Ulucoremcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Ulucoremcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Low-level blockchain interface MCP server for Algorand and Voi networks.
Provides chain primitives: account/asset/app inspection, transaction search, block retrieval, TEAL compilation, and transaction simulation.
npm installnode index.js{
"mcpServers": {
"ulu-core-mcp": {
"command": "node",
"args": ["/absolute/path/to/UluCoreMCP/index.js"]
}
}
}| Network | Chain |
|---|---|
algorand-mainnet | Algorand |
voi-mainnet | Voi |
Default endpoints use Nodely public APIs. Override via the ULU_CORE_NETWORKS environment variable:
{
"algorand-mainnet": {
"chain": "algorand",
"algodUrl": "https://your-algod-url",
"algodToken": "",
"indexerUrl": "https://your-indexer-url",
"indexerToken": ""
}
}index.js MCP server + tool registration
lib/
config.js Network configuration loader
errors.js Error handling utilities
networks.js Algod/Indexer client manager
algod.js Algod wrapper functions
indexer.js Indexer wrapper functions
normalize.js Response normalization (BigInt → string, Uint8Array → base64)UluCoreMCP returns facts, not interpretation. Raw chain data is normalized for JSON safety (BigInts become strings, byte arrays become base64) but otherwise passed through unmodified.
Protocol-specific logic, ecosystem conventions, wallet management, and transaction signing belong to higher-layer MCPs.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.