CcxtSAFE
CCXT MCP Server bridges the gap between AI models and cryptocurrency trading by providing a standardized interface through the Model Context Protocol. Created to empower automated trading strategies, this tool allows AI assistants like Claude and GPT to directly interact with over 100 cryptocurrency
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@lazydino/ccxt-mcp) [](https://www.npmjs.com/package/@lazydino/ccxt-mcp) [](https://github.com/lazy-dinosaur/ccxt-mcp/stargazers) [](https://opensource.org/licenses/MIT)
한국어 버전(Korean version)
CCXT MCP Server is a server that allows AI models to interact with cryptocurrency exchange APIs through the Model Context Protocol (MCP). This server uses the CCXT library to provide access to more than 100 cryptocurrency exchanges and their trading capabilities.
🚀 Quick Start
# Install the package globally npm install -g @lazydino/ccxt-mcp # Run with default settings ccxt-mcp # or run without installation npx @lazydino/ccxt-mcp
Installation and Usage
Global Installation
# Install the package globally npm install -g @lazydino/ccxt-mcp
Running with npx
You can run it directly without installation:
# Using default settings npx @lazydino/ccxt-mcp # Using custom configuration file npx @lazydino/ccxt-mcp --config /path/to/config.json
View help:
npx @lazydino/ccxt-mcp --help
Configuration
Registering the MCP Server in Claude Desktop
- Open Claude Desktop Settings:
- Go to the Settings menu in the Claude Desktop app
- Find the "MCP Servers" section
- Add a New MCP Server:
- Click the "Add Server" button
- Server name:
ccxt-mcp - Command:
npx @lazydino/ccxt-mcp - Additional arguments (optional):
--config /path/to/config.json
- Save and Test the Server:
- Save the settings
- Test the connecti
6846dccc243aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ccxt-mcp -- npx -y @lazydino/[email protected]
{
"mcpServers": {
"ccxt-mcp": {
"command": "npx",
"args": [
"-y",
"@lazydino/[email protected]"
]
}
}
}Exposed tools (20)
16 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyzeConsecutiveProfitLoss | read | Analyze consecutive winning and losing trades |
analyzePeriodicReturns | read | Analyze daily and monthly returns for a configured account |
analyzeTradingPerformance | read | Analyze trading performance for a configured account |
calculateWinRate | read | Calculate win rate and profit metrics for a configured account |
cancelOrder | write | Cancel an existing order using a configured account |
createOrder | write | Create a new order using a configured account |
fetchBalance | read | Fetch account balance for a configured account |
fetchClosedOrders | read | Fetch all closed orders using a configured account |
fetchDeposits | read | Fetch deposit history for a configured account |
fetchMarkets | read | Fetch markets from a cryptocurrency exchange |
fetchMyTrades | read | Fetch personal trade history for a configured account |
fetchOHLCV | read | Fetch OHLCV candlestick data for a symbol on an exchange |
fetchOpenOrders | read | Fetch all open orders using a configured account |
fetchOrder | write | Fetch information about a specific order using a configured account |
fetchOrderBook | write | Fetch order book for a symbol on an exchange |
fetchTicker | read | Fetch ticker information for a symbol on an exchange |
fetchTickers | read | Fetch all tickers from an exchange |
fetchTrades | read | Fetch recent trades for a symbol on an exchange |
fetchWithdrawals | read | Fetch withdrawal history for a configured account |
listAccounts | read | List all configured account names |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
proxy_pass http://127.0.0.1:2298;
if curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer CI_TEST_TOKEN_123" http://127.0.0.1:2298/healthz | grep -q "200"; thenNO_AUTH_STATUS=$(curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:2298/healthz)AUTH_STATUS=$(curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer CI_TEST_TOKEN_123" http://127.0.0.1:2298/healthz)curl -H "Authorization: Bearer YOUR_MCP_TOKEN" http://127.0.0.1:2298/healthz
@modelcontextprotocol/sdk, ccxt, zod, zod-to-json-schema, @types/node, tsx, typescript
always calculate and execute trades using the entire available capital
Gates applied: no_behavioural_pass.
6846dccc243afull audit observations/trust-audit/mcp-server/lazy-dinosaur__ccxt.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6846dccc243a | SAFE | B | 89 | first audit |
Questions
What is the Ccxt MCP server?
CCXT MCP Server bridges the gap between AI models and cryptocurrency trading by providing a standardized interface through the Model Context Protocol. Created to empower automated trading strategies, this tool allows AI assistants like Claude and GPT to directly interact with over 100 cryptocurrency
What tools does Ccxt expose?
20 in total: 16 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ccxt safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Ccxt need?
No credential environment variables were found in its source, so it appears to need none.
How does Ccxt run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @lazydino/ccxt-mcp at 0.4.1.
How current is this page?
The grade is for one exact copy of the source (6846dccc243a), read on 2026-10-07. The repository is watched and re-audited when it changes.