What is the dev.weakspot/weakspot MCP server?
Audit Solidity and Rust smart contracts from your editor. Pays per audit in USDC over x402.
How to install dev.weakspot/weakspot
Copy-paste configuration for popular MCP clients.
WEAKSPOT_PRIVATE_KEYsecretPrivate key of a funded Base wallet. This server SPENDS REAL USDC from it with no human in the loop — use a fresh wallet funded with only what you are willing to lose, never a personal or deployer key. Only weakspot_audit needs it; the pricing, status and wallet-status tools work without one.
WEAKSPOT_MAX_USDHard cap in USD on any single audit (default 4, the highest tier). Checked twice: against the tier price, and again against the amount the server actually quotes. An LLM decides when to call the paying tool, so this is the main spend control.
WEAKSPOT_URLBase URL of the Weakspot deployment to use. Defaults to https://weakspot.dev; override to point at staging or a self-hosted instance.
WEAKSPOT_RPC_URLBase RPC endpoint, used only to read the wallet's USDC balance in weakspot_wallet_status. Nothing else needs it.
Related MCP servers

Free website analyzer: score any public URL 0-100 across 8 quality dimensions. No auth.

WebLens
Scrape, crawl, map and extract the web. Pay per call in USDC, no account or API key.
Coordination hub for AI coding agents: message teammates, ask humans, audit every event.
Cross-product MCP server for CRM, LeadKit, ProjectKit, Bookio. 10 action types, MIT open spec.
UBO, sanctions & ownership graph. 23 tools, 130.7M entities, 31 registries.
x402 game: take the crown, each take raises the next price 1.5x. hill_status is free.

