foundryaudit-coder:7b
Balanced speed and accuracy
The default for everyday PR reviews and CI. Strong Solidity and Foundry test layout awareness.
- Base
- qwen2.5-coder:7b
- Size
- 4.7 GB
- Context
- 32K
ollama create foundryaudit-coder:7bFoundry Audit AI is a collection of open LLMs specialized in Solidity security for Foundry, Hardhat, and EVM projects. They run on your machine via Ollama and return reentrancy, access control, and oracle issues as structured JSON.
❯ curl -s -X POST https://foundryaudit.vercel.app/api/audit -H "Content-Type: text/plain" --data-binary @Vault.sol | jq .report
⠿ foundryaudit-coder:7b analyzing… 212 lines · 2.8s
CRITICAL Reentrancy in withdraw() SWC-107 · L16
HIGH tx.origin used for authorization SWC-115 · L22
LOW Missing events for state changes L10, L18
risk_score: 94 / 100
4
Audit-tuned models
20+
Vulnerability classes (SWC)
0 byte
Code sent to third parties
32K
Context tokens
Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions · Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions
Each model ships as an Ollama Modelfile: a Foundry-aware audit system prompt and tuned parameters on top of proven open-source code LLMs.
Balanced speed and accuracy
The default for everyday PR reviews and CI. Strong Solidity and Foundry test layout awareness.
ollama create foundryaudit-coder:7bStep-by-step deep analysis
Reasons through call flows and state to uncover compound bugs like reentrancy and price manipulation.
ollama create foundryaudit-deep:14bFinal check before mainnet
Flagship model for large protocols and multi-contract codebases, with the lowest false-positive rate.
ollama create foundryaudit-pro:32bLight enough for a laptop
Quick first-pass scans and learning. Great for on-save checks in your editor.
ollama create foundryaudit-lite:3bAccuracy and speed are indicative values for comparing models. Real-world performance depends on your hardware and codebase.
No cloud API keys, no usage billing. Terminal → Ollama → security report — that's the whole pipeline.
01
Send your .sol file with curl. Works with local Ollama (:11434) or this site's /api/audit proxy.
curl --data-binary @Vault.sol02
Ollama runs the audit model while the system prompt walks through the SWC Registry and Foundry test gaps.
ollama · temperature 0.103
Structured JSON with severity, location, SWC ID, and fixes — ready for jq, CI, and dashboards.
format: "json"Foundry Audit AI is your first line of defense before a professional audit. Get instant feedback inside your dev loop.
Analyze unreleased protocol code with confidence. Inference runs in your local Ollama runtime.
No per-token billing — run audits on every commit and every file at zero cost.
JSON mode returns reports in the same schema. Automate without parsing headaches.
With curl and jq, fail GitHub Actions or GitLab CI when a critical issue is found.
Pick a model and OS — commands update automatically. Copy and paste in order.
Install Ollama, the local LLM runtime. The server listens on port :11434.
curl -fsSL https://ollama.com/install.sh | sh # Verify (if server isn't running: ollama serve) ollama --version curl http://localhost:11434/api/version
foundryaudit-coder:7b is built on qwen2.5-coder:7b (4.7 GB).
ollama pull qwen2.5-coder:7b
Download the Modelfile with curl and register it as an Ollama model.
curl -fsSL https://foundryaudit.vercel.app/api/modelfile/foundryaudit-coder-7b -o foundryaudit-coder-7b.Modelfile ollama create foundryaudit-coder:7b -f foundryaudit-coder-7b.Modelfile ollama list | grep foundryaudit
Send a snippet to Ollama /api/generate. format: "json" returns structured output.
curl http://localhost:11434/api/generate -d '{
"model": "foundryaudit-coder:7b",
"prompt": "contract A { function kill() public { selfdestruct(payable(msg.sender)); } }",
"format": "json",
"stream": false
}' | jq -r '.response | fromjson'jq -Rs wraps file contents and pipes to /api/chat.
jq -Rs '{
model: "foundryaudit-coder:7b",
stream: false,
format: "json",
messages: [{ role: "user", content: . }]
}' Vault.sol \
| curl -s http://localhost:11434/api/chat -d @- \
| jq -r '.message.content | fromjson'With npm run dev, /api/audit calls Ollama for you — send .sol as text/plain, no JSON escaping.
curl -s -X POST "https://foundryaudit.vercel.app/api/audit?model=foundryaudit-coder:7b" \ -H "Content-Type: text/plain" \ --data-binary @Vault.sol | jq . # Streaming (NDJSON) curl -N -X POST "https://foundryaudit.vercel.app/api/audit?model=foundryaudit-coder:7b&stream=true" \ -H "Content-Type: text/plain" \ --data-binary @Vault.sol
Auditing a Vault with classic reentrancy and tx.origin auth using foundryaudit-coder:7b.
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
contract Vault {
mapping(address => uint256) public balances;
address public owner;
constructor() { owner = msg.sender; }
function deposit() external payable {
balances[msg.sender] += msg.value;
}
function withdraw() external {
uint256 amount = balances[msg.sender];
(bool ok, ) = msg.sender.call{value: amount}("");
require(ok, "transfer failed");
balances[msg.sender] = 0;
}
function sweep(address to) external {
require(tx.origin == owner, "not owner");
payable(to).transfer(address(this).balance);
}
}{
"model": "foundryaudit-coder:7b",
"duration_ms": 2814,
"report": {
"summary": "Vault is exposed to reentrancy and phishing-based owner takeover. Funds can be fully drained.",
"risk_score": 94,
"findings": [
{
"id": "FA-001",
"title": "Reentrancy in withdraw()",
"severity": "critical",
"swc": "SWC-107",
"location": "withdraw() L16-18",
"description": "External call is made before the balance is zeroed, allowing a malicious receiver to re-enter and withdraw repeatedly.",
"recommendation": "Apply Checks-Effects-Interactions: zero balance before the call, or use ReentrancyGuard.",
"foundry_hint": "forge test --match-test testReentrancyWithdraw"
},
{
"id": "FA-002",
"title": "tx.origin used for authorization",
"severity": "high",
"swc": "SWC-115",
"location": "sweep() L22",
"description": "A contract called by the owner can invoke sweep() and pass the tx.origin check.",
"recommendation": "Replace tx.origin with msg.sender; consider OpenZeppelin Ownable.",
"foundry_hint": "Add unit test where owner EOA calls via malicious intermediary contract"
},
{
"id": "FA-003",
"title": "Missing events for state changes",
"severity": "low",
"swc": null,
"location": "deposit() L10, withdraw() L18",
"description": "Deposits and withdrawals emit no events, hindering off-chain monitoring.",
"recommendation": "Emit Deposit and Withdraw events.",
"foundry_hint": "expectEmit in forge tests for deposit/withdraw"
}
],
"gas_optimizations": ["Declare owner as immutable", "Use custom errors instead of revert strings"],
"foundry_recommendations": ["Add invariant test: total balances <= address(this).balance", "Fuzz withdraw with random callers"]
}
}From classic bugs to DeFi attack vectors, gas tips, and Foundry test recommendations — in one request.
SWC-107 critical
State updated after external calls
SWC-105/106 critical
Missing onlyOwner, unprotected selfdestruct
SWC-112 critical
delegatecall into untrusted callees
critical
Spot price reliance, flash-loan manipulation
high
Phishing contract privilege takeover
SWC-101 high
unchecked blocks or pre-0.8 compilers
SWC-120 medium
block.timestamp / blockhash randomness
SWC-128 medium
Unbounded loops, reverting external calls
Call Ollama (localhost:11434) directly, or use the Foundry Audit proxy for simpler requests.
/api/auditTakes Solidity source, audits with Ollama, returns JSON reportFoundry Audit/api/modelsAvailable models and Modelfile download URLsFoundry Audit/api/modelfile/:slugModelfile for ollama create (text/plain)Foundry Audit/api/chatChat request — pass the contract in messagesOllama/api/generateSingle-prompt request for short snippetsOllama| Name | Type | In | Description |
|---|---|---|---|
| code | string | body | Solidity source (entire body for text/plain) |
| model | string | body · query | Model name. Defaults to foundryaudit-coder:7b |
| stream | boolean | body · query | If true, Ollama NDJSON stream is passed through |
curl -s https://foundryaudit.vercel.app/api/audit \
-H "Content-Type: application/json" \
-d '{
"model": "foundryaudit-pro:32b",
"code": "pragma solidity ^0.8.20; contract T { function f() external { selfdestruct(payable(msg.sender)); } }"
}'for f in src/*.sol; do
curl -s -X POST "https://foundryaudit.vercel.app/api/audit" \
-H "Content-Type: text/plain" --data-binary @"$f" \
| jq -e '[.report.findings[] | select(.severity=="critical" or .severity=="high")] | length == 0' \
|| { echo "❌ $f"; exit 1; }
doneNo. Foundry Audit AI is a first-pass tool for catching common mistakes during development. LLMs can miss issues or produce false positives — contracts holding real funds should also use Slither, Foundry fuzzing/invariants, and a professional audit.