Skip to content

Latest commit

 

History

History
101 lines (64 loc) · 2.55 KB

File metadata and controls

101 lines (64 loc) · 2.55 KB

🟡 dev-bd37-clicks-protocol

Autonomous DeFi yield for AI agents on Base. 4 read-only MCP tools: query agent info, simulate USDC payment splits, get live APY rates (Aave V3/Morpho), check referral stats. No API key needed.

Field Value
Grade B
Risk Score 17
Version smithery
Vendor Smithery
Source dev-bd37-clicks-protocol
Scan Date 2026-04-21
Scanner tooltrust-scanner/v0.3.8

Findings Summary

Severity Count
Critical 0
High 1
Medium 0
Low 1
Info 4

Detailed Findings

AS-014 — DEPENDENCY_INVENTORY_UNAVAILABLE

Severity: Info

Description: Tool did not expose metadata.dependencies or repo_url, so supply-chain coverage is limited.

Recommendation: Review and remediate the identified issue.


AS-014 — DEPENDENCY_INVENTORY_UNAVAILABLE

Severity: Info

Description: Tool did not expose metadata.dependencies or repo_url, so supply-chain coverage is limited.

Recommendation: Review and remediate the identified issue.


AS-014 — DEPENDENCY_INVENTORY_UNAVAILABLE

Severity: Info

Description: Tool did not expose metadata.dependencies or repo_url, so supply-chain coverage is limited.

Recommendation: Review and remediate the identified issue.


🟠 🔑 AS-002 — Excessive Permission Surface

Severity: High

Description: tool declares network permission

Recommendation: Tool requests broad permissions (exec/fs/network). Validate input parameters using Enums where possible, and restrict file system operations to explicit allowed directories.


🔵 ⚡ AS-011 — DoS Resilience — Missing Rate Limit / Timeout

Severity: Low

Description: tool performs network or execution operations but declares no rate-limit, timeout, or retry configuration

Recommendation: Declare explicit rate-limit, timeout, and retry configuration for all network and execution tools. Implement exponential back-off and surface resource state to the calling agent.


AS-014 — DEPENDENCY_INVENTORY_UNAVAILABLE

Severity: Info

Description: Tool did not expose metadata.dependencies or repo_url, so supply-chain coverage is limited.

Recommendation: Review and remediate the identified issue.


Scored using ToolTrust methodology · Raw JSON report