npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@iniit/defi-guard-mcp

v0.2.0

Published

Safety layer that checks a DeFi token or transaction on Base before you sign: honeypot detection, owner-power (mint/pause/blacklist) bytecode scan, unlimited-approval risk, Aave V3 position health, and gas-aware DEX quotes.

Readme

DeFi Guard MCP

The safety layer that checks a DeFi transaction or token before your agent (or you) signs — on Base L2. Sits in front of execution MCPs (it pairs with them, it doesn't compete): honeypot detection, owner-power scans, approval-drain checks, position health, and executable prices — all from live on-chain state.

No API keys required — works out of the box against public Base RPCs (bring your own RPC for speed via BASE_RPC_URL). Read-only: it never holds keys, signs, or submits.

Guard-before-signing tools

| Tool | What it answers | |---|---| | token_safety_screen | "Is this token safe to buy/approve before I sign?" — honeypot detection (can you actually sell it back?), real round-trip cost (fees + tax both ways), and whether ownership is renounced (a live owner can often change taxes / pause / mint). One risk verdict. | | scan_dangerous_capabilities | "What can the owner do to me?" — scans the deployed bytecode for owner-only powers: mint, pause, blacklist, adjustable fees/taxes, max-tx limits, trading toggles, proxy upgradeTo. Flags the capability, no explorer key needed. | | approval_risk | "Is this approval dangerous?" — reads the live allowance an owner granted a spender, flags unlimited approvals (the allowance-drain vector) and whether the spender is a contract or an EOA. Current exposure = what could be pulled right now. |

Data tools

| Tool | What it answers | |---|---| | aave_position_health | "Is this Aave V3 position safe?" — live health factor, collateral/debt in USD, LTV, liquidation threshold, and a plain risk level (healthy / elevated / critical / LIQUIDATABLE). | | quote_swap | "What would this swap actually return right now?" — exact-input quote via Uniswap V3 QuoterV2, best of all 4 fee tiers, with gas estimate. Executable price, not an oracle. | | token_risk_snapshot | "Can I get out of this token?" — ERC-20 metadata + real market depth measured by round-trip quotes (WETH → token → WETH) at two sizes. High round-trip loss = thin or trapped liquidity, whatever the chart says. |

Why round-trip depth instead of "liquidity" numbers

TVL and pool-size numbers are easy to fake and easy to misread. A round-trip quote against live state measures the only thing that matters: what you lose entering and exiting right now (fees + price impact, both ways). If a token can be bought but not sold, this tool says so (UNTRADABLE).

Install

npx @iniit/defi-guard-mcp        # or from source: npm install && npm run build

Claude Code

claude mcp add defi-guard -- npx -y @iniit/defi-guard-mcp

Any MCP client (Cursor, Windsurf, etc.)

{
  "mcpServers": {
    "defi-guard": {
      "command": "npx",
      "args": ["-y", "@iniit/defi-guard-mcp"],
      "env": { "BASE_RPC_URL": "https://your-rpc-if-you-have-one" }
    }
  }
}

BASE_RPC_URL is optional; without it the server rotates across public Base endpoints with automatic fallback and retries.

Example

"Before I approve TOKEN X to this router, is any of it risky?"

The agent calls token_safety_screen (can I sell it back? is ownership renounced?), scan_dangerous_capabilities (can the owner mint/blacklist/pause?), and approval_risk (is this an unlimited allowance to an EOA?) — and answers with live on-chain facts instead of vibes, before you sign.

Honesty notes (read this)

  • Quotes are simulations against live state (eth_call). Real execution adds slippage between quote and inclusion.
  • Contract addresses (Aave V3 Pool, QuoterV2) are Base mainnet constants, validated against live chain state.
  • This is a read-only tool. It never holds keys, signs, or submits transactions.
  • Not financial advice; it reports on-chain state, decisions are yours.

Test

npm run build   # tsc — type-checks and emits dist/. Tools are verified against live Base state.

License

MIT