Foundry Audit AI

Foundry 워크플로에 맞춘 감사, curl 한 번이면 됩니다

Foundry Audit AI는 Foundry·Hardhat·EVM 프로젝트용 Solidity 보안 감사 특화 오픈 LLM 모음입니다. Ollama로 로컬 실행하며 재진입, 접근 제어, 오라클 조작 등을 구조화된 JSON으로 반환합니다.

~/foundry-project — zsh

❯ curl -s -X POST https://foundryaudit.vercel.app/api/audit -H "Content-Type: text/plain" --data-binary @Vault.sol | jq .report

⠿ foundryaudit-coder:7b 분석 중… 212 lines · 2.8s

CRITICAL Reentrancy in withdraw() SWC-107 · L16

HIGH tx.origin used for authorization SWC-115 · L22

LOW Missing events for state changes L10, L18

risk_score: 94 / 100

4

감사 튜닝 모델

20+

취약점 클래스 (SWC)

0 byte

제3자로 전송되는 코드

32K

컨텍스트 토큰

Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions · Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions

워크플로별 네 가지 감사 모델

각 모델은 Ollama Modelfile로 제공됩니다. 검증된 오픈소스 코드 LLM 위에 Foundry 감사 시스템 프롬프트와 파라미터가 올라갑니다.

7B

foundryaudit-coder:7b

속도와 정확도의 균형

추천

일상 PR·CI용 기본 모델. Solidity와 Foundry 테스트 구조 이해도가 높습니다.

베이스
qwen2.5-coder:7b
용량
4.7 GB
컨텍스트
32K
8GB RAM · GPU optional
정확도 79속도 87
ollama create foundryaudit-coder:7b
14B

foundryaudit-deep:14b

단계별 심층 분석

호출 흐름과 상태 변화를 추론해 재진입·가격 조작 등 복합 버그를 찾습니다.

베이스
deepseek-r1:14b
용량
9.0 GB
컨텍스트
32K
16GB RAM · 10GB+ VRAM
정확도 87속도 56
ollama create foundryaudit-deep:14b
32B

foundryaudit-pro:32b

메인넷 전 최종 점검

대형 프로토콜·다중 컨트랙트용 플래그십. 오탐률이 가장 낮습니다.

베이스
qwen2.5-coder:32b
용량
19 GB
컨텍스트
32K
32GB RAM · 24GB+ VRAM
정확도 93속도 32
ollama create foundryaudit-pro:32b
3B

foundryaudit-lite:3b

노트북에서도 가볍게

1차 스캔·학습용. 에디터 저장 시 빠른 점검에 적합합니다.

베이스
llama3.2:3b
용량
2.0 GB
컨텍스트
16K
4GB RAM · CPU-only OK
정확도 65속도 96
ollama create foundryaudit-lite:3b

정확도·속도는 모델 간 비교용 참고치입니다. 실제 성능은 하드웨어와 코드베이스에 따라 달라집니다.

코드는 내 머신을 벗어나지 않습니다

클라우드 API 키·종량 과금 없음. 터미널 → Ollama → 보안 리포트 — 파이프라인은 이것뿐입니다.

01

컨트랙트 전송

curl로 .sol 파일을 그대로 보냅니다. 로컬 Ollama(:11434) 또는 이 사이트 /api/audit 프록시 모두 가능합니다.

curl --data-binary @Vault.sol

02

로컬 LLM 추론

Ollama가 감사 모델을 실행하고, 시스템 프롬프트가 SWC 레지스트리와 Foundry 테스트 공백을 점검합니다.

ollama · temperature 0.1

03

JSON 리포트

심각도·위치·SWC ID·수정안이 담긴 JSON — jq·CI·대시보드에 바로 연결.

format: "json"

24/7 코드를 지키는 Foundry 감사 도우미

전문 감사 전 1차 방어선입니다. 개발 루프 안에서 즉시 피드백을 받으세요.

완전한 프라이버시

미공개 프로토콜도 안심하고 분석. 모든 추론은 로컬 Ollama에서 실행됩니다.

무료·무제한

토큰 과금 없음 — 커밋·파일마다 감사를 돌려도 비용 0.

구조화 출력

JSON 모드로 동일 스키마 리포트. 파싱 지옥 없이 자동화.

CI/CD 친화

curl과 jq만으로 critical/high 발견 시 GitHub Actions·GitLab CI를 실패시킬 수 있습니다.

터미널에서 첫 감사까지 5분

모델과 OS를 고르면 명령이 자동으로 바뀝니다. 순서대로 복사해 실행하세요.

  1. 1

    Ollama 설치

    로컬 LLM 런타임 Ollama를 설치합니다. 서버는 :11434에서 동작합니다.

    install.sh
    curl -fsSL https://ollama.com/install.sh | sh
    
    # Verify (if server isn't running: ollama serve)
    ollama --version
    curl http://localhost:11434/api/version
  2. 2

    베이스 모델 다운로드

    foundryaudit-coder:7b는 qwen2.5-coder:7b(4.7 GB) 기반입니다.

    pull.sh
    ollama pull qwen2.5-coder:7b
  3. 3

    Modelfile 받기 & 감사 모델 생성

    curl로 Modelfile을 받아 ollama create로 등록합니다.

    create.sh
    curl -fsSL https://foundryaudit.vercel.app/api/modelfile/foundryaudit-coder-7b -o foundryaudit-coder-7b.Modelfile
    ollama create foundryaudit-coder:7b -f foundryaudit-coder-7b.Modelfile
    
    ollama list | grep foundryaudit
  4. 4

    빠른 테스트

    짧은 코드를 Ollama /api/generate로 보냅니다. format: "json"으로 구조화 출력.

    quick-test.sh
    curl http://localhost:11434/api/generate -d '{
      "model": "foundryaudit-coder:7b",
      "prompt": "contract A { function kill() public { selfdestruct(payable(msg.sender)); } }",
      "format": "json",
      "stream": false
    }' | jq -r '.response | fromjson'
  5. 5

    전체 .sol 감사

    jq -Rs로 파일 내용을 JSON 문자열로 감싸 /api/chat에 전달합니다.

    audit.sh
    jq -Rs '{
      model: "foundryaudit-coder:7b",
      stream: false,
      format: "json",
      messages: [{ role: "user", content: . }]
    }' Vault.sol \
      | curl -s http://localhost:11434/api/chat -d @- \
      | jq -r '.message.content | fromjson'
  6. 6

    Foundry Audit 프록시 API

    npm run dev 실행 시 /api/audit가 Ollama를 호출합니다 — text/plain으로 .sol 전송, JSON 이스케이프 불필요.

    proxy.sh
    curl -s -X POST "https://foundryaudit.vercel.app/api/audit?model=foundryaudit-coder:7b" \
      -H "Content-Type: text/plain" \
      --data-binary @Vault.sol | jq .
    
    # Streaming (NDJSON)
    curl -N -X POST "https://foundryaudit.vercel.app/api/audit?model=foundryaudit-coder:7b&stream=true" \
      -H "Content-Type: text/plain" \
      --data-binary @Vault.sol

취약 컨트랙트를 넣으면 이런 리포트가 나옵니다

재진입·tx.origin 인증 버그가 있는 Vault를 foundryaudit-coder:7b로 감사한 예시입니다.

Critical 1High 1Low 1risk_score 94/100
입력 · Vault.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

contract Vault {
    mapping(address => uint256) public balances;
    address public owner;

    constructor() { owner = msg.sender; }

    function deposit() external payable {
        balances[msg.sender] += msg.value;
    }

    function withdraw() external {
        uint256 amount = balances[msg.sender];
        (bool ok, ) = msg.sender.call{value: amount}("");
        require(ok, "transfer failed");
        balances[msg.sender] = 0;
    }

    function sweep(address to) external {
        require(tx.origin == owner, "not owner");
        payable(to).transfer(address(this).balance);
    }
}
출력 · POST /api/audit
{
  "model": "foundryaudit-coder:7b",
  "duration_ms": 2814,
  "report": {
    "summary": "Vault is exposed to reentrancy and phishing-based owner takeover. Funds can be fully drained.",
    "risk_score": 94,
    "findings": [
      {
        "id": "FA-001",
        "title": "Reentrancy in withdraw()",
        "severity": "critical",
        "swc": "SWC-107",
        "location": "withdraw() L16-18",
        "description": "External call is made before the balance is zeroed, allowing a malicious receiver to re-enter and withdraw repeatedly.",
        "recommendation": "Apply Checks-Effects-Interactions: zero balance before the call, or use ReentrancyGuard.",
        "foundry_hint": "forge test --match-test testReentrancyWithdraw"
      },
      {
        "id": "FA-002",
        "title": "tx.origin used for authorization",
        "severity": "high",
        "swc": "SWC-115",
        "location": "sweep() L22",
        "description": "A contract called by the owner can invoke sweep() and pass the tx.origin check.",
        "recommendation": "Replace tx.origin with msg.sender; consider OpenZeppelin Ownable.",
        "foundry_hint": "Add unit test where owner EOA calls via malicious intermediary contract"
      },
      {
        "id": "FA-003",
        "title": "Missing events for state changes",
        "severity": "low",
        "swc": null,
        "location": "deposit() L10, withdraw() L18",
        "description": "Deposits and withdrawals emit no events, hindering off-chain monitoring.",
        "recommendation": "Emit Deposit and Withdraw events.",
        "foundry_hint": "expectEmit in forge tests for deposit/withdraw"
      }
    ],
    "gas_optimizations": ["Declare owner as immutable", "Use custom errors instead of revert strings"],
    "foundry_recommendations": ["Add invariant test: total balances <= address(this).balance", "Fuzz withdraw with random callers"]
  }
}

SWC 레지스트리 기반 탐지

고전적 버그부터 DeFi 공격 벡터, 가스 최적화, Foundry 테스트 권고까지 한 번에.

SWC-107 critical

Reentrancy

외부 호출 후 상태 갱신

SWC-105/106 critical

Access Control

onlyOwner 누락, selfdestruct 보호 없음

SWC-112 critical

Delegatecall Injection

신뢰할 수 없는 대상으로 delegatecall

critical

Oracle Manipulation

스팟 가격 의존, 플래시론 조작

high

tx.origin Auth

피싱 컨트랙트를 통한 권한 탈취

SWC-101 high

Integer Over/Underflow

unchecked 또는 0.8 미만 컴파일러

SWC-120 medium

Weak Randomness

block.timestamp / blockhash 난수

SWC-128 medium

DoS with Gas Limit

무한 루프, 외부 호출 revert

두 가지 엔드포인트, 하나의 스키마

Ollama(localhost:11434)를 직접 호출하거나 Foundry Audit 프록시로 더 간단히 요청하세요.

엔드포인트

  • POST/api/auditSolidity 소스를 받아 Ollama로 감사 후 JSON 리포트 반환Foundry Audit
  • GET/api/models사용 가능 모델 및 Modelfile URLFoundry Audit
  • GET/api/modelfile/:slugollama create용 Modelfile (text/plain)Foundry Audit
  • POST/api/chat채팅 요청 — messages에 컨트랙트 전달Ollama
  • POST/api/generate짧은 스니펫용 단일 프롬프트Ollama

POST /api/audit 파라미터

이름타입위치설명
codestringbodySolidity 소스 (text/plain이면 본문 전체)
modelstringbody · query모델명. 기본 foundryaudit-coder:7b
streambooleanbody · querytrue면 Ollama NDJSON 스트림 그대로 전달

JSON 본문 요청

curl -s https://foundryaudit.vercel.app/api/audit \
  -H "Content-Type: application/json" \
  -d '{
    "model": "foundryaudit-pro:32b",
    "code": "pragma solidity ^0.8.20; contract T { function f() external { selfdestruct(payable(msg.sender)); } }"
  }'

CI 파이프라인 게이트

for f in src/*.sol; do
  curl -s -X POST "https://foundryaudit.vercel.app/api/audit" \
    -H "Content-Type: text/plain" --data-binary @"$f" \
  | jq -e '[.report.findings[] | select(.severity=="critical" or .severity=="high")] | length == 0' \
  || { echo "❌ $f"; exit 1; }
done

자주 묻는 질문

  • 아니요. Foundry Audit AI는 개발 중 흔한 실수를 잡는 1차 도구입니다. LLM은 오탐·누락이 있을 수 있으므로, 실자금 컨트랙트는 Slither, Foundry fuzz/invariant, 전문 감사도 병행해야 합니다.