
SaveSaveSaveSave
Read-only safety checks before an AI agent acts. The engine behind savesavesavesave.xyz, as a zero-dependency MCP server. - **scan_message**: checks untrusted text (DMs, emails, web pages, READMEs, prompts) for prompt injection, phishing, requests for secrets, disguised links and hidden characters. Runs locally; the text never leaves the machine. - **check_package**: looks up an npm package before install: removed by npm, reported malicious or vulnerable in OSV.dev, install scripts, look-alike names and signs of a hijacked release. Never downloads the package code. - **scan_address**: checks crypto wallets and tokens with GoPlus Security data, plus sanctions screening for EVM wallets. 14 EVM chains, Solana, Sui and TRON. - **compare_addresses**: compares two addresses character by character to catch address poisoning. Runs locally. Network access is limited to an allowlist of HTTPS hosts. Results are automated risk assessments, not guarantees: every result lists what was not checked.
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | stefan-tsezarov82/savesavesavesave | 2 Oct 2026 | 5 Oct 2026 | 1 |