Atlas / MCP servers / nearai / Near

NearSAFE

mcp/nearai/near

An MCP server for the NEAR blockchain

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 13r · 7w · 3d
Transport
sse · stdio
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/@nearai%2Fnear-mcp) [](https://t.me/nearaialpha)

This project is a Model Context Protocol (MCP) compatible server for interacting with the NEAR blockchain. This tool provides a way for LLMs and AI agents to securely access and interact with NEAR accounts and blockchain functionality.

Quickstart

Here is how to get started with the near-mcp server quickly with the claude code cli

npm install -g @anthropic-ai/claude-code
claude mcp add near-mcp npx @nearai/near-mcp@latest run
claude

Or deploy the MCP server remotely on Phala Cloud, check the instructions here

Installing

near-mcp is meant to be used is with an MCP compatible client. Learn more in the MCP docs

Adding to the `claude` code cli:

claude mcp add near-mcp npx @nearai/near-mcp@latest run

Adding to claude desktop via JSON config:

{
"mcpServers": {
"near-mcp": {
"command": "npx",
"args": ["-y", "@nearai/near-mcp@latest", "run"],
"env": {}
}
}
}

Adding to `goose`

┌   goose-configure
│
◇  What would you like to configure?
│  Add Extension
│
◇  What type of extension would you like to add?
│  Command-line Extension
│
◇  What would you like to call this extension?
│  near-mcp
│
◇  What command should be run?
│  npx @nearai/near-mcp@latest run
│
◇  Please set the timeout for this tool (in secs):
│  60
│
◇  Would you like to add environment variables?
│  No
│
└  Added near-mcp extension

Or you can inst

Read from source at commit e55f69aa3849OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add near-mcp --env NEAR_KEYSTORE=${NEAR_KEYSTORE} -- npx -y @nearai/[email protected]
claude-desktop
{
  "mcpServers": {
    "near-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@nearai/[email protected]"
      ],
      "env": {
        "NEAR_KEYSTORE": "${NEAR_KEYSTORE}"
      }
    }
  }
}
03

Exposed tools (23)

13 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
account_add_access_keywrite
account_create_accountwrite
account_create_implicit_accountwrite
account_delete_access_keysdestructive
account_delete_accountdestructive
account_export_accountread
account_list_access_keysread
account_sign_dataread
account_verify_signatureread
account_view_account_summaryread
contract_call_raw_functionread
contract_call_raw_function_as_read_onlyread
contract_get_function_argsread
contract_view_functionsread
ref_finance_execute_swapwrite
ref_finance_get_poolsread
ref_finance_get_swap_estimateread
search_near_fungible_tokensread
system_import_accountwrite
system_list_local_keypairsreadList all NEAR accounts and their keypairs in the local keystore by network.
system_remove_local_accountdestructive
tokens_send_ftwrite
tokens_send_nearwrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
account_delete_access_keys, account_delete_account, system_remove_local_account
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/run/index.ts:5
import { runMcpServer } from '../../';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/tools/index.ts:7
import { createMcpServer } from '../../services';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/commands/tools/index.ts:8
import { stringify_bigint } from '../../utils';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
tee.md:33
eyJwdWJsaWNfa2V5IjoiZWQyNTUxOTpGcldnQm1EbmJFRVJudHZTVkdpenBVeGs2NExYTmJhRjNVNzdEdTZWUURGUiIsInByaXZhdGVfa2V5IjoiZWQyNTUxOTo0NTdQdzJCeUZmNnVUOHI2SGkzWlFzOVJQQ3NNN0FXb3I0a2dlZW50UE1HVXRhb2ZobUtVanF4M1Zw
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @near-js/accounts, @near-js/client, @near-js/crypto, @near-js/keystores, @near-js/keystores-node, @near-js/types, @near-js/utils
Why it matters. 37 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
TOOLS.md:271
"description": "\nAdd an access key to an account. This can be used to grant full access to an account,\nor allow the specified account to have specific function call access to a contract.",

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e55f69aa3849full audit observations/trust-audit/mcp-server/nearai__near.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e55f69aa3849SAFEB89first audit
06

Questions

What is the Near MCP server?

An MCP server for the NEAR blockchain

What tools does Near expose?

23 in total: 13 read-only, 7 that write, and 3 that can delete or overwrite (account_delete_access_keys, account_delete_account, system_remove_local_account). Every one is listed on this page with its risk.

Is Near safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Near need?

It reads NEAR_KEYSTORE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Near run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @nearai/near-mcp at 0.0.35.

How current is this page?

The grade is for one exact copy of the source (e55f69aa3849), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement