FHI MCP Server Security Audit

Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.

我该使用它吗

质量与安全性

B
描述质量
87%
模式完整度
72%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(2)

  • LOWTool 'payment_info' description lacks action verb在 payment_info 中
  • LOWTool 'sec_material_event_delta' description lacks action verb在 sec_material_event_delta 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~682token 数(工具定义)
~584 B典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.53%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "fhi-x402-security-tools": {
      "url": "https://polished-truth-c514.fhi-llc-1118.workers.dev/mcp"
    }
  }
}

远程端点

https://polished-truth-c514.fhi-llc-1118.workers.dev/mcpstreamable-http

它能做什么

工具清单

工具(6)

🟢 只读🟡 写入🔴 删除⚪ 未知
⚪payment_info

Free guide to the FHI MCP tools, Base-USDC x402 payment flow, and per-tool prices.

输入模式

{
  "type": "object",
  "properties": {}
}
🟡domain_change_evidence(domain)

Stateful DNS, CAA, and certificate-transparency monitoring for a public domain. The first call establishes a baseline; later calls return evidence changes and certificate-expiry signals. ($0.01 USDC on Base)

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪package_install_preflight(ecosystem, name, version, expectedName)

npm or PyPI install preflight: blocks missing packages, detects near-name typosquats when an expected name is supplied, and checks OSV advisories. ($0.01 USDC on Base)

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "PyPI"
      ]
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "version": {
      "type": "string"
    },
    "expectedName": {
      "type": "string"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪sec_material_event_delta(cik, ticker, since)

New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)

输入模式

{
  "type": "object",
  "properties": {
    "cik": {
      "type": "string"
    },
    "ticker": {
      "type": "string"
    },
    "since": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "since"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪mcp_payment_preflight(serverUrl)

MCP server security audit before an agent connects or pays: probes initialize and tools/list, then returns an ALLOW, CAUTION, or BLOCK risk score for command, filesystem, or wallet capabilities; prompt-injection or data-exfiltration signals; permissive JSON-schema inputs; missing HSTS; and a large tool surface. Does not execute tools. ($0.01 USDC on Base)

输入模式

{
  "type": "object",
  "properties": {
    "serverUrl": {
      "type": "string",
      "format": "uri"
    }
  },
  "required": [
    "serverUrl"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪mcp_vendor_due_diligence(mcpUrl, ticker, cik, since)

One decision-ready due-diligence dossier before an agent adopts or pays an MCP vendor: live MCP metadata and tool-risk preflight, DNS/CAA/certificate evidence, plus optional SEC material-filing evidence for a public company. Does not execute vendor tools or certify safety. ($0.10 USDC on Base)

输入模式

{
  "type": "object",
  "properties": {
    "mcpUrl": {
      "type": "string",
      "format": "uri"
    },
    "ticker": {
      "type": "string"
    },
    "cik": {
      "type": "string"
    },
    "since": {
      "type": "string"
    }
  },
  "required": [
    "mcpUrl"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社区

评价此服务器

证据

最近观测

已验证未记录版本6 个工具