跳到主要内容
知仓学习社ZHICANG

slither-analysis

Expert integration with Slither static analyzer for smart contract vulnerability detection, code quality analysis, and security reporting. Supports …

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,9 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Slither Static Analysis Skill

Expert-level integration with Slither, the leading static analysis framework for Solidity smart contracts.

Capabilities

  • Full Detector Suite: Execute Slither with all built-in detectors
  • Custom Configurations: Configure analysis parameters and exclusions
  • Severity Classification: Interpret and classify finding severity
  • False Positive Filtering: Context-aware false positive identification
  • Visual Analysis: Generate call graphs and inheritance diagrams
  • Custom Detectors: Run and develop custom Slither detectors
  • Reporting: Produce comprehensive security reports

Installation

# Install via pip
pip install slither-analyzer

# Or via pipx for isolation
pipx install slither-analyzer

# Verify installation
slither --version

Basic Usage

Run Analysis

# Analyze single file
slither Contract.sol

# Analyze Foundry project
slither . --foundry-compile-all

# Analyze Hardhat project
slither . --hardhat-compile-all

Output Formats

# Human readable (default)
slither .

# JSON output for processing
slither . --json output.json

# Markdown report
slither . --checklist

# SARIF for CI integration
slither . --sarif output.sarif

Detector Categories

High Severity Detectors

| Detector | Description |

|----------|-------------|

| reentrancy-eth | Reentrancy with ETH transfer |

| reentrancy-no-eth | Reentrancy without ETH |

| arbitrary-send-eth | Arbitrary ETH send |

| controlled-delegatecall | Controlled delegatecall |

| suicidal | Functions allowing anyone to destruct |

| uninitialized-storage | Uninitialized storage variables |

Medium Severity Detectors

| Detector | Description |

|----------|-------------|

| reentrancy-benign | Benign reentrancy |

| incorrect-equality | Dangerous strict equality |

| locked-ether | Contracts that lock ether |

| missing-zero-check | Missing zero address validation |

| unchecked-transfer | Unchecked token transfers |

Low Severity Detectors

| Detector | Description |

|----------|-------------|

| naming-convention | Naming convention violations |

| external-function | Functions that could be external |

| constable-states | State variables that could be constant |

| immutable-states | State variables that could be immutable |

Configuration

slither.config.json

{
  "detectors_to_run": "all",
  "exclude_informational": false,
  "exclude_low": false,
  "exclude_medium": false,
  "exclude_high": false,
  "exclude_optimization": false,
  "fail_on": "high,medium",
  "filter_paths": [
    "node_modules",
    "lib",
    "test"
  ],
  "exclude_dependencies": true,
  "legacy_ast": false
}

CLI Configuration

# Run specific detectors
slither . --detect reentrancy-eth,uninitialized-storage

# Exclude detectors
slither . --exclude naming-convention,external-function

# Filter by severity
slither . --exclude-informational --exclude-low

# Exclude specific paths
slither . --filter-paths "test|lib|node_modules"

Advanced Features

Call Graph Generation

# Generate call graph
slither . --print call-graph

# Generate inheritance graph
slither . --print inheritance-graph

# Generate contract summary
slither . --print contract-summary

Function Analysis

# Print function summaries
slither . --print function-summary

# Print variable order (storage layout)
slither . --print variable-order

# Print data dependency
slither . --print data-dependency

Custom Detectors

# custom_detector.py
from slither.detectors.abstract_detector import AbstractDetector, DetectorClassification

class MyCustomDetector(AbstractDetector):
    ARGUMENT = "my-detector"
    HELP = "Detect my custom issue"
    IMPACT = DetectorClassification.HIGH
    CONFIDENCE = DetectorClassification.HIGH

    WIKI = "https://example.com/my-detector"
    WIKI_TITLE = "My Custom Detector"
    WIKI_DESCRIPTION = "Detects..."
    WIKI_EXPLOIT_SCENARIO = "..."
    WIKI_RECOMMENDATION = "..."

    def _detect(self):
        results = []
        for contract in self.compilation_unit.contracts_derived:
            for function in contract.functions:
                # Detection logic
                if self._has_issue(function):
                    info = [function, " has an issue\n"]
                    results.append(self.generate_result(info))
        return results

CI/CD Integration

GitHub Actions

name: Slither Analysis
on: [push, pull_request]

jobs:
  slither:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: Install Foundry
        uses: foundry-rs/foundry-toolchain@v1

      - name: Install Slither
        run: pip install slither-analyzer

      - name: Run Slither
        run: slither . --foundry-compile-all --fail-on high --sarif results.sarif

      - name: Upload SARIF
        uses: github/codeql-action/upload-sarif@v2
        with:
          sarif_file: results.sarif

Interpreting Results

Result Structure

{
  "success": true,
  "error": null,
  "results": {
    "detectors": [
      {
        "check": "reentrancy-eth",
        "impact": "High",
        "confidence": "Medium",
        "description": "Reentrancy in Contract.withdraw()...",
        "elements": [...],
        "first_markdown_element": "...",
        "id": "abc123"
      }
    ]
  }
}

Triage Workflow

  1. High/Medium Impact - Investigate immediately
  2. Check Confidence Level - High confidence = likely real issue
  3. Review Code Context - Understand the actual flow
  4. Verify with Tests - Write tests to confirm behavior
  5. Document Decisions - Mark false positives with rationale

Process Integration

| Process | Purpose |

|---------|---------|

| smart-contract-security-audit.js | Primary security analysis |

| smart-contract-development-lifecycle.js | Development validation |

| formal-verification.js | Pre-verification checks |

Tools Reference

| Tool | Purpose |

|------|---------|

| Slither | Core static analyzer |

| crytic-compile | Compilation framework |

| slither-doctor | Configuration debugger |

Best Practices

  • Run Slither on every commit in CI
  • Configure appropriate exclusions to reduce noise
  • Review all high/medium findings manually
  • Write custom detectors for project-specific patterns
  • Use --triage-database to track false positives

See Also

  • skills/mythril-symbolic/SKILL.md - Symbolic execution analysis
  • skills/echidna-fuzzer/SKILL.md - Property-based fuzzing
  • agents/solidity-auditor/AGENT.md - Security auditor agent
  • Slither Documentation

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/cryptography-blockchain/skills/slither-analysis/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能