MCP server for searching Solodit's blockchain security audit findings database
Strong tool definitions with comprehensive descriptions and well-structured schemas. All 4 tools have clear action-verb names (search_*, get_*, recent_*) and detailed parameter documentation. Descriptions are LLM-optimized with WHEN-TO-USE guidance and cross-references to related tools. Input schemas use proper JSON Schema with types, enums, and descriptions for nearly all parameters. However, output schemas are not explicitly documented in code, which is a notable gap for chaining. No tool annotations (readOnlyHint) despite all being read-only operations. Rate limiting is implemented but not surfaced in tool descriptions.
Retrieve the full content and all metadata of a single Solodit finding by its ID or slug. Use this tool when you already know which finding you want to examine in detail -- for example, after seeing a relevant title in search_findings results. Returns the complete untruncated content, all tags, finders, contest info, and links. When to use: - You have a finding ID or slug and want the full content - Following up on a search result to read the complete vulnerability description - Need all metadata (finders, contest details, all links) for a specific finding Use search_findings instead if you need to search by keyword or apply filters. Use search_by_tag for quick vulnerability pattern lookups. Use recent_findings to browse the latest discoveries.
Browse the most recent Solodit findings from the last N days. Results are sorted by recency (newest first). Default: last 30 days. When to use: - Checking what new vulnerabilities have been discovered recently - Staying up to date on the latest audit findings - Browsing recent findings filtered by impact level, language, or protocol category Use search_findings for complex multi-filter queries. Use search_by_tag to find specific vulnerability patterns regardless of date. Use get_finding_detail to read the full content of a specific finding.
Search Solodit findings by one or more vulnerability tags. Optimized for finding examples of specific vulnerability patterns -- results are sorted by quality score (best examples first). When to use: - Looking for examples of a specific vulnerability type (e.g., Reentrancy, Oracle, Access Control) - Checking if a vulnerability pattern applies to code under review - Finding high-quality writeups about a vulnerability class Available tags include: Reentrancy, Oracle, Access Control, Integer Overflow/Underflow, Front-running, Logic Error, DOS, Price Manipulation, Flash Loan, Griefing, and 190+ more. Use search_findings for complex multi-filter queries (keyword + firm + date + more). Use get_finding_detail to read the full content of a specific finding. Use recent_findings to browse the latest discoveries.
Output schemas not documented in code. Responses are inferred from API calls, not declared via JSONSchema. LLMs cannot plan downstream tool chains (e.g., extract finding_id from search results to pass to get_finding_detail) without seeing the response structure.
No tool annotations. All 4 tools are read-only (cannot modify state), but readOnlyHint is not set in tool definitions. This prevents agents from understanding that these tools are safe to call in any order and multiple times without side effects.
Rate limiting implemented but not surfaced in descriptions or error handling. If an agent hits the limit, the error response from rateLimiter will not guide recovery. No guidance in tool descriptions about rate limits, retry behavior, or backoff strategy.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-03-09 | D | 50 | - | v1 |
Search Solodit's database of 49,000+ blockchain security audit findings with full filter power. Returns structured results with title, impact, summary, tags, firm, scores, and content preview. All parameters are optional -- a bare call returns recent findings. This is the most powerful search tool with 14+ filters. For simpler queries, consider: - get_finding_detail: Get full content of a specific finding by ID or slug - search_by_tag: Quick vulnerability pattern lookup by tag (sorted by quality) - recent_findings: Browse latest discoveries from the last N days When to use: You need complex multi-filter queries combining keywords, firms, date ranges, and other advanced filters that the convenience tools don't support. Available filters: - keywords: Free-text search across titles and content - impact: Severity filter (HIGH, MEDIUM, LOW, GAS) - tags: Vulnerability type (Reentrancy, Oracle, Access Control, Integer Overflow, Front-running, etc.) - firms: Audit firm (Cyfrin, Sherlock, Code4rena, Trail of Bits, OpenZeppelin, etc.) - protocol_category: Protocol type (DeFi, NFT, Lending, DEX, Staking, Governance, Bridge, etc.) - language: Smart contract language (Solidity, Rust, Cairo, Vyper, Move) - protocol: Protocol name (partial match) - finder: Auditor handle (partial match) - quality_min / rarity_min: Minimum score thresholds (0-5) - date_range: Preset ranges (30, 60, 90 days, or alltime) - date_after: Custom date cutoff (ISO format) - sort_by / sort_direction: Ordering (Recency/Quality/Rarity, Desc/Asc) - page / page_size: Pagination controls
No maximum bound on 'days' parameter in recent_findings. Unbounded numerics invite absurd values (e.g., days: 999999) that may cause API timeout or excessive response size. Should set maximum (e.g., days: 365 or 1000).
API key handled via environment variable (correct), but tools do not validate it at registration time, only at call time. If SOLODIT_API_KEY is missing, all 4 tools return a generic error with setup instructions. The error is actionable but only appears after the agent selects the tool.