Klever VMSAFE
MCP server for Klever blockchain smart contract development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server tailored for Klever blockchain smart contract development. This server maintains and serves contextual knowledge including code patterns, best practices, and runtime behavior for developers working with the Klever VM SDK.
Features
- 🚀 Triple Mode Operation: Run as HTTP API server, MCP stdio server, or public hosted MCP server
- 💾 Flexible Storage: In-memory or Redis backend support
- 🔍 Smart Context Retrieval: Query by type, tags, or contract type
- 📝 Automatic Pattern Extraction: Parse Klever contracts to extract examples and patterns
- 🎯 Relevance Ranking: Intelligent scoring and ranking of context
- 🔄 Live Updates: Add and update context in real-time
- 🛡️ Type Safety: Full TypeScript with Zod validation
- 📚 Comprehensive Knowledge Base: Pre-loaded with Klever VM patterns, best practices, and examples
- 🔧 Contract Validation: Automatic detection of common issues and anti-patterns
- 🚀 Deployment Scripts: Ready-to-use scripts for contract deployment, upgrade, and querying
Quick Start
Install and run instantly via npx — no cloning required:
npx -y @klever/mcp-server
Or connect to the hosted public server:
claude mcp add -t http klever-vm https://mcp.klever.org/mcp
See MCP Client Integration for client-specific configuration.
Architecture
mcp-klever-vm/ ├── src/ │ ├── api/ # HTTP API routes with validation │ ├── context/ # Context management service layer │ ├── mcp/ # MCP protocol server implementation │ ├── parsers/ # Klever contract parser and validator │ ├── storage/ # Storage backends (memory/Redis) │ │ ├── memory.ts # In-memory storage with size limits │ │ └── redis.ts # Redis storage with optimized queries │ ├── types/ # TypeScript type definitions │ ├── utils/ # Utilities and ingestion tools │ └── knowledge/ # Modular
3d757b50f745OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server -- npx -y @klever/[email protected]
Exposed tools (28)
18 read · 10 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_context | write | Add a new knowledge entry to the Klever VM context store. Use this to save code examples, best practices, security tips, or documentation that can later be retrieved via query_context or search_documentation. Returns the generated ID of the new entry. |
add_feature | write | Add a feature to an existing Klever smart contract |
contractName | read | Name for the smart contract project |
contractType | write | Type of contract to create (e.g. |
create_smart_contract | write | Guided workflow to create a complete Klever smart contract |
debug_error | read | Diagnose and fix a Klever smart contract compiler or runtime error |
deploy_sc | write | Build an unsigned smart contract deployment transaction for the Klever blockchain. Provide either wasmPath (preferred — reads the file server-side) or wasmHex. Returns the unsigned transaction for client-side signing. The MCP server NEVER handles private keys. |
errorMessage | read | The error message or compiler output |
featureName | write | Name or description of the feature to add |
find_similar | read | Find knowledge base entries similar to a given entry by comparing tags and content. Returns related contexts ranked by similarity score. Useful for discovering related patterns, examples, or documentation after finding one relevant entry. |
freeze_klv | read | Build an unsigned Freeze KLV transaction on the Klever blockchain. Freezing KLV provides energy/bandwidth for network operations and enables staking rewards. Returns the unsigned transaction for client-side signing. |
get_account | read | Get full account details for a Klever blockchain address including nonce, balance, frozen balance, allowance, and permissions. Use this when you need comprehensive account state beyond just the balance. |
get_asset_info | read | Get complete properties and configuration for any asset on the Klever blockchain (KLV, KFI, KDA tokens, NFT collections). Returns supply info, permissions (CanMint, CanBurn, etc.), roles, precision, and metadata. Note: string fields like ID, Name, Ticker are base64-encoded in the raw response. |
get_balance | read | Get the KLV or KDA token balance for a Klever blockchain address. Returns the balance in the smallest unit (for KLV: 1 KLV = 1,000,000 units with 6 decimal places). Optionally specify an asset ID to query a specific KDA token balance instead of KLV. |
get_block | read | Get block information from the Klever blockchain by nonce (block number). If no nonce is provided, returns the latest block. Returns hash, timestamp, proposer, number of transactions, and other block metadata. |
get_context | read | Retrieve a single knowledge base entry by its unique ID. Returns the full entry including content, metadata, tags, and related context IDs. Use this after query_context or find_similar to get complete details for a specific entry. |
get_klever_context | read | Retrieve relevant Klever VM development context for a given query. Searches the knowledge base and returns matching entries with code examples, best practices, and documentation. Designed as a drop-in tool for external MCP servers that need Klever context. |
get_knowledge_stats | read | Get summary statistics of the Klever VM knowledge base. Returns total entry count, counts broken down by context type (code_example, best_practice, security_tip, etc.), and a sample entry title for each type. Useful for understanding what knowledge is available before querying. |
get_transaction | read | Get transaction details by hash from the Klever blockchain. Returns sender, receiver, status, block info, contracts, and receipts. Uses the API proxy for indexed data. |
init_klever_project | read | Scaffold a new Klever smart contract project using the SDK. Creates the Rust project structure via |
install_klever_sdk | write | Download and install Klever SDK tools to ~/klever-sdk/. Fetches the latest versions from the Klever CDN, installs binaries, and downloads required VM library dependencies. Supports macOS (arm64/amd64) and Linux. Run check_sdk_status first to see what is already installed. |
invoke_sc | write | Build an unsigned smart contract invocation transaction on the Klever blockchain. Calls a state-changing endpoint on a deployed contract. Returns the unsigned transaction for client-side signing. For read-only calls, use query_sc instead. |
list_validators | read | List active validators on the Klever blockchain network. Returns validator addresses, names, commission rates, delegation info, and staking amounts. |
query_context | read | Search the Klever VM knowledge base for smart contract development context. Returns structured JSON with matching entries, scores, and pagination. Use this for precise filtering by type or tags; use search_documentation for human-readable |
query_sc | write | Execute a read-only query against a Klever smart contract (VM view call). Returns the contract function result as base64-encoded return data. Arguments must be base64-encoded. Use this to read contract state without modifying it. |
review_contract | read | Comprehensive security and quality review of a Klever smart contract |
send_transfer | write | Build an unsigned KLV or KDA token transfer transaction on the Klever blockchain. Returns the unsigned transaction data and hash for client-side signing. The MCP server NEVER handles private keys — signing must be done externally. |
sourceCode | read | The contract source code producing the error |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
id: atob(asset.ID),
name: atob(asset.Name),
ticker: atob(asset.Ticker),
name: atob(asset.Name || ''),
ticker: atob(asset.Ticker || ''),
@modelcontextprotocol/sdk, @redis/json, @types/cors, @types/express, cors, dotenv, express, express-rate-limit
"content": "// Custom KDA token transfer\n#[endpoint]\nfn transfer_kda(&self, token: TokenIdentifier, to: ManagedAddress, amount: BigUint) {\n require!(!to.is_zero(), \"Invalid recipient\");\n r## 2. Option B: Run Locally (Full Access)
For full access including write operations and project initialization tools, run the server locally.
## 2. Option B: Run Locally (Full Access)
For full access including write operations and project initialization tools, run the server locally.
- **No authentication data:** The public server does not require authentication and does not collect credentials, tokens, or account information.
Gates applied: no_behavioural_pass.
3d757b50f745full audit observations/trust-audit/mcp-server/klever-io__klever-vm.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3d757b50f745 | SAFE | B | 89 | first audit |
Questions
What is the Klever VM MCP server?
MCP server for Klever blockchain smart contract development
What tools does Klever VM expose?
28 in total: 18 read-only, 10 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Klever VM safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Klever VM need?
No credential environment variables were found in its source, so it appears to need none.
How does Klever VM run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @klever/mcp-server at 1.3.0.
How current is this page?
The grade is for one exact copy of the source (3d757b50f745), read on 2026-10-08. The repository is watched and re-audited when it changes.