Lumen Pre-Sign Check
Use before signing an EVM tx or EIP-712 message: risk flags + verdict. Informational, no simulation
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"lumen-presign-check": {
"url": "https://lumenworks-x402-decoder.onrender.com/mcp/presign"
}
}
}Puntos de conexión remotos
https://lumenworks-x402-decoder.onrender.com/mcp/presignstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (2)
🟢explain_before_sign(transaction, calldata, typedData, chainId, expected_pay_to)
Lumen Pre-Sign Check. Use before signing any EVM transaction or EIP-712 message: returns {summary, flags[], verdict} with verdict looks_ok | review | do_not_sign_unless_intended. Flags unlimited approve/increaseAllowance, EIP-2612 Permit and Permit2 (typed data and on-chain), setApprovalForAll, unknown spender, admin calls (upgradeTo/transferOwnership), zero-price Seaport orders, long deadlines, chain mismatch and x402 payTo mismatch; decodes multicall/aggregate3 inner calls one level. Example: USDC approve(spender, 2^256-1) -> do_not_sign_unless_intended, UNLIMITED_APPROVAL. Agent policy: abort on do_not_sign_unless_intended, escalate review. Informational, not a security guarantee; looks_ok does not mean safe; no simulation. $0.002, no signup, free tier 20/h; not charged if the call errors.
Esquema de entrada
{
"type": "object",
"properties": {
"transaction": {
"type": "object",
"description": "Unsigned EVM transaction",
"properties": {
"to": {
"type": "string",
"description": "Target contract/address (0x…)"
},
"data": {
"type": "string",
"description": "Calldata hex (0x…)"
},
"value": {
"type": "string",
"description": "Native value in wei (decimal string)"
}
},
"required": [
"data"
]
},
"calldata": {
"type": "string",
"description": "Shortcut: calldata hex when you have no tx object"
},
"typedData": {
"type": "object",
"description": "EIP-712 typed data {domain, types, primaryType, message} (Permit, Permit2, EIP-3009, Seaport…)"
},
"chainId": {
"type": "number",
"description": "Chain the wallet is on; used for chain-mismatch checks"
},
"expected_pay_to": {
"type": "string",
"description": "For x402/EIP-3009 payments: the payTo you expect; mismatch is flagged"
}
},
"anyOf": [
{
"required": [
"transaction"
]
},
{
"required": [
"calldata"
]
},
{
"required": [
"typedData"
]
}
]
}🟢x402_payment_safety_check(url, method, payment_required, expected_pay_to, expected_network, ...)
FREE, deterministic pre-payment check for an x402 endpoint. Give {url} (we fetch its unpaid 402) and/or {payment_required} (402 JSON or base64 header), plus optional expected_pay_to, expected_network, max_price_usdc, listed_price_usdc, facilitator_url, client_config {max_per_call_usdc, max_daily_usdc, idempotency_key, allow_any_pay_to}. Returns verdict ok/review/do_not_pay with checks: HTTPS/health, payTo validity & mismatch, unknown asset/network, price sanity vs cap/listing, timeout/replay window, multiple payTo, unknown facilitator, missing spend caps/idempotency. Nothing is stored; inputs that look like private keys are rejected.
Esquema de entrada
{
"type": "object",
"properties": {
"url": {
"type": "string"
},
"method": {
"type": "string",
"enum": [
"POST",
"GET"
]
},
"payment_required": {},
"expected_pay_to": {
"type": "string"
},
"expected_network": {
"type": "string"
},
"max_price_usdc": {
"type": "number"
},
"listed_price_usdc": {
"type": "number"
},
"facilitator_url": {
"type": "string"
},
"client_config": {
"type": "object"
}
}
}Comunidad
Evidencia