Provides AI agents access to on-chain intelligence and blockchain analytics through a hosted MCP endpoint.
Review before connecting
The findings on this server are worth reviewing before you connect an agent to it.
Scanned 8 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The agent-zero-intel MCP server exposes 4 tools, focused primarily on general-purpose capabilities. Its published description reads: "Provides AI agents access to on-chain intelligence and blockchain analytics through a hosted MCP endpoint". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates agent-zero-intel C- — the findings are worth reviewing before you connect an agent to it. Its most notable findings include "Data-exfiltration parameters" and "No authorization on a public remote server". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check agent-zero-intel's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add agent-zero-intel to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.onchainagentintel.io/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Live coverage of the ERC-8004 agent economy across Base and Ethereum. Returns counts only: how many agents are indexed, how many expose a live MCP server / OpenAPI / well-known card, total MCP tools a
Top ERC-8004 agents by live capability, plus the most recently indexed. Three ranked lists — top by live MCP tool count, top by OpenAPI method count, and most-recently indexed — each with agent_id, ch
Objective, counts-only signals for one ERC-8004 agent. Args: chain: one of "base", "ethereum". agent_id: the numeric ERC-8004 agent id. Returns reachability, TLS validity, x402 support, payments-recei
A capped teaser of the on-chain agent-to-agent payment graph. Returns connected agents (nodes) and the value flowing between them (edges), capped to a small connected sample (≤200 nodes). This is a tr
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
entity, payment history, peers, market map, full graph).RecommendationRemove side-channel parameters; constrain tool inputs.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
Validates ZUGFeRD, Factur-X, and XRechnung e-invoices against EN 16931 with correction suggestions.
Tracks US tariff and trade-action changes from Federal Register documents and exposes them through an API for AI agents.
Instant rug-check for any EVM or Solana token, distilled to one clear 0-10 risk verdict.
Provides access to Bible translations, books, chapters, verses, and search functionality.
Remote-first MCP adapter for emitting Settlement Attestation Receipts; not a verifier.
Risk-ranked registry of AI tools for enterprise governance, enabling lookup of tool risk and shadow AI domain detection.