Weakspot MCP Server
dev.weakspot/weakspotv0.1.1
Audit Solidity and Rust smart contracts from your editor. Pays per audit in USDC over x402.
context tax
queued
security
queued
cold start
queued
freshness
Maintained34d ago
Install Weakspot MCP server
Install in Claude Code
claude mcp add weakspot -e WEAKSPOT_PRIVATE_KEY='<weakspot-private-key>' -- npx -y weakspot-mcpInstall in Cursor
{
"mcpServers": {
"weakspot": {
"command": "npx",
"args": [
"-y",
"weakspot-mcp"
],
"env": {
"WEAKSPOT_PRIVATE_KEY": "<weakspot-private-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"weakspot": {
"command": "npx",
"args": [
"-y",
"weakspot-mcp"
],
"env": {
"WEAKSPOT_PRIVATE_KEY": "<weakspot-private-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"weakspot": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"weakspot-mcp"
],
"env": {
"WEAKSPOT_PRIVATE_KEY": "<weakspot-private-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"weakspot": {
"command": "npx",
"args": [
"-y",
"weakspot-mcp"
],
"env": {
"WEAKSPOT_PRIVATE_KEY": "<weakspot-private-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| WEAKSPOT_PRIVATE_KEY | — | yes | Private key of a funded Base wallet. This server SPENDS REAL USDC from it with no human in the loop — use a fresh wallet funded with only what you are willing to lose, never a personal or deployer key. Only weakspot_audit needs it; the pricing, status and wallet-status tools work without one. |
| WEAKSPOT_MAX_USD | — | — | Hard cap in USD on any single audit (default 4, the highest tier). Checked twice: against the tier price, and again against the amount the server actually quotes. An LLM decides when to call the paying tool, so this is the main spend control. |
| WEAKSPOT_URL | — | — | Base URL of the Weakspot deployment to use. Defaults to https://weakspot.dev; override to point at staging or a self-hosted instance. |
| WEAKSPOT_RPC_URL | — | — | Base RPC endpoint, used only to read the wallet's USDC balance in weakspot_wallet_status. Nothing else needs it. |
Freshness
Maintained — last maintenance signal 34d ago. The newest of the signals below sets the band.
Last commit (default branch)
no data · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-09-05 · 34d ago · official registry · v0.1.1
FAQ
›How do I install the Weakspot MCP server in Claude Code?
Run: claude mcp add weakspot -e WEAKSPOT_PRIVATE_KEY='<weakspot-private-key>' -- npx -y weakspot-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Weakspot require an API key?
Yes. It expects WEAKSPOT_PRIVATE_KEY, of which 1 is a secret.
›Can I use Weakspot as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Weakspot in the official MCP registry?
Yes, as dev.weakspot/weakspot.