Skip to main content
Glama

Automaton Token Safety

security_scan

LEGACY NAME of token_scan — same route, same arguments, kept so clients written against this server keep working. PAID 0.001 USDC/call, or free trial (3/day/IP). Base token safety analysis: honeypot detection, mint traps, selfdestruct/delegatecall, proxy and tax risks from contract bytecode, with a risk score and signed verdict. On 402, pay the accepts[] terms then retry with the payment tx hash.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
addressYesToken or contract address on Base (0x...).
paymentNoOptional X-PAYMENT base tx hash of the USDC payment.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the exact price (0.001 USDC/call), a free-trial rate limit (3/day/IP), the 402 payment flow and retry mechanism, and the specific risk categories analyzed. This is unusually rich behavioral context for an unannotated, mutation/cost-bearing tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The legacy/pricing context is front-loaded, followed by the analysis scope and the payment fallback. Every sentence carries distinct information with no redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a paid tool with no output schema, the description covers cost, rate limits, error handling, and names the return artifacts (risk score, signed verdict). It stops short of describing the verdict fields or response shape, but is complete enough to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so both parameters are already documented (baseline 3). The description adds value by tying the optional payment parameter to the 402 workflow ('retry with the payment tx hash'), giving the agent context the schema alone does not.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb/resource (token safety analysis on Base contract bytecode) and explicitly identifies the tool as the legacy alias of token_scan with 'same route, same arguments'. An agent can immediately tell what it does and how it relates to the sibling tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly frames when this tool exists ('kept so clients written against this server keep working'), which strongly implies new callers should prefer token_scan, and it provides the payment/retry workflow on 402. However, it never states the exclusion affirmatively ('use token_scan instead'), so the routing guidance is implied rather than explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources