
Any Payment |
...
Submissions
Remaining
SKILLS NEEDED
CONTACT
RELATED LIVE LISTINGS
$1 to be paid inUSDCApplication Date
11 Jun 2026
Submission Title
Neural Sentinel – Automated MCP Security Auditing Infrastructure for NEAR AI Agents
Description of issue
The NEAR AI Agent ecosystem is rapidly expanding, but it currently lacks a foundational infrastructure layer for automated security auditing of MCP (Model Context Protocol) servers and agentic tooling. Developers are shipping AI agents that interact with financial infrastructure (wallets, smart contracts) without standardized security checks.
This creates systemic risks where AI agents can inadvertently execute malicious transactions, leak private keys, or escalate privileges due to unvetted tool definitions. The absence of an automated "security-as-code" pipeline for MCP tools means vulnerabilities are only discovered post-deployment or via slow manual audits, which cannot keep pace with AI agent development.
Supporting Evidence
We recently stress-tested the official nearai/near-mcp repository using our automated gRPC vulnerability scanner. While the README documents the unencrypted keystore as a "known limitation," our scanner identified 6 ADDITIONAL critical, undocumented vulnerabilities in the architecture:
Privilege Chain Escalation (MCP03): Tools combining code execution + secret access can extract all credentials.
Tool Description Injection (MCP01): 4 tools contain exploitable metadata patterns enabling prompt injection and persona hijacking.
Authentication Bypass (MCP08): 9 sensitive financial tools (e.g., tokens_send_near) are exposed with ZERO authentication middleware, critical now that remote deployment is supported.
Excessive Permission Scope (MCP07): account_add_access_key allows AI to grant FullAccess god-mode permissions without human oversight.
Scan ID: SMCP-1781200808-C1ECCB. Risk Score: 100/100 CRITICAL. 23 tools analyzed in 109ms. All findings are verifiable in src/services.ts.
How This Blocks Your Progress
As builders in the AI security space, we cannot effectively scale our automated compliance and security auditing services to the NEAR ecosystem without native integration into the developer workflow. Currently, we have to manually extract manifests and run external scans. This infrastructure gap blocks:
The integration of automated MCP security checks into the NEAR CI/CD pipeline.
The ability for the NEAR AI Agent Hub to automatically verify the safety of agents before listing.
Enterprise adoption of NEAR AI agents, as institutional clients require audit-grade proof of technical robustness (e.g., EU AI Act Article 15 compliance).
Urgency Level
Potential Solutions
CI/CD GitHub Action: Package the Neural Sentinel MCP scanner as an open-source GitHub Action that automatically scans mcp.tool() definitions for privilege chains, auth gaps, and injection surfaces on every PR.
NEAR CLI Integration: Add a near mcp audit command to the NEAR CLI that developers can run locally before deploying an agent.
Agent Hub Pre-Flight Check: Integrate the scanner into the NEAR AI Agent Hub deployment pipeline to automatically generate a "Security Score" for every agent.
Estimated Resources: $15,000 - $30,000 in USDC/NEAR to fund the open-source packaging, CLI integration, and initial ecosystem audit.
Teams/Contributors That Could Help
Neural Sentinel (our team). We have already built the core gRPC scanning engine (LLM, MCP, RAG, Agent, PQC) and proven its efficacy by identifying 8 critical vulnerabilities in the official NEAR MCP server in 109ms. We are uniquely positioned to maintain this security infrastructure as a public good for the NEAR ecosystem.
If understand this isn't a bounty are you aren't going to get paid and this page is just being used as a submission form for the time being. REQUEST $0 sponsorship
Anything Else
We have published the full automated audit report (PDF) and a terminal video demonstrating the scan of nearai/near-mcp on LinkedIn here:
While this form is for ecosystem feedback, we are actively seeking a DevHub Sponsorship ($15k-$30k) to implement these solutions. We are ready to deploy this security infrastructure for NEAR immediately upon funding via a separate DevHub proposal. We invite the Infrastructure Committee to review our findings and discuss how Neural Sentinel can secure the NEAR AI Agent economy.
Threads
|
Filter by
SKILLS NEEDED
Blockchain
Backend
CONTACT
Reach outif you have any questions about this listing