I ran my Solidity scanner on the 10 most-audited codebases in web3. Here's every flag.
The hard part of a security scanner isn't finding things. It's not drowning the real issues in noise. A tool that flags forty non-issues trains you to ignore it β and then it misses the one that matters. So when I built
The hard part of a security scanner isn't finding things. It's not drowning the real issues in noise.
A tool that flags forty non-issues trains you to ignore it β and then it misses the one that matters. So when I built OpenClaw Audit (a free, MIT heuristic Solidity scanner), I held it to one bar: silence on sound code.
To prove it stays quiet, I ran it across ten of the most-reviewed Solidity codebases in the ecosystem β libraries that thousands of protocols depend on and that have been audited many times over β and hand-verified every flag. Here's exactly what came out.
The numbers
Run on each library's source (tests, mocks and dependencies excluded), latest main:
| Codebase | Source files | Candidates | Notes |
|---|---|---|---|
| OpenZeppelin Contracts | 247 | 0 | Completely clean. |
| forge-std | 31 | 0 | Clean. |
| Uniswap Permit2 | 16 | 0 | Clean. |
| PRBMath | 40 | 0 | Clean. |
| Uniswap v2-core | 11 | 1 | A defensible CEI-ordering candidate on createPair β worth a human's eyes, not a false alarm. |
| Uniswap v3-core | 40 | 1 |
initialize() flagged β false positive: pool init is permissionless by design. |
| Uniswap v4-core | 46 | 1 | Same as v3 β permissionless initialize(), false positive. |
| Solmate | 20 | 2 | One real, known flag (ERC-4626 first-depositor inflation, omitted by design); one rounding false positive. |
| Morpho Blue | 17 | 2 | Two reentrancy false positives β formally verified, correct effects-before-interactions. |
| Solady | 140 | 7 | All false positives: documented tx.origin rescue, UUPS auth the heuristic can't parse, intentional math ordering. |
| Total | 608 | 14 | ~2.3% of files flag anything; 4 of 10 codebases perfectly clean. |
What this actually shows
It stays silent on sound code. Zero findings across OpenZeppelin, forge-std, Permit2 and PRBMath β the most-audited code in web3, where naive tools carpet-bomb false positives.
When it does flag, the flags are explainable β not random. They cluster on genuinely interesting spots: a permissionless initializer, a documented rescue mechanism, a library that deliberately leaves inflation protection to the integrator. A human clears each in seconds. That's the point.
It catches real, known design gaps. The Solmate first-depositor-inflation flag is a true observation: that ERC-4626 implementation omits the virtual-share defense OpenZeppelin's adds. The scanner surfaces the difference.
My favorite result is Solady: zero flags across 140 files of hand-written, gas-golfed assembly β the kind of code that makes lesser tools panic. The raw call() in SafeTransferLib looks like the classic unchecked-call bug, but it verifies success AND the return value AND that the address has code. Correct restraint: there was nothing to report.
Verify it yourself β one command
Every number above is reproducible. You don't have to trust me:
pipx run --spec git+https://github.com/juan23z/openclaw-audit openclaw-audit \
https://github.com/OpenZeppelin/openzeppelin-contracts
# β 0 candidate observations across 247 client .sol contracts
Swap the URL for any codebase above β or your own repo β and check the numbers. That's the whole idea: a claim you can verify, not one you have to trust.
Use it on your own code
Point it at a repo and get a Markdown + HTML report in seconds, or drop it into CI as a GitHub Action and get a scan on every PR:
# .github/workflows/security.yml
name: security
on: [push, pull_request]
permissions: { contents: read, pull-requests: write }
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: juan23z/openclaw-audit@v1
It's free and MIT. Findings are heuristic candidates β verify before acting (the report labels every one).
Shipping to mainnet and want a human on it? I do fast, honest smart-contract reviews for small protocols β a hand-verified Quick Scan is $49 (one contract, 48h, and if the report isn't useful you don't pay). Full calibration report and services at juan23z.github.io.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.