solaudit
v1.0
automated security analysis for solana programs

Audit Solana programs
before they ship.

Static analysis, semantic graph mining, adversarial account synthesis, proof-of-concept generation, and automated remediation planning. 15 vulnerability classes. One pipeline.

solaudit-agent

Pipeline

7-stage sequential analysis

01

Parse & AST

~2s

02

15 Detectors

~8s

03

Graph Mining

~3s

04

Adversarial Synth

~4s

05

Proof Plans

~5s

06

Remediation

~3s

07

Report Gen

~1s

Vulnerability Classes

15 detectors

01

Missing signer check

02

Missing owner check

03

PDA derivation mistakes

04

Arbitrary CPI target

05

Type confusion / account substitution

06

Reinitialization / double-init

07

Close-then-revive

08

Unchecked realloc / stale memory

09

Integer overflow/underflow

10

State machine violations

11

Remaining accounts injection

12

Oracle validation failures

13

Token account mismatch

14

Post-CPI stale reads

15

Duplicate account injection

Semantic Graphs

program structure analysis

Authority Flow

Signer propagation paths

Token Flow

SPL token account edges

State Machine

State transition graph

PDA Graph

Derived address mapping