Skip to main content
Glama

TokenOS Smart Contract Audit

Server Details

Scan Solidity & Anchor code

If you are the author of this connector, you can claim ownership by verifying the domain or GitHub account it belongs to. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL

TDQS

A4/5.0

Scored across 1 tool

Disambiguation5/5

With only a single tool, there is no possibility of overlap or misselection. Any agent needing an audit has exactly one unambiguous entry point.

Naming Consistency5/5

The lone name quick_audit is clear, lowercase snake_case, and descriptive of its action. No competing conventions exist to create inconsistency.

Tool Count3/5

One tool is thin for a server branded as a full smart contract audit surface, but the tool itself is broad enough (multi-chain static scan with severities and grading) to be a defensible single-purpose offering.

Completeness3/5

A static heuristic scan covers the core audit need, but there is no way to retrieve raw findings, apply or verify fixes, export a report, or run deeper/dynamic analysis. These are notable gaps an agent would hit on non-trivial audit workflows.

Available Tools

1 tool
quick_auditQuick security scanA
Read-onlyIdempotent
Inspect

Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade.

ParametersJSON Schema
NameRequiredDescriptionDefault
codeYesFull contract source (Solidity, Anchor or native Rust)
languageNoOptional — auto-detected when omitted

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and openWorldHint=false, so the safety profile is covered. The description adds meaningful context beyond that: the scan is static and heuristic, implying approximate/non-exhaustive results and no code execution, and it discloses the returned artifacts. It does not state limits on code size or what the heuristic cannot catch.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense sentence that front-loads the core action and follows immediately with the deliverable. No filler, no redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the burden of describing returns, and it does so (severity, line numbers, fixes, letter grade). It also covers the accepted input types. Minor gaps remain around heuristic limitations and input size constraints, but the definition is otherwise sufficient to call the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters (code, language) are already documented, including the enum values and auto-detection behavior. The description names the supported contract flavors, which loosely maps to the language parameter, but adds no format or syntax detail beyond the schema. Baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (static heuristic scan) and resource (Solidity or Solana/Anchor/Rust contract), and even summarizes the output shape (findings, severity, line numbers, fixes, letter grade). No siblings exist, so no differentiation is needed; the purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The words 'quick' and 'heuristic' imply a lightweight pre-check rather than an exhaustive audit, which hints at usage context. However, there is no explicit statement of when to use this versus a deeper/manual review, and no prerequisites or exclusions are given. Implied usage only.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool update
    • First observedquick_audit

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Enables static security audit of Solidity smart contracts by analyzing source code or deployed bytecode for vulnerabilities, providing risk scores and detailed findings.
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    AI-powered smart contract forge with an 8-agent adversarial security audit system. Generate, audit, fix, and compile Solidity and Anchor/Rust contracts across 8 chains.
    7
    46 npm
    1
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources