MCP Server

FabTally Safe

io.github.zvmzaretsky/crypto-safety
Crypto & Web3 Security Public & reachable MCP 2025-11-25

What this MCP does

Performs read-only crypto safety checks including token risk analysis, wallet approval scans, signature decoding, and transaction simulation.

approvals
Wallet approval-risk scan + revoke calldata (paid $0.01)
PAID $0.01 (x402, USDC on Base). Scan a wallet's ERC-20/721 approvals ranked by exposure; flags unlimited amounts, unverified/known-malicious spenders, and address-poisoning 'fake-approval revoke bait'; returns the exact revoke calldata you execute YOURSELF (never executed/broadcast by us). Without payment returns the x402 challenge; pass x_payment. Free teaser: approvals_free.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['address', 'chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'address': {'type': 'string', 'description': '0x wallet address to scan.'}, 'x_payment': {'type': 'string', 'description': 'x402 payment payload (base64) for this PAID tool. If supplied it is forwarded as the X-PAYMENT header to settle the call and return the real result instead of a 402 challenge. Omit to get the price challenge first.'}}, 'additionalProperties': False}
approvals_free
Approvals — counts + top-3 risks (FREE)
FREE. Approval counts + top-3 riskiest spenders for {address, chain}. Real result, no wallet. Upgrade to approvals for EVERY approval ranked + revoke calldata.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['address', 'chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'address': {'type': 'string', 'description': '0x wallet address to scan.'}}, 'additionalProperties': False}
decode_signature
Decode 'what am I signing' EIP-712 signature (paid $0.01)
PAID $0.01 (x402, USDC on Base). Decode an off-chain EIP-712 typed-data signature (Permit / Permit2 / Seaport / generic) into plain English with risk flags: unlimited approval, unknown/known-malicious spender, never-expiring or already-expired deadlines, zero-consideration NFT-drain orders. Off-chain signatures are the top wallet-drainer vector. Pure offline decode — never signs/broadcasts. Without payment returns the x402 challenge; pass x_payment. Free teaser: decode_signature_free.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['typed_data'], 'properties': {'chain': {'type': 'string', 'description': 'Optional chain override (else read from domain.chainId).'}, 'x_payment': {'type': 'string', 'description': 'x402 payment payload (base64) for this PAID tool. If supplied it is forwarded as the X-PAYMENT header to settle the call and return the real result instead of a 402 challenge. Omit to get the price challenge first.'}, 'typed_data': {'type': 'object', 'description': 'EIP-712 typed data object: {domain, types, primaryType, message}.', 'additionalProperties': {}}}, 'additionalProperties': False}
decode_signature_free
Signature decode — type + summary + risk level (FREE)
FREE. Type + plain-English summary + risk level for an EIP-712 `typed_data`. Real result, no wallet. Upgrade to decode_signature for the full field-by-field decode + all risk flags + malicious-spender screening.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['typed_data'], 'properties': {'chain': {'type': 'string', 'description': 'Optional chain override (else read from domain.chainId).'}, 'typed_data': {'type': 'object', 'description': 'EIP-712 typed data object: {domain, types, primaryType, message}.', 'additionalProperties': {}}}, 'additionalProperties': False}
simulate
Keyless pre-sign transaction simulation (paid $0.02)
PAID $0.02 (x402, USDC on Base). Keyless pre-sign analysis of {chain, from?, to, data, value?}: public-RPC eth_call revert check + static calldata decode predicting approval/transfer deltas + risk flags (unlimited approval, approval-for-all, reverts). Honest keyless limitation stated in the response (no full fork trace). Without payment returns the x402 challenge; pass x_payment. Free teaser: simulate_free.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['chain', 'to'], 'properties': {'to': {'type': 'string', 'description': '0x target contract/recipient.'}, 'data': {'type': 'string', 'description': '0x calldata (omit for a plain value transfer).'}, 'from': {'type': 'string', 'description': '0x sender (optional but improves accuracy).'}, 'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'value': {'type': 'string', 'description': 'Value in wei (optional).'}, 'x_payment': {'type': 'string', 'description': 'x402 payment payload (base64) for this PAID tool. If supplied it is forwarded as the X-PAYMENT header to settle the call and return the real result instead of a 402 challenge. Omit to get the price challenge first.'}}, 'additionalProperties': False}
simulate_free
Simulate — method + revert + risk level (FREE)
FREE. Method + revert flag + risk level + predicted effect types for a transaction. Real result, no wallet. Upgrade to simulate for the full predicted deltas + all risk flags.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['chain', 'to'], 'properties': {'to': {'type': 'string', 'description': '0x target contract/recipient.'}, 'data': {'type': 'string', 'description': '0x calldata (omit for a plain value transfer).'}, 'from': {'type': 'string', 'description': '0x sender (optional but improves accuracy).'}, 'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'value': {'type': 'string', 'description': 'Value in wei (optional).'}}, 'additionalProperties': False}
token_safety
Token honeypot / rug safety check (paid $0.02)
PAID $0.02 (x402, USDC on Base). Multi-chain token honeypot/rug check aggregating GoPlus token-security + honeypot.is buy/sell-tax simulation into a normalized 0-100 risk score with explainable reasons: honeypot/can't-sell, buy/sell tax, mint/blacklist/pausable/ownership privileges, top-holder concentration, LP-lock, contract verified/bytecode. Descriptive facts only — NOT a buy/sell signal. Without payment returns the x402 challenge; pass x_payment to settle. Free teaser: token_safety_free.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['address', 'chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'address': {'type': 'string', 'description': '0x token contract address.'}, 'x_payment': {'type': 'string', 'description': 'x402 payment payload (base64) for this PAID tool. If supplied it is forwarded as the X-PAYMENT header to settle the call and return the real result instead of a 402 challenge. Omit to get the price challenge first.'}}, 'additionalProperties': False}
token_safety_free
Token safety — score band + top-line flags (FREE)
FREE. Score band + top-line honeypot/tax/privilege flags for a token {address, chain}. Real result, no wallet. Upgrade to token_safety for the full numeric breakdown.
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['address', 'chain'], 'properties': {'chain': {'type': 'string', 'description': 'Chain: ethereum | base | bsc | polygon | arbitrum | optimism.'}, 'address': {'type': 'string', 'description': '0x token contract address.'}}, 'additionalProperties': False}
Added
simulate_free
Sept. 17, 2026, 12:53 p.m.
Added
simulate
Sept. 17, 2026, 12:53 p.m.
Added
approvals_free
Sept. 17, 2026, 12:53 p.m.
Added
approvals
Sept. 17, 2026, 12:53 p.m.
Added
decode_signature_free
Sept. 17, 2026, 12:53 p.m.
Added
decode_signature
Sept. 17, 2026, 12:53 p.m.
Added
token_safety_free
Sept. 17, 2026, 12:53 p.m.
Added
token_safety
Sept. 17, 2026, 12:53 p.m.