Atlas / MCP servers / olanetsoft / Midnight

MidnightSAFE

mcp/olanetsoft/midnight

Midnight MCP server giving AI assistants access to Midnight blockchain — search contracts, analyze code, explore docs

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
36 33r · 3w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

## ⚠️ Deprecated — use Kapa + Midnight Expert midnight-mcp is being wound down. Midnight has standardised on two official tools: - Kapa MCP (docs Q&A / search): claude mcp add --transport http midnight https://midnight.mcp.kapa.ai - Midnight Expert (hands-on dev, Claude Code plugins): curl -fsSL https://midnightntwrk.expert/install.sh | bash Migration guide → https://docs.midnight.network/blog/migrating-to-kapa-and-midnight-expert

[](https://www.npmjs.com/package/midnight-mcp) [](https://npm-stat.com/charts.html?package=midnight-mcp) [](./LICENSE) [](https://www.typescriptlang.org/) [](https://github.com/Olanetsoft/midnight-mcp/actions/workflows/ci.yml)

MCP server that gives AI assistants access to Midnight blockchain—search contracts, analyze code, and explore documentation.

This project extends the Midnight Network with additional developer tooling.

Requirements

  • Node.js 20+ (LTS recommended)

Check your version: node --version

Using nvm? Click for Claude Desktop setup

If you use nvm, Claude Desktop may not see your nvm-managed Node. Use this config instead:

{
"mcpServers": {
"midnight": {
"command": "/bin/sh",
"args": [
"-c",
"source ~/.nvm/nvm.sh && nvm use 20 >/dev/null 2>&1 && npx -y midnight-mcp@latest"
]
}
}
}

Quick Start

Claude Desktop

Add to your claude_desktop_config.json:

{
"mcpServers": {
"midnight": {
"command": "npx",
"args": ["-y", "midnight-mcp@latest"]
}
}
}

*Config file locations:

Read from source at commit 4316c1b7477dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add midnight-mcp --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env MIDNIGHT_API_TOKEN=${MIDNIGHT_API_TOKEN} --env MIDNIGHT_GITHUB_TOKEN=${MIDNIGHT_GITHUB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "midnight-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "MIDNIGHT_API_TOKEN": "${MIDNIGHT_API_TOKEN}",
        "MIDNIGHT_GITHUB_TOKEN": "${MIDNIGHT_GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (36)

33 read · 3 write · 0 destructive.

ToolRiskDescription
DocumentationreadAccess documentation by section (guides, api, concepts) and topic
approachesreadSpecific approaches to compare (comma-separated)
complexityreadExpected complexity level (beginner, intermediate, advanced)
conceptreadThe concept to explain (zk-proofs, circuits, witnesses, ledger, etc.)
contractCodereadThe Compact contract code to review
contractTypereadType of contract (token, voting, credential, custom)
errorMessagereadError message or description of the issue
focusAreasreadSpecific areas to emphasize (security, performance, privacy, readability)
levelreadExpertise level (beginner, intermediate, advanced)
midnight-analyze-contractread⚠️ STATIC ANALYSIS ONLY - Analyze contract structure and patterns. 🚫 THIS DOES NOT COMPILE THE CONTRACT. Cannot catch: sealed field rules, disclose() requirements, semantic errors. 👉 Use
midnight-auto-update-configwrite⚠️ DEPRECATED: Auto-update is NOT possible because AI agents run in sandboxed environments without access to local filesystems.
midnight-check-breaking-changesreadCheck if there are breaking changes between your current version and the latest release. Essential before upgrading dependencies.
midnight-check-versionread🔄 Check if you
midnight-compare-syntaxreadCompare a file between two versions to see what changed. Use this before recommending code patterns to ensure they work with the user
midnight-document-contractread📝 AI-POWERED DOCUMENTATION GENERATION Generates comprehensive documentation for Compact smart contracts. Uses the client
midnight-extract-contract-structurereadExtract and analyze Compact contract structure (circuits, witnesses, ledger).
midnight-generate-contractread🔮 AI-POWERED CONTRACT GENERATION Generates Compact smart contracts from natural language requirements. Uses the client
midnight-get-filereadRetrieve a specific file from Midnight repositories. Use repository aliases like
midnight-get-file-at-versionreadGet the exact content of a file at a specific version. CRITICAL: Use this to ensure code recommendations match the user
midnight-get-latest-updatesreadRetrieve recent changes and commits across Midnight repositories. Useful for staying up-to-date with the latest developments.
midnight-get-migration-guidereadGet a detailed migration guide for upgrading between versions, including all breaking changes, deprecations, and recommended steps.
midnight-get-repo-contextwrite🚀 COMPOUND TOOL: Get everything needed to start working with a repository in ONE call. Combines version info + syntax reference + relevant examples. Use this at the start of a coding session instead of multiple individual calls. Saves ~50% tokens.
midnight-get-statusreadGet current server status including rate limits and cache statistics. Quick status check without external API calls.
midnight-get-update-instructionswrite📋 Get detailed, platform-specific instructions for updating Midnight MCP to the latest version.
midnight-get-version-inforeadGet the latest version, release notes, and recent breaking changes for a Midnight repository. Use this to ensure you
midnight-health-checkreadCheck the health status of the Midnight MCP server. Returns server status, API connectivity, and resource availability.
midnight-list-category-toolsread📋 DISCOVERY TOOL: List tools within a specific category. Use after midnight-list-tool-categories to see detailed tool information for a category of interest. Supports progressive disclosure pattern.
midnight-list-examplesreadList available Midnight example contracts and DApps with descriptions, complexity ratings, and key features.
midnight-list-tool-categoriesread📋 DISCOVERY TOOL: List available tool categories for progressive exploration. Use this FIRST to understand what capabilities are available, then drill into specific categories with midnight-list-category-tools. Reduces cognitive load by organizing the available tools into logical groups.
midnight-new-mcpreadShow where midnight-mcp has moved. midnight-mcp is deprecated; Midnight
midnight-review-contractread🔍 AI-POWERED CONTRACT REVIEW Performs security review and analysis of Compact smart contracts. Uses the client
midnight-search-compactreadSemantic search across Compact smart contract code and patterns. Use this to find circuit definitions, witness functions, ledger declarations, and best practices for Midnight smart contracts. USAGE GUIDANCE: • Call at most 2 times per question - if first search doesn
midnight-suggest-toolread🎯 SMART DISCOVERY: Describe what you want to do in natural language, and get tool recommendations. EXAMPLES: •
midnight-upgrade-checkread🚀 COMPOUND TOOL: Complete upgrade analysis in ONE call. Combines version check + breaking changes + migration guide. Use this instead of calling midnight-get-version-info, midnight-check-breaking-changes, and midnight-get-migration-guide separately. Saves ~60% tokens.
privacyLevelreadRequired privacy features (full, partial, public)
problemreadThe problem to solve
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
api/scripts/index-repos.ts:21
config({ path: resolve(__dirname, "../../.env") });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
api/src/templates/components/tables.ts:6
import type { ToolCall } from "../../interfaces";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/analyze/handlers.ts:6
import { parseCompactFile, CodeUnit } from "../../pipeline/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/analyze/handlers.ts:7
import { logger } from "../../utils/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/analyze/handlers.ts:12
} from "../../services/compiler.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/http-security.test.ts:9
"http://127.0.0.1:3000",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/http-security.test.ts:10
"https://127.0.0.1:3000",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
api/package.json
@types/tar-stream, hono, tar-stream, @cloudflare/workers-types, dotenv, octokit, openai, tsx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, chromadb, dotenv, express, js-yaml, octokit, openai, yargs
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:8
> - **Midnight Expert** (hands-on dev, Claude Code plugins): `curl -fsSL https://midnightntwrk.expert/install.sh | bash`

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4316c1b7477dfull audit observations/trust-audit/mcp-server/olanetsoft__midnight.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084316c1b7477dSAFEB89first audit
06

Questions

What is the Midnight MCP server?

Midnight MCP server giving AI assistants access to Midnight blockchain — search contracts, analyze code, explore docs

What tools does Midnight expose?

36 in total: 33 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Midnight safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Midnight need?

It reads CLOUDFLARE_API_TOKEN, GITHUB_TOKEN, MIDNIGHT_API_TOKEN, MIDNIGHT_GITHUB_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Midnight run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as midnight-mcp at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (4316c1b7477d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement