Developer · Local MCP server
Contract Security Scanner
Scans Base L2 contracts for security risks. Risk score 0-100, detects backdoors & proxies.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.fino-oss/contract-scanner- Version
- 1.0.0
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-03-17
- Updated
- 2026-03-17
- Publisher
- fino-oss (GitHub)
- Repository
- github.com/fino-oss/contract-scanner-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @fino314-oss/contract-scanner-mcp | 1.0.0 | stdio |
How to connect Contract Security Scanner
Contract Security Scanner runs locally from a Node.js package published to the npm registry: @fino314-oss/contract-scanner-mcp version 1.0.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @fino314-oss/contract-scanner-mcp@1.0.0. It reads the environment variable BASESCAN_API_KEY (secret); set it in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"contract-scanner": {
"command": "npx",
"args": [
"-y",
"@fino314-oss/contract-scanner-mcp@1.0.0"
],
"env": {
"BASESCAN_API_KEY": "<secret>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| ContinueWithInstall the ContinueWith AI handoff widget from coding agents (Cursor, Claude Code, Codex). | Local · stdio |
| ContinuumShared memory + orchestration for your coding agents. Local-first MCP, vector RAG. | Local · HTTP |
| Contract Ops MCPOne MCP server for the contract-ops suite: all nine local-first CLIs as agent tools. | Local · stdio |
| Contract ScannerContract security scanner — vulnerabilities, risk scores, and calldata decoding. | Local · stdio |
| ContractGateInfer, dry-run, deploy, and inspect ContractGate semantic data contracts. | Local · stdio |
| Contractor License Verification (TradesAPI)Verify contractor licenses: 50 states + DC + 8 cities — status, expiration, disciplinary history. | Remote & Local · HTTP, stdio |
| Control AutoCAD MCP ServerControl AutoCAD with AI: commands, read/edit/write drawing database, AutoLISP, scripts, PDF plots. | Local · stdio |
| Control AutoCAD MCP ServerControl AutoCAD with AI: commands, read/edit/write drawing database, AutoLISP, scripts, PDF plots. | Local · stdio |