Deterministic static pattern scan of Solidity smart-contract source text
Deterministic static pattern scan of Solidity smart-contract source text - a fixed ruleset flagging tx.origin authentication, delegatecall, selfdestruct, unchecked low-level calls, unchecked .send(), floating pragmas, block-timestamp dependence, weak block-derived randomness, value-call reentrancy surface, inline assembly, ecrecover, and missing SPDX headers. Returns line-anchored findings with severities.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://agent402.tools/api/solidity-scan
| Category | Everything else |
|---|---|
| Provider host | agent402.tools |
| Networks | algorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73ktiC1qzkkit8=, eip155:10, eip155:1329, eip155:137, eip155:143, eip155:42161, eip155:42220, eip155:43114, eip155:4663, eip155:8453, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp, stellar:pubnet |
| Payment schemes | exact, upto |
| Self-reported calls, 30 days | 5 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
We never call tools that send, buy, move money or file anything, not even without paying.
Example input (from the provider)
{
"body": {
"source": "pragma solidity ^0.8.0;\ncontract Wallet {\n function drain(address payable to) external {\n require(tx.origin == msg.sender);\n to.call{value: address(this).balance}(\"\");\n }\n}"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"properties": {
"source": {
"description": "Solidity source text to scan (max 512KB).",
"type": "string"
}
},
"required": [
"source"
]
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"properties": {
"disclaimer": {
"type": "string"
},
"findings": {
"items": {
"properties": {
"line": {
"type": "integer"
},
"message": {
"type": "string"
},
"rule": {
"type": "string"
},
"severity": {
"type": "string"
},
"snippet": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"lines": {
"type": "integer"
},
"summary": {
"properties": {
"high": {
"type": "integer"
},
"info": {
"type": "integer"
},
"low": {
"type": "integer"
},
"medium": {
"type": "integer"
}
},
"type": "object"
}
},
"required": [
"lines",
"findings",
"summary",
"disclaimer"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}