Skip to main content
Glama

TokenOS Smart Contract Audit

Quick security scan

quick_audit
Read-onlyIdempotent

Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeYesFull contract source (Solidity, Anchor or native Rust)
languageNoOptional — auto-detected when omitted

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false and openWorldHint=false, so the safety profile is covered. The description adds meaningful context beyond that: the scan is static and heuristic, implying approximate/non-exhaustive results and no code execution, and it discloses the returned artifacts. It does not state limits on code size or what the heuristic cannot catch.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense sentence that front-loads the core action and follows immediately with the deliverable. No filler, no redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the burden of describing returns, and it does so (severity, line numbers, fixes, letter grade). It also covers the accepted input types. Minor gaps remain around heuristic limitations and input size constraints, but the definition is otherwise sufficient to call the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters (code, language) are already documented, including the enum values and auto-detection behavior. The description names the supported contract flavors, which loosely maps to the language parameter, but adds no format or syntax detail beyond the schema. Baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (static heuristic scan) and resource (Solidity or Solana/Anchor/Rust contract), and even summarizes the output shape (findings, severity, line numbers, fixes, letter grade). No siblings exist, so no differentiation is needed; the purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The words 'quick' and 'heuristic' imply a lightweight pre-check rather than an exhaustive audit, which hints at usage context. However, there is no explicit statement of when to use this versus a deeper/manual review, and no prerequisites or exclusions are given. Implied usage only.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources