Atv Sdk — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Atv Sdk (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AI-native access to Aarna's tokenized yield vaults on Ethereum and Base. 20 tools for vault discovery, performance metrics, transaction building, and portfolio tracking.
API Base URL: https://atv-api.aarna.ai MCP Endpoint: https://atv-api.aarna.ai/mcp (Streamable HTTP) API Docs: https://atv-api.aarna.ai/docs
The hosted API at https://atv-api.aarna.ai is available to anyone with a valid API key. All requests require an x-api-key header.
To get an API key, reach out to us at [email protected].
Once you have your API key, add the config to your client:
Edit ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"atv": {
"url": "https://atv-api.aarna.ai/mcp",
"headers": { "x-api-key": "YOUR_API_KEY" }
}
}
}claude mcp add atv --transport http https://atv-api.aarna.ai/mcp --header "x-api-key: YOUR_API_KEY"Create .cursor/mcp.json in your project root:
{
"mcpServers": {
"atv": {
"url": "https://atv-api.aarna.ai/mcp",
"headers": { "x-api-key": "YOUR_API_KEY" }
}
}
}Add to .vscode/settings.json:
{
"mcp": {
"servers": {
"atv": {
"url": "https://atv-api.aarna.ai/mcp",
"headers": { "x-api-key": "YOUR_API_KEY" }
}
}
}
}{
"mcpServers": {
"atv": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://atv-api.aarna.ai/mcp", "--header", "x-api-key:YOUR_API_KEY"]
}
}
}| Tool | Description |
|---|---|
list_vaults | List all vaults, optionally filter by chain |
get_vault | Get metadata for a specific vault by address |
| Tool | Description |
|---|---|
get_vault_nav | Current NAV (Net Asset Value) in USD |
get_vault_tvl | Current TVL (Total Value Locked) in USD |
get_vault_apy | APY breakdown: base + reward + total |
| Tool | Description |
|---|---|
get_deposit_status | Whether deposits are paused |
get_withdraw_status | Whether withdrawals are paused |
get_queue_withdraw_status | Whether queued withdrawals are paused |
| Tool | Description |
|---|---|
build_deposit_tx | Build approve + deposit transaction steps |
build_withdraw_tx | Build withdrawal transaction steps |
build_stake_tx | Build approve + stake steps (timelock vaults) |
build_unstake_tx | Build unstake step (timelock vaults) |
| Tool | Description |
|---|---|
build_queue_withdraw_tx | Initiate a queued withdrawal |
build_unqueue_withdraw_tx | Cancel a pending queued withdrawal |
build_redeem_withdraw_tx | Claim a completed queued withdrawal |
| Tool | Description |
|---|---|
get_vault_portfolio | Underlying token portfolio |
get_historical_nav | NAV data points over a period (7, 30, 60, 360, max) |
get_historical_tvl | TVL data points over a period (7, 30, 60, 360, max) |
get_total_tvl | Platform-wide or per-vault TVL |
get_user_investments | User portfolio and positions |
All endpoints require x-api-key header and are prefixed with /v1.
| Method | Path | Description |
|---|---|---|
| GET | /v1/vaults | List all available vaults |
| GET | /v1/vaults/tvl | Platform-wide TVL |
| GET | /v1/vaults/:address | Vault metadata |
| GET | /v1/vaults/:address/nav | NAV price |
| GET | /v1/vaults/:address/tvl | Vault TVL |
| GET | /v1/vaults/:address/apy | APY breakdown |
| GET | /v1/vaults/:address/deposit-status | Deposit pause status |
| GET | /v1/vaults/:address/withdraw-status | Withdraw pause status |
| GET | /v1/vaults/:address/queue-withdraw-status | Queue-withdraw pause status |
| GET | /v1/vaults/:address/portfolio | Token portfolio |
| GET | /v1/vaults/:address/historical-nav | Historical NAV (days: 7,30,60,360,max) |
| GET | /v1/vaults/:address/historical-tvl | Historical TVL (days: 7,30,60,360,max) |
| Method | Path | Description |
|---|---|---|
| GET | /v1/deposit-tx | Build deposit calldata |
| GET | /v1/withdraw-tx | Build withdraw calldata |
| GET | /v1/stake-tx | Build stake calldata |
| GET | /v1/unstake-tx | Build unstake calldata |
| GET | /v1/queue-withdraw-tx | Build queue-withdraw calldata |
| GET | /v1/unqueue-withdraw-tx | Build unqueue-withdraw calldata |
| GET | /v1/redeem-withdraw-tx | Build redeem-withdraw calldata |
| Method | Path | Description |
|---|---|---|
| GET | /v1/user-investments | User portfolio data |
| ALL | /mcp | MCP server (Streamable HTTP) |
| Method | Path | Description |
|---|---|---|
| GET | /health | Health check |
| GET | /openapi.json | OpenAPI 3.1 spec |
| GET | /docs | Interactive API reference |
| GET | /llms.txt | LLM-friendly documentation (llms.txt spec) |
| GET | /.well-known/agent.json | A2A agent card |
import { AtvClient } from '@atv/sdk';
const client = new AtvClient({
apiKey: 'atv_...',
baseUrl: 'https://atv-api.aarna.ai',
});
const vaults = await client.vaults.list({ chain: 'base' });
const nav = await client.vaults.nav('0xVaultAddress');docker build -t atv-api \
--build-arg AWS_ACCESS_KEY_ID=... \
--build-arg AWS_SECRET_ACCESS_KEY=... \
--build-arg AWS_DEFAULT_REGION=us-east-1 .
docker run -p 3000:3000 atv-apiRequired environment variables (set in AWS Secrets Manager under atv-sdk):
DATABASE_URL — PostgreSQL connection stringREDIS_URL — Redis host:portRPC_URL_ETHEREUM — Ethereum JSON-RPC endpointRPC_URL_BASE — Base JSON-RPC endpointSTRAPI_URL — CMS URLSTRAPI_API_TOKEN — CMS API tokenENGINE_BASE_URL — Aarna engine APIpnpm install
cp .env.example apps/api/.env
# Fill in environment variables
pnpm migrate
pnpm devAPI: http://localhost:3000 | Docs: http://localhost:3000/docs
atv-sdk/
├── apps/api/ # Express API server + MCP server
├── packages/sdk/ # TypeScript SDK (@atv/sdk)
├── packages/mcp-server/ # npm connector package (@aarna-ai/mcp-server-atv)
├── server.json # MCP registry manifest
└── docs/ # Guidespnpm build
# API: apps/api/dist/
# SDK: packages/sdk/dist/ (CJS + ESM)See docs/customer-onboarding.md for how to generate API keys, manage tiers, revoke access, and run admin queries.
MIT — see LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.