← Files TokenOS Contract AuditARCHIVED FILE
plugin.json
8.47 KB · Oct 6, 2026 · 00:02 UTC
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "tokenos-contract-audit",
"version": "1.0.3",
"description": "Paste a Solidity or Anchor contract and get an instant security scan \u2014 reentrancy, access control, signer checks, unchecked math \u2014 with line numbers, severity and a fix for each finding.",
"author": {
"name": "TokenOS",
"email": "info@tokenos.ai",
"url": "https://tokenos.ai"
},
"homepage": "https://tokenos.ai/chatgpt-apps/contract-audit",
"keywords": [
"audit my solidity contract",
"smart contract security checker",
"is this contract safe",
"solidity vulnerability scanner",
"anchor program audit",
"reentrancy check",
"solana smart contract audit",
"smart contract audit tool"
],
"extensions": {
"com.openai": {
"interface": {
"displayName": "TokenOS Contract Audit",
"shortDescription": "Scan Solidity & Anchor code",
"longDescription": "Heuristic security scan of Solidity and Solana (Anchor / native Rust) contracts: reentrancy patterns, missing access control, tx.origin, delegatecall, weak randomness, unchecked calls, missing signer / owner / PDA bump checks, unchecked arithmetic and more \u2014 each with line numbers, severity and a fix, plus an overall letter grade. Read-only: the code you paste is analysed in memory and never stored.\n\nTools:\n\u2022 quick_audit \u2014 Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade.\n\nTargets questions like: \u201caudit my solidity contract\u201d; \u201csmart contract security checker\u201d; \u201cis this contract safe\u201d; \u201csolidity vulnerability scanner\u201d; \u201canchor program audit\u201d; \u201creentrancy check\u201d.\n\nDocumentation: https://tokenos.ai/mcp/contract-audit\n\nOutputs are informational \u2014 on-chain reads, deterministic calculators and heuristic scans \u2014 not financial, legal or security advice. TokenOS is non-custodial and never holds keys or funds; anything you launch, deploy or sign happens from your own wallet.",
"developerName": "TokenOS",
"category": "Developer Tools",
"capabilities": [
"Heuristic security scan for Solidity",
"Heuristic security scan for Solana Anchor / Rust",
"Findings with severity, lines and fixes",
"Letter grade per contract"
],
"websiteURL": "https://tokenos.ai/chatgpt-apps/contract-audit",
"supportURL": "https://tokenos.ai/support",
"privacyPolicyURL": "https://tokenos.ai/privacy",
"termsOfServiceURL": "https://tokenos.ai/terms",
"defaultPrompt": [
"Audit this Solidity contract for vulnerabilities \u2014 I'll paste the source",
"Is this Anchor program safe? Here is the code",
"Check my ERC-20 for reentrancy and access-control issues"
],
"brandColor": "#047857",
"brandColorDark": "#00FF94",
"composerIcon": "./assets/icon.png",
"logo": "./assets/logo.png"
},
"review": {
"test_cases": {
"positive": [
{
"description": "Audit a vulnerable Solidity vault",
"prompt": "Audit this Solidity contract:\n\npragma solidity ^0.8.0;\n\ncontract Vault {\n mapping(address => uint) public balances;\n address owner = msg.sender;\n\n function deposit() external payable {\n balances[msg.sender] += msg.value;\n }\n\n function withdraw() external {\n uint amt = balances[msg.sender];\n (bool ok, ) = msg.sender.call{value: amt}(\"\");\n require(ok);\n balances[msg.sender] = 0;\n }\n\n function kill() external {\n require(tx.origin == owner);\n selfdestruct(payable(owner));\n }\n}",
"tools_triggered": "quick_audit",
"expected_behavior": "Returns grade F with high findings for tx.origin authorisation (L19), selfdestruct (L20) and possible reentrancy in withdraw (L11), plus a low floating-pragma finding, each with a fix; renders the audit widget."
},
{
"description": "Clean contract",
"prompt": "Audit this: pragma solidity 0.8.24; import Ownable; contract Counter is Ownable { uint public n; function bump() external onlyOwner { n += 1; } }",
"tools_triggered": "quick_audit",
"expected_behavior": "Returns grade A (100/100) with no findings, marked as a heuristic scan (widget shows \"1 line\")."
},
{
"description": "Audit an Anchor program",
"prompt": "Is this Anchor program safe?\n\nuse anchor_lang::prelude::*;\n\n#[program]\npub mod vault {\n use super::*;\n pub fn withdraw(ctx: Context<Withdraw>, amount: u64) -> Result<()> {\n let vault = &mut ctx.accounts.vault;\n vault.balance -= amount;\n Ok(())\n }\n}\n\n#[derive(Accounts)]\npub struct Withdraw<'info> {\n #[account(mut)]\n pub vault: Account<'info, Vault>,\n pub authority: AccountInfo<'info>,\n}\n\n#[account]\npub struct Vault {\n pub authority: Pubkey,\n pub balance: u64,\n}",
"tools_triggered": "quick_audit",
"expected_behavior": "Returns grade F with findings for an unchecked AccountInfo (L17), authority not a Signer (L17), mutable account without ownership constraints (L15) and unchecked arithmetic (L8), each with a fix."
},
{
"description": "delegatecall, weak randomness and an unprotected setter",
"prompt": "Check this contract for vulnerabilities:\n\npragma solidity ^0.8.0;\n\ncontract Lottery {\n address public impl;\n\n function setImpl(address i) external {\n impl = i;\n }\n\n function play() external payable {\n if (uint(keccak256(abi.encodePacked(block.timestamp))) % 2 == 0) {\n payable(msg.sender).transfer(address(this).balance);\n }\n }\n\n fallback() external payable {\n (bool ok, ) = impl.delegatecall(msg.data);\n require(ok);\n }\n}",
"tools_triggered": "quick_audit",
"expected_behavior": "Returns findings for delegatecall to a settable address (L17), weak randomness from block.timestamp in play (L11), setImpl having no access control (L6), the native transfer (L12) and a floating pragma (L1), each with a severity and a fix."
},
{
"description": "Input that is not contract source",
"prompt": "Audit this contract: hello world",
"tools_triggered": "quick_audit",
"expected_behavior": "Tool returns a validation error asking for the full contract source; the assistant asks the user to paste the Solidity or Anchor code."
}
],
"negative": [
{
"description": "Unsupported language \u2014 Tool reports unsupported language; the assistant answers generally without a scan grade.",
"prompt": "Audit this Python script for security issues: print('hi')"
},
{
"description": "Empty input \u2014 The assistant asks the user to paste the source instead of calling the tool with nothing.",
"prompt": "Audit my contract"
},
{
"description": "Guarantee request \u2014 No certification; results are presented as heuristics and findings to verify.",
"prompt": "Certify that this contract is 100% secure"
}
]
},
"commerce": false,
"commerce_description": "This plugin does not sell products or process payments. The scan is read-only and the pasted code is not stored.",
"demo_recording_url": "https://tokenos.ai/demos/tokenos-contract-audit-demo.mp4"
},
"publication": {
"release_notes": "1.0.3: TokenOS-branded display name; widgets now implement the MCP Apps standard (_meta.ui.resourceUri + ui/* bridge) alongside the openai/* aliases; listing update \u2014 revised descriptions and capabilities, runnable inline review test cases, demo recording URL. quick_audit is the only tool (deep_audit removed, no commerce). Scanner now catches block.timestamp / block.number randomness inside hashes or modulo and any public setter that changes state without checking the caller; single-line pastes no longer show L1 on every finding. Review test cases carry the exact line numbers the scanner reports. Tools: quick_audit."
},
"apps": "./.app.json"
}
}
}
SHA-256: 41f8ad1db1dc756dc9b154a285842924e1fd067c27be4f5d5e8161eefd4e92cb