Skip to main content
Glama

Who can change this Solana program?

solana_program_authority

Check who can replace a Solana program's code before signing or depositing. Reveals upgrade authority, multisig details, last deploy date, and security flags.

Instructions

Use before signing a transaction for, or depositing into, a Solana mainnet program. Answers who can replace its code: immutable, a single key, a Squads v4 multisig (threshold, members and time lock read on-chain, the vault re-derived as proof), Squads v3 or SPL Governance; plus the last deploy date, OtterSec verified build, embedded security.txt and severity-ranked flags. Costs $0.05 USDC on Solana, paid over x402 from WATCHDOG_SOLANA_PRIVATE_KEY. An address that holds no program is not charged.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
programIdYesProgram address, base58

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations (readOnlyHint=false, non-idempotent, openWorld) are unusual for a query tool, but the description explains the cause: it costs $0.05 USDC via x402 from WATCHDOG_SOLANA_PRIVATE_KEY and is not charged when the address holds no program. That payment/side-effect disclosure is exactly the context annotations cannot convey. It does not cover failure modes or latency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the trigger condition and the core question, then the returned data, then cost mechanics. Dense but every clause carries information; the middle enumeration is long but justified by the variety of authority models.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by enumerating the return contents (authority type and multisig threshold/members/time lock, last deploy date, OtterSec verified build, security.txt, severity-ranked flags). An agent knows both when to call it and what it will receive.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Only one parameter (programId) with 100% schema coverage, so the schema fully documents it. Baseline for a single well-described parameter is a 4; the description adds no format detail beyond base58, but none is needed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific question it answers ('who can replace its code') and enumerates the exact authority models it resolves (immutable, single key, Squads v4/v3, SPL Governance). This distinguishes it cleanly from siblings like evm_contract_control and get_scan_report.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Use before signing a transaction for, or depositing into, a Solana mainnet program' gives an explicit trigger condition and scope. It does not name an alternative tool or exclusion, but the condition is clear enough for correct selection.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.