Atlas / MCP servers / blockrunai / BlockRun

BlockRunCAUTION

mcp/blockrunai/blockrun

Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.

Verdict
CAUTION
Grade
C
Trust score
73 /100
Exposed tools
19 19r · 0w · 0d
Transport
stdio
License
MIT
Stars
395
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

BlockRun MCP

Real-time data — and real trades — for Claude and any AI agent.

Agents can pay like agents: sign transactions from a wallet. Teams can pay like teams: get a BlockRun API key at user.blockrun.ai, add credit by card or wire, and let the MCP call api.blockrun.ai. BlockRun MCP gives your agent 19 tools — markets, research, web search, images, video, on-chain data, and live Polymarket trading — paid per call. Two ways to pay, same tools: a self-custody wallet (USDC on Solana or Base, no account needed) — or a BlockRun API key backed by account credit. Sign up at user.blockrun.ai → Read the odds and place the bet, from one self-custody wallet.

[](https://www.npmjs.com/package/@blockrun/mcp) [](https://www.npmjs.com/package/@blockrun/mcp) [![GitHub stars](https://img.shields.io/github/stars/BlockRunAI/blo

Read from source at commit f0624442b13aOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env BASE_CHAIN_WALLET_KEY=${BASE_CHAIN_WALLET_KEY} --env BLOCKRUN_API_KEY=${BLOCKRUN_API_KEY} --env BLOCKRUN_KEYCHAIN=${BLOCKRUN_KEYCHAIN} --env BLOCKRUN_WALLET_KEY=${BLOCKRUN_WALLET_KEY} -- npx -y @blockrun/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@blockrun/[email protected]"
      ],
      "env": {
        "BASE_CHAIN_WALLET_KEY": "${BASE_CHAIN_WALLET_KEY}",
        "BLOCKRUN_API_KEY": "${BLOCKRUN_API_KEY}",
        "BLOCKRUN_KEYCHAIN": "${BLOCKRUN_KEYCHAIN}",
        "BLOCKRUN_WALLET_KEY": "${BLOCKRUN_WALLET_KEY}"
      }
    }
  }
}
03

Exposed tools (19)

19 read · 0 write · 0 destructive.

ToolRiskDescription
blockrun_chatread
blockrun_defiread
blockrun_dexread
blockrun_exaread
blockrun_imageread
blockrun_marketsread
blockrun_modalread
blockrun_modelsread
blockrun_musicread
blockrun_phoneread
blockrun_polymarketread
blockrun_polymarket_readread
blockrun_priceread
blockrun_realfaceread
blockrun_rpcread
blockrun_searchread
blockrun_speechread
blockrun_videoread
blockrun_walletread
04

Trust audit

CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
CHANGELOG.md:1744
that does it; `api_key="not-needed-for-free-models"` appears nowhere in this
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
skills/crypto-data/SKILL.md:101
blockrun_dex({ token: "So11111111111111111111111111111111111111112" })  // one token
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
skills/gentech-blockrun/SKILL.md:159
blockrun_dex({ token: "0x7Fc66500c84A76Ad7e9c93437bFc5Ac33E2DDaE9" })
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/polymarket-setup-verify.test.ts:14
token: "0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB",
LOWInsecure crypto · crypto.weak_random · CWE-327, CWE-338
test/keychain.test.ts:207
const file = path.join(tmp, `strict-normalised-${Math.random().toString(36).slice(2)}.key`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils/polymarket/fund.ts:20
import type { BudgetState } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/image-materialize.test.ts:24
for (const subtype of ["../../x", "png/../../x", "..\\..\\x", "png/../../../etc/passwd"]) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/path-safety.test.ts:9
assert.equal(hasPathTraversal("../../v1/phone/numbers/buy"), true);
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:2193
onward to the gateway; `169.254.169.254.nip.io` reaches cloud metadata the same
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:2504
- **`security(ssrf)` — strip trailing dots so an FQDN can't bypass the deny-list.** `isBlockedFetchHost` matched names exactly or via `endsWith`, but never stripped the root dot the WHATWG URL parser 
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:2530
- **`fix(security)` — the image SSRF deny-list no longer misses IPv4-mapped IPv6 literals.** `isBlockedFetchHost` (added in 0.24.1) only decoded the decimal `::ffff:127.0.0.1` form, but the WHATWG URL
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/image.test.ts:54
await assert.rejects(() => toImageDataUri("http://169.254.169.254/latest/meta-data/"), /refusing to fetch/i);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/ssrf.test.ts:11
"169.254.169.254", "100.64.0.1",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/http.test.ts:18
const resp = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 300);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/image.test.ts:53
await assert.rejects(() => toImageDataUri("http://127.0.0.1:1/x.png"), /refusing to fetch/i);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/image.test.ts:54
await assert.rejects(() => toImageDataUri("http://169.254.169.254/latest/meta-data/"), /refusing to fetch/i);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/image.test.ts:55
await assert.rejects(() => toImageDataUri("http://10.0.0.5/internal.png"), /refusing to fetch/i);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/video-money-path.test.ts:118
{ image_url: "http://169.254.169.254/latest/meta-data/" },
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
test/polymarket-l1-auth.test.ts:24
"0x800be3f91dff8b8258f7c11c202e0fb1fac364efbc95ed0adaa9bec2b9bca58a404f563d83b55d93943459fd0991e9b829ed7f5b40580acd4ea13d106507ff2b1ccfc66be2a3b30464cb3b588324101f660c9a205fa76e8e5f83ee16a528e1c4cb985
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @blockrun/llm, @modelcontextprotocol/sdk, @polymarket/builder-relayer-client, @solana/spl-token, @solana/web3.js, axios, https-proxy-agent
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:1099
read failure — a locked keychain, an ACL denial, a timeout — as "no wallet
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:620
| `BLOCKRUN_KEYCHAIN` | `auto` | Key storage. `auto` — mirror the key into the OS keychain (macOS Keychain / Linux `secret-tool`) and keep the plaintext file, which stays authoritative so other BlockR
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2466
- **`fix(polymarket)` — buy/sell now self-heal a stale CLOB balance cache instead of failing a funded wallet.** The CLOB keeps a server-side balance/allowance cache; `setup`'s warm-up refresh was best
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2489
- **`fix(wallet)` — top-up now mints a real Coinbase Onramp link instead of the dead `buy.blockrun.ai`.** 0.27.0 opened a static `https://buy.blockrun.ai`, which doesn't resolve (NXDOMAIN) — the brows
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills/blockrun/rules/wallet-and-payment.md:100
`POST https://blockrun.ai/api/v1/onramp/token` with `{"address": "0x..."}`. The endpoint is
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha f0624442b13afull audit observations/trust-audit/mcp-server/blockrunai__blockrun.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30f0624442b13aCAUTIONC73first audit
06

Questions

What is the BlockRun MCP server?

Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.

What tools does BlockRun expose?

19 in total: 19 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is BlockRun safe to connect to an agent?

With care. The audit graded it C (73/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does BlockRun need?

It reads BASE_CHAIN_WALLET_KEY, BLOCKRUN_API_KEY, BLOCKRUN_KEYCHAIN, BLOCKRUN_WALLET_KEY, SOLANA_RPC_API_KEY and SOLANA_WALLET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does BlockRun run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @blockrun/mcp at 0.53.1.

How current is this page?

The grade is for one exact copy of the source (f0624442b13a), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement