Squads MCP
About
A secure MCP implementation for Squads multisig management on the Solana blockchain.
Explore
{ "mcpServers": { "squads-mcp": { "command": "node", "args": [ "node_modules/squads-mcp/dist/index.js" // If installed from npm // OR use "/ABSOLUTE/PATH/TO/YOUR/MCP/PROJECT/FILE" if built from source ] } } }
- CONNECTION_UPDATE: Set Solana connection
- SHOW_CONFIG: Display current configuration
- CREATE_SQUADS_MULTISIG: Create a new multisig
- IMPORT_SQUADS_MULTISIG: Import existing multisig
- GET_MULTISIG_ACCOUNT: View multisig details
- AUDIT_MULTISIG_SECURITY: Security audit with recommendations
- CREATE_PROPOSAL: Create a new proposal
- APPROVE_PROPOSAL: Vote to approve a proposal
- REJECT_PROPOSAL: Vote to reject a proposal
- CANCEL_PROPOSAL: Cancel a pending proposal
- GET_PROPOSAL: View a specific proposal
- GET_PROPOSALS: List all proposals
- EXECUTE_CONFIG_TRANSACTION: Execute configuration changes
- EXECUTE_VAULT_TRANSACTION: Execute vault transactions
- GET_ASSETS: View assets in a multisig vault
- FUND_VAULT: Send SOL to a vault
- TRANSFER_SOL_FROM_VAULT: Send SOL from a vault
TheAUDIT_MULTISIG_SECURITYtool provides enterprise-grade security analysis of Squads multisig configurations:
- Quantitative Security Scoring: Implements a multi-dimensional security algorithm (0-100) evaluating 15+ risk factors including threshold ratios, permission structures, and time lock durations
- Automated Vulnerability Detection: Scans for common security misconfigurations including single-point failures, inadequate thresholds, and insufficient time locks
- Role-Based Access Control Analysis: Evaluates separation of duties across INITIATE, EXECUTE, and VOTE permissions, flagging cases where excessive permissions are concentrated
- Risk Assessment Matrix: Categorizes findings into Critical, High, Medium, and Low severity with color-coded outputs and remediation recommendations
- Threshold Optimization Engine: Calculates optimal threshold settings based on multisig purpose, member count, and asset value exposure
- Time Lock Validation: Enforces minimum time lock periods calibrated to risk profiles (1+ hour for Reserve, 10+ minutes for Upgrades, etc.)
- Configuration Hardening: Generates specific security-hardening recommendations with implementation instructions
- Compliance Verification: Checks configurations against industry best practices for Solana multisig management
- JSON Export: Provides machine-readable output for integration with security monitoring systems
The tool was developed using TypeScript with specialized cryptographic validation routines and a proprietary scoring algorithm based on blockchain security research.
- Always verify addresses: Double-check multisig addresses before operations
- Follow the two-minute rule: Wait at least 2 minutes after approvals before executing critical transactions
- Run regular security audits: UseAUDIT_MULTISIG_SECURITYafter any configuration changes
- Implement proper access control: Separate proposal creation from execution roles
- Use secure devices: Perform sensitive operations on dedicated, secure devices
- Consider transaction simulation: Test critical transactions in a safe environment first
A secure Model Context Protocol (MCP) implementation for Squads multisig management on Solana blockchain. This toolkit prioritizes security at every step while enabling LLMs to safely interact with multisig accounts.
Squads MCP implements multiple security layers to protect your assets and multisig operations:
- Local Private Key Storage: Keys never leave your device, unlike web wallets or browser extensions
- Permission Separation: Distinct INITIATE, EXECUTE, and VOTE roles prevent single-point compromise
- Time Lock Support: Configure mandatory waiting periods before sensitive transactions execute
- Comprehensive Security Auditing: Built-inAUDIT_MULTISIG_SECURITYtool scores your configuration
- Security-Focused Schemas: Every tool includes explicit security warnings and verification steps
- Threshold Recommendations: Smart defaults for different multisig types (Reserve, Operations, etc.)
- Secure Connection Management: Easily switch between networks for testing and production
- Create new multisig accounts with customizable permissions
- Import existing multisig accounts
- Audit multisig security with detailed recommendations
- Configure thresholds, permissions, and time locks
- Create and manage proposals
- Vote on proposals (approve/reject)
- Execute approved transactions
- Cancel pending proposals
- View SOL and token balances in vaults
- Transfer SOL from vaults
- Fund vaults
The implementation promotes Squads security best practices:
- Keep INITIATE and EXECUTE roles separate
- Avoid giving ALL permissions to any member
- For Reserve multisigs: 6+ members, 4+ threshold
- For Program Upgrade multisigs: 6+ members, 4+ threshold
- For Operations multisigs: 3+ members, 2+ threshold
- Reserve: 3600+ seconds (1 hour)
- Program Upgrade: 600+ seconds (10 minutes)
- Operations: 300+ seconds (5 minutes)
This project leverages the Model Context Protocol (MCP) to enable secure interaction between LLMs and Squads multisig functionality. MCP provides a standardized way for AI models to use external tools while maintaining security and context.
┌─────────┐ ┌──────────────┐ ┌────────────┘ ┌────────┐ │ LLM │<-->│ MCP Protocol │<-->│ Squads MCP │<-->│ Solana │ └─────────┘ └──────────────┘ └────────────┘ └────────┘
- Node.js v16+
- Solana CLI tools (optional)
- A Solana wallet (preferably a hardware wallet for production use)
# Using npm npm install squads-mcp # Using yarn yarn add squads-mcp # Using pnpm pnpm add squads-mcp
git clone https://github.com/dorkydhruv/squads-mcp.git cd squads-mcp pnpm install pnpm build
Configuration forclaude_desktop_config.json
{ "mcpServers": { "squads-mcp": { "command": "node", "args": [ "node_modules/squads-mcp/dist/index.js" // If installed from npm // OR use "/ABSOLUTE/PATH/TO/YOUR/MCP/PROJECT/FILE" if built from source ] } } }
- CONNECTION_UPDATE: Set Solana connection
- SHOW_CONFIG: Display current configuration
- CREATE_SQUADS_MULTISIG: Create a new multisig
- IMPORT_SQUADS_MULTISIG: Import existing multisig
- GET_MULTISIG_ACCOUNT: View multisig details
- AUDIT_MULTISIG_SECURITY: Security audit with recommendations
- CREATE_PROPOSAL: Create a new proposal
- APPROVE_PROPOSAL: Vote to approve a proposal
- REJECT_PROPOSAL: Vote to reject a proposal
- CANCEL_PROPOSAL: Cancel a pending proposal
- GET_PROPOSAL: View a specific proposal
- GET_PROPOSALS: List all proposals
- EXECUTE_CONFIG_TRANSACTION: Execute configuration changes
- EXECUTE_VAULT_TRANSACTION: Execute vault transactions
- GET_ASSETS: View assets in a multisig vault
- FUND_VAULT: Send SOL to a vault
- TRANSFER_SOL_FROM_VAULT: Send SOL from a vault
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



