Skip to main content
Glama

HexScan Token Security

Server Details

Honeypot detection & token risk scan for ERC-20s. Risk score 0-100, tax, source verification.

If you are the author of this connector, you can claim ownership with GitHub, an HTTP challenge, or a DNS record. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP
URL

TDQS

A3.6/5.0

Scored across 2 tools

Disambiguation4/5

The two tools are clearly distinct in purpose: honeypot_check is a fast, focused honeypot detector, while scan_token is a comprehensive security scan. They overlap in that scan_token includes honeypot detection, but the descriptions make the intended use case clear, reducing ambiguity.

Naming Consistency4/5

Both tool names use snake_case and are descriptive, but the pattern differs: 'honeypot_check' is a noun-verb construction while 'scan_token' is a verb-noun construction. This is a minor inconsistency that does not impede understanding.

Tool Count4/5

With only two tools, the set is concise and focused for a token security scanner. It provides a quick-check option and a full-featured scan, which is reasonable for the domain, though a slightly larger set could offer more granular controls.

Completeness4/5

The tool set covers core security scanning needs: honeypot detection, risk scoring, tax analysis, and source verification. It lacks tools for specific aspects like ownership or liquidity checks, but the full scan appears to integrate these, so major gaps are not evident.

Available Tools

2 tools
honeypot_checkBInspect

Fast honeypot check. Args: address (0x...), chain. Returns: honeypot boolean, canBuy, canSell, buyTax, sellTax, riskScore.

ParametersJSON Schema
NameRequiredDescriptionDefault
chainYesChain name
addressYesToken contract address

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description must carry behavioral transparency. It does enumerate the returned fields (honeypot boolean, canBuy, canSell, buyTax, sellTax, riskScore), which gives some insight into what the tool reports. However, it does not state whether the operation is read-only, whether it performs on-chain calls, or whether any side effects or external dependencies exist.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise and free of unnecessary words, directly stating purpose, arguments, and return fields in a compact format.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Because there is no output schema, listing return fields is helpful and partially compensates for missing output types. However, the description lacks explicit data types (e.g., whether canBuy/canSell are booleans), error behavior, and examples for the chain parameter, leaving some ambiguity for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

All two parameters are described in the schema, and the description adds useful detail by specifying '0x...' for the address and clarifying it as a token contract address. The 'chain' parameter remains generic ('Chain name'), but the overall parameter meaning is clear for typical use.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The phrase 'Fast honeypot check' clearly identifies the tool's purpose as evaluating whether a token is a honeypot, and the listed return fields reinforce that intent. However, it lacks an explicit verb and does not directly contrast with the sibling 'scan_token' tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to choose this tool over the sibling scan_token, nor does it mention any context such as speed trade-offs or suitability. The word 'Fast' hints at performance, but this is not developed into actionable selection criteria.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_tokenBInspect

Full token security scan. Args: address (0x...), chain (ethereum|base|arbitrum|optimism|polygon|bsc|avalanche). Returns risk score 0-100, honeypot, tax, source verification.

ParametersJSON Schema
NameRequiredDescriptionDefault
chainYesChain name
addressYesToken contract address

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions what the tool returns (risk score, honeypot, tax, source verification) but does not state whether the operation is read-only, has side effects, requires network access, or has any rate limits. For a security scan, the read-only nature is implied but not stated, leaving behavioral ambiguity.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence that efficiently packs the tool's purpose, arguments, and return fields. It is front-loaded with the primary action and leaves no wasted words. The structure is clear and easy to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given there is no output schema, the description compensates by listing the return values. It covers both parameters adequately and provides allowed chain values. It does not mention error handling or edge cases (e.g., invalid address), but for a scan tool with no annotations, this is reasonably complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema provides only generic descriptions ('Chain name', 'Token contract address'), but the tool description adds concrete meaning by listing the allowed chain values and the address format (0x...). This is meaningful additional context beyond the schema, even though schema coverage is 100%.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action ('Full token security scan') on a specific resource (token), making the core purpose clear. It does not explicitly contrast with the sibling honeypot_check, but the word 'Full' implies a broader scope, so it is somewhat distinguishable. Still, the lack of explicit differentiation prevents a perfect score.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is given on when to use this tool versus honeypot_check. The description lists arguments and return values but does not state conditions like 'use when you need comprehensive analysis' or 'use honeypot_check for a quick check.' An agent must infer the difference from the tool names.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 2 tool updates
    • First observedhoneypot_check
    • First observedscan_token

Frequently Asked Questions

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Token safety oracle for AI agents. Honeypot detection, 17 scam pattern checks, LP lock verification across 6 EVM chains. Score 0-100 with risk flags. ERC Token Safety Score standard.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Quick-scan a smart contract for rug, honeypot, or centralization risk before sending funds. It combines verified source, live on-chain state, and heuristic Solidity analysis to return a SAFE/CAUTION/HIGH-RISK verdict.
    1
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources