Contract audit

Triage a smart contract before an agent interacts with it: verified Solidity source, heuristic vulnerability scan, known-address check, function-selector resolution, and a read-only dry-run of the exact call you plan to make.

$0.022 per call · one payment for the whole workflow
POST /api/skill/contract-audit
Sample output + API docs →

5 tools run server-side in one request. You pay once, settle once, and get a single response - no orchestration, no per-step payments, and a partial-success envelope if any step fails. USDC over x402 on any supported chain.

When to use this pack

An agent is about to approve, transfer, or call an unfamiliar contract - you want the verified Solidity source scanned for red flags, the address checked against known labels, and the intended calldata simulated before anything is signed or broadcast: the first pass a smart-contract auditor would run.

Tools in this pack

All 5 run inside the single $0.022 call above. Each is also callable on its own if you only need one part.

Bought one at a time, these 5 tools cost $0.024 together; the pack is that sum less a 10% bundle discount, rounded up to the $0.001 settlement floor, which is $0.022.

Workflow

  1. Fetch the verified Solidity source and compiler metadata from Sourcify via contract-source - an unverified contract is itself a finding.
  2. Run solidity-scan over the returned source for line-anchored heuristic findings: tx.origin auth, delegatecall, selfdestruct, unchecked calls, weak randomness, and more.
  3. Resolve the 4-byte selector of the calldata you plan to send with selector-lookup so you know exactly which function it hits.
  4. Check the address against the curated known-address dataset with address-label - is this the real token/router/bridge or an impostor?
  5. Dry-run the exact call with tx-simulate (eth_call + gas estimate, strictly read-only) to see whether it succeeds or reverts before anything is signed.

Arguments

NameRequiredDescriptionExample
addressyes0x-prefixed contract address to audit0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
networknoEVM network (ethereum / base / polygon / arbitrum / optimism, default base)base
datano0x-prefixed calldata you intend to send (default: a balanceOf probe)0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0

What one call returns

A JSON object with pack, args, steps, summary; steps holds one entry per tool (contract-source, solidity-scan, selector-lookup, address-label, tx-simulate), each with its own result or error. Full example on the API page.

Call it directly

Any x402 client pays the 402 and gets the whole workflow back in one response. With the agent402-client SDK (npm i agent402-client, an ES module):

import { Agent402 } from "agent402-client";
// payFetch: an x402-wrapped fetch your wallet signs (@x402/fetch).
// Tools on the free tier need no options: new Agent402() pays them by proof-of-work.
// an existing prepaid credits key also works: new Agent402({ creditsKey })
const client = new Agent402({ fetch: payFetch });
const result = await client.call("skill-contract-audit", {"address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","network":"base","data":"0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0"});

Run it in Claude

claude mcp add agent402 -s user -- npx -y agent402-mcp@latest

Then paste this prompt into Claude:

Audit the contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 on base before interacting with it, using Agent402's contract-audit skill pack. (1) Fetch the verified source from Sourcify, (2) run the heuristic Solidity scan over it, (3) resolve the selector of the planned calldata 0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0, (4) check the address against known labels, (5) simulate the call read-only. Report: verification status, scan findings by severity, what the calldata does, whether the address is a known contract, and the dry-run verdict.

← All skill packs