HexScan Token Security
Server Details
Honeypot detection & token risk scan for ERC-20s. Risk score 0-100, tax, source verification.
- Status
- Healthy
- Uptime
- 100.0% over 22 days
- Last Tested
- Transport
- Streamable HTTP ยท MCP 2025-03-26
- URL
TDQS
Scored across 3 tools
honeypot_check and scan_token overlap in outputs such as honeypot, tax, and risk score, but the fast/full distinction and simulate_transfer's simulation role keep purposes mostly clear. One pair could still cause an agent to pick the wrong scan for a given need.
All tools use a consistent verb_noun snake_case pattern: honeypot_check, scan_token, simulate_transfer. The naming is predictable and clearly communicates both the action and the target.
Three tools is on the lower end, but each fills a distinct tier in the workflow: quick check, full scan, and behavioral simulation. It feels slightly lean but still well-scoped for a focused token-security server.
The toolset covers the core security workflow with both static analysis and dynamic simulation, so there are no critical dead ends. Additional on-chain checks like liquidity locks or holder distribution could strengthen it, but scan_token is broad enough to cover most needs.
Available Tools
3 toolshoneypot_checkBInspect
Fast honeypot check. Args: address (0x...), chain. Returns: honeypot boolean, canBuy, canSell, buyTax, sellTax, riskScore.
| Name | Required | Description | Default |
|---|---|---|---|
| chain | Yes | Chain name | |
| address | Yes | Token contract address |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must carry behavioral transparency. It does enumerate the returned fields (honeypot boolean, canBuy, canSell, buyTax, sellTax, riskScore), which gives some insight into what the tool reports. However, it does not state whether the operation is read-only, whether it performs on-chain calls, or whether any side effects or external dependencies exist.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise and free of unnecessary words, directly stating purpose, arguments, and return fields in a compact format.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Because there is no output schema, listing return fields is helpful and partially compensates for missing output types. However, the description lacks explicit data types (e.g., whether canBuy/canSell are booleans), error behavior, and examples for the chain parameter, leaving some ambiguity for an agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
All two parameters are described in the schema, and the description adds useful detail by specifying '0x...' for the address and clarifying it as a token contract address. The 'chain' parameter remains generic ('Chain name'), but the overall parameter meaning is clear for typical use.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The phrase 'Fast honeypot check' clearly identifies the tool's purpose as evaluating whether a token is a honeypot, and the listed return fields reinforce that intent. However, it lacks an explicit verb and does not directly contrast with the sibling 'scan_token' tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to choose this tool over the sibling scan_token, nor does it mention any context such as speed trade-offs or suitability. The word 'Fast' hints at performance, but this is not developed into actionable selection criteria.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
scan_tokenBInspect
Full token security scan. Args: address (0x...), chain (ethereum|base|arbitrum|optimism|polygon|bsc|avalanche). Returns risk score 0-100, honeypot, tax, source verification.
| Name | Required | Description | Default |
|---|---|---|---|
| chain | Yes | Chain name | |
| address | Yes | Token contract address |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions what the tool returns (risk score, honeypot, tax, source verification) but does not state whether the operation is read-only, has side effects, requires network access, or has any rate limits. For a security scan, the read-only nature is implied but not stated, leaving behavioral ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that efficiently packs the tool's purpose, arguments, and return fields. It is front-loaded with the primary action and leaves no wasted words. The structure is clear and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given there is no output schema, the description compensates by listing the return values. It covers both parameters adequately and provides allowed chain values. It does not mention error handling or edge cases (e.g., invalid address), but for a scan tool with no annotations, this is reasonably complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema provides only generic descriptions ('Chain name', 'Token contract address'), but the tool description adds concrete meaning by listing the allowed chain values and the address format (0x...). This is meaningful additional context beyond the schema, even though schema coverage is 100%.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action ('Full token security scan') on a specific resource (token), making the core purpose clear. It does not explicitly contrast with the sibling honeypot_check, but the word 'Full' implies a broader scope, so it is somewhat distinguishable. Still, the lack of explicit differentiation prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is given on when to use this tool versus honeypot_check. The description lists arguments and return values but does not state conditions like 'use when you need comprehensive analysis' or 'use honeypot_check for a quick check.' An agent must infer the difference from the tool names.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
simulate_transferAInspect
Simulate buy-then-sell on-chain. Args: address (0x...), chain. Returns: canBuy, canSell, revertReason, verdict (ALLOW/REVIEW/BLOCK). Uses real eth_call simulation.
| Name | Required | Description | Default |
|---|---|---|---|
| chain | Yes | Chain name | |
| address | Yes | Token contract address |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It does mention 'Uses real eth_call simulation' and lists return values including revertReason, which gives some insight into execution behavior. However, it does not explicitly state that the operation is read-only, any potential side effects, or limitations such as chain support or rate limits, leaving gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise, with two sentences that front-load the purpose and then cover args, returns, and method. Every sentence contributes information, and there is no fluff or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with only two parameters and no output schema, the description covers the essential details: what it does, the arguments, the return values, and the simulation method. It could be improved by mentioning supported chains or typical use cases, but it is sufficiently complete for basic invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already documents both parameters with 100% coverage, so the baseline is 3. The description adds value by specifying the address format as '0x...', which clarifies the expected input format beyond the schema's 'Token contract address'. This extra hint justifies a 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool simulates a buy-then-sell on-chain operation, which is a specific verb and resource. It also lists the return fields, making the purpose unambiguous. However, it does not explicitly differentiate this tool from its siblings (honeypot_check, scan_token), so it lacks the distinction that would earn a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool instead of alternatives. It simply states what it does without indicating scenarios or exclusions. The agent must infer from the name or context, which is insufficient for clear routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Added
simulate_transfer
2 tool updates
- First observed
honeypot_check - First observed
scan_token
Related MCP Connectors
Token Risk โ rug-pull / honeypot screening for crypto tokens.
Instant rug-check for any EVM or Solana token, distilled to one clear 0-10 risk verdict.
Crypto security, honeypot detection, wallet analysis, and token risk scoring across 31 blockchains.
Solana token/wallet rug-risk scoring. Free scan; $2 SOL unlocks full wallet report. No signup.
Related MCP Servers
- AlicenseAqualityBmaintenanceOn-chain rug-pull & honeypot risk screen for ERC-20 tokens, providing a SAFE / CAUTION / HIGH-RISK verdict based on live public RPC reads.2MIT
- AlicenseNot gradedqualityCmaintenanceToken safety oracle for AI agents. Honeypot detection, 17 scam pattern checks, LP lock verification across 6 EVM chains. Score 0-100 with risk flags. ERC Token Safety Score standard.1MIT
- FlicenseBqualityCmaintenanceEnables AI agents to perform token security audits, honeypot detection, liquidity analysis, and risk scoring to avoid crypto scams.1-
- AlicenseAqualityBmaintenanceQuick-scan a smart contract for rug, honeypot, or centralization risk before sending funds. It combines verified source, live on-chain state, and heuristic Solidity analysis to return a SAFE/CAUTION/HIGH-RISK verdict.1MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.