GoatCAUTION
[Archived] Read-only historical snapshot. No issues, PRs, or updates. Use as-is.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!WARNING] [Archived] This repository is a read-only historical snapshot. It is no longer actively maintained, and no issues, pull requests, or updates will be accepted. Use as-is.
Sponsored by
Table of Contents
- 🐐 Overview
- 🚀 Quickstarts
- 📘 Typescript
- 🐍 Python
- 🛠️ Supported tools and frameworks
- Tools
- Chains and wallets
- Agent Frameworks
- 💻 Contributing
- 🤝 Community
GOAT is the largest agentic finance toolkit for AI agents.
Create agents that can:
- Send and receive payments
- Purchase physical and digital goods and services
- Engage in various investment strategies:
- Earn yield
- Bet on prediction markets
- Purchase crypto assets
- Tokenize any asset
- Get financial insights
How it works
GOAT leverages blockchains, cryptocurrencies (such as stablecoins), and wallets as the infrastructure to enable agents to becom
39e038851d18OBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add scripts --env ALCHEMY_API_KEY=${ALCHEMY_API_KEY} --env CROSSMINT_API_KEY=${CROSSMINT_API_KEY} --env CROSSMINT_STAGING_API_KEY=${CROSSMINT_STAGING_API_KEY} --env CROSSMINT_STAGING_API_KEY_CUSTODIAL=${CROSSMINT_STAGING_API_KEY_CUSTODIAL} -- npx -y @goat-sdk/scripts{
"mcpServers": {
"scripts": {
"command": "npx",
"args": [
"-y",
"@goat-sdk/scripts"
],
"env": {
"ALCHEMY_API_KEY": "${ALCHEMY_API_KEY}",
"CROSSMINT_API_KEY": "${CROSSMINT_API_KEY}",
"CROSSMINT_STAGING_API_KEY": "${CROSSMINT_STAGING_API_KEY}",
"CROSSMINT_STAGING_API_KEY_CUSTODIAL": "${CROSSMINT_STAGING_API_KEY_CUSTODIAL}"
}
}
}
}Exposed tools (200)
173 read · 28 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
0x_get_price | read | Get the price of a token |
0x_swap | read | Swap tokens using 0x |
1inch_get_balances | read | Get the balances of a wallet address on a specific chain |
add_liquidity | write | Add liquidity to a Velodrome pool. Gets quote first and ensures sufficient allowance. |
add_liquidity_to_balancer | write | Add liquidity to a Balancer pool |
admin | read | Get the pool admin |
approve_token_evm | read | Approve an amount (specified in base units) of an ERC20 token for a spender |
betswirl_coinToss | read | Flip a coin on BetSwirl. The player is betting that the rolled face will be the one chosen. The user input also contains the bet amount (in ether unit), and the token symbol. |
betswirl_dice | read | Play the BetSwirl Dice. The player is betting that the rolled number will be above this chosen number. The user input also contains the bet amount (in ether unit), and the token symbol. |
betswirl_getBet | read | Get a bet from its hash. |
betswirl_getBets | read | Get bets from BetSwirl. If no player is specified its listing the current connected player bets. If no game is specified its listing all games bets. |
betswirl_roulette | read | Play the BetSwirl Roulette. The player is betting that the rolled number will be one of the chosen numbers. The user input also contains the bet amount (in ether unit), and the token symbol. |
birdeye_get_ohlcv | read | Get OHLCV price of token |
birdeye_get_ohlcv_pair | read | Get OHLCV price of pair |
birdeye_get_token_history_price | read | Get historical price line chart for a token |
birdeye_get_token_price | read | Get price information for a token or multiple tokens (max 100) |
birdeye_get_token_security | read | Get security information of a token |
birdeye_get_trending_tokens | read | Get trending tokens |
birdeye_search_token | read | Search for a token |
borrow_iusd_ironclad | read | Deposit collateral and borrow iUSD against it |
buy_curves_token | read | Buy curves tokens for a specific subject |
buy_token | read | Buy a token such as an NFT, SFT or item tokenized by them, listed on any blockchain |
calculate_max_withdrawable_ironclad | read | Calculate maximum withdrawable amount while maintaining health factor |
cancel_all_polymarket_orders | read | Cancel all orders on Polymarket |
cancel_polymarket_order | write | Cancel an order on Polymarket |
change_votes_mode | destructive | Change existing votes for a veNFT. Must reset existing votes first. |
check_ezeth_balance_in_renzo | read | Check the ezETH balance of an address |
check_transaction_status | write | Check the status of bridge transactions using their order IDs. |
claim_hedgey_rewards | read | Claim staking rewards and Hedgey tokens on Optimism |
claim_merkl_incentives | read | Claim protocol incentives and Merkl rewards for a given address and chain |
close_decrease_position | read | Close or decrease a long or short position on BMX with specified parameters |
close_position_orderly | read | Close a position at Orderly Network |
coingecko_get_coin_categories | read | Get all coin categories |
coingecko_get_coin_data | read | Get detailed coin data by ID (including contract address, market data, community data, developer stats, and more) |
coingecko_get_coin_price_by_contract_address | read | Get coin price by contract address |
coingecko_get_coin_prices | read | Get the prices of specific coins from CoinGecko |
coingecko_get_historical_data | read | Get historical data for a coin by ID |
coingecko_get_ohlc_data | read | Get OHLC chart data for a coin by ID |
coingecko_get_pool_data_by_pool_address | read | Get data for a specific pool by its address |
coingecko_get_token_data_by_token_address | read | Get data for a specific token by its address |
coingecko_get_tokens_info_by_pool_address | read | Get data for all tokens in a specific pool by its address |
coingecko_get_top_gainers_losers | read | Get top gainers and losers for a specific duration |
coingecko_get_trending_coin_categories | read | Get trending coin categories |
coingecko_get_trending_coins | read | Get the list of trending coins from CoinGecko |
coingecko_get_trending_pools | read | Get trending pools for a specific network |
coingecko_get_trending_pools_by_network | read | Get trending pools for a specific network |
coingecko_search_coins | read | Search for coins by keyword |
convert_from_base_units | read | Convert a token amount from its smallest unit (e.g., wei) to human-readable units. |
convert_to_base_units | read | Convert a token amount from human-readable units to its smallest unit (e.g., wei). |
create_bridge_order | write | Create a bridge order to transfer tokens between chains. Use the user requested target asset full address(eg:DBRiDgJAMsM95moTzJs7M9LnkGErpbv9v6CUR1DXnUu5) for dstChainTokenOut do NOT use the ticker(eg:DBR) for dstChainTokenOut EVM to EVM: 1. Set dstChainTokenOutRecipient to recipient |
create_or_update_or_delete_flow | destructive | Create, update, or delete a flow of tokens from sender to receiver |
create_order_on_polymarket | write | Create an order on Polymarket |
create_order_orderly | write | Create an order at Orderly Network |
delegate_voting_power | read | Delegate your voting power to a specified address |
deposit_curves | read | Deposit ERC20 tokens to curves tokens |
deposit_erc20_LST_into_renzo | read | Deposit ERC20 LST tokens into Renzo, approve the ERC20 contract to spend the tokens before calling this |
deposit_eth_into_renzo | read | Deposit ETH into Renzo |
deposit_orderly_evm | read | Deposit USDC into Orderly Network |
dexscreener_get_pairs_by_chain_and_pair | read | Fetch pairs by chainId and pairId from Dexscreener |
dexscreener_get_token_pairs_by_token_address | read | Get all DEX pairs for given token addresses (up to 30) from Dexscreener |
dexscreener_search_pairs | read | Search for DEX pairs matching a query string on Dexscreener |
disperse_erc20_token_to_multiple_addresses | read | Spray or Disperse ERC-20 tokens to multiple recipients in a single transaction |
disperse_eth_to_multiple_addresses | read | Spray or Disperse Ether to multiple recipients in a single transaction |
distribution_from_any_address | read | Check if addresses other than the pool admin can distribute via the pool |
download_data | read | Download data from the Irys network |
dpsn_subscription_tool | read | Subscribe to the given dpsn_topic |
dpsn_unsubscribe_tool | read | Unsubscribe from given dpsn_topic |
enso_route | write | Find the most optimal route between tokenIn and tokenOut and execute it |
execute_bridge_transaction | write | Execute a bridge transaction using tx data from create_bridge_order tool. Always ask for confirmation before proceeding |
fund_irys_account | read | Fund your account on the Irys network |
getLiveTokenPrice | read | Gets the current CHR token price |
getTransactionLink | read | Gets the transaction explorer link |
get_account_balance | read | Get account balance from Etherscan |
get_account_transactions | read | Get account transactions from Etherscan |
get_active_polymarket_orders | read | Get the active orders on Polymarket |
get_address | read | Get the address of the wallet |
get_address_from_ens | read | Get the address from an ENS (Ethereum Name Service, e.g. goat.eth) name |
get_all_gauges_mode | read | Get a list of all available voting gauges on Mode Network. Use veMODE for MODE token gauges or veBPT for Balancer Pool Token gauges. |
get_allowed_symbol_by_network | read | Get allowed symbol by network and token |
get_balance | read | Get the balance of the wallet for the native token or a specific token by passing its address. |
get_balance_holdings_orderly | read | Get balance of user token holdings in Orderly. |
get_block_by_number | read | Get block by number from Etherscan |
get_borrower_address_ironclad | read | Get the Borrower contract address. Use this before approving ic-tokens to deposit into Borrow contract to get iUSD. |
get_bridge_quote | read | Get a quote for bridging tokens between chains. Use get_token_info first to get correct token addresses. |
get_buy_curves_token | read | Get curves token buy price for a specific subject |
get_chain | read | Get the chain of the wallet |
get_claimable_now | read | Get the claimable balance for a member at the current time in the pool |
get_contract_abi | read | Get contract ABI from Etherscan |
get_contract_source_code | read | Get contract source code from Etherscan |
get_curves_balance | read | Get curves token balance for a subject |
get_curves_erc20 | read | Get Curves minted ERC20 token information for a subject |
get_delegated_to | read | Get the address to which the voting power is delegated |
get_event_logs | read | Get event logs from Etherscan |
get_flow_rate | read | Get the current flowrate between a sender and receiver for a specific token |
get_gas_price | read | Get current gas price from Etherscan |
get_gauge_info_mode | read | Get detailed information about a specific gauge |
get_ic_vault_ironclad | read | Get the corresponding ic-vault address for a token. Use this before approving tokens for deposit. |
get_lending_pool_address_ironclad | read | Get the Lending Pool contract address. Use this address to approve tokens for looped deposit. |
get_member_flow_rate | read | Get the flow rate of a member in a Superfluid Pool |
get_member_units | read | Get the units of a member in a Superfluid Pool |
get_net_flow | read | Get the net flow of a specific token for an account |
get_polymarket_events | read | Get the events on Polymarket, including their markets, with optional filters |
get_polymarket_market_info | read | Get the info of a specific market on Polymarket |
get_position | read | View current position details for a specific token |
get_push_balance | write | Get the $PUSH balance of an address |
get_push_token_address | write | Get the address of the PUSH token. |
get_safe_address | read | Get the address of the agent |
get_sell_curves_token | read | Get curves token sell price for a specific subject |
get_spray_supported_tokens | read | Get a list of all tokens supported by ModeSpray |
get_spray_token_info_by_symbol | read | Get Spray token info by symbol |
get_supported_chains | read | Get a list of all chains supported by DeBridge protocol. |
get_token_allowance_evm | read | Get the allowance of an ERC20 token for a spender (returns amount in base units) |
get_token_balance | read | Get token balance from Etherscan |
get_token_info | read | Get token information from a chain. For EVM: use 0x-prefixed address. For Solana: use base58 token address. |
get_token_info_by_symbol | read | Get information about a configured token (like mint address and decimals) by its symbol. |
get_token_info_by_ticker | read | Get information about a configured token (like contract address and decimals) by its ticker symbol. |
get_total_amount_received_by_member | read | Get the total amount received by a member in the pool |
get_total_connected_flow_rate | read | Get the flow rate of the connected members |
get_total_connected_units | read | Get the total number of units of connected members |
get_total_disconnected_flow_rate | read | Get the flow rate of the disconnected members |
get_total_disconnected_units | read | Get the total number of units of disconnected members |
get_total_flow_rate | read | Get the total flow rate of a Superfluid Pool |
get_total_units | read | Get the total units of the pool |
get_transaction_receipt | read | Get transaction receipt from Etherscan |
get_transaction_status | read | Get transaction status from Etherscan |
get_usdc_info_orderly | read | Get the info of the USDC token. |
get_velodrome_token_address | read | Get the address of the Velodrome contract. |
get_voting_power | read | Get the current voting power of an address |
get_voting_power_mode | read | Get the current voting power for a specific veNFT token ID |
ionic_borrow_asset | read | Borrow an asset from an Ionic Protocol pool |
ionic_get_health_metrics | read | Get health metrics for an Ionic Protocol position including LTV and liquidation risk |
ionic_loop_asset | read | Loop (leverage) an asset position in Ionic Protocol |
ionic_supply_asset | read | Supply an asset to an Ionic Protocol pool. Make sure to approve the pool first. |
ionic_swap_collateral | read | Swap one collateral asset for another while maintaining borrow position |
is_member_connected | read | Check if the specified member is connected to a Superfluid Pool |
kim_burn | read | Burn a liquidity position NFT after all tokens have been collected. |
kim_collect | read | Collect all available tokens from a liquidity position. Can be rewards or tokens removed from a liquidity position. So, should be called after decreasing liquidity as well as on its own. |
kim_decrease_liquidity | read | Decrease liquidity in an existing position by specifying a percentage (0-100). Returns a transaction hash on success. Once you get a transaction hash, the decrease is complete - do not call this function again. |
kim_get_swap_router_address | read | Get the address of the swap router |
kim_increase_liquidity | read | Increase liquidity in an existing position. Returns a transaction hash on success. Once you get a transaction hash, the increase is complete - do not call this function again. |
kim_mint_position | read | Mint a new liquidity position in a pool. Returns a transaction hash on success. Once you get a transaction hash, the mint is complete - do not call this function again. |
kim_swap_exact_input_multi_hop | read | Swap an exact amount of input tokens in multiple hops |
kim_swap_exact_output_multi_hop | read | Swap tokens to receive an exact amount of output tokens in multiple hops |
kim_swap_exact_output_single_hop | read | Swap an exact amount of output tokens for a single hop. Have the token amounts in their base units. Don |
lifi_bridge | read | Bridge tokens across chains using the LiFi protocol, call this lifi_bridge tool directly when users want to bridge. Approvals are also handled automatically. |
lifi_get_quote | write | Get a quote for a cross-chain token transfer using the LiFi API |
loop_deposit_ironclad | write | Perform a looped deposit (recursive borrowing) on Ironclad. Send the amount of the asset (in base units) you want to deposit as the initial amount. |
loop_withdraw_ironclad | read | Withdraw a looped position on Ironclad |
lulo_deposit_usdc | read | Deposit USDC into Lulo |
lulo_withdraw_usdc | read | Withdraw USDC from Lulo |
mayan_swap_from_evm | read | Swap from EVM to solana, EVM, sui chain |
mayan_swap_from_solana | read | Swap from solana to solana, EVM, sui chain |
mint_curves_erc20 | write | Set name and symbol for your ERC20 token and mint it |
monitor_loop_position_ironclad | read | Monitor health of a looped position on Ironclad |
monitor_position_ironclad | read | Monitor health of a Trove position |
nansen_get_nft_details | read | Get details for a specific NFT collection or token from Nansen |
nansen_get_nft_trades | read | Get trades for a specific NFT collection or token from Nansen |
nansen_get_token_details | read | Get details for a specific token from Nansen |
nansen_get_token_trades | read | Get trades for a specific token from Nansen |
nansen_get_trading_signal | read | Get trading signals and alerts based on onchain data and patterns |
open_increase_position | read | Open or increase a long or short position on BMX with specified parameters |
opengradient_llm_chat | read | Interact with an LLM using a chat interface through OpenGradient |
opengradient_llm_completion | read | Generate text completions using an LLM through OpenGradient |
opengradient_model_inference | write | Run inference on a machine learning model using OpenGradient |
plunderswap_balance | read | Get the user |
plunderswap_quote | read | Get a quote for how many tokens would be received if the given tokens were swapped for another token. |
plunderswap_swap | read | Exchange the given tokens for another token. |
plunderswap_tokens | read | Get the symbols for the tokens on the current blockchain that can be exchaged using PlunderSwap. |
plunderswap_zil_unwrap | read | Unwrap native ZIL from an ERC-20 wrapper: change WZIL for ZIL. |
plunderswap_zil_wrap | read | Wrap native ZIL in an ERC-20 wrapper: change ZIL for WZIL. |
remove_liquidity | destructive | remove liquidity to a Velodrome pool. |
remove_liquidity_from_balancer | destructive | Remove liquidity from a Balancer pool proportionally |
renzo_get_deposit_address | read | Get the Renzo deposit contract address for the current chain. Call this to get the address to send ETH to, not needed for ERC20 deposits. |
repay_iusd_ironclad | read | Repay all iUSD and close the Trove position |
revoke_token_approval_evm | destructive | Revoke approval for an ERC20 token from a spender (sets allowance to 0) |
rugcheck_generate_token_report_summary | read | Generate a report summary for the given token mint |
rugcheck_get_most_voted_tokens_24h | read | Get tokens with the most votes in the last 24h from RugCheck |
rugcheck_get_recently_detected_tokens | read | Get recently detected tokens from RugCheck |
rugcheck_get_recently_verified_tokens | read | Get recently verified tokens from RugCheck |
rugcheck_get_trending_tokens_24h | read | Get trending tokens in the last 24h from RugCheck |
sell_curves_token | read | Sell curves tokens for a specific subject |
send_APT | write | Send APT to an address. |
send_CHR | write | Send a Chromia asset to an address |
send_ZETRIX | write | Send ZETRIX to an address. |
send_fuel_ETH | write | Send ETH to a Fuel address |
send_sui | write | Send SUI to an address. |
send_token | write | Send native currency or an ERC20 token to a recipient, in base units. |
send_xrd | write | Send xrd to an address. |
sign_message | read | Sign a message with the wallet |
sign_typed_data_evm | read | Sign an EIP-712 typed data structure (EVM) |
super_token | read | Get the SuperToken for the pool |
swap_exact_tokens | read | Swap an exact amount of tokens on Velodrome. |
swap_on_balancer | write | Swap a token on Balancer using Smart Order Router |
synth_api_prediction_best_in_one_day | read | Get the prediction of future possible bitcoin price according to the best miner in synth subnet, by step of 5 minutes over the next 24 hours, times are in UTC ISO format. It returns the all the paths of the prediction, so 100 times 288 points, so it |
synth_api_prediction_best_in_one_day_first_path | read | Get the prediction of future possible bitcoin price according to the best miner in synth subnet on bittensor, by step of 5 minutes over the next 24 hours, times are in UTC ISO format. It returns the first path of the prediction, so 288 points. So it |
transferability_for_units_owner | write | Check if pool members can transfer their units |
uniswap_check_approval | read | Check if the wallet has enough approval for a token and return the transaction to approve the token. The approval must takes place before the swap transaction |
uniswap_get_quote | read | Get the quote for a swap |
uniswap_swap_tokens | read | Swap tokens on Uniswap. Make sure to check the approval with the uniswap_check_approval tool before calling this tool. No need to call uniswap_get_quote before calling this tool. |
update_member_units | write | Update the units for a member in a Superfluid Pool |
Trust audit
CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
name: "beacon",
inputs: [{ indexed: true, internalType: "address", name: "beacon", type: "address" }],name: "beacon",
name: "beacon",
name: "beacon",
api_key="your-crossmint-api-key"
change_votes_mode, create_or_update_or_delete_flow, remove_liquidity, remove_liquidity_from_balancer, revoke_token_approval_evm
.env.template
.env.template
.env.template
.env.template
.env.template
console.log(`i️ Minted Capacity Credit with token id: ${capacityCredit.capacityTokenId}`);console.log(`i️ Minted Capacity Credit with token id: ${capacityCredit.capacityTokenId}`);dev_dependencies += '\ngoat-sdk-wallet-evm = { path = "../../wallets/evm", develop = true }'dev_dependencies += '\ngoat-sdk-wallet-solana = { path = "../../wallets/solana", develop = true }'import { treeShakableConfig } from "../../../tsup.config.base";import { treeShakableConfig } from "../../../tsup.config.base";import { treeShakableConfig } from "../../../tsup.config.base";ENV RPC_PROVIDER_URL=http://127.0.0.1:8545
return "4hXTCkRzt9WyecNzV1XPgCDfGAZzQKNxLXgynz5QDuWWPSAZBZSHptvWRL3BjCvzUXRdKvHL2b7yGrRQcWyaqsaBCncVG7BFggS8w9snUts67BSh3EqKpXLUm5UMHfD7ZBe9GhARjbNQMLJ1QD3Spr6oMTBU6EhdB4RD8CP2xUxr2u3d6fos36PD98XS6oX8
return "AVXo5X7UNzpuOmYzkZ+fqHDGiRLTSMlWlUCcZKzEV5CIKlrdvZa3/2GrJJfPrXgZqJbYDaGiOnP99tI/sRJfiwwBAAEDRQ/n5E5CLbMbHanUG3+iVvBAWZu0WFM6NoB5xfybQ7kNwwgfIhv6odn2qTUu/gOisDtaeCW1qlwW/gx3ccr/4wAAAAAAAAAAAAAA
raw_bytes = bytes.fromhex(serialized_tx[2:])
base64.b64decode(swap_transaction)).decode()
base64.b64decode(transaction)).decode()
Gates applied: no_behavioural_pass.
39e038851d18full audit observations/trust-audit/mcp-server/goat-sdk__goat-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 39e038851d18 | CAUTION | D | 69 | first audit |
Questions
What is the Goat MCP server?
[Archived] Read-only historical snapshot. No issues, PRs, or updates. Use as-is.
What tools does Goat expose?
200 in total: 173 read-only, 28 that write, and 5 that can delete or overwrite (change_votes_mode, create_or_update_or_delete_flow, remove_liquidity, remove_liquidity_from_balancer, revoke_token_approval_evm). Every one is listed on this page with its risk.
Is Goat safe to connect to an agent?
With care. The audit graded it D (69/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Goat need?
It reads ALCHEMY_API_KEY, CROSSMINT_API_KEY, CROSSMINT_STAGING_API_KEY, CROSSMINT_STAGING_API_KEY_CUSTODIAL, CROSSMINT_STAGING_API_KEY_SMART, DPSN_PRIVATE_KEY, EVM_PRIVATE_KEY, EVM_WALLET_PVT_KEY, FUEL_WALLET_PRIVATE_KEY, NEXT_PUBLIC_COINGECKO_API_KEY, OPENAI_API_KEY and ORDERLY_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Goat run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @goat-sdk/scripts.
How current is this page?
The grade is for one exact copy of the source (39e038851d18), read on 2026-09-26. The repository is watched and re-audited when it changes.