Lido MCP Server (the-wunmi/lido-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 80 tools. No publisher has claimed this listing.
Enables AI agents to interact with the Lido protocol for ETH staking, position management, and governance participation across Ethereum and L2 networks. It provides tools for querying balances, simulating transactions, and executing complex workflows like withdrawals and DAO voting through a safety-first interface.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
the-wunmi
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
lido_get_staking_aprlido_get_aragon_votelido_vote_on_proposallido_analyze_aragon_votelido_get_aragon_vote_scriptlido_get_aragon_vote_timelinelido_get_balanceslido_get_chain_infolido_convert_amountslido_get_easytrack_motionslido_get_easytrack_motionlido_get_easytrack_configGet Easy Track system configuration: objection threshold, motion duration, motions count limit, and registered factories.
lido_get_easytrack_factorieslido_object_easytrack_motionlido_check_gas_conditionslido_lock_steth_governancelido_unlock_steth_governancelido_estimate_veto_impactlido_get_veto_thresholdslido_get_governance_timelinelido_get_governance_position_impactlido_get_governance_statelido_get_voting_powerlido_l2_get_steth_balancelido_l2_transfer_stethlido_l2_get_wsteth_balancelido_l2_transfer_wstethlido_get_all_l2_balanceslido_l2_get_wsteth_infolido_analyze_positionlido_get_protocol_infolido_get_staking_modulesList all staking router modules (curated, community, DVT, etc.) with their IDs and status.
lido_get_node_operatorslido_get_contract_addresseslido_get_protocol_statuslido_get_rewardslido_get_snapshot_proposalslido_get_snapshot_proposallido_vote_on_snapshotlido_stake_ethlido_check_steth_ratelido_list_vaultslido_get_vaultlido_get_vault_hub_statsGet VaultHub overview: total vault count, hub address, and factory address.
lido_vault_fundlido_vault_withdrawlido_vault_pause_beacon_depositslido_vault_resume_beacon_depositslido_vault_mint_shareslido_vault_burn_shareslido_vault_rebalancelido_vault_createlido_vault_request_validator_exitlido_get_swap_quotelido_swap_eth_for_ldolido_get_token_infoGet token metadata for stETH, wstETH, or LDO: name, symbol, decimals, total supply, and contract address.
lido_get_allowancelido_approve_tokenlido_transfer_tokenlido_revoke_approvallido_list_earn_vaultslido_watch_vaultlido_unwatch_vaultStop watching a vault. Unsubscribes from events and removes from config.
lido_add_rulelido_remove_ruleRemove an alert rule from a watched vault by rule ID.
lido_test_notificationslido_list_watchesList all watched vaults with their rules, thresholds, and latest status.
lido_check_vaultlido_get_vault_alertsGet recent alerts from the vault monitor. Optionally filter by vault address.
lido_request_withdrawallido_claim_withdrawallido_get_withdrawal_requestslido_get_claimable_ethGet the total amount of ETH claimable from finalized withdrawal requests for an address.
lido_get_withdrawal_nft_ownerlido_transfer_withdrawal_nftlido_approve_withdrawal_nftlido_estimate_withdrawal_timelido_wrap_steth_to_wstethlido_wrap_eth_to_wstethlido_unwrap_wsteth_to_stethDisclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Unsafe object property setter in mathjs
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
ANTHROPIC_API_KEYAI explanations (optional) — when is set, each alert is passed to Claude which generates a plain-language explanation covering:ANTHROPIC_MODELLIDO_ALLOWED_RECEIVERSLIDO_ARBITRUM_RPC_URLLIDO_BASE_RPC_URLLIDO_BSC_RPC_URLLIDO_LINEA_RPC_URLLIDO_MANTLE_RPC_URLLIDO_MAX_TRANSACTION_ETHLIDO_MODELIDO_MODE_RPC_URLLIDO_OPTIMISM_RPC_URLLIDO_POLYGON_RPC_URLLIDO_PRIVATE_KEYLIDO_SCROLL_RPC_URLLIDO_ZIRCUIT_RPC_URLLIDO_ZKSYNC_RPC_URLMAINNET_RPC_URLTELEGRAM_BOT_TOKENTELEGRAM_CHAT_IDSMTP_FROMSMTP_HOSTSMTP_PASSSMTP_PORTSMTP_SECURESMTP_USERLicense file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tool test coverage
27/80 tools referenced in tests (34%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 4 high severity in production deps — mathjs@15.1.1 (high), mathjs@15.1.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/the-wunmi/lido-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check