Skip to main content
Glama

pactlint: scan Solidity source

scan_contract_source

pactlint: static security scan of Solidity source code, before you deploy, review or depend on a contract. Input: source (one .sol file, no imports, up to 200 KB) or standard_json (solc standard-JSON input with every import inline, up to 1 MB and 500 files); optional filename, compiler_version (X.Y.Z; default from the pragma) and the include_* flags. Checks: solc + Slither + custom detectors for recurring DeFi bug classes (unchecked ERC-20 returns, zero slippage limits, stale or spot-price oracles, ERC-4626 share inflation, signature replay and more), triaged and de-duplicated. Returns the JSON report (status; findings with severity, confidence, file:line, explanation and recommendation) plus a Markdown rendering. Price: USD 0.25 up to 3,000 normalised source lines (nSLOC), USD 0.75 up to 15,000; larger inputs are refused. Refused inputs are never charged. Free: 3 scans or 30 txpeek checks per IP per UTC day (one shared pool). Typically 1-5 s for one file and up to about 30 s for a large project; at most 60 s per scan (past it: status timeout), one scan at a time; a request waits at most 25 s in a queue of 3 (less when paid, so every answer arrives within about 90 s), otherwise 503 with Retry-After, not charged. Automated and heuristic, not an audit: findings can be false positives and an empty report does not prove the code is free of bugs.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sourceNoA single Solidity file (no imports). Give either source or standard_json.
filenameNoContract.sol
include_noisyNo
standard_jsonNosolc standard-JSON input with inline 'content' for every file.
compiler_versionNoExact solc version (default: from pragma).
include_dependenciesNo
include_informationalNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden and does so thoroughly: pricing tiers and refusal of oversized inputs, no-charge-on-refusal and no-charge-on-503 semantics, free-tier pool, per-scan timeout, queue depth, concurrency limits, Retry-After behavior, expected latency, and the false-positive limitation. This is unusually complete for a tool with zero annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense paragraph, correctly front-loaded with purpose and inputs before cost and SLA details. The operational specifics (price, queue, timeout, refunds) mostly earn their place, though the packing makes it a heavy read and some latency detail could be trimmed.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 7-parameter, zero-required tool with no output schema, the description supplies everything an agent needs: input shape and limits, parameter defaults, what the report contains (status, findings with severity/confidence/file:line/explanation/recommendation, plus Markdown), and the full cost/latency/error envelope.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 43%, so the description must compensate — and it does for the key parameters: the source vs standard_json trade-off, their size/file limits, filename, and that compiler_version defaults from the pragma. The three include_* flags are mentioned as a group but never individually explained, leaving that gap only partly closed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource — 'static security scan of Solidity source code' — and names the exact input forms accepted (single .sol file or solc standard-JSON). This is plainly distinguishable from the sibling tools, which operate on a contract address or an agent package rather than raw source.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear usage context ('before you deploy, review or depend on a contract') and a strong misuse caveat ('Automated and heuristic, not an audit'). It does not, however, explicitly name when to reach for a sibling tool instead, nor state exclusions beyond the input-size refusals.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources