Skip to main content
Glama

Script Master Labs x402 Gateway

token_security_audit

Token contract security audit: honeypot, rugpull risk, taxes, ownership. (x402: 0.001 USDC per call)

HTTP equivalent: GET /x402/token-security-audit Payment: x402 protocol — send X-PAYMENT header with base64 payment payload, or X-API-Key / X-Owner-Key / Bearer token to bypass.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

TDQS

B3.3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Without readOnlyHint or destructiveHint annotations, the description carries the full transparency burden. It adds useful behavioral context about the x402 payment requirement (0.001 USDC) and authentication bypass methods, but it does not disclose the return format, potential errors, or whether the tool performs any state-changing operations besides the read-only audit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise and well-structured. The first sentence states the core function and checks, the second provides the HTTP equivalent and payment method. Every sentence adds value without redundancy, making it easy to scan and understand.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of a security audit, the empty schema, and no output schema, the description is incomplete. It explains what the tool does and payment, but omits how to pass the token, what the response contains, and any usage prerequisites. The agent would struggle to invoke the tool correctly without additional documentation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema is empty with additionalProperties=true, and the description does not mention any parameters. Since the tool obviously requires a token identifier (e.g., address or symbol), the description fails to explain how to specify the token. This is a significant gap given the parameter count is zero in the schema but the tool conceptually needs input.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function with a specific verb ('security audit') and resource ('token contract'), listing concrete checks (honeypot, rugpull risk, taxes, ownership). This distinguishes it from single-purpose siblings like honeypot_check or rugpull_detector by presenting a comprehensive audit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives such as honeypot_check or rugpull_detector. It lacks explicit when-to-use/when-not-to-use instructions or mention of complementary tools, leaving the agent to infer applicability.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

C2/5.0
Disambiguation1/5

Multiple tool pairs are exact duplicates (e.g., wallet_analysis/wallet_analyzer, honeypot_check/rugpull_detector, defi_yield/defi_yield_rates) with identical descriptions, and many overlapping scanners (squeeze_scanner variants). An agent cannot reliably distinguish these tools.

Naming Consistency2/5

Names are all snake_case, but conventions vary wildly: some are resource names (btc_price), some are actions (list_magnets), some are generic utilities (calculator), and duplicates use different naming patterns for the same function (wallet_analysis vs wallet_analyzer). No consistent verb_noun or resource_action pattern.

Tool Count1/5

139 tools is an extreme count for any MCP server, far exceeding the 50+ threshold. The scope is a grab-bag of unrelated domains (crypto, FDA, SEC, utilities, web scraping), suggesting no curation.

Completeness2/5

The set is a shallow pile of read-only queries and utilities with no lifecycle management for any one domain. Many sub-areas have only one or two tools, and duplicates occupy slots where distinct operations should be. The lack of a clear domain makes completeness impossible to assess, but the surface is redundant rather than comprehensive.

Resources