Tanod
dev.tanod/tanod · 0.1.0
Pay-per-call security checks for AI agents: contract scan, pre-tx check, skill/MCP scan.
Nobody here has read this server's code, because it publishes none. The description above is the maker's own, from the registry. A connection test shows whether it answers and what tools it says it has; it never calls a tool, so it cannot show what one does with your data.
Where it sits in the directory's order
What can be seen from outside, weighed as the directory publishes.
Observable signals: 45 of 100 points (at most 60 here)
| Input | Points | What was seen |
|---|---|---|
| Source published | held at 0 | No entry here publishes source: that is what puts it in this directory. |
| Licence stated | held at 0 | With no files, there is nothing for a licence to be stated in or held against. |
| Advisory state | held at 0 | Advisory databases index packages, and these entries publish none, so there is nothing to look up. |
| Auth declared | 0 of 15 | The registry entry declares no key. That is what it declares, not a finding that it has no protection. |
| Latest connection test reached it | 20 of 20 |
Where it answers
https://tanod.dev/mcpstreamable-http
Connection test
The MCP handshake, then a request for the tool list, with no key and no data of yours. Run nightly, and by anyone, at most once every ten minutes per server.
It completed the handshake and listed 4 tools.
- Protocol
- 2025-06-18
- Calls itself
- tanod 0.1.0
- Handshake time
- 933 ms
- HTTP status
- 200
The tools it lists (4, as of 2 hours ago)
The tool-description rules found nothing in these descriptions. They look for instructions aimed at a model and for hidden characters; they cannot see what a tool does when it runs.
scan_contract_sourcepactlint: static security scan of Solidity source code, before you deploy, review or depend on a contract. Input: `source` (one .sol file, no imports, up to 200 KB) or `standard_json` (solc standard-JSON input with every import inline, up to 1 MB and 500 files); optional `filename`, `compiler_version` (X.Y.Z; default from the pragma) and the include_* flags. Checks: solc + Slither + custom detectors for recurring DeFi bug classes (unchecked ERC-20 returns, zero slippage limits, stale or spot-price oracles, ERC-4626 share inflation, signature replay and more), triaged and de-duplicated. Returns
scan_contract_addresspactlint: static security scan of a deployed contract on Ethereum or Base, by address. Input: `address` (0x + 40 hex) and `chain` (ethereum | base); optional include_* flags. Fetches the verified source from Sourcify, then runs the same analysis as scan_contract_source: solc + Slither + custom detectors for recurring DeFi bug classes (unchecked ERC-20 returns, zero slippage limits, stale or spot-price oracles, ERC-4626 share inflation, signature replay and more), triaged and de-duplicated. Returns the JSON report plus a Markdown rendering. Contracts without verified source are refused (not_ver
check_contract_before_interactiontxpeek: pre-transaction risk check. Call it right before you send a transaction to, approve, or buy a token at an address on Base or Ethereum. Input: `address` (0x + 40 hex) and `chain` (base | ethereum). Returns verdict (low | caution | high | unknown), risk_score 0-100 and plain-language reasons, e.g. upgradeable by a single key, unverified source, mint/blacklist/fee functions, SELFDESTRUCT or DELEGATECALL, an EOA where a contract was expected; plus proxy, token and verification details and the block it was checked at. Price: USD 0.005. Free: 3 scans or 30 txpeek checks per IP per UTC day (o
scan_agent_packagetoolsniff: static security scan of an AI-agent skill (SKILL.md bundle) or MCP server package. Call this before installing or enabling one. Input: `source` (npm:name[@version] | pypi:name[==version] | github:owner/repo[@ref][//subdir] | https://github.com/owner/repo[/tree/ref/dir] | clawhub:[owner/]slug[@version]) or `content_base64` (a .zip/.tar/.tgz/.tar.bz2/.tar.xz archive up to 20 MB, or one file with `filename`, e.g. SKILL.md). It downloads the published package or takes your upload, unpacks it in a sandbox and reads every file as text; nothing is installed, imported or run. Returns verdic
How this entry becomes a listing
For the maker. The catalogue lists what it can read, and this server publishes nothing to read yet. There are two routes, and only the first is open today.
Publish the source Open today
- Put the server's source in a public repository on github.com, with a licence.
- Keep a server.json in that repository naming this server,
dev.tanod/tanod, and declare the repository in it:"repository": { "url": "https://github.com/owner/repo", "source": "github" }, adding"subfolder"when the server lives in a folder. - Publish that version to the official MCP registry.
- The nightly registry sweep records the declaration. This page stays, dated, and says the source is declared but not yet read.
- The catalogue reads declared repositories at a pinned commit, in batches run by hand, and lists the servers that meet the batch's rules (among them a server.json at that commit naming the server, an https endpoint and a licence). When it lists this server, this page links to the listing. There is no schedule, so no date can be promised.
List it through the maker studio Not open yet
From the official MCP registry, last updated there 3 hours ago. The registry entry · tanod.dev