Rust-based Solidity AST analyzer backend providing MCP tools for smart contract analysis
Aderyn MCP server demonstrates solid definition quality with consistent naming patterns, comprehensive parameter descriptions, and well-structured schemas across all 7 tools. All tools follow verb_noun naming convention (explore_*, list_*, get_*) and include detailed descriptions. Parameter schemas are properly typed with JSON Schema. However, there are gaps in output schema documentation, limited error handling guidance, and no tool annotations. The server is domain-focused (Solidity AST analysis) with specialized but coherent tool design. Tool composition is good, tools chain naturally (project_overview → list_contracts → contract_surface_inspector → callgraph). The tool_guide and node_finder tools serve as discovery/orchestration helpers, which is thoughtful. Average tool description length ~250 chars (slightly above baseline 194 but acceptable for technical domain). All 7 tools have descriptions and typed parameters. No security concerns with credentials. Main weaknesses: missing explicit output schema documentation, no error recovery guidance, and lack of tool annotations (readOnlyHint present implicitly but not declared in annotations).
Analyzes the surface area of a specific deployable contract within a compilation unit. Returns details such as contract's state variables (own and inherited), and all entrypoint functions (own and inherited). Use the Node ID from the list contracts tool to specify which contract to analyze.
The callgraph provider tool maps and analyzes function execution flows within Solidity smart contracts by tracing all possible internal function calls and modifier executions triggered by the given entrypoint function's Node ID. It provides inheritance-aware analysis across contract hierarchies and imported libraries. It returns compilation unit index and NodeIDs of the various functions in the call chain.
It returns project configuration such as the root directory, source directory (where the contracts are kept), 3rd party libraries, remappings, list of source files, user preference for included and excluded files, etc.
MUST be called once at the beginning to have that base knowledge required to solve user's problems. Provides glossary, general approaches to common scenarios, advanced tool calling strategies and tips to leverage Aderyn's MCP tools for high performance and accuracy.
Enumerates deployable contracts within a specific compilation unit. Returns contract names, file names (relative to the project root) and node IDs.
No explicit output schema documentation for any tool. While input schemas are well-defined, return types are not documented in code or descriptions. LLMs cannot reliably know what fields to expect from responses, forcing trial-and-error exploration of outputs.
Error handling lacks recovery guidance. Tool definitions (sampled from callgraph/tool.rs) show error support via McpError but descriptions contain no 'if X fails, try Y' guidance. LLMs cannot self-correct when a tool fails.
Tool annotations missing. No readOnlyHint, destructiveHint, or idempotentHint declared. All tools are read-only (Risk: READ_ONLY listed in metadata) but this is not formally annotated in the MCP schema. Modern clients expect tool annotations for safety reasoning.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
| 2026-03-09 | C | 68 | - | v1 |
Retrieve nodes IDs and compilation unit indexes of nodes matched by either supplying the exact names of functions, modifiers and contracts or grep them with a regular expression. Important: Input only 1 search field (chose from functions, modifiers, contracts, events, errors and grep) Optionally also input 'compilation_unit_index' to limit the search to a specific compilation unit.
Given a compilation unit index and a Node ID, returns a focused summary of that exact AST node (e.g. function, modifier, event, variable, struct) and the source code snippet. Also in metadata show the callgraphs that collide with the node if it is a function.
aderyn_node_finder has optional mutually-exclusive parameters (search_functions_by_exact_name, search_modifiers_by_exact_name, search_contract_classes_by_exact_name, search_nodes_by_grep, get_all_events, get_all_errors) but the mutual exclusivity constraint is documented only in the description ('Important: Input only 1 search field'), not as a formal JSON Schema constraint. LLMs may pass multiple fields.
Parameter descriptions mention prerequisite calls (e.g. 'Use the project overview tool first') but do not explain what happens if the prerequisite is skipped. No recovery path documented.
get_project_overview and get_tool_guide have generic descriptions and empty/minimal input schemas, making them less discoverable. Descriptions do not explain WHEN to call them relative to other tools.