Oct 9, 2026 · 2 saved observations
Discoverability changed from “UNLISTED” to “LISTED”.
Metadata evidence →Listing evidence →TokenOS v1.0.3
From the marketplace listing
Heuristic security scan of Solidity and Solana (Anchor / native Rust) contracts: reentrancy patterns, missing access control, tx.origin, delegatecall, weak randomness, unchecked calls, missing signer / owner / PDA bump checks, unchecked arithmetic and more — each with line numbers, severity and a fix, plus an overall letter grade. Read-only: the code you paste is analysed in memory and never stored. Tools: • quick_audit — Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade. Targets questions like: “audit my solidity contract”; “smart contract security checker”; “is this contract safe”; “solidity vulnerability scanner”; “anchor program audit”; “reentrancy check”. Documentation: https://tokenos.ai/mcp/contract-audit Outputs are informational — on-chain reads, deterministic calculators and heuristic scans — not financial, legal or security advice. TokenOS is non-custodial and never holds keys or funds; anything you launch, deploy or sign happens from your own wallet.
Language: English · Automatically detected from descriptions.
Search terms declared by the publisher.
Exact text from the indicated source. A mention alone does not establish support for your task.
Heuristic security scan of Solidity and Solana (Anchor / native Rust) contracts: reentrancy patterns, missing access control, tx.origin, delegatecall, weak randomness, unchecked calls, missing signer / owner / PDA bump checks, unchecked arithmetic and more — each with line numbers, severity and a fix, plus an overall letter grade. Read-only: the code you paste is analysed in memory and never stored. Tools: • quick_audit — Static heuristic scan of a Solidity or Solana (Anchor / Rust) contract: findings with severity, line numbers and fixes, plus a letter grade. Targets questions like: “audit my solidity contract”; “smart contract security checker”; “is this contract safe”; “solidity vulnerability scanner”; “anchor program audit”; “reentrancy check”. Documentation: https://tokenos.ai/mcp/contract-audit Outputs are informational — on-chain reads, deterministic calculators and heuristic scans — not financial, legal or security advice. TokenOS is non-custodial and never holds keys or funds; anything you launch, deploy or sign happens from your own wallet.
Oct 9, 2026 · 2 saved observations
Discoverability changed from “UNLISTED” to “LISTED”.
Metadata evidence →Listing evidence →1.0.3: TokenOS-branded display name; widgets now implement the MCP Apps standard (_meta.ui.resourceUri + ui/* bridge) alongside the openai/* aliases; listing update — revised descriptions and capabilities, runnable inline review test cases, demo recording URL. quick_audit is the only tool (deep_audit removed, no commerce). Scanner now catches block.timestamp / block.number randomness inside hashes or modulo and any public setter that changes state without checking the caller; single-line pastes no longer show L1 on every finding. Review test cases carry the exact line numbers the scanner reports. Tools: quick_audit.
Declared in the saved package. Remote tools may change independently.
Publisher declarations from the archived package. These are separate from our research and the live service's terms.
Package observed Oct 9, 2026.
plugin_asdk_app_6ac05dd7a5d88191a8ffe686556b9a3b
Download plugin data (JSON)Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.
Check marketplace availability ↗
We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.
Compare researched pricing and access models →
Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.