68
/ 100
25 days ago
glama

x402nano

Provides free Polymarket discovery data alongside paid deep-market intelligence tools via live x402 HTTP handshakes on Base mainnet. It allows AI agents to securely settle real, ultra-low-cost USDC micro-payments (0.05 USDC) directly over the Model Context Protocol.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 5 credentials: CDP_API_KEY_SECRET, FACILITATOR_SECRET, LEAD_PACK_ADMIN_TOKEN, MAINNET_BUYER_PRIVATE_KEY, X402_FACILITATOR_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high5 medium6 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highvite@6.0.0GHSA-fx2h-pf6j-xcff

vite: `server.fs.deny` bypass on Windows alternate paths

highvite@6.0.0GHSA-p9ff-h696-f583

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

mediumvite@6.0.0GHSA-356w-63v5-8wf4

Vite has an `server.fs.deny` bypass with an invalid `request-target`

mediumvite@6.0.0GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

mediumvite@6.0.0GHSA-859w-5945-r5v3

Vite's server.fs.deny bypassed with /. for files under project root

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAGENT_API_ORIGIN
configBASE_MAINNET_RPC_URL
configBRANCH
configBUYER_ADDRESS
configCDP_API_KEY_ID
🔐 secretCDP_API_KEY_SECRET
configCOMMIT_SHA
🔐 secretFACILITATOR_SECRET
configGIT_BRANCH
configGIT_COMMIT
configHOST
🔐 secretLEAD_PACK_ADMIN_TOKEN
configLEAD_PACK_FILE
configLEAD_PACK_FILE_REFRESH_MS
configLEAD_PACK_MODE
🔐 secretMAINNET_BUYER_PRIVATE_KEY
configMAINNET_EXPECTED_SELLER_ADDRESS
configMAINNET_MAX_USDC$env:="0.05"
configMAINNET_PAID_PATH$env:="/api/markets/brief?slug=will-gideon-saar-be-the-next-prime-minister-of-israel"
configMAINNET_PAYMENT_ACK$env:="PREFLIGHT_ONLY"
configMARKET_BRIEF_DISCLAIMER
configMARKET_BRIEF_ENABLED
configPARTNER_SELLER_ADDRESS
configPOLYMARKET_CLOB_URL
configPOLYMARKET_GAMMA_URL
configPOLYMARKET_MARKET_LIMIT
configPOLYMARKET_MARKET_POOL_LIMIT
configPOLYMARKET_MIN_LIQUIDITY
configPOLYMARKET_MIN_VOLUME
configPOLYMARKET_USER_AGENT
configPORT
configPREMIUM_LEAD_PACK_JSON
configPRICE_USDC
configRELEASE_NAME
configRELEASE_VERSION
configSELLER_ADDRESS
configSERVICE_NAME
configSOURCE_VERSION
configX402NANO_MCP_URL
configX402_ASSET
🔐 secretX402_FACILITATOR_API_KEY
configX402_FACILITATOR_URL
configX402_NETWORK
configX402_PAYMENT_MODE
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/bobjonesgood-x402nano-cizfw1)](https://m8ven.ai/mcp/bobjonesgood-x402nano-cizfw1)
commit: e7fe2e55b1fb1a095ddbb873fb44124b29b8fc11
code hash: 092cd4bc74139b4a295ccd349d2bee41db6baae60727c97fde461aeab3595d80
verified: 7/6/2026, 10:32:44 AM
view raw JSON →