EVM MCP Auditor
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| evm_audit_contractA | Audit Solidity smart contract source code for critical security vulnerabilities (Reentrancy, Unsafe Delegatecall, Tx.Origin authentication, Unchecked Calls, etc.) and generate a security score. |
| evm_fetch_sourceA | Fetch verified smart contract source code from block explorers across Ethereum, Base, Arbitrum, Optimism, or Polygon. |
| evm_decode_calldataA | Decode raw EVM transaction calldata into function selector, parameter segments, and byte length. |
| evm_estimate_gasB | Get real-time gas price and network execution telemetry across supported EVM networks. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool occupies a completely distinct role: estimating gas, auditing source, fetching source, and decoding calldata. There is zero functional overlap between the four, eliminating any chance of an agent selecting the wrong tool for a given intent.
All tools follow a flawless 'evm_verb_noun' snake_case convention with no exceptions. The consistent prefix plus action word makes the API predictable and easy to reason about.
Four focused tools is perfectly scoped for a specialized auditing server covering the key audit workflow without bloat. It hits the sweet spot of being comprehensive for its domain without unnecessary features.
The core fetch-source-and-audit workflow is well covered, with useful supporting utilities for gas analysis and calldata decoding. However, there's no way to list past audits, compare versions, or interact with the broader transaction context, which are minor gaps for a full auditing lifecycle.