{"id":5407,"external_id":"plugin_asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b","name":"tokenos-contract-audit","display_name":"TokenOS Contract Audit","developer":"TokenOS","category":"Developer Tools","listing_language":"en","listing_language_details":{"method":"cld-0.13.0/listing-v1","reliable":true,"detected_at":"2026-10-06T00:01:49Z","input_sha256":"3f8ab7b205b01d3da957032628ef28580954cf5038e0adeda09a562785b2e4a6","source_fields":["release.description","release.interface.short_description","release.interface.long_description"]},"version":"1.0.3","skill_count":0,"first_seen_at":"2026-10-06T00:00:00.990Z","last_seen_at":"2026-10-06T12:00:11.932Z","last_changed_at":"2026-10-06T00:00:00.990Z","install_count":null,"search_matches":[],"research_summary":null,"research_reviewed_at":null,"metadata":{"canonical_app_id":"asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b","connector_id":"asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b","created_at":"2026-10-03T20:19:54.880542Z","discoverability":"UNLISTED","id":"plugin_asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b","is_template":false,"name":"tokenos-contract-audit","release":{"app_ids":["asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b"],"app_manifest":{"apps":{"contract-audit":{"id":"asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b","required":true}}},"app_templates":[],"description":"Paste a Solidity or Anchor contract and get an instant security scan — reentrancy, access control, signer checks, unchecked math — with line numbers, severity and a fix for each finding.","display_name":"TokenOS Contract Audit","id":"pluginrel_39b71e6ca07c8191b3beb0d9d52c43bc","interface":{"brand_color":"#047857","capabilities":["Heuristic security scan for Solidity","Heuristic security scan for Solana Anchor / Rust","Findings with severity, lines and fixes","Letter grade per contract"],"category":"Developer Tools","composer_icon_dark_url":null,"composer_icon_url":"https://files.openai.com/content?id=file_00000000acb881f5b4527fef7e10c9c9","default_prompt":"Audit this Solidity contract for vulnerabilities — I'll paste the source","default_prompts":["Audit this Solidity contract for vulnerabilities — I'll paste the source","Is this Anchor program safe? Here is the code","Check my ERC-20 for reentrancy and access-control issues"],"developer_name":"TokenOS","logo_url":"https://files.openai.com/content?id=file_00000000db0481f58f1f25ac6eaaebf8","logo_url_dark":null,"long_description":"Heuristic security scan of Solidity and Solana (Anchor / native Rust) contracts: reentrancy patterns, missing access control, tx.origin, delegatecall, weak randomness, unchecked calls, missing signer / owner / PDA bump checks, unchecked arithmetic and more — each with line numbers, severity and a fix, plus an overall letter grade. Read-only: the code you paste is analysed in memory and never stored.\n\nTools:\n• quick_audit — Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade.\n\nTargets questions like: “audit my solidity contract”; “smart contract security checker”; “is this contract safe”; “solidity vulnerability scanner”; “anchor program audit”; “reentrancy check”.\n\nDocumentation: https://tokenos.ai/mcp/contract-audit\n\nOutputs are informational — on-chain reads, deterministic calculators and heuristic scans — not financial, legal or security advice. TokenOS is non-custodial and never holds keys or funds; anything you launch, deploy or sign happens from your own wallet.","plugin_category_id":"developer tools","privacy_policy_url":"https://tokenos.ai/privacy","screenshot_urls":[],"short_description":"Scan Solidity & Anchor code","terms_of_service_url":"https://tokenos.ai/terms","website_url":"https://tokenos.ai/chatgpt-apps/contract-audit"},"keywords":["audit my solidity contract","smart contract security checker","is this contract safe","solidity vulnerability scanner","anchor program audit","reentrancy check","solana smart contract audit","smart contract audit tool"],"onboarding_skill_name":null,"requires_local_executor":false,"skills":[],"version":"1.0.3"},"scope":"GLOBAL","status":"ENABLED"},"research":null,"package_metadata":{"name":"tokenos-contract-audit","author":{"url":"https://tokenos.ai","name":"TokenOS"},"sources":[{"path":"plugin.json","sha256":"41f8ad1db1dc756dc9b154a285842924e1fd067c27be4f5d5e8161eefd4e92cb"}],"version":"1.0.3","commerce":false,"homepage":"https://tokenos.ai/chatgpt-apps/contract-audit","keywords":["audit my solidity contract","smart contract security checker","is this contract safe","solidity vulnerability scanner","anchor program audit","reentrancy check","solana smart contract audit","smart contract audit tool"],"artifact_id":29246,"observed_at":"2026-10-06T00:02:39Z","support_url":"https://tokenos.ai/support","capabilities":["Heuristic security scan for Solidity","Heuristic security scan for Solana Anchor / Rust","Findings with severity, lines and fixes","Letter grade per contract"],"field_sources":{"name":0,"author":0,"version":0,"commerce":0,"homepage":0,"keywords":0,"support_url":0,"capabilities":0,"release_notes":0,"review_case_counts":0,"commerce_description":0},"release_notes":"1.0.3: TokenOS-branded display name; widgets now implement the MCP Apps standard (_meta.ui.resourceUri + ui/* bridge) alongside the openai/* aliases; listing update — revised descriptions and capabilities, runnable inline review test cases, demo recording URL. quick_audit is the only tool (deep_audit removed, no commerce). Scanner now catches block.timestamp / block.number randomness inside hashes or modulo and any public setter that changes state without checking the caller; single-line pastes no longer show L1 on every finding. Review test cases carry the exact line numbers the scanner reports. Tools: quick_audit.","extraction_version":1,"review_case_counts":{"negative":3,"positive":5},"conflicts_or_errors":[],"commerce_description":"This plugin does not sell products or process payments. The scan is read-only and the pasted code is not stored."}}