BlockRunCAUTION
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
BlockRun MCP
Real-time data — and real trades — for Claude and any AI agent.
Agents can pay like agents: sign transactions from a wallet. Teams can pay like teams: get a BlockRun API key at user.blockrun.ai, add credit by card or wire, and let the MCP call api.blockrun.ai. BlockRun MCP gives your agent 19 tools — markets, research, web search, images, video, on-chain data, and live Polymarket trading — paid per call. Two ways to pay, same tools: a self-custody wallet (USDC on Solana or Base, no account needed) — or a BlockRun API key backed by account credit. Sign up at user.blockrun.ai → Read the odds and place the bet, from one self-custody wallet.
[](https://www.npmjs.com/package/@blockrun/mcp) [](https://www.npmjs.com/package/@blockrun/mcp) [
19 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
blockrun_chat | read | |
blockrun_defi | read | |
blockrun_dex | read | |
blockrun_exa | read | |
blockrun_image | read | |
blockrun_markets | read | |
blockrun_modal | read | |
blockrun_models | read | |
blockrun_music | read | |
blockrun_phone | read | |
blockrun_polymarket | read | |
blockrun_polymarket_read | read | |
blockrun_price | read | |
blockrun_realface | read | |
blockrun_rpc | read | |
blockrun_search | read | |
blockrun_speech | read | |
blockrun_video | read | |
blockrun_wallet | read |
Trust audit
CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
that does it; `api_key="not-needed-for-free-models"` appears nowhere in this
blockrun_dex({ token: "So11111111111111111111111111111111111111112" }) // one tokenblockrun_dex({ token: "0x7Fc66500c84A76Ad7e9c93437bFc5Ac33E2DDaE9" })token: "0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB",
const file = path.join(tmp, `strict-normalised-${Math.random().toString(36).slice(2)}.key`);import type { BudgetState } from "../../types.js";for (const subtype of ["../../x", "png/../../x", "..\\..\\x", "png/../../../etc/passwd"]) {assert.equal(hasPathTraversal("../../v1/phone/numbers/buy"), true);onward to the gateway; `169.254.169.254.nip.io` reaches cloud metadata the same
- **`security(ssrf)` — strip trailing dots so an FQDN can't bypass the deny-list.** `isBlockedFetchHost` matched names exactly or via `endsWith`, but never stripped the root dot the WHATWG URL parser
- **`fix(security)` — the image SSRF deny-list no longer misses IPv4-mapped IPv6 literals.** `isBlockedFetchHost` (added in 0.24.1) only decoded the decimal `::ffff:127.0.0.1` form, but the WHATWG URL
await assert.rejects(() => toImageDataUri("http://169.254.169.254/latest/meta-data/"), /refusing to fetch/i);"169.254.169.254", "100.64.0.1",
const resp = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 300);await assert.rejects(() => toImageDataUri("http://127.0.0.1:1/x.png"), /refusing to fetch/i);await assert.rejects(() => toImageDataUri("http://169.254.169.254/latest/meta-data/"), /refusing to fetch/i);await assert.rejects(() => toImageDataUri("http://10.0.0.5/internal.png"), /refusing to fetch/i);{ image_url: "http://169.254.169.254/latest/meta-data/" },"0x800be3f91dff8b8258f7c11c202e0fb1fac364efbc95ed0adaa9bec2b9bca58a404f563d83b55d93943459fd0991e9b829ed7f5b40580acd4ea13d106507ff2b1ccfc66be2a3b30464cb3b588324101f660c9a205fa76e8e5f83ee16a528e1c4cb985
@anthropic-ai/sdk, @blockrun/llm, @modelcontextprotocol/sdk, @polymarket/builder-relayer-client, @solana/spl-token, @solana/web3.js, axios, https-proxy-agent
read failure — a locked keychain, an ACL denial, a timeout — as "no wallet
| `BLOCKRUN_KEYCHAIN` | `auto` | Key storage. `auto` — mirror the key into the OS keychain (macOS Keychain / Linux `secret-tool`) and keep the plaintext file, which stays authoritative so other BlockR
- **`fix(polymarket)` — buy/sell now self-heal a stale CLOB balance cache instead of failing a funded wallet.** The CLOB keeps a server-side balance/allowance cache; `setup`'s warm-up refresh was best
- **`fix(wallet)` — top-up now mints a real Coinbase Onramp link instead of the dead `buy.blockrun.ai`.** 0.27.0 opened a static `https://buy.blockrun.ai`, which doesn't resolve (NXDOMAIN) — the brows
`POST https://blockrun.ai/api/v1/onramp/token` with `{"address": "0x..."}`. The endpoint isGates applied: no_behavioural_pass.
f0624442b13afull audit observations/trust-audit/mcp-server/blockrunai__blockrun.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | f0624442b13a | CAUTION | C | 73 | first audit |
Questions
What is the BlockRun MCP server?
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
What tools does BlockRun expose?
19 in total: 19 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is BlockRun safe to connect to an agent?
With care. The audit graded it C (73/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does BlockRun need?
It reads BASE_CHAIN_WALLET_KEY, BLOCKRUN_API_KEY, BLOCKRUN_KEYCHAIN, BLOCKRUN_WALLET_KEY, SOLANA_RPC_API_KEY and SOLANA_WALLET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does BlockRun run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @blockrun/mcp at 0.53.1.
How current is this page?
The grade is for one exact copy of the source (f0624442b13a), read on 2026-09-30. The repository is watched and re-audited when it changes.