Team Ai
Apppublic

shravankumar8/DeFi_Security_Agent

sourceHugging Faceupdated 1y agoView on Hugging Face
0likes
App README

πŸ›‘οΈ DeFi Security Agent - Gradio Agents & MCP Hackathon 2025

Track Tags: mcp-server-track, agent-demo-track

Overview

The DeFi Security Agent is an AI-powered tool designed for the Gradio Agents & MCP Hackathon 2025, competing in both the MCP Server/Tool and Agentic Demo Showcase tracks. This project leverages the Model Context Protocol (MCP) and Gradio 5 to provide comprehensive security analysis for DeFi smart contracts. It integrates with Claude AI, Web3, and a real-time vulnerability database to identify risks, suggest fixes, and optimize gas usage, making it a robust tool for blockchain developers.

🎯 Hackathon Tracks

  • β€”MCP Server/Tool: The app functions as an MCP server, exposing endpoints like /mcp/comprehensive_audit and /mcp/fetch_contract to extend LLM capabilities for smart contract analysis.
  • β€”Agentic Demo Showcase: The Gradio interface showcases an AI agent that performs multi-layered analysis (security, DeFi risks, gas optimization, and compliance) with interactive visualizations.

✨ Features

  • β€”AI-Powered Security Analysis: Uses Claude AI to detect vulnerabilities like reentrancy, integer overflows, and access control issues.
  • β€”DeFi Risk Assessment: Identifies DeFi-specific risks, such as flash loan attacks, price oracle manipulation, and MEV vulnerabilities.
  • β€”MCP Integration: Acts as an MCP server, enabling LLMs to access real-time blockchain data and vulnerability databases.
  • β€”Real-time Vulnerability Database: Pulls data from SWC Registry and includes common DeFi vulnerabilities for up-to-date analysis.
  • β€”Gas Optimization: Provides actionable recommendations to reduce gas costs, with before/after code examples.
  • β€”Interactive UI: Built with Gradio 5, featuring a dashboard with risk distribution charts, complexity analysis, and fix suggestions.
  • β€”Sample Contracts: Includes pre-loaded DeFi contract examples (e.g., Vulnerable Flash Loan, AMM DEX) for testing.

πŸ› οΈ Tech Stack

  • β€”Gradio 5: For the interactive web interface and MCP server frontend.
  • β€”Claude AI (Anthropic): Powers the AI-driven security and DeFi analysis.
  • β€”MCP Protocol: Enables standardized context sharing with LLMs.
  • β€”Web3.py: Fetches real blockchain data (e.g., contract bytecode).
  • β€”FastAPI: Hosts MCP server endpoints for seamless integration.
  • β€”SQLite: Manages a local cache for vulnerabilities and audit history.
  • β€”Matplotlib/Pandas: Generates risk and complexity visualizations.

πŸ“½οΈ Demo Video

Watch the demo video here Note: Replace the above placeholder with the actual link to your video demo, showcasing the app in action (e.g., analyzing a sample contract via an MCP client like Claude Desktop or another Gradio app).

πŸš€ How to Use

  1. 1.Load a Sample Contract: Select a pre-loaded DeFi contract (e.g., "Flash Loan Vulnerability") from the dropdown or paste your own Solidity code.
  2. 2.Choose Analysis Mode: Select from Quick Security Scan, Comprehensive Analysis, Gas Optimization Focus, or DeFi Protocol Audit.
  3. 3.Analyze: Click "Analyze Contract" to run the AI agent and view results, including:
  4. 4.Security score and risk distribution charts.
  5. 5.Detailed vulnerability reports with fix suggestions.
  6. 6.DeFi-specific risk analysis and gas optimization recommendations.
  7. 7.Test MCP Integration: Click "Test MCP Integration" to verify the MCP server’s functionality and available tools.
  8. 8.Review Results: Explore tabs for vulnerabilities, DeFi risks, gas optimizations, and fix suggestions.

Important: This tool provides automated analysis. Always perform a manual review before deploying contracts to mainnet.

πŸ–₯️ Setup Instructions

To run the app locally or deploy it to Hugging Face Spaces:

  1. 1.Clone the Repository:
bash
   git clone https://huggingface.co/spaces/YourUsername/Your-Space-Name
   cd Your-Space-Name
  1. 1.Install Dependencies: Ensure Python 3.8+ is installed, then run:
bash
   pip install -r requirements.txt
  1. 1.Set Environment Variables: Add your Anthropic API key to the environment:
bash
   export ANTHROPIC_API_KEY="your-anthropic-api-key"

For Hugging Face Spaces, add the key as a repository secret in the Space’s settings.

  1. 1.Run Locally:
bash
   python app.py

requirements.txt:

txt
gradio==5.0.0
anthropic
requests
beautifulsoup4
matplotlib
pandas
web3
fastapi
sqlite3

πŸ”— MCP Integration

The app serves as an MCP server with endpoints like:

  • β€”/mcp/comprehensive_audit: Analyzes contract code and returns a JSON report.
  • β€”/mcp/fetch_contract: Fetches blockchain contract data (e.g., bytecode).
  • β€”/mcp/tools: Lists available tools for LLM integration.

Test the MCP server using an MCP client (e.g., Claude Desktop) or another Gradio app. The demo video demonstrates this integration.

πŸ“Š Impact and Innovation

  • β€”Innovation: Combines AI-driven analysis with real-time blockchain data and MCP integration for a novel approach to DeFi security.
  • β€”Usability: Intuitive Gradio interface with sample contracts and visualizations simplifies complex security analysis.
  • β€”Impact: Helps developers identify and mitigate DeFi risks, improving the safety of blockchain protocols.

πŸ“ Notes

πŸ™Œ Acknowledgments

Thanks to the hackathon sponsors (Modal Labs, Anthropic, Hugging Face, and others) for providing API and compute credits, enabling this project’s development.