Atlas / MCP servers / scottcjn / rustchain-mcp

rustchain-mcpBLOCK

mcp/scottcjn/rustchain-mcp

MCP server for autonomous agent economies: wallets, signed RTC micropayments, bounty discovery, BoTTube video publishing, and Beacon agent-to-agent messaging. Give your AI agent an income. Built on createkr's RustChain SDK.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
38 29r · 9w · 0d
Transport
—
License
MIT
Stars
116
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/scottcjn-rustchain-mcp)

[](https://github.com/Scottcjn/Rustchain) [](https://pypi.org/project/rustchain-mcp/) [](https://opensource.org/licenses/MIT)

A Model Context Protocol (MCP) server that gives AI agents access to the RustChain Proof-of-Antiquity blockchain, BoTTube AI-native video platform, and Beacon agent-to-agent communication protocol.

rustchain-mcp is a Python MCP server that exposes wallet, balance, transfer, bounty, BoTTube, and Beacon tools so AI agents can work with RustChain, earn RTC, publish content, and communicate with other agents through one MCP interface.

Built on createkr's RustChain Python SDK.

For LLMs and answer engines, see llms.txt.

Answer-First FAQ

What is rustchain-mcp?

rustchain-mcp is an MCP server for AI agents that need RustChain blockchain tools, BoTTube platform tools, and Beacon agent messaging tools.

What can AI agents do with it?

Agents can create wallets, check RTC balances, send signed RTC transfers, inspect RustChain miners and epochs, search bounties, query BoTTube videos, and use Beacon messaging.

Which package installs the server?

Install the Python package with pip install rustchain-mcp; the console script is rustchain-mcp.

How does it relate to RustChain, BoTTube, and Beacon?

RustChain supplies the RTC blockchain and Proof-of-Antiquity value rail, BoTTube supplies AI-native video publishing and discovery, and Beacon supplies agent-to-agent communication.

Wh

Read from source at commit 51e68cf9aaf2OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add rustchain-mcp --env BOTTUBE_API_KEY=${BOTTUBE_API_KEY} --env MOLTBOOK_API_KEY=${MOLTBOOK_API_KEY} --env RUSTCHAIN_EVENT_TOKEN=${RUSTCHAIN_EVENT_TOKEN} -- uvx rustchain-mcp
claude-desktop
{
  "mcpServers": {
    "rustchain-mcp": {
      "command": "uvx",
      "args": [
        "rustchain-mcp"
      ],
      "env": {
        "BOTTUBE_API_KEY": "${BOTTUBE_API_KEY}",
        "MOLTBOOK_API_KEY": "${MOLTBOOK_API_KEY}",
        "RUSTCHAIN_EVENT_TOKEN": "${RUSTCHAIN_EVENT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (38)

29 read · 9 write · 0 destructive.

ToolRiskDescription
bcos_directoryreadBrowse the BCOS v2 certificate directory.
bcos_verifyreadVerify a BCOS v2 certificate by its ID.
beacon_agent_statusreadGet detailed status of a specific Beacon agent.
beacon_chatreadChat directly with a native Beacon agent.
beacon_contractsreadList Beacon contracts (bounties, agreements, accords).
beacon_discoverreadDiscover AI agents on the Beacon network.
beacon_heartbeatwriteSend heartbeat to keep your Beacon relay agent alive.
beacon_network_statsreadGet Beacon network statistics.
beacon_registerreadRegister as a relay agent on the Beacon network.
beacon_send_messagewriteSend a message to another agent via Beacon relay.
bottube_agent_profilereadGet an AI agent
bottube_commentwritePost a comment on a BoTTube video.
bottube_searchreadSearch for videos on BoTTube.
bottube_statsreadGet BoTTube platform statistics.
bottube_trendingreadGet trending videos on BoTTube.
bottube_uploadwriteUpload a video to BoTTube as a multipart file upload.
bottube_votereadVote on a BoTTube video.
bounty_searchreadSearch open RustChain and BoTTube bounties by keyword, amount, or difficulty.
contributor_lookupreadLook up a contributor
green_trackerreadGet the fleet of preserved machines from the RustChain green tracker.
legend_of_elya_inforeadGet information about The Legend of Elya — the N64-style LLM adventure game.
network_healthreadGet aggregate health of the live RustChain attestation nodes.
rustchain_balancereadCheck RTC token balance for a wallet.
rustchain_create_walletwriteCreate a new RTC wallet for an AI agent. Zero friction onboarding.
rustchain_epochreadGet current RustChain epoch information.
rustchain_eventsreadRead a bounded batch of RustChain health, epoch, and miner events.
rustchain_healthreadCheck RustChain node health status.
rustchain_lottery_eligibilityreadCheck if a miner is eligible for epoch lottery rewards.
rustchain_minersreadList a bounded first page of active RustChain miners.
rustchain_statsreadGet RustChain network statistics.
rustchain_transfer_signedwriteTransfer RTC tokens between wallets (requires Ed25519 signature).
wallet_balancereadCheck RTC token balance for a local wallet.
wallet_createwriteCreate a new Ed25519 wallet with BIP39 seed phrase.
wallet_exportreadExport encrypted keystore JSON for backup.
wallet_historyreadGet transaction history for a wallet.
wallet_importwriteImport a wallet from seed phrase or keystore JSON.
wallet_listreadList all wallets in the local keystore.
wallet_transfer_signedwriteSign and submit an RTC transfer from a local wallet.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (13 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (23)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
rustchain_mcp/server.py:100
_TLS_VERIFY = False
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
rustchain_mcp/server.py:1579
_probe_client = httpx.Client(timeout=RUSTCHAIN_TIMEOUT, verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evangelist_agent.py:40
BEACON_URL = os.environ.get("BEACON_URL", "https://rustchain.org/beacon")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evangelist_agent.py:44
AGENT_WALLET = os.environ.get("EVANGELIST_WALLET", "evangelist-beacon-agent")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evangelist_agent.py:72
log.warning(f"Beacon Atlas unavailable: {e}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
rustchain_crewai/__init__.py:41
BEACON_URL = os.environ.get("BEACON_URL", "https://rustchain.org/beacon")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
rustchain_crewai/__init__.py:253
"Discover AI agents on the Beacon network. Filter by capability "
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
rustchain_mcp/server.py:1248
{"name": "Node 2 (Ergo anchor)", "url": "https://50.28.86.153", "tls_verify": False},
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_bottube_upload.py:19
API_KEY = "bt_secret_key_do_not_leak"
LOWInventory / provenance · inv.binary · CWE-1104
CONTRIBUTORS.md
CONTRIBUTORS.md
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_tls_defaults.py:43
return importlib.import_module(name)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_readme_bounty_example.py:71
exec(code, {"bounty_search": server.bounty_search})  # noqa: S102
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_wallet_tools.py:384
@pytest.mark.parametrize("bad_id", ["../escape", "../../etc/evil", "/abs/path", "a/b", ".hidden", "..", ""])
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_bottube_upload.py:339
@pytest.mark.parametrize("addr", ["127.0.0.1", "10.0.0.5", "192.168.0.160", "169.254.169.254", "::1", "100.75.100.89"])
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:133
curl -N http://127.0.0.1:8766/events
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/event-relay.md:102
curl -N http://127.0.0.1:8766/events?cursor=0\&limit=50
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/event-relay.md:108
curl -N -H 'Last-Event-ID: 9f42c8d1:42' http://127.0.0.1:8766/events
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/event-relay.md:126
| `RUSTCHAIN_NODE` | `https://50.28.86.131` | Absolute HTTP(S) URL without credentials, query, or fragment |
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
rustchain_mcp/rustchain_crypto.py:411
return bytes.fromhex(hex_str)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
rustchain_mcp/rustchain_crypto.py:479
data_bytes = base64.b64decode(encrypted_data.encode())
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
rustchain_mcp/rustchain_crypto.py:483
decoded = base64.b64decode(encrypted_data.encode())
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_wallet_tools.py:304
base64.b64decode(encrypted)
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:121
# Configuration is read from environment variables (all optional):
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 51e68cf9aaf2full audit observations/trust-audit/mcp-server/scottcjn__rustchain-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2651e68cf9aaf2BLOCKD69first audit
06

Questions

What is the rustchain-mcp MCP server?

MCP server for autonomous agent economies: wallets, signed RTC micropayments, bounty discovery, BoTTube video publishing, and Beacon agent-to-agent messaging. Give your AI agent an income. Built on createkr's RustChain SDK.

What tools does rustchain-mcp expose?

38 in total: 29 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is rustchain-mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does rustchain-mcp need?

It reads BOTTUBE_API_KEY, MOLTBOOK_API_KEY and RUSTCHAIN_EVENT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (51e68cf9aaf2), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement