{"_id":"3ilm-mcp","_rev":"2-55afa107be7ba3d578d32102c9c56cd4","name":"3ilm-mcp","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"3ilm-mcp","version":"1.0.0","keywords":["mcp","smart-contract","security","vulnerabilities","solidity","audit","sherlock","defi","bug-bounty"],"author":{"name":"holistis"},"license":"MIT","_id":"3ilm-mcp@1.0.0","maintainers":[{"name":"alghanima","email":"info@holistischadviseur.nl"}],"homepage":"https://github.com/holistis/3ilm-mcp#readme","bugs":{"url":"https://github.com/holistis/3ilm-mcp/issues"},"bin":{"3ilm-mcp":"dist/index.js"},"dist":{"shasum":"396b43666ab25b8879bd5b9b38b47023ccecca38","tarball":"https://registry.npmjs.org/3ilm-mcp/-/3ilm-mcp-1.0.0.tgz","fileCount":11,"integrity":"sha512-Bk8u/1RhYlKjsC/7/KqYsnWYfNRupHUQPSMlI/Z8uFWQrzzoG/ZxGTiKzvhQG0YBXu5q9w583NDTpEuL3wyR0g==","signatures":[{"sig":"MEQCID7DKVeL1VdggwgQiIa7suJH8vmNv7wxiNr2iJ13LKXDAiA3HkHwVjfw6ni84hq2QOBxu2VD9nOdBcS6uzC50xrrWw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49847},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"773524d7bd288106e8bbcd693d3bbb25f5b4efb7","scripts":{"dev":"node --loader ts-node/esm src/index.ts","build":"tsc","check":"tsc --noEmit","start":"node dist/index.js","prepare":"tsc"},"_npmUser":{"name":"alghanima","email":"info@holistischadviseur.nl"},"repository":{"url":"git+https://github.com/holistis/3ilm-mcp.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP server exposing 3ilm — a curated knowledge base of 1,032 smart contract vulnerability findings from 10 fully-reconciled Sherlock audit contests. Search patterns by keyword, get acceptance rates, and learn from real accepted/rejected examples.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.5","@types/node":"^20.12.7"},"_npmOperationalInternal":{"tmp":"tmp/3ilm-mcp_1.0.0_1785060368787_0.03164946001665614","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"3ilm-mcp","version":"1.0.1","description":"MCP server exposing 3ilm — a curated knowledge base of 1,032 smart contract vulnerability findings from 10 fully-reconciled Sherlock audit contests. Search patterns by keyword, get acceptance rates, and learn from real accepted/rejected examples.","keywords":["mcp","smart-contract","security","vulnerabilities","solidity","audit","sherlock","defi","bug-bounty"],"author":{"name":"holistis"},"license":"MIT","type":"module","main":"dist/index.js","bin":{"3ilm-mcp":"dist/index.js"},"scripts":{"prepare":"tsc","build":"tsc","start":"node dist/index.js","dev":"node --loader ts-node/esm src/index.ts","check":"tsc --noEmit"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^3.23.8"},"devDependencies":{"typescript":"^5.4.5","@types/node":"^20.12.7"},"engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/holistis/3ilm-mcp.git"},"homepage":"https://github.com/holistis/3ilm-mcp#readme","mcpName":"io.github.holistis/3ilm-mcp","gitHead":"425974aaa7b6f29c78134627d9cf46274439d185","types":"./dist/index.d.ts","_id":"3ilm-mcp@1.0.1","bugs":{"url":"https://github.com/holistis/3ilm-mcp/issues"},"_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-+d4JVnVO1bBxYuUSxFnYOQsgHMfYCmihFyt8o5TbMlZOAJ5vxZzOUXR0CXAfOmkwD3TbJMR3pv56y8kpuhLvbg==","shasum":"c100ace9acb017b70625f9141c88985d2925432e","tarball":"https://registry.npmjs.org/3ilm-mcp/-/3ilm-mcp-1.0.1.tgz","fileCount":11,"unpackedSize":49899,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDTUNx8cBLfBVfzwBgc3JZN+O6+UmMbemOybggedilmnAIgaz39sDuKZ7VL0/Fb+doBgJ9IjYJaDBbQruJkx2yV5VU="}]},"_npmUser":{"name":"alghanima","email":"info@holistischadviseur.nl"},"directories":{},"maintainers":[{"name":"alghanima","email":"info@holistischadviseur.nl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/3ilm-mcp_1.0.1_1785060498947_0.6965689673183879"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-26T10:06:08.563Z","modified":"2026-07-26T10:08:19.211Z","1.0.0":"2026-07-26T10:06:08.906Z","1.0.1":"2026-07-26T10:08:19.089Z"},"bugs":{"url":"https://github.com/holistis/3ilm-mcp/issues"},"author":{"name":"holistis"},"license":"MIT","homepage":"https://github.com/holistis/3ilm-mcp#readme","keywords":["mcp","smart-contract","security","vulnerabilities","solidity","audit","sherlock","defi","bug-bounty"],"repository":{"type":"git","url":"git+https://github.com/holistis/3ilm-mcp.git"},"description":"MCP server exposing 3ilm — a curated knowledge base of 1,032 smart contract vulnerability findings from 10 fully-reconciled Sherlock audit contests. Search patterns by keyword, get acceptance rates, and learn from real accepted/rejected examples.","maintainers":[{"name":"alghanima","email":"info@holistischadviseur.nl"}],"readme":"# 3ilm MCP Server\n\nMCP server exposing **3ilm** — a curated knowledge base of 1,032 smart contract vulnerability findings from 10 fully-reconciled [Sherlock](https://audits.sherlock.xyz) audit contests.\n\nBuilt for AI agents, security researchers, and audit tools that need structured data on which bug classes get paid, at what rates, and why.\n\n## What it is\n\n3ilm (Arabic: علم, \"knowledge\") contains:\n\n- **1,032 verified findings** from 10 Sherlock contests (fully reconciled against contest outcomes)\n- **12 vulnerability pattern categories** with real acceptance rates, not estimates\n- **Accepted and rejected examples** per category — learn what passes triage\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `search_vulnerabilities` | Keyword search across all 12 categories. Returns matching patterns with acceptance rates and examples. |\n| `get_pattern_details` | Full stats table for one specific pattern: totals, acceptance rate, Sherlock-specific note, examples. |\n| `list_patterns` | All 12 patterns ranked by volume with 🟢🟡🔴 acceptance indicators. |\n\n## Install\n\n```bash\nnpx 3ilm-mcp\n```\n\n## Add to Claude / Cursor\n\n**Claude Desktop** — add to `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"3ilm\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@holistis/3ilm-mcp\"]\n    }\n  }\n}\n```\n\n**Cursor** — add to `.cursor/mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"3ilm\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@holistis/3ilm-mcp\"]\n    }\n  }\n}\n```\n\n## Example queries\n\nAsk your AI assistant:\n\n- \"What is the acceptance rate for oracle manipulation findings on Sherlock?\"\n- \"Show me all vulnerability patterns and their payout rates\"\n- \"Search for reentrancy vulnerabilities — what percentage get accepted?\"\n- \"What does a accepted flash loan finding look like vs a rejected one?\"\n\n## Data source\n\nAll data from the verified `sherlock/_index.json` in the [3ilm knowledge base](https://github.com/holistis/3ilm-mcp). Findings are reconciled against actual contest outcomes — no scraping, no estimates.\n\nThe 12 patterns: `fee-miscalculation`, `dos-griefing`, `reentrancy`, `trusted-actor`, `overflow`, `staleness`, `rounding`, `access-control`, `oracle-manipulation`, `mev-slippage`, `liquidation`, `flash-loan`.\n\n## Related\n\n- HTTP API (pay-per-query, USDC on Base): `https://wazir-x402.duckdns.org/api/vuln-search?q=oracle`\n- x402 Tollbooth: all endpoints listed at `/api/status`\n\n## License\n\nMIT\n","readmeFilename":"README.md"}