just import as above.

Safety preflight (the wedge)

Before an agent signs, hand the unsigned tx to preflight() — it decodes the calldata and returns the risks, or use assert_safe() to hard-stop on a HIGH flag. Offline, no network, never raises.

from chain_signer import preflight, assert_safe

# an unlimited-allowance approve() to a spender — the classic drain setup
tx = {"to": token, "data": "0x095ea7b3" + spender_padded + "f"*64, "value": 0}

report = preflight(tx)
# {'decoded': {...}, 'ok': False,
#  'risk_flags': [{'code': 'unlimited_approval', 'severity': 'HIGH',

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Chain Signer: common questions

Is Chain Signer MCP server safe?
Yes, by our scan: it is graded A (88/100). Read the Chain Signer safety report
How do I install Chain Signer?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Chain Signer need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Chain Signer maintained?
The last commit was 84 days ago (2026-07-06). The latest release is v0.5.31.
What can I use instead of Chain Signer?
Servers from other publishers that do the same job: Bawbel Scanner MCP server, Safeinstall MCP server and Snyk MCP server. Compare all Chain Signer alternatives.

Alternatives to Chain Signer

Same job from other publishers: the closest match first, then the best rated.

All Chain Signer alternatives →
  • Bawbel Scanner
    Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
    B
  • Safeinstall
    Local-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks
    A
  • Snyk
    Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
    B
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • SSH Manager
    SSH server management for agents, with per-server read-only and allowlist security modes
    B

More from Kevthetech143 →