Atlas / MCP servers / lazy-dinosaur / Ccxt

CcxtSAFE

mcp/lazy-dinosaur/ccxt

CCXT MCP Server bridges the gap between AI models and cryptocurrency trading by providing a standardized interface through the Model Context Protocol. Created to empower automated trading strategies, this tool allows AI assistants like Claude and GPT to directly interact with over 100 cryptocurrency

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
20 16r · 4w · 0d
Transport
sse · stdio
License
MIT
Stars
95
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@lazydino/ccxt-mcp) [](https://www.npmjs.com/package/@lazydino/ccxt-mcp) [](https://github.com/lazy-dinosaur/ccxt-mcp/stargazers) [](https://opensource.org/licenses/MIT)

한국어 버전(Korean version)

CCXT MCP Server is a server that allows AI models to interact with cryptocurrency exchange APIs through the Model Context Protocol (MCP). This server uses the CCXT library to provide access to more than 100 cryptocurrency exchanges and their trading capabilities.

🚀 Quick Start

# Install the package globally
npm install -g @lazydino/ccxt-mcp

# Run with default settings
ccxt-mcp

# or run without installation
npx @lazydino/ccxt-mcp

Installation and Usage

Global Installation

# Install the package globally
npm install -g @lazydino/ccxt-mcp

Running with npx

You can run it directly without installation:

# Using default settings
npx @lazydino/ccxt-mcp

# Using custom configuration file
npx @lazydino/ccxt-mcp --config /path/to/config.json

View help:

npx @lazydino/ccxt-mcp --help

Configuration

Registering the MCP Server in Claude Desktop

  1. Open Claude Desktop Settings:
  • Go to the Settings menu in the Claude Desktop app
  • Find the "MCP Servers" section
  1. Add a New MCP Server:
  • Click the "Add Server" button
  • Server name: ccxt-mcp
  • Command: npx @lazydino/ccxt-mcp
  • Additional arguments (optional): --config /path/to/config.json
  1. Save and Test the Server:
  2. Save the settings
  3. Test the connecti
Read from source at commit 6846dccc243aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ccxt-mcp -- npx -y @lazydino/[email protected]
claude-desktop
{
  "mcpServers": {
    "ccxt-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@lazydino/[email protected]"
      ]
    }
  }
}
03

Exposed tools (20)

16 read · 4 write · 0 destructive.

ToolRiskDescription
analyzeConsecutiveProfitLossreadAnalyze consecutive winning and losing trades
analyzePeriodicReturnsreadAnalyze daily and monthly returns for a configured account
analyzeTradingPerformancereadAnalyze trading performance for a configured account
calculateWinRatereadCalculate win rate and profit metrics for a configured account
cancelOrderwriteCancel an existing order using a configured account
createOrderwriteCreate a new order using a configured account
fetchBalancereadFetch account balance for a configured account
fetchClosedOrdersreadFetch all closed orders using a configured account
fetchDepositsreadFetch deposit history for a configured account
fetchMarketsreadFetch markets from a cryptocurrency exchange
fetchMyTradesreadFetch personal trade history for a configured account
fetchOHLCVreadFetch OHLCV candlestick data for a symbol on an exchange
fetchOpenOrdersreadFetch all open orders using a configured account
fetchOrderwriteFetch information about a specific order using a configured account
fetchOrderBookwriteFetch order book for a symbol on an exchange
fetchTickerreadFetch ticker information for a symbol on an exchange
fetchTickersreadFetch all tickers from an exchange
fetchTradesreadFetch recent trades for a symbol on an exchange
fetchWithdrawalsreadFetch withdrawal history for a configured account
listAccountsreadList all configured account names
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
ccxt-mcp.nginx:39
proxy_pass http://127.0.0.1:2298;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/main.yml:47
if curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer CI_TEST_TOKEN_123" http://127.0.0.1:2298/healthz | grep -q "200"; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/main.yml:53
NO_AUTH_STATUS=$(curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:2298/healthz)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/main.yml:54
AUTH_STATUS=$(curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer CI_TEST_TOKEN_123" http://127.0.0.1:2298/healthz)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:330
curl -H "Authorization: Bearer YOUR_MCP_TOKEN" http://127.0.0.1:2298/healthz
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, ccxt, zod, zod-to-json-schema, @types/node, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · review.instruction_override · CWE-94, CWE-1427
README.md
always calculate and execute trades using the entire available capital
Why it matters. The README embeds a recommended prompt that directs the AI agent to use the user's entire available capital for trades by default, overriding the user's actual intent and the agent's normal caution about financial actions.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6846dccc243afull audit observations/trust-audit/mcp-server/lazy-dinosaur__ccxt.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076846dccc243aSAFEB89first audit
06

Questions

What is the Ccxt MCP server?

CCXT MCP Server bridges the gap between AI models and cryptocurrency trading by providing a standardized interface through the Model Context Protocol. Created to empower automated trading strategies, this tool allows AI assistants like Claude and GPT to directly interact with over 100 cryptocurrency

What tools does Ccxt expose?

20 in total: 16 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ccxt safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ccxt need?

No credential environment variables were found in its source, so it appears to need none.

How does Ccxt run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @lazydino/ccxt-mcp at 0.4.1.

How current is this page?

The grade is for one exact copy of the source (6846dccc243a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement