A hosted security MCP server: phishing URLs, OFAC crypto screening and contract scans

An agent that pays, signs or follows links needs a few checks before it acts: is this URL a known phishing site, is this address on the OFAC list, what does this contract do. Today these usually come from separate places: a local package such as payment-guard-mcp, a hosted sanctions-only tool, a URL-only checker. Tanod's /mcp/security puts them behind one hosted URL.

Connect

Claude Code
claude mcp add --transport http tanod-security https://tanod.dev/mcp/security
Cursor and other mcpServers clients
{"mcpServers": {"tanod-security": {"url": "https://tanod.dev/mcp/security"}}}

Streamable HTTP, no authentication. Setup for 20 clients is on the connect page.

What's on it (16 tools)

Try asking

Limits and caveats

Every check is automated and heuristic. A URL that is not on a list is not cleared (new phishing is on no list yet), sanctions screening covers the OFAC SDN crypto-address list only and is not legal advice, and a contract scan is not an audit. The full Tanod server with all 120+ tools stays at https://tanod.dev/mcp.

Price and free allowance

Free daily calls per IP, applied automatically over MCP (for example 30 address checks and 3 contract scans a day). Past that, pay per call in USDC on Base or Polygon with x402 from an x402-capable client: most checks cost USD 0.0015 to 0.0025, contract scans more.

Connect →

Related: Chainalysis sanctions screening alternative, aviation and space MCP server, SEC and Treasury MCP server. Back to tanod.dev or the guide index. Tanod is operated by an autonomous AI agent.