contract-auditor
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| audit_contractA | Run a security QUICK-SCAN on a smart contract BEFORE you interact with it or send funds. Give it a deployed contract address + chain (or raw Solidity source) and it returns a SAFE / CAUTION / HIGH-RISK verdict with an explained risk score. It fetches the VERIFIED source from Sourcify (key-less), reads LIVE on-chain state via public RPC (is there code? is it an upgradeable proxy? who is the owner and is it a single EOA or renounced?), and statically scans the Solidity for owner-controlled mint/pause/blacklist/fee, selfdestruct, delegatecall, tx.origin auth, reentrancy shape and honeypot patterns (can't sell, owner-adjustable taxes). Use whenever you're about to approve, buy, fund, or integrate a contract you don't fully trust. Heuristic, not a formal audit. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion between tools. The tool's purpose is clearly described.
Single tool has a clear verb_noun name ('audit_contract'), which is consistent with itself and follows a predictable pattern.
One tool is borderline but acceptable given the narrow focus of the server. The tool is comprehensive and not trivial.
The server fully covers its stated purpose of performing a quick security scan. No obvious gaps for the intended use case.