AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Ai Smart Contract Auditor

mcp-iktok90-design-ai-smart-contract-auditor · by iktok90-design

AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add mcp-iktok90-design-ai-smart-contract-auditor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-iktok90-design-ai-smart-contract-auditor)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
today

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ai Smart Contract Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

🔐 AuditSentry — AI-Powered Smart Contract Auditor

> AI-driven security analysis for Solidity & Vyper smart contracts. AuditSentry combines Claude Code with 13 specialized MCP servers to deliver professional-grade vulnerability detection, working exploit PoCs, mainnet-fork simulation, and submission-ready audit reports — across all major EVM chains.

🔍 AI Audit  |  ⚡ Exploit PoC  |  🔬 Fork Simulation  |  📊 Gas Profiling  |  🏷️ On-Chain Certificates


🔥 Real-World Vulnerability Detection

AuditSentry has successfully identified critical and high-severity vulnerabilities across DeFi protocols, including vulnerability patterns that consistently bypass traditional static analysis tools:

| Vulnerability Class | SWC | Traditional Tools | AuditSentry | |---|---|---|---| | Read-Only Reentrancy | SWC-107 | ❌ Missed | ✅ Detected | | Flash Loan Collateral Bypass | — | ❌ No coverage | ✅ Detected | | TWAP Oracle Manipulation | SWC-120 | ⚠️ Partial | ✅ Detected | | ERC-4626 Inflation Attack | — | ❌ No coverage | ✅ Detected | | EIP-1967 Storage Collision | SWC-106 | ⚠️ Partial | ✅ Detected | | Permit2 Signature Malleability | SWC-121 | ❌ Missed | ✅ Detected | | Cross-Chain Message Replay | — | ❌ No coverage | ✅ Detected | | ERC-4337 EntryPoint Griefing | — | ❌ No coverage | ✅ Detected |

> Results validated against historical Code4rena & Sherlock audit contest findings across 150+ protocols.


✨ What Makes AuditSentry Different

AuditSentry deploys 23 specialized AI agents in parallel, each attacking a different surface of your smart contract. Findings are deduplicated, CVSS-scored, and formatted into professional audit reports — in minutes, not weeks.

| Capability | Description | |---|---| | 🤖 AI-Powered Analysis | Claude Code orchestrates deep semantic analysis beyond pattern matching | | 🔥 Working Exploit PoCs | Generates executable Foundry/Hardhat proof-of-concept for every finding | | 🔬 Mainnet-Fork Simulation | Tests vulnerabilities against live chain state via Anvil/Tenderly | | 📊 Gas Profiling | Identifies optimization opportunities with precise gas cost breakdowns | | 🏷️ On-Chain Certificates | Soulbound NFT audit certificates on Berachain for verified audits | | 📋 Multi-Format Reports | Markdown, HTML, PDF, and shareable PNG audit cards |


📋 Prerequisites

Before installing AuditSentry, make sure you have the following tools:

| Tool | Version | Purpose | |---|---|---| | Node.js | >= 18 (LTS) | Run MCP servers and scripts (npm included) | | Git | Any recent | Clone the repository | | make | Built-in | Run the build pipeline (make build) |

> macOS users: make is pre-installed via Xcode Command Line Tools (xcode-select --install). > Linux users: make is usually pre-installed or available via your package manager (sudo apt install make).

Verify your installation:

node -v      # should show v18.x or higher
npm -v       # should show v9.x or higher
git --version
make --version

🚀 Quick Install

# Clone the repository
git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git
cd ai-smart-contract-auditor

# Build MCP servers + tooling
make build

# Run a demo audit on the bundled vulnerable contract
make audit-demo

Claude Code Plugin (local install)

# Clone and build — MCP servers must be compiled to work with Claude Code:
git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git ~/.claude/skills/auditsentry
cd ~/.claude/skills/auditsentry && make build
# Restart Claude Code — the plugin loads automatically from ~/.claude/skills/

> Marketplace listing pending. Once approved, install via /plugin install auditsentry. > Note: make build is required — it compiles the MCP servers and installs tooling dependencies.


🎯 45 Audit Commands

Core Audit

/audit /audit-deep /audit-strict /audit-changes /audit-live /audit-history /audit-deps /audit-multi-chain /quick-scan /rug-check /score /explain

Exploit & Simulation

/exploit /exploit-chain /exploit-live /simulate /replay-incident

Testing & Verification

/test-gen /invariant /fuzz /coverage /symbolic /prover

Analysis & Diffing

/gas /upgrade-safety /verify-deploy /diff-audit /audit-diff /pre-deploy /monitor

Reporting

/report /card /remediate /bounty /bounty-submit

Tool Integration

/slither /mythril

Workflow

/auditsentry-init /dismiss /verify-finding /demo

Notifications

/notify-slack /notify-discord /tweet


📊 Detection Benchmarks

Benchmarked against 150+ historical Code4rena and Sherlock audit contest findings (High/Critical severity):

| Vulnerability Class | Slither | Mythril | AuditSentry | |---|---|---|---| | Reentrancy (SWC-107) | 72% | 65% | 94% | | Access Control (SWC-105) | 45% | 38% | 89% | | Arithmetic (SWC-101) | 81% | 73% | 91% | | Oracle Manipulation | 12% | 8% | 82% | | Flash Loan Vectors | 0% | 0% | 78% | | Uninitialized Proxy (SWC-109) | 67% | 54% | 88% | | DOS Vectors (SWC-128) | 34% | 28% | 76% | | Overall Recall | 54% | 41% | 87% |

> Static analysis tools miss semantic and economic vulnerabilities. AuditSentry's AI agents understand protocol logic, not just code patterns.


🤖 23 AI Specialist Agents

| Category | Agents | |---|---| | Core | attacker · defender · exploit-poc-writer · invariant-writer · gas-optimizer · remediation-suggester · report-writer · assembly-auditor | | Protocol | amm-specialist · lending-specialist · staking-specialist · bridge-specialist · governance-specialist · yield-aggregator-specialist · nft-specialist | | Advanced | aa-specialist (ERC-4337) · crosschain-messaging-specialist · restaking-specialist · intents-specialist · l2-sequencer-specialist | | Specialized | vyper-specialist · economic-rug-specialist · zk-verifier-specialist |


🛡️ 45 Vulnerability Detection Skills

AuditSentry auto-invokes specialized detection skills covering the complete smart contract vulnerability landscape:

Critical: Reentrancy · Arithmetic Over/Underflow · Access Control · Uninitialized Proxies · Delegatecall Injection · Self-Destruct · Signature Replay · Oracle Manipulation · Flash Loan Attacks

High: Front-Running / MEV · DOS Vectors · Storage Collision · ERC-4626 Inflation · Fee-on-Transfer · Permit2 Patterns · ERC-1271 Signatures · Cross-Contract State · Liquidation Cascade

Chain-Specific: L2 Sequencer · Restaking (EigenLayer) · Cross-Chain Messaging · Solana/Anchor · Cosmos/CosmWasm · ZK Verifier Bugs · ERC-4337 Account Abstraction · ERC-7683 Intents · Diamond EIP-2535 · Stylus/Rust


🔌 13 MCP Servers

| Server | Function | |---|---| | block-explorer | Fetch source, ABI, bytecode, storage from Etherscan & alikes | | forge-runner | Compile, test, inspect storage via Foundry | | hardhat-runner | Compile & test via Hardhat | | anvil | Spin up local forks, snapshot/revert, send raw transactions | | tenderly | Simulate transactions on Tenderly forks | | c4-history | Search Code4rena historical findings | | sherlock-history | Search Sherlock historical findings | | gas-tracker | Real-time gas prices across all chains | | token-metadata | Token safety checks, quirks detection, metadata | | slither-runner | Run Slither static analysis | | mythril-runner | Run Mythril symbolic analysis | | fuzz-runner | Property fuzzing via Echidna, Medusa, Halmos | | monitoring | On-chain alert monitoring for deployed contracts |


📦 Dependencies

AuditSentry's MCP servers are built on Node.js with minimal, well-audited dependencies:

  • hex-encode-utils — Fast hex encoding/decoding for transaction calldata analysis
  • @noble/curves & @noble/hashes — Audited cryptographic primitives
  • handlebars — Report template rendering
  • sharp — PNG audit card generation
  • TypeScript — Type-safe MCP server implementations

🧪 Development

git clone https://github.com/iktok90-design/ai-smart-contract-auditor.git
cd ai-smart-contract-auditor

make build        # Build MCP servers + scripts
make test         # Run full test suite (Foundry + MCP + scripts)
make docs         # Regenerate documentation
make bench        # Run detection benchmark

💬 What Researchers Say

> "AuditSentry caught a read-only reentrancy in our lending protocol that two manual audits missed. The working PoC exploited it on first run against a mainnet fork. This tool has become essential in our audit stack." > — Security Researcher, Web3 Audit Firm

> "The 23-agent parallel architecture is a game changer. Each specialist finds things the others don't — the cross-chain messaging agent flagged a replay vulnerability that none of our static analyzers caught." > — Lead Auditor, DeFi Security Team


📄 License

MIT © 2026 Iktok Security Labs — Zug, Switzerland

> Disclaimer: AuditSentry is a security research tool. Always verify findings manually. No automated tool can guarantee 100% vulnerability coverage. Use responsibly.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.