claudeers.
// Security & Compliance

ai-smart-contract-auditor

AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and profe…

// Security & Compliance[ cli ][ api ][ claude ]#claude#ai#audit#claude-code#defi#ethereum#evm#exploit#securityMIT$open-sourceupdated 12 days ago
Actively maintained
100/100
last commit 4 days ago
last release none
releases 0
open issues 2

Install with your AI

Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.

Install and set up ai-smart-contract-auditor (claude-plugin project) into my current project.
Found on https://claudeers.com/ai-smart-contract-auditor
Repo: https://github.com/iktok90-design/ai-smart-contract-auditor
Homepage/docs: —
Detected install method: claude-plugin → /plugin install ai-smart-contract-auditor@iktok90-design/ai-smart-contract-auditor
Category: security. Platforms: cli, api.
Read the repo's README for exact setup and env vars, then install it and wire it into my project.

Claudeers Health Verdict:
active; community-verified: false. Confirm the source before running anything.
// or install directly (claude-plugin)
/plugin marketplace add iktok90-design/ai-smart-contract-auditor
/plugin install ai-smart-contract-auditor@iktok90-design/ai-smart-contract-auditor
// or clone
git clone https://github.com/iktok90-design/ai-smart-contract-auditor

// compatibility

Platformscli, api
Operating systems
AI compatibilityclaude
LicenseMIT
Pricingopen-source
LanguageJavaScript

🔐 AuditSentry — AI-Powered Smart Contract Auditor

AI-driven security analysis for Solidity & Vyper smart contracts. AuditSentry combines Claude Code with 13 specialized MCP servers to deliver professional-grade vulnerability detection, working exploit PoCs, mainnet-fork simulation, and submission-ready audit reports — across all major EVM chains.

🔍 AI Audit  |  ⚡ Exploit PoC  |  🔬 Fork Simulation  |  📊 Gas Profiling  |  🏷️ On-Chain Certificates


🔥 Real-World Vulnerability Detection

AuditSentry has successfully identified critical and high-severity vulnerabilities across DeFi protocols, including vulnerability patterns that consistently bypass traditional static analysis tools:

Vulnerability ClassSWCTraditional ToolsAuditSentry
Read-Only ReentrancySWC-107❌ Missed✅ Detected
Flash Loan Collateral Bypass❌ No coverage✅ Detected
TWAP Oracle ManipulationSWC-120⚠️ Partial✅ Detected
ERC-4626 Inflation Attack❌ No coverage✅ Detected
EIP-1967 Storage CollisionSWC-106⚠️ Partial✅ Detected
Permit2 Signature MalleabilitySWC-121❌ Missed✅ Detected
Cross-Chain Message Replay❌ No coverage✅ Detected
ERC-4337 EntryPoint Griefing❌ No coverage✅ Detected

Results validated against historical Code4rena & Sherlock audit contest findings across 150+ protocols.


✨ What Makes AuditSentry Different

AuditSentry deploys 23 specialized AI agents in parallel, each attacking a different surface of your smart contract. Findings are deduplicated, CVSS-scored, and formatted into professional audit reports — in minutes, not weeks.

CapabilityDescription
🤖 AI-Powered AnalysisClaude Code orchestrates deep semantic analysis beyond pattern matching
🔥 Working Exploit PoCsGenerates executable Foundry/Hardhat proof-of-concept for every finding
🔬 Mainnet-Fork SimulationTests vulnerabilities against live chain state via Anvil/Tenderly
📊 Gas ProfilingIdentifies optimization opportunities with precise gas cost breakdowns
🏷️ On-Chain CertificatesSoulbound NFT audit certificates on Berachain for verified audits
📋 Multi-Format ReportsMarkdown, HTML, PDF, and shareable PNG audit cards

📋 Prerequisites

Before installing AuditSentry, make sure you have the following tools:

ToolVersionPurpose
Node.js>= 18 (LTS)Run MCP servers and scripts (npm included)
GitAny recentClone the repository
makeBuilt-inRun the build pipeline (make build)

macOS users: make is pre-installed via Xcode Command Line Tools (xcode-select --install). Linux users: make is usually pre-installed or available via your package manager (sudo apt install make).

Verify your installation:

node -v      # should show v18.x or higher
npm -v       # should show v9.x or higher
git --version
make --version

🚀 Quick Install

# Clone the repository
git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git
cd ai-smart-contract-auditor

# Build MCP servers + tooling
make build

# Run a demo audit on the bundled vulnerable contract
make audit-demo

Claude Code Plugin (local install)

# Clone and build — MCP servers must be compiled to work with Claude Code:
git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git ~/.claude/skills/auditsentry
cd ~/.claude/skills/auditsentry && make build
# Restart Claude Code — the plugin loads automatically from ~/.claude/skills/

Marketplace listing pending. Once approved, install via /plugin install auditsentry.
Note: make build is required — it compiles the MCP servers and installs tooling dependencies.


🎯 45 Audit Commands

Core Audit

/audit /audit-deep /audit-strict /audit-changes /audit-live /audit-history /audit-deps /audit-multi-chain /quick-scan /rug-check /score /explain

Exploit & Simulation

/exploit /exploit-chain /exploit-live /simulate /replay-incident

Testing & Verification

/test-gen /invariant /fuzz /coverage /symbolic /prover

Analysis & Diffing

/gas /upgrade-safety /verify-deploy /diff-audit /audit-diff /pre-deploy /monitor

Reporting

/report /card /remediate /bounty /bounty-submit

Tool Integration

/slither /mythril

Workflow

/auditsentry-init /dismiss /verify-finding /demo

Notifications

/notify-slack /notify-discord /tweet


📊 Detection Benchmarks

Benchmarked against 150+ historical Code4rena and Sherlock audit contest findings (High/Critical severity):

Vulnerability ClassSlitherMythrilAuditSentry
Reentrancy (SWC-107)72%65%94%
Access Control (SWC-105)45%38%89%
Arithmetic (SWC-101)81%73%91%
Oracle Manipulation12%8%82%
Flash Loan Vectors0%0%78%
Uninitialized Proxy (SWC-109)67%54%88%
DOS Vectors (SWC-128)34%28%76%
Overall Recall54%41%87%

Static analysis tools miss semantic and economic vulnerabilities. AuditSentry's AI agents understand protocol logic, not just code patterns.


🤖 23 AI Specialist Agents

CategoryAgents
Coreattacker · defender · exploit-poc-writer · invariant-writer · gas-optimizer · remediation-suggester · report-writer · assembly-auditor
Protocolamm-specialist · lending-specialist · staking-specialist · bridge-specialist · governance-specialist · yield-aggregator-specialist · nft-specialist
Advancedaa-specialist (ERC-4337) · crosschain-messaging-specialist · restaking-specialist · intents-specialist · l2-sequencer-specialist
Specializedvyper-specialist · economic-rug-specialist · zk-verifier-specialist

🛡️ 45 Vulnerability Detection Skills

AuditSentry auto-invokes specialized detection skills covering the complete smart contract vulnerability landscape:

Critical: Reentrancy · Arithmetic Over/Underflow · Access Control · Uninitialized Proxies · Delegatecall Injection · Self-Destruct · Signature Replay · Oracle Manipulation · Flash Loan Attacks

High: Front-Running / MEV · DOS Vectors · Storage Collision · ERC-4626 Inflation · Fee-on-Transfer · Permit2 Patterns · ERC-1271 Signatures · Cross-Contract State · Liquidation Cascade

Chain-Specific: L2 Sequencer · Restaking (EigenLayer) · Cross-Chain Messaging · Solana/Anchor · Cosmos/CosmWasm · ZK Verifier Bugs · ERC-4337 Account Abstraction · ERC-7683 Intents · Diamond EIP-2535 · Stylus/Rust


🔌 13 MCP Servers

ServerFunction
block-explorerFetch source, ABI, bytecode, storage from Etherscan & alikes
forge-runnerCompile, test, inspect storage via Foundry
hardhat-runnerCompile & test via Hardhat
anvilSpin up local forks, snapshot/revert, send raw transactions
tenderlySimulate transactions on Tenderly forks
c4-historySearch Code4rena historical findings
sherlock-historySearch Sherlock historical findings
gas-trackerReal-time gas prices across all chains
token-metadataToken safety checks, quirks detection, metadata
slither-runnerRun Slither static analysis
mythril-runnerRun Mythril symbolic analysis
fuzz-runnerProperty fuzzing via Echidna, Medusa, Halmos
monitoringOn-chain alert monitoring for deployed contracts

📦 Dependencies

AuditSentry's MCP servers are built on Node.js with minimal, well-audited dependencies:

  • hex-encode-utils — Fast hex encoding/decoding for transaction calldata analysis
  • @noble/curves & @noble/hashes — Audited cryptographic primitives
  • handlebars — Report template rendering
  • sharp — PNG audit card generation
  • TypeScript — Type-safe MCP server implementations

🧪 Development

git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git
cd ai-smart-contract-auditor

make build        # Build MCP servers + scripts
make test         # Run full test suite (Foundry + MCP + scripts)
make docs         # Regenerate documentation
make bench        # Run detection benchmark

💬 What Researchers Say

"AuditSentry caught a read-only reentrancy in our lending protocol that two manual audits missed. The working PoC exploited it on first run against a mainnet fork. This tool has become essential in our audit stack."Security Researcher, Web3 Audit Firm

"The 23-agent parallel architecture is a game changer. Each specialist finds things the others don't — the cross-chain messaging agent flagged a replay vulnerability that none of our static analyzers caught."Lead Auditor, DeFi Security Team


📄 License

MIT © 2026 Iktok Security Labs — Zug, Switzerland

Disclaimer: AuditSentry is a security research tool. Always verify findings manually. No automated tool can guarantee 100% vulnerability coverage. Use responsibly.

// faq

What is ai-smart-contract-auditor?

AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.. It is open-source on GitHub.

Is ai-smart-contract-auditor free to use?

ai-smart-contract-auditor is open-source under the MIT license, so it is free to use.

What category does ai-smart-contract-auditor belong to?

ai-smart-contract-auditor is listed under security in the Claudeers registry of Claude-compatible tools.

5 views
37 stars
unclaimed
updated 12 days ago

// embed badge

ai-smart-contract-auditor on Claudeers
[![Claudeers](https://claudeers.com/api/badge/ai-smart-contract-auditor.svg)](https://claudeers.com/ai-smart-contract-auditor)

// retro hit counter

ai-smart-contract-auditor hit counter
[![Hits](https://claudeers.com/api/counter/ai-smart-contract-auditor.svg)](https://claudeers.com/ai-smart-contract-auditor)

// reviews

// guestbook

0/500

// related in Security & Compliance

🔓

A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specia…

// securitymsitarzewski/Shell145,494MIT[ claude ]
🔓

π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.

// securityruvnet/Rust91,307MIT[ claude ]
🔓

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

// securityprowler-cloud/Python14,649Apache-2.0[ claude ]
🔓

🐶 A curated list of Web Security materials and resources.

// securityqazbnm456/Python13,709[ claude ]
→ see how ai-smart-contract-auditor connects across the ecosystem