# Token Security Audit

> Token Security Audit is a paid API for AI agents from mcp.dropenginehq.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Audits an EVM token contract for security risks using GoPlus security intelligence, returning detailed threat signals and risk metadata.

## Facts

- Endpoint: POST https://mcp.dropenginehq.com/api/token-security-audit?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/token-security-audit-e7c6b457
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_RbzgaInObEAWlD8PEjc0v

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability token-security-audit-e7c6b457 -d '<json body>'
```

Example prompt: Can you run a security audit on the token at address 0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48 on Ethereum — I want to know if it's safe to trade before I interact with it.

## When to prefer this

Choose this endpoint when you need structured, machine-readable security intelligence on an EVM token contract before trading, listing, or interacting with it. It is specifically powered by GoPlus, a recognized crypto security oracle, making it preferable over generic contract scanners when you need standardized risk signals across Ethereum, Base, Arbitrum, Optimism, Polygon, and BSC in a single paid API call.

## Known failure modes

- Invalid token address format (must match 0x + 40 hex chars) returns validation error
- Unsupported chain name returns enum validation error
- GoPlus upstream unavailability may return partial:true or failed_sources populated
- Unknown or unindexed token address may return empty data object with success:true
- Network timeout may increase latency_ms significantly

## How this service works

Audit an EVM token using GoPlus security intelligence.

## Output

Returns a JSON object with a 'data' field containing GoPlus security intelligence (risk flags, contract properties, ownership info, liquidity lock status, etc.), a 'success' boolean, a timestamp, and 'meta' with cache hit status, age, latency, and source details.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "chain": {
   "enum": [
    "ethereum",
    "base",
    "arbitrum",
    "optimism",
    "polygon",
    "bsc"
   ],
   "type": "string"
  },
  "token_address": {
   "type": "string",
   "pattern": "^0x[a-fA-F0-9]{40}$"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "data": {},
  "meta": {
   "cache": {
    "hit": false,
    "age_ms": 0
   },
   "partial": false,
   "sources": [],
   "latency_ms": 1,
   "failed_sources": []
  },
  "tool": "crypto_intelligence_tool",
  "success": true,
  "timestamp": "2026-01-01T00:00:00.000Z"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/token-security-audit-e7c6b457/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from mcp.dropenginehq.com](https://www.zero.xyz/host/mcp.dropenginehq.com/llms.txt)
