Atlas / MCP servers / zen7-labs / Zen7 Payment Agent

Zen7 Payment AgentCAUTION

mcp/zen7-labs/zen7-payment-agent

Zen7 Payment Agent is the first implementation project of DePA (Decentralized Payment Agent), pioneers next-generation intelligent payment infrastructure.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
1 0r · 1w · 0d
Transport
sse
License
Apache-2.0
Stars
178
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://python.org) [](https://github.com/astral-sh/uv) 中文版本

Real-time progress updates can be viewed on page Real-time progress For support on the x402 protocol, please click here

Zen7 Payment Agent is the first practical implementation of DePA (Decentralized Payment Agent), pioneering the next generation of intelligent payment infrastructure. It not only fully implements the core functionalities of DePA but also successfully deploys innovative application cases in the agentic commerce domain.

As the first practical project in the DePA ecosystem, Zen7 implements several key features: automated encrypted payments between agents, a "permissionless authorization" mechanism, and LLM-driven intent recognition and interaction.

Zen7 Payment Agent adopts a multi-agent collaborative architecture, supporting both A2A and MCP protocols, as well as custodial and non-custodial payment models. It provides a comprehensive payment solution for AI Agents and native Dapp applications with multi-chain, multi-currency, multi-wallet support, high-frequency transactions, gasless operations, and passwordless authentication.

Navigating the Repository

This repository contains the complete implementation of Zen7 Payment Agent, showcasing the core components and architectural design based on the Zen7 Payment Agent (Decentralized Payment Agent) protocol.

Core Directory Structure

The core implementation of the project is located in the following key directories:

**[host_agent](ht

Read from source at commit 8902686008f7OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add zen7-payment-agent --env ACTIVE_TOKEN=${ACTIVE_TOKEN} --env FEE_PAYER_KEY=${FEE_PAYER_KEY} --env PAYER_PRIVATE_KEY=${PAYER_PRIVATE_KEY} --env PRIVATE_KEY=${PRIVATE_KEY} -- uvx zen7-payment-agent
claude-desktop
{
  "mcpServers": {
    "zen7-payment-agent": {
      "command": "uvx",
      "args": [
        "zen7-payment-agent"
      ],
      "env": {
        "ACTIVE_TOKEN": "${ACTIVE_TOKEN}",
        "FEE_PAYER_KEY": "${FEE_PAYER_KEY}",
        "PAYER_PRIVATE_KEY": "${PAYER_PRIVATE_KEY}",
        "PRIVATE_KEY": "${PRIVATE_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
proceed_payment_or_settlement_or_order_or_allowance_detailswrite
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (15)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/execute_sign.py:215
logger.info(f">>> {token} Contract Address: {TOKEN_ADDRESS}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/execute_sign_solana.py:147
logger.info(f">>> {token} Mint Address (Token Contract): {token_config['mint_address']}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/execute_sign_solana.py:167
logger.info(f">>> Payer {token} Balance: {token_balance_display} {token}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/execute_sign_solana.py:175
logger.warning(f"Warning: Payer's {token} Token Account does not exist")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/execute_sign_solana.py:177
logger.warning(f"Warning: Failed to query {token} balance: {e}")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
services/custodial/transfer_handler.py:337
bytes.fromhex(r[2:]) if r.startswith('0x') else bytes.fromhex(r),  # Remove 0x prefix
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
services/custodial/transfer_handler.py:338
bytes.fromhex(s[2:]) if s.startswith('0x') else bytes.fromhex(s)  # Remove 0x prefix
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
services/custodial/transfer_handler.py:472
bytes.fromhex(r[2:]) if r.startswith('0x') else bytes.fromhex(r),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
services/custodial/transfer_handler.py:473
bytes.fromhex(s[2:]) if s.startswith('0x') else bytes.fromhex(s)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
services/execute_sign_solana.py:126
key_bytes = bytes.fromhex(key_hex)
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/development_guide-zh.md:38
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/development_guide.md:38
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install-uv-python-git-zh.md:112
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/install-uv-python-git.md:112
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/quick_start-zh.md:45
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 8902686008f7full audit observations/trust-audit/mcp-server/zen7-labs__zen7-payment-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-068902686008f7CAUTIONB86first audit
06

Questions

What is the Zen7 Payment Agent MCP server?

Zen7 Payment Agent is the first implementation project of DePA (Decentralized Payment Agent), pioneers next-generation intelligent payment infrastructure.

What tools does Zen7 Payment Agent expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Zen7 Payment Agent safe to connect to an agent?

With care. The audit graded it B (86/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Zen7 Payment Agent need?

It reads ACTIVE_TOKEN, FEE_PAYER_KEY, PAYER_PRIVATE_KEY, PRIVATE_KEY, SOLANA_PAYER_PRIVATE_KEY and SPENDER_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Zen7 Payment Agent run?

It speaks sse, so it runs as a service you connect to over the network. It is published on PyPI as zen7-payment-agent.

How current is this page?

The grade is for one exact copy of the source (8902686008f7), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement