npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

trustagent-mcp

v0.3.0

Published

MCP server for counterparty verification: OFAC sanctions screening, sybil-filtered ERC-8004 reputation, and contract bytecode analysis. Three tools work with no wallet and no signup.

Readme

trustagent-mcp

Is this counterparty safe to pay? An MCP server that screens EVM addresses, contracts and ERC-8004 agents — OFAC sanctions checks, sybil-filtered reputation, and contract bytecode analysis — as tools your assistant can call.

Three tools work with no wallet, no API key and no signup — and the free install carries no wallet dependencies at all.

Install

Add to your MCP client config (Claude Desktop: claude_desktop_config.json):

{
  "mcpServers": {
    "trustagent": {
      "command": "npx",
      "args": ["-y", "trustagent-mcp"]
    }
  }
}

That's it. Restart the client and ask something like "is 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 safe to send funds to?"

Free tools

| Tool | Answers | |---|---| | trustagent_check_address | Risk band, OFAC sanctions verdict, flag counts, confidence | | trustagent_resolve_agent | ERC-8004 identity: owner, payout wallet, and whether it is a working agent or an unactivated placeholder | | trustagent_pricing | What the paid tools cost, before spending anything |

Paid tools

Nine more tools appear when you supply a funded Base wallet. They pay per call over x402 in USDC — no account, no subscription, no minimum.

| Tool | Cost | Adds | |---|---|---| | trustagent_verify_address | $0.002 | Numeric 0–100 score, every scoring component itemised, all flags explained | | trustagent_analyze_contract | $0.01 | Bytecode analysis: privileged functions, proxy/upgradeability, dangerous opcodes | | trustagent_screen_addresses | $0.01 | Up to 10 addresses in one call | | trustagent_agent_reputation | $0.002 | Sybil-filtered ERC-8004 reputation | | trustagent_list_agents | $0.01 | The filtered ERC-8004 directory: which registered agents are actually alive and which accept x402, 100 per page with payout wallets — for finding counterparties rather than screening one you already have | | trustagent_search_agents | $0.005 | Finds live agents by declared skill, domain or free text — each row with its service endpoint and payout wallet | | trustagent_screen_endpoint | $0.005 | Takes an x402 endpoint URL instead of an address: reads its challenge under both protocol versions and screens the payout wallet it advertises | | trustagent_trace_funding | $0.01 | Walks an address's funding chain upward to who paid for it, with a cluster id — two addresses sharing one were not independent | | trustagent_watch_addresses | $0.002 | Re-checks up to 50 already-screened addresses for OFAC designations or delistings since a point in time — flat price, not per address |

Paying needs the x402-fetch client, which is an optional peer dependency — it pulls in the browser wallet stack (MetaMask, WalletConnect) that this server never uses, so the free install does not carry it. Add it alongside the package:

{
  "mcpServers": {
    "trustagent": {
      "command": "npx",
      "args": ["-y", "-p", "trustagent-mcp", "-p", "x402-fetch", "trustagent-mcp"],
      "env": { "TRUSTAGENT_WALLET_KEY": "0x…" }
    }
  }
}

If the wallet key is set but x402-fetch is missing, the paid tools are not registered and the server says so on startup — rather than offering tools that would fail when called.

Spending safety

These tools move real money, called by a model rather than a person. So:

  • Paid tools are not registered without both a wallet and the x402 client. An unconfigured install cannot spend by accident, and a model is never offered a tool that would fail — a tool that errors gets retried, a tool that is absent does not.
  • Per-call ceiling — TRUSTAGENT_MAX_PER_CALL_USD, default 0.05.
  • Session budget — TRUSTAGENT_MAX_SESSION_USD, default 1.00. A model looping on a retry is the realistic failure, and a per-call limit does not catch it.
  • Every paid tool states its cost in the description the model reads before calling it.

Use a wallet funded with only what you intend to spend. A few dollars of USDC on Base covers thousands of calls.

Configuration

| Variable | Default | Purpose | |---|---|---| | TRUSTAGENT_URL | https://trust-agent.io | Service to query | | TRUSTAGENT_WALLET_KEY | — | Funded Base wallet; enables the paid tools (needs x402-fetch installed) | | TRUSTAGENT_MAX_PER_CALL_USD | 0.05 | Refuse any single call above this | | TRUSTAGENT_MAX_SESSION_USD | 1.00 | Total across all paid calls this session |

What the answers mean

  • A sanctions hit is a strong signal warranting review. A miss is not clearance — the OFAC SDN list covers designated entities' known addresses, not funds that have moved through them, and not other jurisdictions' regimes.
  • Reputation is chain-scoped. Scores do not transfer between chains.
  • recommendation: "insufficient_data" means no judgment was possible — treat it as unknown, not as risky.
  • 92.6% of ERC-8004 feedback on Base is coordinated, which is why the reputation tool filters by funding provenance rather than reading the registry at face value.

The service reads the registries and never writes feedback, so it cannot inflate the data it scores.

Links

MIT