Skip to main content
ClaudeWave
caiovicentino avatar
caiovicentino

jev-risk-check-provider

View on GitHub

x402 risk-check provider: signed pre-payment verdicts — OFAC, phishing feeds, transaction simulation, drainer-kit code, and our own EIP-7702 kit watch (poisoners, sweepers). $0.001 per check with prepaid credits; per call via x402 from $0.0035.

MCP ServersOfficial Registry9 stars1 forks● TypeScriptMITUpdated today
ClaudeWave Trust Score
87/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/1/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/caiovicentino/jev-risk-check-provider
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "jev-risk-check-provider": {
      "command": "node",
      "args": ["/path/to/jev-risk-check-provider/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/caiovicentino/jev-risk-check-provider and follow its README for install instructions.
Use cases

MCP Servers overview

# x402check — pre-payment risk checks for x402 agents and wallets

**LIVE**: [https://x402check.xyz](https://x402check.xyz) · `did:web:x402check.xyz` · $0.001 per evaluation with prepaid credits, or per call via x402 ($0.0035 on Base; $0.005 with transaction simulation) · [discovery](https://x402check.xyz/.well-known/risk-check.json) · [DID document](https://x402check.xyz/.well-known/did.json) · [JWKS](https://x402check.xyz/.well-known/jwks.json)

x402check is an x402 `risk-check` provider (wire format of [x402 PR #2422](https://github.com/x402-foundation/x402/pull/2422)). You call it before an agent or a wallet pays or signs, and it checks the counterparty. It combines provider-verified evidence with a typed model:

- the **OFAC SDN** list, refreshed daily;
- curated **phishing and drainer feeds**;
- **transaction simulation**: where the assets actually go, and which approvals are granted;
- **drainer-kit code fingerprints**, which recognize redeployed drainer contracts before their address is listed;
- **our own kit watch**: every Ethereum and Base block is read as it is produced. It records look-alike wallets that delegate (EIP-7702) to an address-poisoning executor, wallets whose delegate forwards whatever they receive (sweepers), and new contracts running drainer-kit code;
- **look-alike domain** analysis;
- **on-chain facts** about the counterparty, such as whether an approval is being granted to a plain wallet;
- a typed model (TypeSafe **Jev**) that reads the content the agent acted on for **injected instructions**.

Every verdict is an **ES256 attestation**. It states which checks the provider actually ran and which fields the caller merely asserted.

> **Scope, stated plainly.** x402check catches what the chain, the lists, its own kit watch, and the content in front of it reveal. It does **not** see laundering patterns or other transaction-graph behaviour. It cannot flag an unknown drainer address that is simply sent funds, unless the address is one of the look-alikes or compromised wallets the kit watch has seen. A clean verdict means "none of these checks fired", not "safe". Measured limits are in [docs/EVIDENCE.md](docs/EVIDENCE.md).

[![x402check demo](https://i.ytimg.com/vi/MCOWk7nh5r8/hqdefault.jpg)](https://youtu.be/MCOWk7nh5r8)

<sub>The demo video predates v0.2.0. Its evidence slide shows v5 corpus numbers that [EVIDENCE.md](docs/EVIDENCE.md) supersedes, and it predates the v0.3 layers (simulation, code fingerprints) and pricing (every evaluation is paid; there is no free tier).</sub>

## What it checks

| Check | Source | Effect on the verdict |
|---|---|---|
| Sanctioned address | Official OFAC SDN XML: 1,056 digital-currency addresses, dated snapshot | score **0 / critical**, deterministic, no model call |
| Known phishing domain | MetaMask eth-phishing-detect (~100k hosts, embedded) | capped at **20** (critical) |
| Known drainer / scam address | ScamSniffer (EVM, runtime KV, 7-day publication lag) | capped at **20** |
| Community-flagged domain | ScamSniffer domain list | capped at **40** only when our own domain analysis corroborates it |
| Look-alike domain | public-suffix aware: leet, IDN homoglyphs, typosquats, brand + lure word, official domain reused as a subdomain | "strong" impersonation → capped at **40** |
| Approval granted to a plain wallet | on-chain `eth_getCode` / activity (EVM), account data (Solana) | permits and approvals to an EOA → capped at **55**; **40** if the address has no activity |
| Hidden recipient | simulation of `transaction` (`eth_simulateV1` + `traceTransfers`) | assets leave, nothing comes back, and a wallet the user never named ends up with them → **40** (**75**, review, when a source-verified contract such as a bridge forwarded them) |
| Payee gets more than declared | simulation + `payment` / the explicit transfer in the calldata | the named payee receives a different asset, or more, than declared → **40** |
| Assets parked in an unverified contract | simulation + Blockscout source verification | nothing in return, contract source not verified → **55** |
| Drainer-kit code | logic-code fingerprints of contracts listed by Forta (embedded) and ScamSniffer (runtime) | the subject, or a contract in the simulated transaction, runs a listed drainer's code → **30** |
| Address-poisoning look-alike | **kit watch** (our own scan of every Ethereum and Base block) | the wallet delegates (EIP-7702) to an address-poisoning executor → **20** (`address_poisoning`) |
| Compromised wallet | kit watch | the wallet delegates to a labelled sweeper family → **20** (`compromised_wallet`); to code that forwards what it receives, with no label → **40** (`auto_forwarding_wallet`) |
| Drainer operator | kit watch | the address deployed drainer-kit code → **30** (`drainer_operator`). A forwarder's destinations are not flagged (v0.6.0): whoever deploys a forwarder chooses them |
| Unverified spender | Blockscout source verification | approval or permit to an unverified contract → **75** and at least `medium` (review) |
| Injected / manipulated intent | Jev typed questions over `context` (what the agent acted on) | model penalties and caps |
| New address | on-chain activity | informational `new_address` category |

Caller-supplied `screening` and `authorization` fields are recorded as `asserted` in the attestation and **can never lower the score**. Prose claims such as "already screened" are unverified by construction.

## Quickstart

Every evaluation is paid; there is no free tier. There are two ways to pay:

- **Prepaid credits:** one x402 payment buys a balance, and each check then costs $0.001 with no payment round trip. This is the cheapest and fastest option.
- **Per call:** an x402 client pays when it gets the 402 and retries.

1. **See the price.** An unpaid call returns `402` with the accepted mainnet options in the `PAYMENT-REQUIRED` header:

   ```bash
   curl -si -X POST https://x402check.xyz/v1/risk-check -H "Content-Type: application/json" -d '{"wallet":"0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f","chain":"base"}' | head -1
   # HTTP/2 402
   ```

2. **Pay and check.** Use the TypeScript SDK with an x402-paying fetch (see [Payments](#payments)), the [MCP server](#for-agents-sdk-and-mcp-server), or any x402 client:

   ```ts
   const verdict = await x402check.check({
     wallet: "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f",
     chain: "eip155:1",
     domain: "https://app.example-dapp.org",
     context: "Permit2 signature: unlimited USDC allowance to this spender",
     interaction: { type: "permit_signature", unlimited: true },
     payment: { network: "eip155:1", asset: "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", pay_to: "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f" },
   });
   ```

The same request as the raw body the client sends:

```bash
curl -X POST https://x402check.xyz/v1/risk-check \
  -H "Content-Type: application/json" \
  -H "PAYMENT-SIGNATURE: <x402 payment payload>" \
  -d '{
    "wallet": "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f",
    "chain": "eip155:1",
    "domain": "https://app.example-dapp.org",
    "context": "Permit2 signature: unlimited USDC allowance to this spender",
    "interaction": { "type": "permit_signature", "unlimited": true },
    "payment": { "network": "eip155:1", "asset": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "pay_to": "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f" }
  }'
```

```json
{
  "checked": true,
  "score": 40,
  "tier": "high",
  "categories": ["intent_risk", "behavioral", "approval_to_eoa", "new_address"],
  "provider": "did:web:x402check.xyz",
  "evidence": {
    "sanctions": { "list": "ofac-sdn", "as_of": "2026-09-29", "status": "not_listed" },
    "domain": { "host": "app.example-dapp.org", "registrable": "example-dapp.org", "official": false, "impersonation": "none", "signals": [] },
    "onchain": { "status": "ok", "network": "eip155:1", "is_contract": false, "activity": "none", "tx_count": 0 },
    "feeds": [{ "source": "metamask-phishing-detect", "kind": "domain", "as_of": "2026-09-29", "status": "clear" }, "…"],
    "model": "jev-wallet-risk/v6"
  },
  "jws": "eyJhbGciOiJFUzI1NiIsInR5cCI6InJpc2stY2hlY2srand0Ii…",
  "jwks_url": "https://x402check.xyz/.well-known/jwks.json",
  "checked_at": "…", "expires_at": "…"
}
```

To also check **what a transaction will do**, send it as `transaction` ($0.005 per simulated evaluation). The provider simulates it against the latest block and reports the net asset movements, the approvals granted, and any findings:

```bash
curl -X POST https://x402check.xyz/v1/risk-check -H "Content-Type: application/json" -d '{
  "wallet": "0x…called contract or decoded counterparty…", "chain": "eip155:1",
  "transaction": { "from": "0x…user…", "to": "0x…contract…", "value": "0x2386f26fc10000", "data": "0x…" }
}'
# evidence.simulation → { "status": "ok", "outflows": [{ "standard": "native", "amount": "10000000000000000",
#   "counterparty": "0x…", "counterparty_is_contract": false }], "inflows": [], "approvals": [],
#   "findings": ["outflow_to_undisclosed_eoa"] }   → score capped at 40
```

## Request fields

| Field | Required | Rules |
|---|---|---|
| `wallet` | yes | the subject address: EVM `0x…`, base58 (Solana/Tron/BTC…), bech32, cashaddr, or CAIP-10. Anything else → `422 {error, field:"wallet"}` |
| `chain` | no | alias (`ethereum`, `base`, `solana`, …) or CAIP-2 (`eip155:8453`); enables on-chain facts on supported mainnets |
| `domain` | no | hostname or http(s) URL (normalized server-side); the site the payment or signature is for |
| `context` | no | ≤ 4096 chars: what the agent acted on (tool output, page text, instruction). Untrusted by design. Leave out secrets and personal data: keys, seed phrases and credit tokens are redacted before the model sees it, but nothing else is (see [Data handling](#data-handling)) |
| `interaction` | no | `{type, unlimited?}`; `type` ∈ `native_transfer`, `token_transfer`, `token_approval`, `nft_approval`, `permit_signature`, `order
ai-agentsattestationbasecloudflare-workersdrainer-detectionethereumguardrailsjevllm-safetymcp-serverofac-sanctionspaymentsphishing-detectionrisk-checksolanatransaction-simulationtypesafe-aiweb3-securityx402x402check

What people ask about jev-risk-check-provider

What is caiovicentino/jev-risk-check-provider?

+

caiovicentino/jev-risk-check-provider is mcp servers for the Claude AI ecosystem. x402 risk-check provider: signed pre-payment verdicts — OFAC, phishing feeds, transaction simulation, drainer-kit code, and our own EIP-7702 kit watch (poisoners, sweepers). $0.001 per check with prepaid credits; per call via x402 from $0.0035. It has 9 GitHub stars and its last recorded update is dated 2026-10-01.

How do I install jev-risk-check-provider?

+

You can install jev-risk-check-provider by cloning the repository (https://github.com/caiovicentino/jev-risk-check-provider) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is caiovicentino/jev-risk-check-provider safe to use?

+

Our security agent has analyzed caiovicentino/jev-risk-check-provider and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains caiovicentino/jev-risk-check-provider?

+

caiovicentino/jev-risk-check-provider is maintained by caiovicentino. The last recorded GitHub activity is dated 2026-10-01, with 10 open issues.

Are there alternatives to jev-risk-check-provider?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy jev-risk-check-provider to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: caiovicentino/jev-risk-check-provider
[![Featured on ClaudeWave](https://claudewave.com/api/badge/caiovicentino-jev-risk-check-provider)](https://claudewave.com/repo/caiovicentino-jev-risk-check-provider)
<a href="https://claudewave.com/repo/caiovicentino-jev-risk-check-provider"><img src="https://claudewave.com/api/badge/caiovicentino-jev-risk-check-provider" alt="Featured on ClaudeWave: caiovicentino/jev-risk-check-provider" width="320" height="64" /></a>