Private · unpublished · litmus-v14
Base-network MCP index
Independent, reproducible behavioral grades for the MCP servers an onchain agent on Base can use — the projects integrating Base MCP, and the wider DeFi, data, and infrastructure servers that support the network.
Base’s own skill states its plugins are “built by third parties… Base doesn’t operate, endorse, or audit them.” This is that audit — extended to the wider set of Base-supporting MCP servers.
Monitor this ecosystem
Monitor the Base MCP ecosystem.
This index is a snapshot. We re-grade Base's MCP servers and skills on a cadence and flag regressions — a dropped grade, a newly failing probe, a changed tool surface — before they reach your users. Set up per network.
Prefer to write us directly? hello@polygraph.so
C-01 tool-output injection · C-02 permission/egress overreach · C-03 sensitive-data handling · C-04 adversarial input (off-table; caps the letter at D). Adoption is reach (0–100), not safety — the grade is the verdict. Reproduce any grade by re-running the open harness against the same ref. Each server links to its polygraph report; see the full MCP Security Index.