MCP-Server

Contract Powers

io.github.ofirbaranesad-agent/contract-powers
Krypto & Web3 Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Analyzes EVM contracts for administrative control, upgradeability, owner powers, risky opcodes, and recent power changes.

check_any_contract
Free preview for ANY verified EVM contract on base, ethereum or polygon — including addresses not in the registry. Returns contract type, verification, name, whether it is a proxy, how many powers were found, how many owner-only functions went uncategorised, and whether an owner was found. The decision fields (which powers, the evidence, the admin address, the implementation) are withheld and listed by name. Use get_contract_powers first if the contract is already in the registry — that is free and complete.
Eingabeschema
{'type': 'object', 'required': ['address'], 'properties': {'chain': {'enum': ['base', 'ethereum', 'polygon'], 'type': 'string', 'description': 'Default base.'}, 'address': {'type': 'string', 'description': '0x-prefixed 20-byte address.'}}}
get_contract_powers
Full free analysis of one contract that is in the registry: verification, proxy pattern and implementation address, who the admin is and whether it is a single key, every retained power (upgrade / mint / grant-minter / pause / blacklist / seize / fees / sweep / burn-from / ownership transfer / limits) with the evidence and confidence behind it, reachable DELEGATECALL / SELFDESTRUCT / CREATE2 opcodes, and the owner-only functions the classifier could NOT categorise — which is where the unusual powers hide. Accepts an address or a symbol such as USDC or AERO.
Eingabeschema
{'type': 'object', 'required': ['contract'], 'properties': {'chain': {'enum': ['base', 'ethereum', 'polygon'], 'type': 'string', 'description': 'Required if a symbol is ambiguous.'}, 'contract': {'type': 'string', 'description': 'A 0x address, or a symbol such as USDC.'}}}
list_watched_contracts
List the EVM contracts in the Contract Powers registry, with a one-line risk shape for each: is the code upgradeable, is the admin a single key (EOA) rather than a contract, how many powers are declared, and is it covered by a bug bounty. Use this to see what is already analysed before spending a lookup. Filters are optional and combine with AND.
Eingabeschema
{'type': 'object', 'properties': {'chain': {'enum': ['base', 'ethereum', 'polygon'], 'type': 'string', 'description': 'Restrict to one chain.'}, 'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'Default 200.'}, 'upgradeable': {'type': 'boolean', 'description': 'true = only contracts whose code can still be replaced.'}, 'single_key_admin': {'type': 'boolean', 'description': 'true = only contracts whose admin is a plain wallet (EOA), not a contract/multisig/timelock.'}}}
recent_power_changes
What actually changed behind the watched contracts: implementation swapped, owner moved, a power appeared or disappeared, verification lost. Each event carries the before and after value and the window it was detected in. Severity is one of critical / material / low. Use this to answer "has anything changed behind this contract recently?".
Eingabeschema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Default 25.'}, 'contract': {'type': 'string', 'description': 'Filter to one address or symbol.'}, 'severity': {'enum': ['critical', 'material', 'low'], 'type': 'string', 'description': 'Minimum severity to return.'}}}
Geändert
get_contract_powers
29. September 2026 02:50
Hinzugefügt
recent_power_changes
23. September 2026 02:40
Hinzugefügt
check_any_contract
23. September 2026 02:40
Hinzugefügt
get_contract_powers
23. September 2026 02:40
Hinzugefügt
list_watched_contracts
23. September 2026 02:40