shravankumar8/DeFi_Security_Agent
π‘οΈ DeFi Security Agent - Gradio Agents & MCP Hackathon 2025
Track Tags: mcp-server-track, agent-demo-track
Overview
The DeFi Security Agent is an AI-powered tool designed for the Gradio Agents & MCP Hackathon 2025, competing in both the MCP Server/Tool and Agentic Demo Showcase tracks. This project leverages the Model Context Protocol (MCP) and Gradio 5 to provide comprehensive security analysis for DeFi smart contracts. It integrates with Claude AI, Web3, and a real-time vulnerability database to identify risks, suggest fixes, and optimize gas usage, making it a robust tool for blockchain developers.
π― Hackathon Tracks
- MCP Server/Tool: The app functions as an MCP server, exposing endpoints like
/mcp/comprehensive_auditand/mcp/fetch_contractto extend LLM capabilities for smart contract analysis. - Agentic Demo Showcase: The Gradio interface showcases an AI agent that performs multi-layered analysis (security, DeFi risks, gas optimization, and compliance) with interactive visualizations.
β¨ Features
- AI-Powered Security Analysis: Uses Claude AI to detect vulnerabilities like reentrancy, integer overflows, and access control issues.
- DeFi Risk Assessment: Identifies DeFi-specific risks, such as flash loan attacks, price oracle manipulation, and MEV vulnerabilities.
- MCP Integration: Acts as an MCP server, enabling LLMs to access real-time blockchain data and vulnerability databases.
- Real-time Vulnerability Database: Pulls data from SWC Registry and includes common DeFi vulnerabilities for up-to-date analysis.
- Gas Optimization: Provides actionable recommendations to reduce gas costs, with before/after code examples.
- Interactive UI: Built with Gradio 5, featuring a dashboard with risk distribution charts, complexity analysis, and fix suggestions.
- Sample Contracts: Includes pre-loaded DeFi contract examples (e.g., Vulnerable Flash Loan, AMM DEX) for testing.
π οΈ Tech Stack
- Gradio 5: For the interactive web interface and MCP server frontend.
- Claude AI (Anthropic): Powers the AI-driven security and DeFi analysis.
- MCP Protocol: Enables standardized context sharing with LLMs.
- Web3.py: Fetches real blockchain data (e.g., contract bytecode).
- FastAPI: Hosts MCP server endpoints for seamless integration.
- SQLite: Manages a local cache for vulnerabilities and audit history.
- Matplotlib/Pandas: Generates risk and complexity visualizations.
π½οΈ Demo Video
Watch the demo video here Note: Replace the above placeholder with the actual link to your video demo, showcasing the app in action (e.g., analyzing a sample contract via an MCP client like Claude Desktop or another Gradio app).
π How to Use
- Load a Sample Contract: Select a pre-loaded DeFi contract (e.g., "Flash Loan Vulnerability") from the dropdown or paste your own Solidity code.
- Choose Analysis Mode: Select from Quick Security Scan, Comprehensive Analysis, Gas Optimization Focus, or DeFi Protocol Audit.
- Analyze: Click "Analyze Contract" to run the AI agent and view results, including:
- Security score and risk distribution charts.
- Detailed vulnerability reports with fix suggestions.
- DeFi-specific risk analysis and gas optimization recommendations.
- Test MCP Integration: Click "Test MCP Integration" to verify the MCP serverβs functionality and available tools.
- Review Results: Explore tabs for vulnerabilities, DeFi risks, gas optimizations, and fix suggestions.
Important: This tool provides automated analysis. Always perform a manual review before deploying contracts to mainnet.
π₯οΈ Setup Instructions
To run the app locally or deploy it to Hugging Face Spaces:
- Clone the Repository:
git clone https://huggingface.co/spaces/YourUsername/Your-Space-Name
cd Your-Space-Name- Install Dependencies: Ensure Python 3.8+ is installed, then run:
pip install -r requirements.txt- Set Environment Variables: Add your Anthropic API key to the environment:
export ANTHROPIC_API_KEY="your-anthropic-api-key"For Hugging Face Spaces, add the key as a repository secret in the Spaceβs settings.
- Run Locally:
python app.pyrequirements.txt:
gradio==5.0.0
anthropic
requests
beautifulsoup4
matplotlib
pandas
web3
fastapi
sqlite3π MCP Integration
The app serves as an MCP server with endpoints like:
/mcp/comprehensive_audit: Analyzes contract code and returns a JSON report./mcp/fetch_contract: Fetches blockchain contract data (e.g., bytecode)./mcp/tools: Lists available tools for LLM integration.
Test the MCP server using an MCP client (e.g., Claude Desktop) or another Gradio app. The demo video demonstrates this integration.
π Impact and Innovation
- Innovation: Combines AI-driven analysis with real-time blockchain data and MCP integration for a novel approach to DeFi security.
- Usability: Intuitive Gradio interface with sample contracts and visualizations simplifies complex security analysis.
- Impact: Helps developers identify and mitigate DeFi risks, improving the safety of blockchain protocols.
π Notes
- Built during the hackathon period (June 2β8, 2025).
- Complies with the hackathonβs Code of Conduct and Submission Guidelines.
- Join the Gradio Discord (
agents-mcp-hackathonchannel) for support.
π Acknowledgments
Thanks to the hackathon sponsors (Modal Labs, Anthropic, Hugging Face, and others) for providing API and compute credits, enabling this projectβs development.
