FoundryBLOCK
An experimental MCP Server for foundry built for Solidity devs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A simple, lightweight and fast MCP (Model Context Protocol) server that provides Solidity development capabilities using the Foundry toolchain (Forge, Cast, and Anvil).
Overview
This server connects LLM assistants to the Foundry ecosystem, enabling them to:
- Interact with nodes (local Anvil instances or remote RPC endpoints)
- Analyze smart contracts and blockchain data
- Perform common EVM operations using Cast
- Manage, deploy, and execute Solidity code and scripts
- Work with a persistent Forge workspace
Features
Network Interaction
- Start and manage local Anvil instances
- Connect to any remote network (just specify the RPC)
- Get network/chain information
Contract Interaction
- Call contract functions (read-only)
- Send transactions to contracts (if
PRIVATE_KEYis configured) - Get transaction receipts
- Read contract storage
- Analyze transaction traces
- Retrieve contract ABIs and sources from block explorers
Solidity Development
- Maintain a dedicated Forge workspace
- Create and edit Solidity files
- Install dependencies
- Run Forge scripts
- Deploy contracts
Utility Functions
- Calculate contract addresses
- Check contract bytecode size
- Estimate gas costs
- Convert between units (hex to decimals, etc.,)
- Generate wallets
- Get event logs
- Lookup function and event signatures
Smart Contract Analysis (Heimdall)
- Disassemble EVM bytecode into human-readable opcodes
- Decode raw calldata without requiring ABI
- Decompile EVM bytecode to Solidity source code and ABI
- Generate visual control flow graphs for EVM bytecode
- Detailed transaction inspection with calldata decoding and trace analysis
Usage
The server is designed to be used as an MCP tool provider for MCP Clients. When connected to a client, it enables the clients(claude desktop, cursor, client, etc.,) to perform Solidity and onchain operations directly.
Requirements
- [N
2f8359351517OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add foundry-mcp-server --env PRIVATE_KEY=${PRIVATE_KEY} -- npx -y @pranesh.asp/[email protected]{
"mcpServers": {
"foundry-mcp-server": {
"command": "npx",
"args": [
"-y",
"@pranesh.asp/[email protected]"
],
"env": {
"PRIVATE_KEY": "${PRIVATE_KEY}"
}
}
}
}Exposed tools (16)
11 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
anvil_start | write | Start a new Anvil instance (local Ethereum node) |
anvil_status | read | Check if Anvil is running and get its status |
anvil_stop | write | Stop a running Anvil instance |
cast_balance | read | Check the ETH balance of an address |
cast_call | read | Call a contract function (read-only) |
cast_chain | read | Get information about the current chain |
cast_receipt | read | Get the transaction receipt |
cast_send | write | Send a transaction to a contract function |
convert_eth_units | read | Convert between Ethereum units (wei, gwei, ether) |
create_solidity_file | write | Create or update a Solidity file in the workspace |
forge_script | write | Run a Forge script from the workspace |
heimdall_cfg | read | Generate visual control flow graph for EVM bytecode using Heimdall |
heimdall_decode | read | Decode raw calldata without requiring ABI using Heimdall |
heimdall_decompile | read | Decompile EVM bytecode to Solidity source code and ABI using Heimdall |
heimdall_disassemble | read | Disassemble EVM bytecode into human-readable opcodes using Heimdall |
heimdall_inspect | read | Detailed inspection of Ethereum transactions including calldata decoding, trace analysis, and log visualization using Heimdall |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
const child = exec(command, (error, stdout, stderr) => {async ({ scriptPath, sig = "run()", rpcUrl, broadcast = false, verify = false }) => {bun.lockb
import { checkFoundryInstalled, FOUNDRY_PATHS, FOUNDRY_NOT_INSTALLED_ERROR } from "../../utils/command.js";import { getAnvilInfo } from "../../utils/rpc.js";import { getAnvilInfo } from "../../utils/rpc.js";import { getAnvilInfo } from "../../utils/rpc.js";import { checkFoundryInstalled, executeCommand, FOUNDRY_PATHS, FOUNDRY_NOT_INSTALLED_ERROR } from "../../utils/command.js";@modelcontextprotocol/sdk, @pranesh.asp/foundry-mcp-server, dotenv, typescript, zod, @types/bun
curl -L https://foundry.paradigm.xyz | bash
assets/analysis_gif.gif
Gates applied: no_behavioural_pass.
2f8359351517full audit observations/trust-audit/mcp-server/praneshasp__foundry-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 2f8359351517 | BLOCK | D | 69 | first audit |
Questions
What is the Foundry MCP server?
An experimental MCP Server for foundry built for Solidity devs
What tools does Foundry expose?
16 in total: 11 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Foundry safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Foundry need?
It reads PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Foundry run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pranesh.asp/foundry-mcp-server at 0.1.5.
How current is this page?
The grade is for one exact copy of the source (2f8359351517), read on 2026-10-06. The repository is watched and re-audited when it changes.