AgentekCAUTION
An extensible TypeScript toolkit that simplifies complex EVM blockchain interactions into composable, intent-based tools. Provides a unified, type-safe interface for both on-chain actions and off-chain data services, enabling developers to programmatically execute any blockchain operation across mul
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An extensible TypeScript toolkit for EVM and Solana blockchain interactions. 177 composable tools covering on-chain actions, DeFi protocols, market data, and off-chain services — designed for AI agents, MCP clients, and developers.
Quick Start
Requires Node.js 20.18.1 or newer.
CLI (fastest way to try it):
npx @agentek/cli list # browse up to 177 tools
npx @agentek/cli info getBalance # inspect a specific tool
npx @agentek/cli exec getBalance '{"chainId":1,"address":"vitalik.eth"}'MCP Server (for Claude Desktop, Cursor, etc.):
pnpx @agentek/mcp-server
TypeScript SDK:
pnpm add @agentek/tools
Packages
Requirements
- Node.js >= 18.17.0
- pnpm (for development)
Installation
# Core tools pnpm add @agentek/tools viem zod # Vercel AI SDK integration pnpm add @agentek/ai-sdk @agentek/tools viem zod
Usage
Using with Vercel AI SDK
import { allTools } from '@agentek/tools';
import { AgentekToolkit } from '@agentek/ai-sdk';
import { http } from 'viem';
import { mainnet } from 'viem/chains';
const tools = await allTools({
perplexityApiKey: process.env.PERPLEXITY_API_KEY,
zeroxApiKey: process.env.ZEROX_API_KEY,
});
const toolkit = new AgentekToolkit({
accountOrAddress: '0x...',
chains: [mainnet],
transports: [http()],
tools,
});
// Pass to Vercel AI SDK
const aiTools = toolkit.getTools();Using the toolkit directly
import { createAgentekCli4bb61a21d90fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tools --env COINDESK_API_KEY=${COINDESK_API_KEY} --env COINMARKETCAL_API_KEY=${COINMARKETCAL_API_KEY} --env DRPC_KEY=${DRPC_KEY} --env FIREWORKS_API_KEY=${FIREWORKS_API_KEY} -- npx -y @agentek/[email protected]{
"mcpServers": {
"tools": {
"command": "npx",
"args": [
"-y",
"@agentek/[email protected]"
],
"env": {
"COINDESK_API_KEY": "${COINDESK_API_KEY}",
"COINMARKETCAL_API_KEY": "${COINMARKETCAL_API_KEY}",
"DRPC_KEY": "${DRPC_KEY}",
"FIREWORKS_API_KEY": "${FIREWORKS_API_KEY}"
}
}
}
}Exposed tools (200)
202 read · 21 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ACCOUNT | read | Hex address to use as the sender (read-only) |
ARBITRUM_RPC_URL | read | Arbitrum One JSON-RPC endpoint |
BASE_RPC_URL | read | Base JSON-RPC endpoint |
COINDESK_API_KEY | read | CoinDesk news/data tools |
COINMARKETCAL_API_KEY | read | CoinMarketCal event tools |
ETHEREUM_RPC_URL | read | Ethereum mainnet JSON-RPC endpoint |
FIREWORKS_API_KEY | read | Fireworks AI tools |
JUPITER_API_KEY | read | Jupiter Tokens V2 and Swap V2 tools |
MODE_RPC_URL | read | Mode JSON-RPC endpoint |
OPTIMISM_RPC_URL | read | Optimism JSON-RPC endpoint |
PERPLEXITY_API_KEY | read | Perplexity AI search tools |
PINATA_JWT | read | Pinata IPFS tools |
POLYGON_RPC_URL | read | Polygon JSON-RPC endpoint |
PRIVATE_KEY | read | Hex-encoded private key for signing transactions |
RPC_URLS | read | EVM JSON-RPC endpoints as a comma-separated chainId=url list (e.g. 1=https://...,8453=https://...) |
SEPOLIA_RPC_URL | read | Sepolia testnet JSON-RPC endpoint |
SOLANA_ACCOUNT | read | Base58 Solana address to use as the sender (read-only) |
SOLANA_PRIVATE_KEY | read | Base58 or JSON-array Solana secret key for signing Solana transactions |
SOLANA_RPC_URL | read | Solana JSON-RPC endpoint (defaults to the public mainnet-beta endpoint) |
TALLY_API_KEY | read | Tally governance tools |
X_ACCESS_TOKEN | read | X/Twitter OAuth user access token |
X_ACCESS_TOKEN_SECRET | read | X/Twitter OAuth user access token secret |
X_API_KEY | read | X/Twitter OAuth application key |
X_API_KEY_SECRET | read | X/Twitter OAuth application secret |
X_BEARER_TOKEN | read | X/Twitter read tools (Bearer token) |
ZEROX_API_KEY | read | 0x swap/quote tools |
askPerplexitySearch | read | Search the web using Perplexity AI and get a concise, sourced answer. Good for current events, crypto news, protocol documentation, and general knowledge questions. |
canUnlockSlow | write | Check if a transfer can be unlocked and get info about it |
checkMaliciousAddress | read | Check if an Ethereum address has been flagged as malicious in the ScamSniffer blacklist database. Returns whether the address is known to be associated with scams or exploits. |
checkMaliciousWebsite | read | Check if a website domain has been flagged in the ScamSniffer blacklist as associated with crypto scams, phishing, or malicious activity. |
coinchanGetCoins | read | Fetch a list of Coinchan token IDs between index ranges. Use coinchanGetCoinsCount first to know the valid range. |
coinchanGetCoinsCount | read | Get the total number of Coinchan tokens created on the given chain. |
coinchanGetVestableAmount | read | Get the amount of liquidity currently available to vest for a locked Coinchan token. |
depositWETH | read | Wrap native ETH into WETH (Wrapped ETH) by depositing into the WETH contract. You receive an equal amount of WETH, an ERC20 token. |
discoverLPPositions | read | Read up to three owned Uniswap V3 position NFT IDs at a fixed block. Continue with returned block, blockHash and nextOffset. Failed indices remain unknown; fresh ownership checks are required before acting. Excludes staked positions and other managers. |
discoverTokenPermissions | read | Partial ERC20 approval discovery: one 2000-block window, at most 4096 logs, 64 pairs and 24 live allowance reads. Empty is not proof of no permissions. Read-only; never signs. |
estimateGas | read | Estimate the gas required for a transaction. If chainId is omitted, estimates on all supported chains. |
estimateGasCost | read | Estimate the gas cost for a transaction in both native token and USD |
generateAndPinImage | write | Generate an image from text with Fireworks AI (${model}), then upload |
getAaveReserveData | read | Fetches reserve data for a given asset from Aave including available liquidity, total stable and variable debt, and interest rates. |
getAaveUserData | read | Fetches Aave user data including total collateral, total debt, available borrowing power, current liquidation threshold, LTV, and health factor. |
getAccountPortfolio | read | Given a wallet address, return all token balances the account holds, including coin metadata. |
getActiveApprovals | read | Scan all ERC-20 token approvals for an address on a specific chain. Returns every (token, spender) pair that currently has a non-zero allowance, with the approved amount and token metadata. Similar to revoke.cash. |
getAddressBlocksValidated | read | Get blocks validated (proposed) by a specific validator address. |
getAddressCoinBalanceHistory | read | Get the native coin balance history for an address (every balance change event). |
getAddressCoinBalanceHistoryByDay | read | Get the daily native coin balance snapshots for an address (one data point per day). |
getAddressCounters | read | Get aggregate counters for an address: total transactions, token transfers, gas usage, and validations count. |
getAddressInfo | read | Get detailed information about an address including native coin balance (formatted in ETH with USD value), token count, transaction count, and whether it is a contract. |
getAddressInternalTransactions | read | Get internal (trace-level) transactions for an address, including contract-to-contract calls and ETH transfers within transactions. |
getAddressLogs | read | Get event logs emitted by a specific address (useful for tracking contract events). |
getAddressNFTCollections | read | Get NFTs owned by an address, grouped by collection (ERC721/ERC1155). |
getAddressNFTs | read | Get all NFTs (ERC721/ERC1155) owned by an address. |
getAddressTokenBalances | read | Get all ERC20/ERC721/ERC1155 token balances held by a specific address, with token metadata. |
getAddressTokenTransfers | read | Get ERC20/ERC721/ERC1155 token transfers involving a specific address. |
getAddressTokens | read | Get token balances for an address with filtering and pagination support. Returns token metadata alongside balances. |
getAddressTransactions | read | Get the list of transactions sent from or received by a specific address. |
getAddressWithdrawals | read | Get beacon chain withdrawals received by a specific address. |
getAllowance | read | Gets the ERC20 token allowance between an owner and spender |
getBalance | read | Get the native token (ETH) balance for an address. If chainId is omitted, returns balances across all supported chains. |
getBalanceOf | read | Gets the ERC20 token balance of an address |
getBlock | read | Get information about a block including timestamp, transactions, gas used, etc. Returns the latest block if no block number is specified. |
getBlockInfo | read | Get information about a specific block |
getBlockNumber | read | Get the current (latest) block number. If chainId is omitted, returns block numbers for all supported chains. |
getBlockTransactions | read | Get transactions within a specific block |
getBlockWithdrawals | read | Get withdrawals within a specific block |
getBlockscoutSearch | read | Perform a search query to find blocks, transactions, addresses, or tokens on the blockchain. |
getBtcAddressInfo | read | Fetches information about a Bitcoin address including balance and tx count. |
getBtcBlockTxids | read | Returns a list of transaction IDs in a block, given the block hash. |
getBtcTxDetails | read | Fetches details for a given Bitcoin transaction ID (txid). |
getCanReverseSlowTransfer | write | Check if a transfer can be reversed |
getCode | read | Get the deployed bytecode at an address. Returns empty if the address is an EOA (not a contract). If chainId is omitted, queries all supported chains. |
getCoin | read | Fetch metadata about a ZAMM coin by its ticker symbol, including name, total supply, image, and pool information. |
getCoinBalance | read | Returns the balance of a given address for a specific ERC6909 token ID from the Coins contract. |
getCoinTokenMetadata | read | Returns the name, symbol, and URI of a given ERC6909 token ID from the Coins contract. |
getCryptoPrice | read | Get the current price of a cryptocurrency in USD |
getDecimals | read | Gets the number of decimals of an ERC20 token |
getFearAndGreedIndex | read | Retrieves the current Fear and Greed Index value from Alternative.me API. |
getFeeHistory | read | Get historical gas fee info |
getGasPrice | read | Get the current gas price. If chainId is not specified, returns gas prices for all supported chains. |
getHolders | read | Fetch the list of holders for a given ZAMM coin, ordered by balance descending. |
getHomeTimeline | read | Get the authenticated user |
getLatestBtcBlock | read | Fetches the latest Bitcoin block details. |
getLatestCoindeskNewsTool | read | Get the latest cryptocurrency and blockchain news articles from CoinDesk. |
getLatestTokens | read | Get trending tokens from Dexscreener with market data including USD price, 24h volume, and 24h price change. Filters by the specified chain. |
getMarketEvents | read | Fetches upcoming cryptocurrency market events from CoinMarketCal (e.g. token launches, airdrops, listings, forks). Optionally filter by event category. Returns up to 50 events with dates, coins, proof links, and community votes. |
getNFTMetadata | read | Gets metadata for an NFT token by contract address and token ID |
getName | read | Gets the name of an ERC20 token |
getNaniProposals | read | Get the latest proposals from NANI DAO |
getNativeCoinHolders | read | Get the top native coin (ETH/MATIC/etc.) holders on the specified chain, ranked by balance. |
getPool | read | Fetch the latest state of a ZAMM liquidity pool, including reserves, prices, swap fee, and token metadata. |
getPoolFeeData | read | Gets fee growth globals and protocol fee data for a Uniswap V3 pool. |
getPositionDetails | read | Gets detailed information about a specific Uniswap V3 LP position including token pair, fee tier, tick range, liquidity, and owed fees. |
getQuote | read | Get a price quote for swapping ERC20 or ERC6909 tokens via the zRouter. Returns expected output amount and routing info. Does not execute the swap. |
getSlowGuardianInfo | read | Get guardian information for a user |
getSlowStatus | read | Get information about tokens, unlocked balances, and pending transfers in SLOW |
getSlowTransferApprovalRequired | write | Check if a transfer needs guardian approval |
getSmartContract | read | Retrieve the source code, ABI, and metadata of a verified smart contract by its address. |
getSmartContracts | read | Search for verified smart contracts by name, address, or symbol. Optionally filter by programming language. |
getSolBalance | read | Get the native SOL balance of a Solana address, in both lamports and SOL. |
getSolanaAccountInfo | read | Get on-chain account info for a Solana address: owning program, lamports, data size, and parsed contents when the owning program is one the RPC can decode. |
getSolanaBlock | read | Get a Solana block by slot, or the latest finalized block when no slot is given. Skipped slots are stepped over automatically when searching for the latest. |
getSolanaLatestProfiles | read | Get the latest Solana token profiles published on Dexscreener. A profile is promotional/discovery metadata and does not imply organic interest, liquidity, or safety. |
getSolanaNetworkStatus | read | Get Solana network status from the RPC: health, node version, current slot, block height and epoch progress. |
getSolanaPriorityFees | read | Get recent Solana priority fees in micro-lamports per compute unit, summarised as percentiles. Use |
getSolanaPromotedTokens | read | Get Solana tokens with the most active paid Dexscreener boosts. Results are explicitly paid promotion and must not be treated as trending, organic, or safe. |
getSolanaRecentTokens | read | Get recently listed Solana tokens from Jupiter, ordered by first pool creation time rather than mint creation. New listings are highly risky and require independent on-chain checks. |
getSolanaSwapQuote | write | Get a quote-only exact-input Solana swap order from Jupiter Swap V2. Returns expected raw output and routing/fee data but no signable transaction and does not move funds. |
getSolanaTokenBalance | read | Get a Solana wallet |
getSolanaTokenBalances | read | List every SPL token balance held by a Solana wallet, across both the Token and Token-2022 programs. Zero balances are hidden unless requested. |
getSolanaTokenMarketData | read | Get Jupiter |
getSolanaTokenPairs | read | Get Dexscreener market pairs for a Solana token, sorted by reported USD liquidity. Includes DEX, quote token, price, transactions, volume, liquidity, market cap, and pair age when available. |
getSolanaTokenSupply | read | Get the total circulating supply and decimals of an SPL token mint. Accepts a mint address or a known symbol. |
getSolanaTransaction | read | Get details of a Solana transaction by signature: success, fee, compute units and its decoded instructions. Pass verbose for the full raw RPC response including logs and balance changes. |
getSolanaTransactionHistory | read | List recent transaction signatures for a Solana address, newest first. Paginate with the |
getSolanaTrendingTokens | read | Get Solana tokens ranked by Jupiter for price trend, traded volume, or organic activity over a selected window. This is a discovery signal, not an endorsement or safety verdict. |
getStats | read | Get aggregate blockchain statistics including total blocks, transactions, addresses, and average block time. |
getSwaps | read | Fetch recent swap events for a given ZAMM pool, optionally filtered by block range. |
getSymbol | read | Gets the symbol of an ERC20 token |
getTokenChart | read | Gets historical price chart data for one or more tokens from DeFi Llama |
getTokenHolders | read | Retrieve token holders and their balances for a given token. |
getTokenInfo | read | Fetch metadata for a token contract. |
getTokenMetadata | read | Gets all metadata (name, symbol, decimals, totalSupply) of an ERC20 token |
getTokenTransfers | read | List transfers for a specific token contract with pagination support. |
getTotalSupply | read | Gets the total supply of an ERC20 token |
getTransaction | read | Get details about a transaction including sender, recipient, value, gas, and input data. |
getTransactionCount | read | Get the nonce (number of transactions sent) from an address. If chainId is omitted, returns counts across all supported chains. |
getTransactionInfo | read | Retrieve detailed information for a given transaction hash. |
getTransactionInternalTransactions | read | Retrieve internal transactions that occurred within a given transaction. |
getTransactionLogs | read | Retrieve logs that were generated from a specific transaction. |
getTransactionRawTrace | read | Retrieve raw trace information for a specific transaction. |
getTransactionReceipt | read | Get the receipt of a mined transaction including status, gas used, and logs. |
getTransactionStateChanges | read | Retrieve state changes that occurred during a transaction. |
getTransactionSummary | read | Retrieve a summary of data related to a transaction. |
getTransactionTokenTransfers | read | Retrieve all token transfers that occurred within a given transaction. |
getTransactionsChart | read | Get daily transaction count chart data for the specified chain. Returns time-series data useful for activity trends. |
getTweetById | read | Get a specific tweet by its ID from X/Twitter. Returns the full tweet with author info and engagement metrics. |
getUniV3Pool | read | Gets the current state of a Uniswap V3 pool including sqrtPriceX96, current tick, and whether the pool is unlocked. |
getUserPositions | read | Gets all Uniswap V3 LP positions owned by a user. Defaults to the connected wallet if no user address is provided. |
getWNSBalance | read | Get the number of .wei names owned by an address. |
getWNSContenthash | read | Get the contenthash for a .wei name. |
getWNSExpiration | read | Get the expiration timestamp (unix seconds) for a .wei name. |
getWNSFee | read | Get the registration fee for a .wei name based on label length. |
getWNSOwner | read | Get the owner address of a .wei name. |
getWNSText | read | Get a text record for a .wei name (e.g. |
getWNSTokenURI | read | Get the token URI (metadata) for a .wei name. |
getX402PaymentInfo | read | Check the x402 payment requirements for a URL without making a payment. Returns pricing, accepted networks, and payment details. |
getXUserByUsername | read | Look up an X/Twitter user by their username/handle. Returns their profile info, follower counts, and bio. |
getXUserTweets | read | Get recent tweets from a specific X/Twitter user by their user ID. Use getXUserByUsername first to get the user ID from a handle. |
intent0xSwap | read | Swap tokens on Ethereum, Optimism, Arbitrum, or Base via the 0x/Matcha aggregator. Automatically handles ERC20 approval if needed. Checks balance before swapping. |
intentAaveBorrow | read | Borrows tokens from Aave using your supplied collateral. By default, the variable rate mode (2) is used. |
intentAaveDeposit | read | Deposits tokens into the Aave protocol to supply liquidity and earn interest. |
intentAaveRepay | read | Repays your Aave debt. By default, the variable rate mode (2) is used for repayment. |
intentAaveWithdraw | read | Withdraws tokens from Aave, redeeming your supplied assets (aTokens). |
intentApprove | read | Creates an intent to approve token spending. Supports |
intentApproveSlowTransfer | write | Guardian approves a transfer in SLOW contract |
intentCoinchanAirdrop | read | Airdrop a Coinchan token to multiple addresses in a single transaction. |
intentCoinchanClaimVested | read | Claim vested liquidity for a locked Coinchan token. Only works if vesting was enabled at creation. |
intentCoinchanMake | write | Create a new Coinchan token, mint supplies and add initial liquidity via ZAMM |
intentCoinchanMakeHold | write | Create a new Coinchan token and hold liquidity for the creator instead of locking it. |
intentCoinchanMakeLocked | write | Create a new Coinchan token with locked liquidity and optional vesting schedule. |
intentCollectFees | read | Collects all accumulated trading fees and any tokens from decreased liquidity for a Uniswap V3 LP position. |
intentCreateCoinToken | read | Creates a new ERC6909 token inside the Coins contract with a name, symbol, metadata URI, owner, and initial supply. |
intentDecreaseLiquidity | read | Removes liquidity from a Uniswap V3 LP position. The removed tokens are not automatically collected — use intentCollectFees afterwards to withdraw them. |
intentDepositToSlow | read | Deposit tokens or ETH into SLOW contract with a timelock |
intentGovernorVote | read | Cast a vote on a Governor Bravo governance proposal via Tally. Resolves the governor contract address from the space slug automatically. |
intentGovernorVoteWithReason | read | Cast a vote with an on-chain reason on a Governor Bravo governance proposal via Tally. Resolves the governor contract address from the space slug automatically. |
intentIncreaseLiquidity | read | Adds more liquidity to an existing Uniswap V3 LP position identified by its NFT token ID. |
intentMintPosition | read | Creates a new Uniswap V3 liquidity position by minting an LP NFT. Requires both tokens to be approved for the Position Manager contract beforehand. |
intentProposeNani | write | Create a new governance proposal for NANIDAO |
intentRegisterSubdomainWNS | read | Generate a transaction intent for registering a subdomain under a .wei name. |
intentRegisterWNS | write | Generate transaction intents for registering a .wei name. Returns the commit and reveal transactions needed for the two-step registration process. |
intentRenewWNS | read | Generate a transaction intent for renewing a .wei name. |
intentReverseSlowTransfer | write | Reverse a pending transfer in SLOW contract |
intentRevokeAllApprovals | destructive | Revoke ALL active ERC-20 token approvals for the connected wallet on a specific chain. Scans for approvals first, then creates revoke transactions for each one. Use with caution — this will revoke approvals needed by DeFi protocols you actively use. |
intentRevokeApproval | destructive | Revoke (set to zero) an ERC-20 token approval for a specific spender. This is equivalent to calling approve(spender, 0). |
intentSendTransaction | write | Send an arbitrary transaction to any address. Specify a human-readable ABI signature with function name and arguments to encode calldata automatically, or provide raw hex data. Use this for any contract interaction not covered by other tools. |
intentSetPrimaryWNS | read | Generate a transaction intent for setting a .wei name as the primary name. |
intentSetSlowGuardian | write | Set a guardian for a user in the SLOW contract |
intentSetWNSAddr | read | Generate a transaction intent for setting the address record on a .wei name. |
intentSetWNSContenthash | read | Generate a transaction intent for setting the contenthash on a .wei name. |
intentSetWNSText | read | Generate a transaction intent for setting a text record on a .wei name. |
intentStakeNani | read | Stake NANI tokens to receive xNANI tokens, which can be used for governance |
intentSwap | read | Swap ERC20 or ERC6909 tokens via the zRouter. Automatically handles token approvals, finds the best route (including Matcha/0x aggregation), and executes the swap. |
intentSwapSolana | read | Build an exact-input Jupiter Swap V2 intent for the configured Solana account. Returns the untrusted base64 transaction and request ID for an external wallet to decode, validate, simulate, approve, sign, and execute. Agentek does not sign or submit it. |
intentTransfer | write | Transfer ERC20 tokens or native ETH to an address or ENS name. Supports ENS resolution, automatic decimal handling, and auto-selects the cheapest chain if chainId is omitted. |
intentTransferFrom | write | Transfer ERC20 tokens from another address using transferFrom. Requires prior ERC20 approval from the |
intentTransferPosition | read | Transfers ownership of a Uniswap V3 LP NFT to another address using safeTransferFrom. |
intentTransferSol | write | Transfer native SOL to an address. Signs and submits when a Solana key is configured, otherwise returns an unsigned base64 transaction for you to sign. |
intentTransferSplToken | write | Transfer an SPL token (including Token-2022 mints) to a wallet address, creating the recipient |
intentUnlockSlow | write | Unlock a time-locked transfer in SLOW contract |
intentUnstakeNani | read | Unstake xNANI tokens back to NANI tokens |
intentVoteNaniProposal | read | Vote on an existing NANIDAO governance proposal |
intentWithdrawFromSlow | read | Withdraw unlocked tokens from SLOW contract |
intentWriteContract | write | Write to any smart contract by calling a state-changing function. Builds a transaction intent that can be executed if a wallet is connected. If the ABI is not provided, it will be auto-fetched from Blockscout for verified contracts. |
isAvailableWNS | read | Check if a .wei label is available for registration. |
isExpiredWNS | read | Check if a .wei name is expired. |
lookupENS | read | Looks up the ENS name for an Ethereum address |
mockTool | read | A mock tool for testing |
observeAaveAccount | read | Exact read-only Aave V3 account aggregates at one block. Not a supplied-asset breakdown, executable withdrawal amount or portfolio total. A failed read is unknown, never zero. |
observeLPPosition | read | Read an explicitly requested owned Uniswap V3 NFT and its pool range at one checked block. Range failure stays unknown alongside valid details. No accrued-fee estimate, executable withdrawal amount or signing. Code and pool identity checks do not verify implementation safety. |
Trust audit
CAUTIONgrade C · trust 74/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (19)
description: "Get beacon chain withdrawals received by a specific address.",
token: "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48",
token: "0x0000000000000000000000000000000000000000",
const TOKEN = "0x00000000000007C8612bA63Df8DdEfD9E6077c97";
const owner='0x1111111111111111111111111111111111111111',token='0x2222222222222222222222222222222222222222',other='0x3333333333333333333333333333333333333333';
intentRevokeAllApprovals, intentRevokeApproval
return new Function("document", "NodeFilter", "return " + pageExtractionScript)(document, {SHOW_TEXT:4});import { assertOkResponse } from '../../utils/fetch.js';"http://169.254.169.254/latest/meta-data/",
"http://169.254.169.254/latest/meta-data/",
return new Response(Uint8Array.from(atob(response.body), c => c.charCodeAt(0)), { status: response.status, headers: { 'content-type': 'application/json' } });const bytes = Uint8Array.from(atob(trimmed), (c) => c.charCodeAt(0));
@openrouter/ai-sdk-provider, @types/node, dotenv, tsup, typescript, viem, vitest
ai, @types/node, typescript
@modelcontextprotocol/sdk, node-fetch, @types/node, shx, typescript, vitest
@x402/core, @x402/evm, @x402/fetch, cheerio, twitter-api-v2, wns-utils
| `X_API_KEY` + `X_API_KEY_SECRET` | Twitter/X OAuth (full access) |
Open `.env` in your editor and add the required API keys
# Add to your shell profile (~/.bashrc, ~/.zshrc, etc.)
Gates applied: no_behavioural_pass.
4bb61a21d90ffull audit observations/trust-audit/mcp-server/nanidao__agentek.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4bb61a21d90f | CAUTION | C | 74 | first audit |
Questions
What is the Agentek MCP server?
An extensible TypeScript toolkit that simplifies complex EVM blockchain interactions into composable, intent-based tools. Provides a unified, type-safe interface for both on-chain actions and off-chain data services, enabling developers to programmatically execute any blockchain operation across mul
What tools does Agentek expose?
200 in total: 202 read-only, 21 that write, and 2 that can delete or overwrite (intentRevokeAllApprovals, intentRevokeApproval). Every one is listed on this page with its risk.
Is Agentek safe to connect to an agent?
With care. The audit graded it C (74/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Agentek need?
It reads COINDESK_API_KEY, COINMARKETCAL_API_KEY, DRPC_KEY, FIREWORKS_API_KEY, JUPITER_API_KEY, OPENROUTER_API_KEY, PERPLEXITY_API_KEY, PRIVATE_KEY, SOLANA_PRIVATE_KEY, TALLY_API_KEY, X_ACCESS_TOKEN and X_ACCESS_TOKEN_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Agentek run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @agentek/tools at 0.1.26.
How current is this page?
The grade is for one exact copy of the source (4bb61a21d90f), read on 2026-10-08. The repository is watched and re-audited when it changes.