by BlockRunAI
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
# Add to your Claude Code skills
git clone https://github.com/BlockRunAI/blockrun-mcpLast scanned: 5/18/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@blockrun/llm: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@solana/buffer-layout-utils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@solana/spl-token: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "bigint-buffer: bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function",
"severity": "high"
},
{
"type": "npm-audit",
"message": "bn.js: bn.js affected by an infinite loop",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express-rate-limit: express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono added timing comparison hardening in basicAuth and bearerAuth",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "low"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
}
],
"status": "WARNING",
"scannedAt": "2026-05-18T08:03:51.644Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how blockrun-mcp compares with popular alternatives.
blockrun-mcp is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by BlockRunAI. Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments. It has 395 GitHub stars.
blockrun-mcp returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/BlockRunAI/blockrun-mcp" and add it to your Claude Code skills directory (see the Installation section above).
blockrun-mcp is primarily written in TypeScript. It is open-source under BlockRunAI on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh blockrun-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
claude mcp add blockrun -s user -- npx -y @blockrun/mcp@latest
BlockRun MCP is an open-source Model Context Protocol server that gives Claude — and any MCP-compatible agent — 19 tools for real-time data and real actions: 82 LLMs, image & video generation, prediction-market data, live web/X search, on-chain queries across 40 chains, and the ability to place real, USDC-settled bets on Polymarket.
You pay per call, and you choose how. Wallet mode authenticates with a signature and settles each call in USDC via the x402 protocol — no account, no credit card, no subscription, on Solana or Base. Account mode authenticates with a BlockRun API key (brk_live_…) from user.blockrun.ai, routes service calls through api.blockrun.ai, and draws down card- or wire-funded account credit at exact usage. Same 19 tools either way. MIT licensed.
Read live Polymarket odds and place the bet, from one self-custody wallet, pay-per-call. Jump to Polymarket trading →
Every other data integration was built for human developers — create an account, copy an API key into .env, add a credit card, repeat for every vendor.
BlockRun gives you both payment rails without rebuilding the integration. Use a wallet when the agent should self-custody funds, or use an account key when a team wants card-funded credits and a dashboard.
blockrun_chat mode:"free", blockrun_dex, crypto blockrun_price, blockrun_models) costs $0.blockrun_polymarket places real, confirm-gated trades.BLOCKRUN_CONFIRM_SPEND=on and the agent pauses before any paid call above your threshold; nothing is signed until you approve. Details ↓~/.blockrun/.session, 0600 — or the OS keychain once you opt into BLOCKRUN_KEYCHAIN=strict). BlockRun can't move your funds.| Raw provider APIs | Typical single-vendor MCP | BlockRun MCP | |
|---|---|---|---|
| Setup | Account + API key per vendor | Account/key for 1 vendor | Wallet auto-created — or one BlockRun key for everything |
| Payment | Credit card, monthly minimums | Credit card / vendor plan | USDC per-call via x402, or card/wire-funded account credit |
| Data sources | One per integration | One vendor | 19 tools — LLMs, media, markets, chain |
| Place real bets | Build it yourself | Rare | Yes — Polymarket CLOB, confirm-gated |
| Pay-chain | — | — | Solana + Base, or api.blockrun.ai with no chain at all |
| Agent budgets | Manual | — | Built-in per-agent delegation |
| Spend approval | — | — | Ask-before-pay dialog (MCP elicitation) |
| Generative UI | — | Rare | Order card + wallet panel (MCP Apps) |
| Open source | Varies | Varies | Yes (MIT) |
✓ One wallet or one account key · ✓ Pay-per-call · ✓ Reads and trades · ✓ Multi-chain · ✓ Agent-ready · ✓ Open source
Before BlockRun, Claude can't answer:
After BlockRun, it can. Each query costs fractions of a cent — billed from a local USDC wallet, or from card-funded credit on a BlockRun account through api.blockrun.ai. No subscriptions, no per-vendor signups.
| Wallet (default) | API key | |
|---|---|---|
| Setup | Nothing — a wallet is created on first run | Sign in at user.blockrun.ai, mint a key, use it against [api.bl |