Contractscan
FreeNot checkedContractScan MCP Server — multi-engine Solidity vulnerability scanner for LLM agents
About
ContractScan MCP Server — multi-engine Solidity vulnerability scanner for LLM agents
README
Scan Solidity smart contracts for security vulnerabilities in your CI/CD pipeline.
ContractScan uses Slither static analysis with AI-enhanced reporting to detect vulnerabilities in your smart contracts on every push and pull request.
Usage
# Free tier (no API key needed):
- name: Scan smart contracts
uses: h33min/contractscan-action@v1
# With API key (unlimited scans):
- name: Scan smart contracts
uses: h33min/contractscan-action@v1
with:
api-key: ${{ secrets.CONTRACTSCAN_API_KEY }}
Inputs
| Input | Required | Default | Description |
|---|---|---|---|
api-key |
No | — | ContractScan API key. Optional for free tier. Store as a repository secret for paid plans. |
api-url |
No | https://contract-scanner.raccoonworld.xyz |
ContractScan API base URL |
path |
No | **/*.sol |
Glob pattern for Solidity files to scan |
fail-on |
No | Critical |
Minimum severity that fails CI (Critical, High, Medium, Low) |
report-format |
No | markdown |
Output format: markdown or json |
max-files |
No | 300 |
Maximum number of files to scan per run |
Features
- ZIP bundling: Automatically bundles your Solidity source files and dependency directories (
node_modules/,lib/,dependencies/) into a single archive for correct import resolution - Free tier: No API key required. Daily usage limits apply.
- Multi-engine: Slither static analysis + AI vulnerability detection
- Real hack references: Cross-references findings with real DeFi exploit patterns
Outputs
| Output | Description |
|---|---|
findings-count |
Total number of findings |
critical-count |
Number of Critical severity findings |
passed |
true if all scans passed the threshold |
Example Workflow
See example-workflow.yml for a complete example including PR comments.
Get an API Key
Free tier works without an API key. For unlimited scans, visit ContractScan to generate an API key.
License
MIT
Installing Contractscan
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/h33min/contractscan-actionFAQ
Is Contractscan MCP free?
Yes, Contractscan MCP is free — one-click install via Unyly at no cost.
Does Contractscan need an API key?
No, Contractscan runs without API keys or environment variables.
Is Contractscan hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Contractscan in Claude Desktop, Claude Code or Cursor?
Open Contractscan on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzCompare Contractscan with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
