Atlas / MCP servers / nanidao / Agentek

AgentekCAUTION

mcp/nanidao/agentek

An extensible TypeScript toolkit that simplifies complex EVM blockchain interactions into composable, intent-based tools. Provides a unified, type-safe interface for both on-chain actions and off-chain data services, enabling developers to programmatically execute any blockchain operation across mul

Verdict
CAUTION
Grade
C
Trust score
74 /100
Exposed tools
200 202r · 21w · 2d
Transport
stdio
License
AGPL-3.0
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An extensible TypeScript toolkit for EVM and Solana blockchain interactions. 177 composable tools covering on-chain actions, DeFi protocols, market data, and off-chain services — designed for AI agents, MCP clients, and developers.

Quick Start

Requires Node.js 20.18.1 or newer.

CLI (fastest way to try it):

npx @agentek/cli list          # browse up to 177 tools
npx @agentek/cli info getBalance  # inspect a specific tool
npx @agentek/cli exec getBalance '{"chainId":1,"address":"vitalik.eth"}'

MCP Server (for Claude Desktop, Cursor, etc.):

pnpx @agentek/mcp-server

TypeScript SDK:

pnpm add @agentek/tools

Packages

Requirements

  • Node.js >= 18.17.0
  • pnpm (for development)

Installation

# Core tools
pnpm add @agentek/tools viem zod

# Vercel AI SDK integration
pnpm add @agentek/ai-sdk @agentek/tools viem zod

Usage

Using with Vercel AI SDK

import { allTools } from '@agentek/tools';
import { AgentekToolkit } from '@agentek/ai-sdk';
import { http } from 'viem';
import { mainnet } from 'viem/chains';

const tools = await allTools({
perplexityApiKey: process.env.PERPLEXITY_API_KEY,
zeroxApiKey: process.env.ZEROX_API_KEY,
});

const toolkit = new AgentekToolkit({
accountOrAddress: '0x...',
chains: [mainnet],
transports: [http()],
tools,
});

// Pass to Vercel AI SDK
const aiTools = toolkit.getTools();

Using the toolkit directly

import { createAgentekCli
Read from source at commit 4bb61a21d90fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tools --env COINDESK_API_KEY=${COINDESK_API_KEY} --env COINMARKETCAL_API_KEY=${COINMARKETCAL_API_KEY} --env DRPC_KEY=${DRPC_KEY} --env FIREWORKS_API_KEY=${FIREWORKS_API_KEY} -- npx -y @agentek/[email protected]
claude-desktop
{
  "mcpServers": {
    "tools": {
      "command": "npx",
      "args": [
        "-y",
        "@agentek/[email protected]"
      ],
      "env": {
        "COINDESK_API_KEY": "${COINDESK_API_KEY}",
        "COINMARKETCAL_API_KEY": "${COINMARKETCAL_API_KEY}",
        "DRPC_KEY": "${DRPC_KEY}",
        "FIREWORKS_API_KEY": "${FIREWORKS_API_KEY}"
      }
    }
  }
}
03

Exposed tools (200)

202 read · 21 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ACCOUNTreadHex address to use as the sender (read-only)
ARBITRUM_RPC_URLreadArbitrum One JSON-RPC endpoint
BASE_RPC_URLreadBase JSON-RPC endpoint
COINDESK_API_KEYreadCoinDesk news/data tools
COINMARKETCAL_API_KEYreadCoinMarketCal event tools
ETHEREUM_RPC_URLreadEthereum mainnet JSON-RPC endpoint
FIREWORKS_API_KEYreadFireworks AI tools
JUPITER_API_KEYreadJupiter Tokens V2 and Swap V2 tools
MODE_RPC_URLreadMode JSON-RPC endpoint
OPTIMISM_RPC_URLreadOptimism JSON-RPC endpoint
PERPLEXITY_API_KEYreadPerplexity AI search tools
PINATA_JWTreadPinata IPFS tools
POLYGON_RPC_URLreadPolygon JSON-RPC endpoint
PRIVATE_KEYreadHex-encoded private key for signing transactions
RPC_URLSreadEVM JSON-RPC endpoints as a comma-separated chainId=url list (e.g. 1=https://...,8453=https://...)
SEPOLIA_RPC_URLreadSepolia testnet JSON-RPC endpoint
SOLANA_ACCOUNTreadBase58 Solana address to use as the sender (read-only)
SOLANA_PRIVATE_KEYreadBase58 or JSON-array Solana secret key for signing Solana transactions
SOLANA_RPC_URLreadSolana JSON-RPC endpoint (defaults to the public mainnet-beta endpoint)
TALLY_API_KEYreadTally governance tools
X_ACCESS_TOKENreadX/Twitter OAuth user access token
X_ACCESS_TOKEN_SECRETreadX/Twitter OAuth user access token secret
X_API_KEYreadX/Twitter OAuth application key
X_API_KEY_SECRETreadX/Twitter OAuth application secret
X_BEARER_TOKENreadX/Twitter read tools (Bearer token)
ZEROX_API_KEYread0x swap/quote tools
askPerplexitySearchreadSearch the web using Perplexity AI and get a concise, sourced answer. Good for current events, crypto news, protocol documentation, and general knowledge questions.
canUnlockSlowwriteCheck if a transfer can be unlocked and get info about it
checkMaliciousAddressreadCheck if an Ethereum address has been flagged as malicious in the ScamSniffer blacklist database. Returns whether the address is known to be associated with scams or exploits.
checkMaliciousWebsitereadCheck if a website domain has been flagged in the ScamSniffer blacklist as associated with crypto scams, phishing, or malicious activity.
coinchanGetCoinsreadFetch a list of Coinchan token IDs between index ranges. Use coinchanGetCoinsCount first to know the valid range.
coinchanGetCoinsCountreadGet the total number of Coinchan tokens created on the given chain.
coinchanGetVestableAmountreadGet the amount of liquidity currently available to vest for a locked Coinchan token.
depositWETHreadWrap native ETH into WETH (Wrapped ETH) by depositing into the WETH contract. You receive an equal amount of WETH, an ERC20 token.
discoverLPPositionsreadRead up to three owned Uniswap V3 position NFT IDs at a fixed block. Continue with returned block, blockHash and nextOffset. Failed indices remain unknown; fresh ownership checks are required before acting. Excludes staked positions and other managers.
discoverTokenPermissionsreadPartial ERC20 approval discovery: one 2000-block window, at most 4096 logs, 64 pairs and 24 live allowance reads. Empty is not proof of no permissions. Read-only; never signs.
estimateGasreadEstimate the gas required for a transaction. If chainId is omitted, estimates on all supported chains.
estimateGasCostreadEstimate the gas cost for a transaction in both native token and USD
generateAndPinImagewriteGenerate an image from text with Fireworks AI (${model}), then upload
getAaveReserveDatareadFetches reserve data for a given asset from Aave including available liquidity, total stable and variable debt, and interest rates.
getAaveUserDatareadFetches Aave user data including total collateral, total debt, available borrowing power, current liquidation threshold, LTV, and health factor.
getAccountPortfolioreadGiven a wallet address, return all token balances the account holds, including coin metadata.
getActiveApprovalsreadScan all ERC-20 token approvals for an address on a specific chain. Returns every (token, spender) pair that currently has a non-zero allowance, with the approved amount and token metadata. Similar to revoke.cash.
getAddressBlocksValidatedreadGet blocks validated (proposed) by a specific validator address.
getAddressCoinBalanceHistoryreadGet the native coin balance history for an address (every balance change event).
getAddressCoinBalanceHistoryByDayreadGet the daily native coin balance snapshots for an address (one data point per day).
getAddressCountersreadGet aggregate counters for an address: total transactions, token transfers, gas usage, and validations count.
getAddressInforeadGet detailed information about an address including native coin balance (formatted in ETH with USD value), token count, transaction count, and whether it is a contract.
getAddressInternalTransactionsreadGet internal (trace-level) transactions for an address, including contract-to-contract calls and ETH transfers within transactions.
getAddressLogsreadGet event logs emitted by a specific address (useful for tracking contract events).
getAddressNFTCollectionsreadGet NFTs owned by an address, grouped by collection (ERC721/ERC1155).
getAddressNFTsreadGet all NFTs (ERC721/ERC1155) owned by an address.
getAddressTokenBalancesreadGet all ERC20/ERC721/ERC1155 token balances held by a specific address, with token metadata.
getAddressTokenTransfersreadGet ERC20/ERC721/ERC1155 token transfers involving a specific address.
getAddressTokensreadGet token balances for an address with filtering and pagination support. Returns token metadata alongside balances.
getAddressTransactionsreadGet the list of transactions sent from or received by a specific address.
getAddressWithdrawalsreadGet beacon chain withdrawals received by a specific address.
getAllowancereadGets the ERC20 token allowance between an owner and spender
getBalancereadGet the native token (ETH) balance for an address. If chainId is omitted, returns balances across all supported chains.
getBalanceOfreadGets the ERC20 token balance of an address
getBlockreadGet information about a block including timestamp, transactions, gas used, etc. Returns the latest block if no block number is specified.
getBlockInforeadGet information about a specific block
getBlockNumberreadGet the current (latest) block number. If chainId is omitted, returns block numbers for all supported chains.
getBlockTransactionsreadGet transactions within a specific block
getBlockWithdrawalsreadGet withdrawals within a specific block
getBlockscoutSearchreadPerform a search query to find blocks, transactions, addresses, or tokens on the blockchain.
getBtcAddressInforeadFetches information about a Bitcoin address including balance and tx count.
getBtcBlockTxidsreadReturns a list of transaction IDs in a block, given the block hash.
getBtcTxDetailsreadFetches details for a given Bitcoin transaction ID (txid).
getCanReverseSlowTransferwriteCheck if a transfer can be reversed
getCodereadGet the deployed bytecode at an address. Returns empty if the address is an EOA (not a contract). If chainId is omitted, queries all supported chains.
getCoinreadFetch metadata about a ZAMM coin by its ticker symbol, including name, total supply, image, and pool information.
getCoinBalancereadReturns the balance of a given address for a specific ERC6909 token ID from the Coins contract.
getCoinTokenMetadatareadReturns the name, symbol, and URI of a given ERC6909 token ID from the Coins contract.
getCryptoPricereadGet the current price of a cryptocurrency in USD
getDecimalsreadGets the number of decimals of an ERC20 token
getFearAndGreedIndexreadRetrieves the current Fear and Greed Index value from Alternative.me API.
getFeeHistoryreadGet historical gas fee info
getGasPricereadGet the current gas price. If chainId is not specified, returns gas prices for all supported chains.
getHoldersreadFetch the list of holders for a given ZAMM coin, ordered by balance descending.
getHomeTimelinereadGet the authenticated user
getLatestBtcBlockreadFetches the latest Bitcoin block details.
getLatestCoindeskNewsToolreadGet the latest cryptocurrency and blockchain news articles from CoinDesk.
getLatestTokensreadGet trending tokens from Dexscreener with market data including USD price, 24h volume, and 24h price change. Filters by the specified chain.
getMarketEventsreadFetches upcoming cryptocurrency market events from CoinMarketCal (e.g. token launches, airdrops, listings, forks). Optionally filter by event category. Returns up to 50 events with dates, coins, proof links, and community votes.
getNFTMetadatareadGets metadata for an NFT token by contract address and token ID
getNamereadGets the name of an ERC20 token
getNaniProposalsreadGet the latest proposals from NANI DAO
getNativeCoinHoldersreadGet the top native coin (ETH/MATIC/etc.) holders on the specified chain, ranked by balance.
getPoolreadFetch the latest state of a ZAMM liquidity pool, including reserves, prices, swap fee, and token metadata.
getPoolFeeDatareadGets fee growth globals and protocol fee data for a Uniswap V3 pool.
getPositionDetailsreadGets detailed information about a specific Uniswap V3 LP position including token pair, fee tier, tick range, liquidity, and owed fees.
getQuotereadGet a price quote for swapping ERC20 or ERC6909 tokens via the zRouter. Returns expected output amount and routing info. Does not execute the swap.
getSlowGuardianInforeadGet guardian information for a user
getSlowStatusreadGet information about tokens, unlocked balances, and pending transfers in SLOW
getSlowTransferApprovalRequiredwriteCheck if a transfer needs guardian approval
getSmartContractreadRetrieve the source code, ABI, and metadata of a verified smart contract by its address.
getSmartContractsreadSearch for verified smart contracts by name, address, or symbol. Optionally filter by programming language.
getSolBalancereadGet the native SOL balance of a Solana address, in both lamports and SOL.
getSolanaAccountInforeadGet on-chain account info for a Solana address: owning program, lamports, data size, and parsed contents when the owning program is one the RPC can decode.
getSolanaBlockreadGet a Solana block by slot, or the latest finalized block when no slot is given. Skipped slots are stepped over automatically when searching for the latest.
getSolanaLatestProfilesreadGet the latest Solana token profiles published on Dexscreener. A profile is promotional/discovery metadata and does not imply organic interest, liquidity, or safety.
getSolanaNetworkStatusreadGet Solana network status from the RPC: health, node version, current slot, block height and epoch progress.
getSolanaPriorityFeesreadGet recent Solana priority fees in micro-lamports per compute unit, summarised as percentiles. Use
getSolanaPromotedTokensreadGet Solana tokens with the most active paid Dexscreener boosts. Results are explicitly paid promotion and must not be treated as trending, organic, or safe.
getSolanaRecentTokensreadGet recently listed Solana tokens from Jupiter, ordered by first pool creation time rather than mint creation. New listings are highly risky and require independent on-chain checks.
getSolanaSwapQuotewriteGet a quote-only exact-input Solana swap order from Jupiter Swap V2. Returns expected raw output and routing/fee data but no signable transaction and does not move funds.
getSolanaTokenBalancereadGet a Solana wallet
getSolanaTokenBalancesreadList every SPL token balance held by a Solana wallet, across both the Token and Token-2022 programs. Zero balances are hidden unless requested.
getSolanaTokenMarketDatareadGet Jupiter
getSolanaTokenPairsreadGet Dexscreener market pairs for a Solana token, sorted by reported USD liquidity. Includes DEX, quote token, price, transactions, volume, liquidity, market cap, and pair age when available.
getSolanaTokenSupplyreadGet the total circulating supply and decimals of an SPL token mint. Accepts a mint address or a known symbol.
getSolanaTransactionreadGet details of a Solana transaction by signature: success, fee, compute units and its decoded instructions. Pass verbose for the full raw RPC response including logs and balance changes.
getSolanaTransactionHistoryreadList recent transaction signatures for a Solana address, newest first. Paginate with the
getSolanaTrendingTokensreadGet Solana tokens ranked by Jupiter for price trend, traded volume, or organic activity over a selected window. This is a discovery signal, not an endorsement or safety verdict.
getStatsreadGet aggregate blockchain statistics including total blocks, transactions, addresses, and average block time.
getSwapsreadFetch recent swap events for a given ZAMM pool, optionally filtered by block range.
getSymbolreadGets the symbol of an ERC20 token
getTokenChartreadGets historical price chart data for one or more tokens from DeFi Llama
getTokenHoldersreadRetrieve token holders and their balances for a given token.
getTokenInforeadFetch metadata for a token contract.
getTokenMetadatareadGets all metadata (name, symbol, decimals, totalSupply) of an ERC20 token
getTokenTransfersreadList transfers for a specific token contract with pagination support.
getTotalSupplyreadGets the total supply of an ERC20 token
getTransactionreadGet details about a transaction including sender, recipient, value, gas, and input data.
getTransactionCountreadGet the nonce (number of transactions sent) from an address. If chainId is omitted, returns counts across all supported chains.
getTransactionInforeadRetrieve detailed information for a given transaction hash.
getTransactionInternalTransactionsreadRetrieve internal transactions that occurred within a given transaction.
getTransactionLogsreadRetrieve logs that were generated from a specific transaction.
getTransactionRawTracereadRetrieve raw trace information for a specific transaction.
getTransactionReceiptreadGet the receipt of a mined transaction including status, gas used, and logs.
getTransactionStateChangesreadRetrieve state changes that occurred during a transaction.
getTransactionSummaryreadRetrieve a summary of data related to a transaction.
getTransactionTokenTransfersreadRetrieve all token transfers that occurred within a given transaction.
getTransactionsChartreadGet daily transaction count chart data for the specified chain. Returns time-series data useful for activity trends.
getTweetByIdreadGet a specific tweet by its ID from X/Twitter. Returns the full tweet with author info and engagement metrics.
getUniV3PoolreadGets the current state of a Uniswap V3 pool including sqrtPriceX96, current tick, and whether the pool is unlocked.
getUserPositionsreadGets all Uniswap V3 LP positions owned by a user. Defaults to the connected wallet if no user address is provided.
getWNSBalancereadGet the number of .wei names owned by an address.
getWNSContenthashreadGet the contenthash for a .wei name.
getWNSExpirationreadGet the expiration timestamp (unix seconds) for a .wei name.
getWNSFeereadGet the registration fee for a .wei name based on label length.
getWNSOwnerreadGet the owner address of a .wei name.
getWNSTextreadGet a text record for a .wei name (e.g.
getWNSTokenURIreadGet the token URI (metadata) for a .wei name.
getX402PaymentInforeadCheck the x402 payment requirements for a URL without making a payment. Returns pricing, accepted networks, and payment details.
getXUserByUsernamereadLook up an X/Twitter user by their username/handle. Returns their profile info, follower counts, and bio.
getXUserTweetsreadGet recent tweets from a specific X/Twitter user by their user ID. Use getXUserByUsername first to get the user ID from a handle.
intent0xSwapreadSwap tokens on Ethereum, Optimism, Arbitrum, or Base via the 0x/Matcha aggregator. Automatically handles ERC20 approval if needed. Checks balance before swapping.
intentAaveBorrowreadBorrows tokens from Aave using your supplied collateral. By default, the variable rate mode (2) is used.
intentAaveDepositreadDeposits tokens into the Aave protocol to supply liquidity and earn interest.
intentAaveRepayreadRepays your Aave debt. By default, the variable rate mode (2) is used for repayment.
intentAaveWithdrawreadWithdraws tokens from Aave, redeeming your supplied assets (aTokens).
intentApprovereadCreates an intent to approve token spending. Supports
intentApproveSlowTransferwriteGuardian approves a transfer in SLOW contract
intentCoinchanAirdropreadAirdrop a Coinchan token to multiple addresses in a single transaction.
intentCoinchanClaimVestedreadClaim vested liquidity for a locked Coinchan token. Only works if vesting was enabled at creation.
intentCoinchanMakewriteCreate a new Coinchan token, mint supplies and add initial liquidity via ZAMM
intentCoinchanMakeHoldwriteCreate a new Coinchan token and hold liquidity for the creator instead of locking it.
intentCoinchanMakeLockedwriteCreate a new Coinchan token with locked liquidity and optional vesting schedule.
intentCollectFeesreadCollects all accumulated trading fees and any tokens from decreased liquidity for a Uniswap V3 LP position.
intentCreateCoinTokenreadCreates a new ERC6909 token inside the Coins contract with a name, symbol, metadata URI, owner, and initial supply.
intentDecreaseLiquidityreadRemoves liquidity from a Uniswap V3 LP position. The removed tokens are not automatically collected — use intentCollectFees afterwards to withdraw them.
intentDepositToSlowreadDeposit tokens or ETH into SLOW contract with a timelock
intentGovernorVotereadCast a vote on a Governor Bravo governance proposal via Tally. Resolves the governor contract address from the space slug automatically.
intentGovernorVoteWithReasonreadCast a vote with an on-chain reason on a Governor Bravo governance proposal via Tally. Resolves the governor contract address from the space slug automatically.
intentIncreaseLiquidityreadAdds more liquidity to an existing Uniswap V3 LP position identified by its NFT token ID.
intentMintPositionreadCreates a new Uniswap V3 liquidity position by minting an LP NFT. Requires both tokens to be approved for the Position Manager contract beforehand.
intentProposeNaniwriteCreate a new governance proposal for NANIDAO
intentRegisterSubdomainWNSreadGenerate a transaction intent for registering a subdomain under a .wei name.
intentRegisterWNSwriteGenerate transaction intents for registering a .wei name. Returns the commit and reveal transactions needed for the two-step registration process.
intentRenewWNSreadGenerate a transaction intent for renewing a .wei name.
intentReverseSlowTransferwriteReverse a pending transfer in SLOW contract
intentRevokeAllApprovalsdestructiveRevoke ALL active ERC-20 token approvals for the connected wallet on a specific chain. Scans for approvals first, then creates revoke transactions for each one. Use with caution — this will revoke approvals needed by DeFi protocols you actively use.
intentRevokeApprovaldestructiveRevoke (set to zero) an ERC-20 token approval for a specific spender. This is equivalent to calling approve(spender, 0).
intentSendTransactionwriteSend an arbitrary transaction to any address. Specify a human-readable ABI signature with function name and arguments to encode calldata automatically, or provide raw hex data. Use this for any contract interaction not covered by other tools.
intentSetPrimaryWNSreadGenerate a transaction intent for setting a .wei name as the primary name.
intentSetSlowGuardianwriteSet a guardian for a user in the SLOW contract
intentSetWNSAddrreadGenerate a transaction intent for setting the address record on a .wei name.
intentSetWNSContenthashreadGenerate a transaction intent for setting the contenthash on a .wei name.
intentSetWNSTextreadGenerate a transaction intent for setting a text record on a .wei name.
intentStakeNanireadStake NANI tokens to receive xNANI tokens, which can be used for governance
intentSwapreadSwap ERC20 or ERC6909 tokens via the zRouter. Automatically handles token approvals, finds the best route (including Matcha/0x aggregation), and executes the swap.
intentSwapSolanareadBuild an exact-input Jupiter Swap V2 intent for the configured Solana account. Returns the untrusted base64 transaction and request ID for an external wallet to decode, validate, simulate, approve, sign, and execute. Agentek does not sign or submit it.
intentTransferwriteTransfer ERC20 tokens or native ETH to an address or ENS name. Supports ENS resolution, automatic decimal handling, and auto-selects the cheapest chain if chainId is omitted.
intentTransferFromwriteTransfer ERC20 tokens from another address using transferFrom. Requires prior ERC20 approval from the
intentTransferPositionreadTransfers ownership of a Uniswap V3 LP NFT to another address using safeTransferFrom.
intentTransferSolwriteTransfer native SOL to an address. Signs and submits when a Solana key is configured, otherwise returns an unsigned base64 transaction for you to sign.
intentTransferSplTokenwriteTransfer an SPL token (including Token-2022 mints) to a wallet address, creating the recipient
intentUnlockSlowwriteUnlock a time-locked transfer in SLOW contract
intentUnstakeNanireadUnstake xNANI tokens back to NANI tokens
intentVoteNaniProposalreadVote on an existing NANIDAO governance proposal
intentWithdrawFromSlowreadWithdraw unlocked tokens from SLOW contract
intentWriteContractwriteWrite to any smart contract by calling a state-changing function. Builds a transaction intent that can be executed if a wallet is connected. If the ABI is not provided, it will be auto-fetched from Blockscout for verified contracts.
isAvailableWNSreadCheck if a .wei label is available for registration.
isExpiredWNSreadCheck if a .wei name is expired.
lookupENSreadLooks up the ENS name for an Ethereum address
mockToolreadA mock tool for testing
observeAaveAccountreadExact read-only Aave V3 account aggregates at one block. Not a supplied-asset breakdown, executable withdrawal amount or portfolio total. A failed read is unknown, never zero.
observeLPPositionreadRead an explicitly requested owned Uniswap V3 NFT and its pool range at one checked block. Range failure stays unknown alongside valid details. No accrued-fee estimate, executable withdrawal amount or signing. Code and pool identity checks do not verify implementation safety.
04

Trust audit

CAUTIONgrade C · trust 74/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (19)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
packages/shared/blockscout/tools.ts:492
description: "Get beacon chain withdrawals received by a specific address.",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/shared/approvals/tools.test.ts:105
token: "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/shared/erc20/intents.test.ts:151
token: "0x0000000000000000000000000000000000000000",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/shared/erc20/tools.test.ts:31
const TOKEN = "0x00000000000007C8612bA63Df8DdEfD9E6077c97";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/verify-yield-bridge.ts:11
const owner='0x1111111111111111111111111111111111111111',token='0x2222222222222222222222222222222222222222',other='0x3333333333333333333333333333333333333333';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
intentRevokeAllApprovals, intentRevokeApproval
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/shared/web/extraction.test.ts:8
return new Function("document", "NodeFilter", "return " + pageExtractionScript)(document, {SHOW_TEXT:4});
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/shared/defillama/utils/api.ts:9
import { assertOkResponse } from '../../utils/fetch.js';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/shared/solana/tools.test.ts:365
"http://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/shared/solana/tools.test.ts:365
"http://169.254.169.254/latest/meta-data/",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/shared/credentialTools/index.ts:71
return new Response(Uint8Array.from(atob(response.body), c => c.charCodeAt(0)), { status: response.status, headers: { 'content-type': 'application/json' } });
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/shared/x402/payments.ts:58
const bytes = Uint8Array.from(atob(trimmed), (c) => c.charCodeAt(0));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@openrouter/ai-sdk-provider, @types/node, dotenv, tsup, typescript, viem, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/ai-sdk/package.json
ai, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp/package.json
@modelcontextprotocol/sdk, node-fetch, @types/node, shx, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/shared/package.json
@x402/core, @x402/evm, @x402/fetch, cheerio, twitter-api-v2, wns-utils
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:328
| `X_API_KEY` + `X_API_KEY_SECRET` | Twitter/X OAuth (full access) |
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CONTRIBUTING.md:23
Open `.env` in your editor and add the required API keys
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
packages/cli/GUIDE.md:354
# Add to your shell profile (~/.bashrc, ~/.zshrc, etc.)
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4bb61a21d90ffull audit observations/trust-audit/mcp-server/nanidao__agentek.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084bb61a21d90fCAUTIONC74first audit
06

Questions

What is the Agentek MCP server?

An extensible TypeScript toolkit that simplifies complex EVM blockchain interactions into composable, intent-based tools. Provides a unified, type-safe interface for both on-chain actions and off-chain data services, enabling developers to programmatically execute any blockchain operation across mul

What tools does Agentek expose?

200 in total: 202 read-only, 21 that write, and 2 that can delete or overwrite (intentRevokeAllApprovals, intentRevokeApproval). Every one is listed on this page with its risk.

Is Agentek safe to connect to an agent?

With care. The audit graded it C (74/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Agentek need?

It reads COINDESK_API_KEY, COINMARKETCAL_API_KEY, DRPC_KEY, FIREWORKS_API_KEY, JUPITER_API_KEY, OPENROUTER_API_KEY, PERPLEXITY_API_KEY, PRIVATE_KEY, SOLANA_PRIVATE_KEY, TALLY_API_KEY, X_ACCESS_TOKEN and X_ACCESS_TOKEN_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Agentek run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @agentek/tools at 0.1.26.

How current is this page?

The grade is for one exact copy of the source (4bb61a21d90f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement