AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

Claudit

mcp-marchev-claudit · by marchev

MCP server for searching Solodit smart contract security findings

No reviews yet
0 installs
39 views
0.0% view→install

Install

$ agentstack add mcp-marchev-claudit

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

2 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Destructive filesystem operation.
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
5mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Claudit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

claudit

Smart contract security findings for AI coding agents

Search Solodit's 20,000+ audit findings from Claude Code and Codex CLI.

[](https://www.npmjs.com/package/@marchev/claudit) [](LICENSE) [](package.json) [](https://giveth.io/project/claudit-0)

[Quick Start](#quick-start) · [Tools](#tools) · [Examples](#examples) · [Configuration](#configuration)



Quick Start

curl -fsSL https://raw.githubusercontent.com/marchev/claudit/main/install.sh | sh

The installer detects Claude Code and/or Codex CLI, prompts for your Solodit API key, and registers the MCP server.

Then just ask:

> Find 5 solo findings by 0x52 at Sherlock

Manual install

Claude Code

claude mcp add --scope user --transport stdio solodit \
  --env SOLODIT_API_KEY=sk_your_key_here \
  -- npx -y @marchev/claudit@latest

# (Optional) Install companion skill
mkdir -p ~/.claude/skills/solodit
curl -fsSL https://raw.githubusercontent.com/marchev/claudit/main/.claude/skills/solodit/SKILL.md \
  -o ~/.claude/skills/solodit/SKILL.md

Codex CLI

codex mcp add solodit \
  --env SOLODIT_API_KEY=sk_your_key_here \
  -- npx -y @marchev/claudit@latest

Tools

search_findings

Search across all findings with filters.

| Parameter | Type | Description | |:----------|:-----|:------------| | keywords | string | Text search in title and content | | severity | string[] | HIGH MEDIUM LOW GAS (case-insensitive) | | firms | string[] | Audit firm names | | tags | string[] | Vulnerability tags | | language | string | Programming language | | protocol | string | Protocol name (partial match) | | reported | string | 30 60 90 alltime | | sort_by | string | Recency Quality Rarity | | sort_direction | string | Desc (default) Asc | | page | int | Page number (default 1) | | page_size | int | Results per page (default 10, max 100) | | advanced_filters | object | See below |

Advanced filters

| Field | Type | Description | |:------|:-----|:------------| | quality_score | number | Minimum quality score (0-5) | | rarity_score | number | Minimum rarity score (0-5) | | user | string | Finder/auditor handle | | min_finders | number | Minimum number of finders | | max_finders | number | Maximum number of finders | | reported_after | string | ISO date string | | protocol_category | string[] | Protocol categories | | forked | string[] | Forked protocol names |

get_finding

Get full details for a specific finding by numeric ID, Solodit URL, or slug.

get_filter_options

List all valid filter values — firms, tags, categories, languages — with finding counts.


Examples

Search Solodit for oracle manipulation HIGH severity findings
Find all Sherlock findings about flash loans
What reentrancy issues exist in lending protocols?
Show me solo findings by 0x52
Get recent HIGH severity Solidity findings sorted by quality

Configuration

Update API key

Claude Code:

claude mcp remove solodit
claude mcp add --scope user --transport stdio solodit \
  --env SOLODIT_API_KEY=sk_new_key \
  -- npx -y @marchev/claudit@latest

Codex CLI:

codex mcp remove solodit
codex mcp add solodit \
  --env SOLODIT_API_KEY=sk_new_key \
  -- npx -y @marchev/claudit@latest

Cursor MCP

{
  "mcpServers": {
    "solodit": {
      "command": "npx",
      "args": ["-y", "@marchev/claudit@latest"],
      "env": {
        "SOLODIT_API_KEY": "sk_new_key"
      }
    }
  }
}

Uninstall

Claude Code:

claude mcp remove solodit
rm -rf ~/.claude/skills/solodit

Codex CLI:

codex mcp remove solodit

Development

git clone https://github.com/marchev/claudit.git
cd claudit
npm install
npm run build

# Test locally
SOLODIT_API_KEY=sk_your_key node dist/index.js

Support

Claudit is a solo-maintained public good for Ethereum security. If it saves you time or finds bugs for you, consider supporting its continued development on Giveth:

giveth.io/project/claudit-0


MIT License

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.