FHI MCP Server Security Audit
Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.
Should I use this
Quality & Safety
Findings (2)
- LOWin payment_info
- LOWin sec_material_event_delta
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"fhi-x402-security-tools": {
"url": "https://polished-truth-c514.fhi-llc-1118.workers.dev/mcp"
}
}
}Remote endpoints
https://polished-truth-c514.fhi-llc-1118.workers.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (6)
⚪payment_info
Free guide to the FHI MCP tools, Base-USDC x402 payment flow, and per-tool prices.
Input Schema
{
"type": "object",
"properties": {}
}🟡domain_change_evidence(domain)
Stateful DNS, CAA, and certificate-transparency monitoring for a public domain. The first call establishes a baseline; later calls return evidence changes and certificate-expiry signals. ($0.01 USDC on Base)
Input Schema
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"minLength": 1
}
},
"required": [
"domain"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪package_install_preflight(ecosystem, name, version, expectedName)
npm or PyPI install preflight: blocks missing packages, detects near-name typosquats when an expected name is supplied, and checks OSV advisories. ($0.01 USDC on Base)
Input Schema
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"enum": [
"npm",
"PyPI"
]
},
"name": {
"type": "string",
"minLength": 1
},
"version": {
"type": "string"
},
"expectedName": {
"type": "string"
}
},
"required": [
"ecosystem",
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪sec_material_event_delta(cik, ticker, since)
New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)
Input Schema
{
"type": "object",
"properties": {
"cik": {
"type": "string"
},
"ticker": {
"type": "string"
},
"since": {
"type": "string",
"minLength": 1
}
},
"required": [
"since"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪mcp_payment_preflight(serverUrl)
MCP server security audit before an agent connects or pays: probes initialize and tools/list, then returns an ALLOW, CAUTION, or BLOCK risk score for command, filesystem, or wallet capabilities; prompt-injection or data-exfiltration signals; permissive JSON-schema inputs; missing HSTS; and a large tool surface. Does not execute tools. ($0.01 USDC on Base)
Input Schema
{
"type": "object",
"properties": {
"serverUrl": {
"type": "string",
"format": "uri"
}
},
"required": [
"serverUrl"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪mcp_vendor_due_diligence(mcpUrl, ticker, cik, since)
One decision-ready due-diligence dossier before an agent adopts or pays an MCP vendor: live MCP metadata and tool-risk preflight, DNS/CAA/certificate evidence, plus optional SEC material-filing evidence for a public company. Does not execute vendor tools or certify safety. ($0.10 USDC on Base)
Input Schema
{
"type": "object",
"properties": {
"mcpUrl": {
"type": "string",
"format": "uri"
},
"ticker": {
"type": "string"
},
"cik": {
"type": "string"
},
"since": {
"type": "string"
}
},
"required": [
"mcpUrl"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence