TokenOS Smart Contract Audit
Server Details
Scan Solidity & Anchor code
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 1 tool
With only a single tool, there is no possibility of overlap or misselection. Any agent needing an audit has exactly one unambiguous entry point.
The lone name quick_audit is clear, lowercase snake_case, and descriptive of its action. No competing conventions exist to create inconsistency.
One tool is thin for a server branded as a full smart contract audit surface, but the tool itself is broad enough (multi-chain static scan with severities and grading) to be a defensible single-purpose offering.
A static heuristic scan covers the core audit need, but there is no way to retrieve raw findings, apply or verify fixes, export a report, or run deeper/dynamic analysis. These are notable gaps an agent would hit on non-trivial audit workflows.
Available Tools
1 toolquick_auditQuick security scanARead-onlyIdempotentInspect
Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade.
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | Full contract source (Solidity, Anchor or native Rust) | |
| language | No | Optional — auto-detected when omitted |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and openWorldHint=false, so the safety profile is covered. The description adds meaningful context beyond that: the scan is static and heuristic, implying approximate/non-exhaustive results and no code execution, and it discloses the returned artifacts. It does not state limits on code size or what the heuristic cannot catch.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single dense sentence that front-loads the core action and follows immediately with the deliverable. No filler, no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the burden of describing returns, and it does so (severity, line numbers, fixes, letter grade). It also covers the accepted input types. Minor gaps remain around heuristic limitations and input size constraints, but the definition is otherwise sufficient to call the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters (code, language) are already documented, including the enum values and auto-detection behavior. The description names the supported contract flavors, which loosely maps to the language parameter, but adds no format or syntax detail beyond the schema. Baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (static heuristic scan) and resource (Solidity or Solana/Anchor/Rust contract), and even summarizes the output shape (findings, severity, line numbers, fixes, letter grade). No siblings exist, so no differentiation is needed; the purpose is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The words 'quick' and 'heuristic' imply a lightweight pre-check rather than an exhaustive audit, which hints at usage context. However, there is no explicit statement of when to use this versus a deeper/manual review, and no prerequisites or exclusions are given. Implied usage only.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
quick_audit
Related MCP Connectors
EVM audit (Slither + source + security.txt + MCP-probe + wallet-exposure). 6 tools + /trace.
PQC scanner for GitHub repos and smart contracts. Detects quantum-vulnerable ECDSA/RSA.
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Solana token/wallet rug-risk scoring. Free scan; $2 SOL unlocks full wallet report. No signup.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables static security audit of Solidity smart contracts by analyzing source code or deployed bytecode for vulnerabilities, providing risk scores and detailed findings.1MIT
- FlicenseAqualityCmaintenanceFetches verified EVM smart contract source code, scans for vulnerabilities, analyzes token holder distribution, and generates audit reports.5-
- AlicenseAqualityBmaintenanceAI-powered smart contract security analysis for AI agents and developers, enabling scanning of Solidity repos for vulnerabilities.315 npm10MIT

Pentagonalofficial
AlicenseAqualityCmaintenanceAI-powered smart contract forge with an 8-agent adversarial security audit system. Generate, audit, fix, and compile Solidity and Anchor/Rust contracts across 8 chains.746 npm1MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.