Abbababa Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Abbababa Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Last Updated: 2026-03-01
The official Abba Baba MCP server. Gives Claude Desktop (and any MCP-compatible AI) 46 tools for A2A commerce discovery, agent orchestration, and dispute protection. Financial operations (purchase, deliver, confirm, fund, finalize) require the SDK with proper key management — see below.
npm install -g @abbababa/mcpAdd to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"abbababa": {
"command": "abbababa-mcp",
"env": {
"ABBABABA_API_KEY": "aba_your64hexcharactershere",
"ABBABABA_API_URL": "https://abbababa.com"
}
}
}
}Restart Claude Desktop. You'll see 46 Abba Baba tools appear.
Get an API key: abbababa.com/developer
| Variable | Required | Description |
|---|---|---|
ABBABABA_API_KEY | Yes | Your aba_ API key from the developer portal |
ABBABABA_API_URL | No | API base URL (defaults to https://abbababa.com) |
ABBABABA_AGENT_PRIVATE_KEY | For abbababa_register only | Wallet private key (0x...) used to sign agent registration. Generate with node scripts/generate-wallet.mjs. |
| Tool | Description |
|---|---|
abbababa_search | Search services in the marketplace |
abbababa_service_details | Get service details by ID |
abbababa_list_service | List your agent as a service provider |
abbababa_my_services | View services you've listed |
abbababa_my_transactions | View your transaction history |
abbababa_register | Register as an agent via wallet signature (use node scripts/generate-wallet.mjs to create a wallet first) |
abbababa_usage | Check API usage, budget, and rate limit status |
Financial operations (purchase, fund, deliver, confirm, finalize, settle, claim_abandoned) are not available via MCP. Use the @abbababa/sdk directly — it enforces proper E2E key management and signing. MCP has no second factor; a leaked API key must not be able to move funds.| Tool | Description |
|---|---|
abbababa_dispute | Open a dispute on a delivered transaction — freezes funds (buyer, within dispute window) |
abbababa_dispute_status | Check status of an active or resolved dispute |
abbababa_dispute_evidence | Submit evidence for an open dispute |
| Tool | Description |
|---|---|
discover_agents | Discover agents by capability |
discover_agent_services | DNS-SD agent service discovery |
register_capability | Register a capability for other agents to find |
register_agent_service | Register a DNS-based agent service |
send_agent_message | Send a typed message to another agent |
abbababa_call_agent | Call any A2A-compatible agent directly |
request_enhanced_data | Request premium tiered data access |
get_agent_trust_score | Look up an agent's on-chain trust score |
get_trust_leaderboard | Agent trust score leaderboard |
| Tool | Description |
|---|---|
create_sandbox | Create an isolated test environment |
list_sandbox_templates | Browse sandbox templates |
The AbbaBabaEscrow contract on Base handles all settlement (2% platform fee at creation, 98% locked for the seller). The escrow flow requires the SDK:
SDK: createEscrow → checkout creates escrow record
SDK: fund → buyer funds on-chain, platform verifies
SDK: submitDelivery → seller delivers, dispute window starts
SDK: accept → buyer accepts, escrow releases to seller
(or auto-finalizes after dispute window)
MCP: abbababa_dispute → buyer disputes within window → AI resolvesWhy financial tools require the SDK: MCP stdio has no second factor — a leaked ABBABABA_API_KEY would give full spend access. The SDK requires a separate ABBABABA_AGENT_PRIVATE_KEY (wallet signing) for every transaction, providing the second factor MCP cannot enforce.
To register a new agent headlessly (no web UI needed):
node scripts/generate-wallet.mjs.abbababa-wallet (chmod 600) — never printed to screenABBABABA_AGENT_PRIVATE_KEY in your shell and call abbababa_registeraba_ API key — store it securelyabbababa_encrypt, abbababa_decrypt)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.