Atlas / MCP servers / goat-sdk / Goat

GoatCAUTION

mcp/goat-sdk/goat-1

[Archived] Read-only historical snapshot. No issues, PRs, or updates. Use as-is.

Verdict
CAUTION
Grade
D
Trust score
69 /100
Exposed tools
200 173r · 28w · 5d
Transport
stdio
License
MIT
Stars
1,008
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!WARNING] [Archived] This repository is a read-only historical snapshot. It is no longer actively maintained, and no issues, pull requests, or updates will be accepted. Use as-is.

Sponsored by

Table of Contents

  • 🐐 Overview
  • 🚀 Quickstarts
  • 📘 Typescript
  • 🐍 Python
  • 🛠️ Supported tools and frameworks
  • Tools
  • Chains and wallets
  • Agent Frameworks
  • 💻 Contributing
  • 🤝 Community

GOAT is the largest agentic finance toolkit for AI agents.

Create agents that can:

  • Send and receive payments
  • Purchase physical and digital goods and services
  • Engage in various investment strategies:
  • Earn yield
  • Bet on prediction markets
  • Purchase crypto assets
  • Tokenize any asset
  • Get financial insights

How it works

GOAT leverages blockchains, cryptocurrencies (such as stablecoins), and wallets as the infrastructure to enable agents to becom

Read from source at commit 39e038851d18OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add scripts --env ALCHEMY_API_KEY=${ALCHEMY_API_KEY} --env CROSSMINT_API_KEY=${CROSSMINT_API_KEY} --env CROSSMINT_STAGING_API_KEY=${CROSSMINT_STAGING_API_KEY} --env CROSSMINT_STAGING_API_KEY_CUSTODIAL=${CROSSMINT_STAGING_API_KEY_CUSTODIAL} -- npx -y @goat-sdk/scripts
claude-desktop
{
  "mcpServers": {
    "scripts": {
      "command": "npx",
      "args": [
        "-y",
        "@goat-sdk/scripts"
      ],
      "env": {
        "ALCHEMY_API_KEY": "${ALCHEMY_API_KEY}",
        "CROSSMINT_API_KEY": "${CROSSMINT_API_KEY}",
        "CROSSMINT_STAGING_API_KEY": "${CROSSMINT_STAGING_API_KEY}",
        "CROSSMINT_STAGING_API_KEY_CUSTODIAL": "${CROSSMINT_STAGING_API_KEY_CUSTODIAL}"
      }
    }
  }
}
03

Exposed tools (200)

173 read · 28 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
0x_get_pricereadGet the price of a token
0x_swapreadSwap tokens using 0x
1inch_get_balancesreadGet the balances of a wallet address on a specific chain
add_liquiditywriteAdd liquidity to a Velodrome pool. Gets quote first and ensures sufficient allowance.
add_liquidity_to_balancerwriteAdd liquidity to a Balancer pool
adminreadGet the pool admin
approve_token_evmreadApprove an amount (specified in base units) of an ERC20 token for a spender
betswirl_coinTossreadFlip a coin on BetSwirl. The player is betting that the rolled face will be the one chosen. The user input also contains the bet amount (in ether unit), and the token symbol.
betswirl_dicereadPlay the BetSwirl Dice. The player is betting that the rolled number will be above this chosen number. The user input also contains the bet amount (in ether unit), and the token symbol.
betswirl_getBetreadGet a bet from its hash.
betswirl_getBetsreadGet bets from BetSwirl. If no player is specified its listing the current connected player bets. If no game is specified its listing all games bets.
betswirl_roulettereadPlay the BetSwirl Roulette. The player is betting that the rolled number will be one of the chosen numbers. The user input also contains the bet amount (in ether unit), and the token symbol.
birdeye_get_ohlcvreadGet OHLCV price of token
birdeye_get_ohlcv_pairreadGet OHLCV price of pair
birdeye_get_token_history_pricereadGet historical price line chart for a token
birdeye_get_token_pricereadGet price information for a token or multiple tokens (max 100)
birdeye_get_token_securityreadGet security information of a token
birdeye_get_trending_tokensreadGet trending tokens
birdeye_search_tokenreadSearch for a token
borrow_iusd_ironcladreadDeposit collateral and borrow iUSD against it
buy_curves_tokenreadBuy curves tokens for a specific subject
buy_tokenreadBuy a token such as an NFT, SFT or item tokenized by them, listed on any blockchain
calculate_max_withdrawable_ironcladreadCalculate maximum withdrawable amount while maintaining health factor
cancel_all_polymarket_ordersreadCancel all orders on Polymarket
cancel_polymarket_orderwriteCancel an order on Polymarket
change_votes_modedestructiveChange existing votes for a veNFT. Must reset existing votes first.
check_ezeth_balance_in_renzoreadCheck the ezETH balance of an address
check_transaction_statuswriteCheck the status of bridge transactions using their order IDs.
claim_hedgey_rewardsreadClaim staking rewards and Hedgey tokens on Optimism
claim_merkl_incentivesreadClaim protocol incentives and Merkl rewards for a given address and chain
close_decrease_positionreadClose or decrease a long or short position on BMX with specified parameters
close_position_orderlyreadClose a position at Orderly Network
coingecko_get_coin_categoriesreadGet all coin categories
coingecko_get_coin_datareadGet detailed coin data by ID (including contract address, market data, community data, developer stats, and more)
coingecko_get_coin_price_by_contract_addressreadGet coin price by contract address
coingecko_get_coin_pricesreadGet the prices of specific coins from CoinGecko
coingecko_get_historical_datareadGet historical data for a coin by ID
coingecko_get_ohlc_datareadGet OHLC chart data for a coin by ID
coingecko_get_pool_data_by_pool_addressreadGet data for a specific pool by its address
coingecko_get_token_data_by_token_addressreadGet data for a specific token by its address
coingecko_get_tokens_info_by_pool_addressreadGet data for all tokens in a specific pool by its address
coingecko_get_top_gainers_losersreadGet top gainers and losers for a specific duration
coingecko_get_trending_coin_categoriesreadGet trending coin categories
coingecko_get_trending_coinsreadGet the list of trending coins from CoinGecko
coingecko_get_trending_poolsreadGet trending pools for a specific network
coingecko_get_trending_pools_by_networkreadGet trending pools for a specific network
coingecko_search_coinsreadSearch for coins by keyword
convert_from_base_unitsreadConvert a token amount from its smallest unit (e.g., wei) to human-readable units.
convert_to_base_unitsreadConvert a token amount from human-readable units to its smallest unit (e.g., wei).
create_bridge_orderwriteCreate a bridge order to transfer tokens between chains. Use the user requested target asset full address(eg:DBRiDgJAMsM95moTzJs7M9LnkGErpbv9v6CUR1DXnUu5) for dstChainTokenOut do NOT use the ticker(eg:DBR) for dstChainTokenOut EVM to EVM: 1. Set dstChainTokenOutRecipient to recipient
create_or_update_or_delete_flowdestructiveCreate, update, or delete a flow of tokens from sender to receiver
create_order_on_polymarketwriteCreate an order on Polymarket
create_order_orderlywriteCreate an order at Orderly Network
delegate_voting_powerreadDelegate your voting power to a specified address
deposit_curvesreadDeposit ERC20 tokens to curves tokens
deposit_erc20_LST_into_renzoreadDeposit ERC20 LST tokens into Renzo, approve the ERC20 contract to spend the tokens before calling this
deposit_eth_into_renzoreadDeposit ETH into Renzo
deposit_orderly_evmreadDeposit USDC into Orderly Network
dexscreener_get_pairs_by_chain_and_pairreadFetch pairs by chainId and pairId from Dexscreener
dexscreener_get_token_pairs_by_token_addressreadGet all DEX pairs for given token addresses (up to 30) from Dexscreener
dexscreener_search_pairsreadSearch for DEX pairs matching a query string on Dexscreener
disperse_erc20_token_to_multiple_addressesreadSpray or Disperse ERC-20 tokens to multiple recipients in a single transaction
disperse_eth_to_multiple_addressesreadSpray or Disperse Ether to multiple recipients in a single transaction
distribution_from_any_addressreadCheck if addresses other than the pool admin can distribute via the pool
download_datareadDownload data from the Irys network
dpsn_subscription_toolreadSubscribe to the given dpsn_topic
dpsn_unsubscribe_toolreadUnsubscribe from given dpsn_topic
enso_routewriteFind the most optimal route between tokenIn and tokenOut and execute it
execute_bridge_transactionwriteExecute a bridge transaction using tx data from create_bridge_order tool. Always ask for confirmation before proceeding
fund_irys_accountreadFund your account on the Irys network
getLiveTokenPricereadGets the current CHR token price
getTransactionLinkreadGets the transaction explorer link
get_account_balancereadGet account balance from Etherscan
get_account_transactionsreadGet account transactions from Etherscan
get_active_polymarket_ordersreadGet the active orders on Polymarket
get_addressreadGet the address of the wallet
get_address_from_ensreadGet the address from an ENS (Ethereum Name Service, e.g. goat.eth) name
get_all_gauges_modereadGet a list of all available voting gauges on Mode Network. Use veMODE for MODE token gauges or veBPT for Balancer Pool Token gauges.
get_allowed_symbol_by_networkreadGet allowed symbol by network and token
get_balancereadGet the balance of the wallet for the native token or a specific token by passing its address.
get_balance_holdings_orderlyreadGet balance of user token holdings in Orderly.
get_block_by_numberreadGet block by number from Etherscan
get_borrower_address_ironcladreadGet the Borrower contract address. Use this before approving ic-tokens to deposit into Borrow contract to get iUSD.
get_bridge_quotereadGet a quote for bridging tokens between chains. Use get_token_info first to get correct token addresses.
get_buy_curves_tokenreadGet curves token buy price for a specific subject
get_chainreadGet the chain of the wallet
get_claimable_nowreadGet the claimable balance for a member at the current time in the pool
get_contract_abireadGet contract ABI from Etherscan
get_contract_source_codereadGet contract source code from Etherscan
get_curves_balancereadGet curves token balance for a subject
get_curves_erc20readGet Curves minted ERC20 token information for a subject
get_delegated_toreadGet the address to which the voting power is delegated
get_event_logsreadGet event logs from Etherscan
get_flow_ratereadGet the current flowrate between a sender and receiver for a specific token
get_gas_pricereadGet current gas price from Etherscan
get_gauge_info_modereadGet detailed information about a specific gauge
get_ic_vault_ironcladreadGet the corresponding ic-vault address for a token. Use this before approving tokens for deposit.
get_lending_pool_address_ironcladreadGet the Lending Pool contract address. Use this address to approve tokens for looped deposit.
get_member_flow_ratereadGet the flow rate of a member in a Superfluid Pool
get_member_unitsreadGet the units of a member in a Superfluid Pool
get_net_flowreadGet the net flow of a specific token for an account
get_polymarket_eventsreadGet the events on Polymarket, including their markets, with optional filters
get_polymarket_market_inforeadGet the info of a specific market on Polymarket
get_positionreadView current position details for a specific token
get_push_balancewriteGet the $PUSH balance of an address
get_push_token_addresswriteGet the address of the PUSH token.
get_safe_addressreadGet the address of the agent
get_sell_curves_tokenreadGet curves token sell price for a specific subject
get_spray_supported_tokensreadGet a list of all tokens supported by ModeSpray
get_spray_token_info_by_symbolreadGet Spray token info by symbol
get_supported_chainsreadGet a list of all chains supported by DeBridge protocol.
get_token_allowance_evmreadGet the allowance of an ERC20 token for a spender (returns amount in base units)
get_token_balancereadGet token balance from Etherscan
get_token_inforeadGet token information from a chain. For EVM: use 0x-prefixed address. For Solana: use base58 token address.
get_token_info_by_symbolreadGet information about a configured token (like mint address and decimals) by its symbol.
get_token_info_by_tickerreadGet information about a configured token (like contract address and decimals) by its ticker symbol.
get_total_amount_received_by_memberreadGet the total amount received by a member in the pool
get_total_connected_flow_ratereadGet the flow rate of the connected members
get_total_connected_unitsreadGet the total number of units of connected members
get_total_disconnected_flow_ratereadGet the flow rate of the disconnected members
get_total_disconnected_unitsreadGet the total number of units of disconnected members
get_total_flow_ratereadGet the total flow rate of a Superfluid Pool
get_total_unitsreadGet the total units of the pool
get_transaction_receiptreadGet transaction receipt from Etherscan
get_transaction_statusreadGet transaction status from Etherscan
get_usdc_info_orderlyreadGet the info of the USDC token.
get_velodrome_token_addressreadGet the address of the Velodrome contract.
get_voting_powerreadGet the current voting power of an address
get_voting_power_modereadGet the current voting power for a specific veNFT token ID
ionic_borrow_assetreadBorrow an asset from an Ionic Protocol pool
ionic_get_health_metricsreadGet health metrics for an Ionic Protocol position including LTV and liquidation risk
ionic_loop_assetreadLoop (leverage) an asset position in Ionic Protocol
ionic_supply_assetreadSupply an asset to an Ionic Protocol pool. Make sure to approve the pool first.
ionic_swap_collateralreadSwap one collateral asset for another while maintaining borrow position
is_member_connectedreadCheck if the specified member is connected to a Superfluid Pool
kim_burnreadBurn a liquidity position NFT after all tokens have been collected.
kim_collectreadCollect all available tokens from a liquidity position. Can be rewards or tokens removed from a liquidity position. So, should be called after decreasing liquidity as well as on its own.
kim_decrease_liquidityreadDecrease liquidity in an existing position by specifying a percentage (0-100). Returns a transaction hash on success. Once you get a transaction hash, the decrease is complete - do not call this function again.
kim_get_swap_router_addressreadGet the address of the swap router
kim_increase_liquidityreadIncrease liquidity in an existing position. Returns a transaction hash on success. Once you get a transaction hash, the increase is complete - do not call this function again.
kim_mint_positionreadMint a new liquidity position in a pool. Returns a transaction hash on success. Once you get a transaction hash, the mint is complete - do not call this function again.
kim_swap_exact_input_multi_hopreadSwap an exact amount of input tokens in multiple hops
kim_swap_exact_output_multi_hopreadSwap tokens to receive an exact amount of output tokens in multiple hops
kim_swap_exact_output_single_hopreadSwap an exact amount of output tokens for a single hop. Have the token amounts in their base units. Don
lifi_bridgereadBridge tokens across chains using the LiFi protocol, call this lifi_bridge tool directly when users want to bridge. Approvals are also handled automatically.
lifi_get_quotewriteGet a quote for a cross-chain token transfer using the LiFi API
loop_deposit_ironcladwritePerform a looped deposit (recursive borrowing) on Ironclad. Send the amount of the asset (in base units) you want to deposit as the initial amount.
loop_withdraw_ironcladreadWithdraw a looped position on Ironclad
lulo_deposit_usdcreadDeposit USDC into Lulo
lulo_withdraw_usdcreadWithdraw USDC from Lulo
mayan_swap_from_evmreadSwap from EVM to solana, EVM, sui chain
mayan_swap_from_solanareadSwap from solana to solana, EVM, sui chain
mint_curves_erc20writeSet name and symbol for your ERC20 token and mint it
monitor_loop_position_ironcladreadMonitor health of a looped position on Ironclad
monitor_position_ironcladreadMonitor health of a Trove position
nansen_get_nft_detailsreadGet details for a specific NFT collection or token from Nansen
nansen_get_nft_tradesreadGet trades for a specific NFT collection or token from Nansen
nansen_get_token_detailsreadGet details for a specific token from Nansen
nansen_get_token_tradesreadGet trades for a specific token from Nansen
nansen_get_trading_signalreadGet trading signals and alerts based on onchain data and patterns
open_increase_positionreadOpen or increase a long or short position on BMX with specified parameters
opengradient_llm_chatreadInteract with an LLM using a chat interface through OpenGradient
opengradient_llm_completionreadGenerate text completions using an LLM through OpenGradient
opengradient_model_inferencewriteRun inference on a machine learning model using OpenGradient
plunderswap_balancereadGet the user
plunderswap_quotereadGet a quote for how many tokens would be received if the given tokens were swapped for another token.
plunderswap_swapreadExchange the given tokens for another token.
plunderswap_tokensreadGet the symbols for the tokens on the current blockchain that can be exchaged using PlunderSwap.
plunderswap_zil_unwrapreadUnwrap native ZIL from an ERC-20 wrapper: change WZIL for ZIL.
plunderswap_zil_wrapreadWrap native ZIL in an ERC-20 wrapper: change ZIL for WZIL.
remove_liquiditydestructiveremove liquidity to a Velodrome pool.
remove_liquidity_from_balancerdestructiveRemove liquidity from a Balancer pool proportionally
renzo_get_deposit_addressreadGet the Renzo deposit contract address for the current chain. Call this to get the address to send ETH to, not needed for ERC20 deposits.
repay_iusd_ironcladreadRepay all iUSD and close the Trove position
revoke_token_approval_evmdestructiveRevoke approval for an ERC20 token from a spender (sets allowance to 0)
rugcheck_generate_token_report_summaryreadGenerate a report summary for the given token mint
rugcheck_get_most_voted_tokens_24hreadGet tokens with the most votes in the last 24h from RugCheck
rugcheck_get_recently_detected_tokensreadGet recently detected tokens from RugCheck
rugcheck_get_recently_verified_tokensreadGet recently verified tokens from RugCheck
rugcheck_get_trending_tokens_24hreadGet trending tokens in the last 24h from RugCheck
sell_curves_tokenreadSell curves tokens for a specific subject
send_APTwriteSend APT to an address.
send_CHRwriteSend a Chromia asset to an address
send_ZETRIXwriteSend ZETRIX to an address.
send_fuel_ETHwriteSend ETH to a Fuel address
send_suiwriteSend SUI to an address.
send_tokenwriteSend native currency or an ERC20 token to a recipient, in base units.
send_xrdwriteSend xrd to an address.
sign_messagereadSign a message with the wallet
sign_typed_data_evmreadSign an EIP-712 typed data structure (EVM)
super_tokenreadGet the SuperToken for the pool
swap_exact_tokensreadSwap an exact amount of tokens on Velodrome.
swap_on_balancerwriteSwap a token on Balancer using Smart Order Router
synth_api_prediction_best_in_one_dayreadGet the prediction of future possible bitcoin price according to the best miner in synth subnet, by step of 5 minutes over the next 24 hours, times are in UTC ISO format. It returns the all the paths of the prediction, so 100 times 288 points, so it
synth_api_prediction_best_in_one_day_first_pathreadGet the prediction of future possible bitcoin price according to the best miner in synth subnet on bittensor, by step of 5 minutes over the next 24 hours, times are in UTC ISO format. It returns the first path of the prediction, so 288 points. So it
transferability_for_units_ownerwriteCheck if pool members can transfer their units
uniswap_check_approvalreadCheck if the wallet has enough approval for a token and return the transaction to approve the token. The approval must takes place before the swap transaction
uniswap_get_quotereadGet the quote for a swap
uniswap_swap_tokensreadSwap tokens on Uniswap. Make sure to check the approval with the uniswap_check_approval tool before calling this tool. No need to call uniswap_get_quote before calling this tool.
update_member_unitswriteUpdate the units for a member in a Superfluid Pool
04

Trust audit

CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (9 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
typescript/packages/plugins/ionic/src/abis/PoolDirectory.ts:27
name: "beacon",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
typescript/packages/plugins/merkl/src/abi/merkl.abi.ts:26
inputs: [{ indexed: true, internalType: "address", name: "beacon", type: "address" }],
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
typescript/packages/plugins/mode-voting/src/abi/clock.ts:58
name: "beacon",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
typescript/packages/plugins/mode-voting/src/abi/escrowCurve.ts:73
name: "beacon",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
typescript/packages/plugins/mode-voting/src/abi/gaugeVoter.ts:136
name: "beacon",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
python/src/plugins/headless/README.md:23
api_key="your-crossmint-api-key"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
change_votes_mode, create_or_update_or_delete_flow, remove_liquidity, remove_liquidity_from_balancer, revoke_token_approval_evm
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
python/examples/by-framework/ag2/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
python/examples/by-framework/crewai/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
python/examples/by-framework/langchain/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
python/examples/by-framework/openai-agents-sdk/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
python/examples/by-framework/smolagents/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
typescript/examples/by-wallet/lit/src/evm.ts:48
console.log(`i️  Minted Capacity Credit with token id: ${capacityCredit.capacityTokenId}`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
typescript/examples/by-wallet/lit/src/sol.ts:56
console.log(`i️  Minted Capacity Credit with token id: ${capacityCredit.capacityTokenId}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
python/scripts/create_plugin.py:24
dev_dependencies += '\ngoat-sdk-wallet-evm = { path = "../../wallets/evm", develop = true }'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
python/scripts/create_plugin.py:26
dev_dependencies += '\ngoat-sdk-wallet-solana = { path = "../../wallets/solana", develop = true }'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
typescript/packages/adapters/eleven-labs/tsup.config.ts:2
import { treeShakableConfig } from "../../../tsup.config.base";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
typescript/packages/adapters/eliza/tsup.config.ts:2
import { treeShakableConfig } from "../../../tsup.config.base";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
typescript/packages/adapters/langchain/tsup.config.ts:2
import { treeShakableConfig } from "../../../tsup.config.base";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
typescript/examples/by-framework/model-context-protocol/Dockerfile:9
ENV RPC_PROVIDER_URL=http://127.0.0.1:8545
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
python/src/wallets/crossmint/tests/conftest.py:60
return "4hXTCkRzt9WyecNzV1XPgCDfGAZzQKNxLXgynz5QDuWWPSAZBZSHptvWRL3BjCvzUXRdKvHL2b7yGrRQcWyaqsaBCncVG7BFggS8w9snUts67BSh3EqKpXLUm5UMHfD7ZBe9GhARjbNQMLJ1QD3Spr6oMTBU6EhdB4RD8CP2xUxr2u3d6fos36PD98XS6oX8
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
python/src/wallets/crossmint/tests/conftest.py:66
return "AVXo5X7UNzpuOmYzkZ+fqHDGiRLTSMlWlUCcZKzEV5CIKlrdvZa3/2GrJJfPrXgZqJbYDaGiOnP99tI/sRJfiwwBAAEDRQ/n5E5CLbMbHanUG3+iVvBAWZu0WFM6NoB5xfybQ7kNwwgfIhv6odn2qTUu/gOisDtaeCW1qlwW/gx3ccr/4wAAAAAAAAAAAAAA
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
python/src/plugins/headless/goat_plugins/crossmint_headless_checkout/service.py:33
raw_bytes = bytes.fromhex(serialized_tx[2:])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
python/src/plugins/jupiter/goat_plugins/jupiter/service.py:108
base64.b64decode(swap_transaction)).decode()
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
python/src/wallets/crossmint/goat_wallets/crossmint/solana_smart_wallet.py:363
base64.b64decode(transaction)).decode()

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 39e038851d18full audit observations/trust-audit/mcp-server/goat-sdk__goat-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2639e038851d18CAUTIOND69first audit
06

Questions

What is the Goat MCP server?

[Archived] Read-only historical snapshot. No issues, PRs, or updates. Use as-is.

What tools does Goat expose?

200 in total: 173 read-only, 28 that write, and 5 that can delete or overwrite (change_votes_mode, create_or_update_or_delete_flow, remove_liquidity, remove_liquidity_from_balancer, revoke_token_approval_evm). Every one is listed on this page with its risk.

Is Goat safe to connect to an agent?

With care. The audit graded it D (69/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Goat need?

It reads ALCHEMY_API_KEY, CROSSMINT_API_KEY, CROSSMINT_STAGING_API_KEY, CROSSMINT_STAGING_API_KEY_CUSTODIAL, CROSSMINT_STAGING_API_KEY_SMART, DPSN_PRIVATE_KEY, EVM_PRIVATE_KEY, EVM_WALLET_PVT_KEY, FUEL_WALLET_PRIVATE_KEY, NEXT_PUBLIC_COINGECKO_API_KEY, OPENAI_API_KEY and ORDERLY_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Goat run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @goat-sdk/scripts.

How current is this page?

The grade is for one exact copy of the source (39e038851d18), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement