@hexrailsec/mcp
v0.1.0
Published
HexRail as a Model Context Protocol server — give your AI agent (Claude Desktop, Cursor, Cline) the ability to scan smart contracts and code, replay famous exploit patterns, and post onchain attestations.
Maintainers
Readme
@hexrailsec/mcp
HexRail as a Model Context Protocol server. Give your AI coding agent the ability to scan smart contracts and code, replay famous exploit patterns, and look up onchain attestations — without leaving the IDE.
Install
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"hexrail": {
"command": "npx",
"args": ["-y", "@hexrailsec/mcp"]
}
}
}Restart Claude Desktop. The 4 HexRail tools appear in the MCP indicator.
Cursor
Settings → MCP → Add server:
{ "command": "npx", "args": ["-y", "@hexrailsec/mcp"] }Cline / Continue / any MCP-compatible client
Same one-liner — install as a stdio server with the npx command above.
Tools
| Tool | What it does |
|---|---|
| hexrail_scan | Scan a code snippet for security vulnerabilities |
| hexrail_scan_address | Scan a deployed contract by 0x address (Ethereum / Robinhood / Arbitrum / Optimism / Polygon) |
| hexrail_replay_hacks | Test code against 8 famous-exploit patterns (Bybit, Ronin, Euler, Beanstalk, Multichain, Curve, Radiant, zkSync) |
| hexrail_agent_identity | Return HexRail's onchain agent card (ERC-8004, pricing, capabilities) |
Optional env vars
HEXRAIL_API_KEY— Bearer key for the paid/api/v1/scanendpoint (bypasses x402 micropayment for higher throughput).HEXRAIL_BASE_URL— Override the defaulthttps://hexrailsec.io(for self-hosting).
Pricing
All tools above hit HexRail's free public endpoints. For higher rate limits or AI-powered deep review, the underlying API supports x402 pay-per-call in USDC on Robinhood or Solana (1¢ per scan, 2¢ per review).
License
MIT
