Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol server for the Blackhole DEX on Avalanche. Provides 48 tools for swaps, liquidity, CL positions, zaps, voting, locks, gauges, bribes, portfolio queries, pool analytics, gas estimation, and transaction execution.
| Category | Tools |
|---|---|
| Swap | swap_steps, quote |
| Liquidity (V2) | add_liquidity_steps, remove_liquidity_steps, withdraw_liquidity_steps |
| Liquidity (CL) | add_liquidity_cl_steps, create_cl_pool_steps |
| Deposit math | get_deposit_amounts |
| Zap | zap_add_liquidity_steps, zap_mint_cl_steps, zap_increase_liquidity_steps, zap_remove_liquidity_steps, zap_split_plan |
| Staking | stake_liquidity_steps, unstake_liquidity_steps |
| Fees & Emissions | claim_fees_steps, claim_emissions_steps, claim_rebase_steps, claim_voting_rewards_steps, claim_voting_rewards_payload |
| Locks (veNFT) | create_lock_steps, increase_lock_steps, merge_lock_steps, lock_advanced_steps |
| Voting | vote_steps, get_lock_vote_state, vote_leaderboard |
| Epoch | get_epoch_state |
| Gauges & Bribes | create_gauge_steps, add_bribes_steps |
| Portfolio & discovery | resolve_address, get_token_balances, get_user_positions, get_user_locks, get_whitelisted_tokens, get_opportunities |
| Pools, yield & ALM | pool_yield, get_pool_status, get_pool_lp_providers, get_alm_vaults, get_tokenomics |
| CL math & simulation | cl_tick_to_price, cl_price_to_tick, cl_position_detail, cl_apr_simulator |
| Operational / Safety | get_allowances, estimate_gas_and_tx_cost |
| Execution | execute_transactions |
#### Cursor (.cursor/mcp.json)
{
"mcpServers": {
"blackhole-mcp": {
"command": "npx",
"args": ["@blackhole-dex/blackhole-mcp-server"],
"env": {
"PRIVATE_KEY": "0x..."
}
}
}
}Or from source:
{
"mcpServers": {
"blackhole-mcp": {
"command": "bash",
"args": ["-lc", "cd /path/to/mcp-server && NODE_ENV=prod npx tsx src/index.ts"],
"env": {
"PRIVATE_KEY": "0x..."
}
}
}
}#### Claude Desktop
Option A — one command (recommended):
From npm:
claude mcp add --scope user blackhole-mcp -- npx @blackhole-dex/blackhole-mcp-serverFrom source:
claude mcp add --scope user blackhole-mcp -- bash -lc "cd /path/to/mcp-server && NODE_ENV=prod npx tsx src/index.ts"--scope user writes to your global Claude config (~/.claude.json) so the server is available in every project. Restart Claude Desktop after running.
Option B — manual JSON (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
From npm:
{
"mcpServers": {
"blackhole-mcp": {
"command": "npx",
"args": ["@blackhole-dex/blackhole-mcp-server"]
}
}
}From source:
{
"mcpServers": {
"blackhole-mcp": {
"command": "bash",
"args": ["-lc", "cd /path/to/mcp-server && NODE_ENV=prod npx tsx src/index.ts"]
}
}
}Restart Claude Desktop after editing the file.
#### Codex
Codex reads MCP server config from ~/.codex/config.toml (global) or .codex/config.toml (project-scoped, trusted projects only). The CLI and IDE extension share this file. See the Codex MCP docs for details.
Option A — Codex app / IDE (UI)
npx with args @blackhole-dex/blackhole-mcp-server, and add PRIVATE_KEY under environment variables if you plan to execute transactions.Codex MCP settings UI
Option B — CLI:
From npm:
codex mcp add blackhole-mcp --env PRIVATE_KEY=0x... -- npx @blackhole-dex/blackhole-mcp-serverFrom source:
codex mcp add blackhole-mcp --env PRIVATE_KEY=0x... -- bash -lc "cd /path/to/mcp-server && NODE_ENV=prod npx tsx src/index.ts"In the Codex TUI, use /mcp to verify the server is active.
Option C — manual `config.toml` (~/.codex/config.toml or .codex/config.toml in the project):
From npm:
[mcp_servers.blackhole-mcp]
command = "npx"
args = ["@blackhole-dex/blackhole-mcp-server"]
[mcp_servers.blackhole-mcp.env]
PRIVATE_KEY = "0x..."From source:
[mcp_servers.blackhole-mcp]
command = "bash"
args = ["-lc", "cd /path/to/mcp-server && NODE_ENV=prod npx tsx src/index.ts"]
[mcp_servers.blackhole-mcp.env]
PRIVATE_KEY = "0x..."npm install @blackhole-dex/blackhole-mcp-serverimport { createMcpServer } from "@blackhole-dex/blackhole-mcp-server";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
const server = createMcpServer();
const transport = new StdioServerTransport();
await server.connect(transport);Options:
createMcpServer()toolDefinitions, toolHandlersThe server uses production Avalanche mainnet configuration.
| Env | Network | RPC |
|---|---|---|
prod | Avalanche Mainnet | https://api.avax.network/ext/bc/C/rpc |
Optional runtime variables:
| Variable | Purpose |
|---|---|
RPC_URL | Override the Avalanche C-Chain RPC endpoint used for reads and execution. |
BASIC_GRAPH_URL | Override the basic pools subgraph URL. |
CL_GRAPH_URL | Override the concentrated-liquidity subgraph URL. |
GAMMA_VAULT_ADDRESSES | Comma-separated Gamma vault allowlist override. |
PRIVATE_KEY | Private key used by execute_transactions. The server derives userAddress from this key for any tool that needs it. |
USER_ADDRESS | Read-only fallback address when no private key is configured. |
When PRIVATE_KEY is configured, tools with userAddress can omit it; the server fills in the private key-derived address. execute_transactions requires the private key and will only broadcast when called with confirm: true.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.