I ran my Solidity scanner on the 10 most-audited codebases in web3. Here’s every flag.
The hard part of a security scanner isn’t finding things. It’s not drowning the real issues in noise. A tool that flags forty non-issues trains you to ignore it — and then it misses the one that matters. So when I built OpenClaw Audit (a free, MIT heuristic Solidity scanner), I held it to one bar: silence on sound code. To prove it stays quiet, I ran it across ten of the most-reviewed Solidity codebases in the ecosystem — libraries that thousands of protocols depend on and that have been audited many times over — and hand-verified every flag. Here’s exactly what came out. The numbers Run on each library’s source (tests, mocks and dependencies excluded), latest main: Codebase Source files Candidates Notes OpenZeppelin Contracts 247 0 Completely clean. forge-std 31 0 Clean. Uniswap Permit2 16 0 Clean. PRBMath 40 0 Clean. Uniswap v2-core 11 1 A defensible CEI-ordering candidate on createPair — worth a human’s eyes, not a false alarm. Uniswap v3-core 40 1 initialize() flagged — false positive: pool init is permissionless by design. Uniswap v4-core 46 1 Same as v3 — permissionless initialize(), false positive. Solmate 20 2 One real, known flag (ERC-4626 first-depositor inflation, omitted by design); one rounding false positive. Morpho Blue 17 2 Two reentrancy false positives — formally verified, correct effects-before-interactions. Solady 140 7 All false positives: documented tx.origin rescue, UUPS auth the heuristic can’t parse, intentional math ordering. Total 608 14 ~2.3% of files flag anything; 4 of 10 codebases perfectly clean. What this actually shows It stays silent on sound code. Zero findings across OpenZeppelin, forge-std, Permit2 and PRBMath — the most-audited code in web3, where naive tools carpet-bomb false positives. When it does flag, the flags are explainable — not random. They cluster on genuinely interesting spots: a permissionless initializer, a documented rescue mechanism, a library that deliberately leaves inflation protection to the integrator. A human clears each in seconds. That’s the point. It catches real, known design gaps. The Solmate first-depositor-inflation flag is a true observation: that ERC-4626 implementation omits the virtual-share defense OpenZeppelin’s adds. The scanner surfaces the difference. My favorite result is Solady: zero flags across 140 files of hand-written, gas-golfed assembly — the kind of code that makes lesser tools panic. The raw call() in SafeTransferLib looks like the classic unchecked-call bug, but it verifies success AND the return value AND that the address has code. Correct restraint: there was nothing to report. Verify it yourself — one command Every number above is reproducible. You don’t have to trust me: pipx run —spec git+https://github.com/juan23z/openclaw-audit openclaw-audit \ https://github.com/OpenZeppelin/openzeppelin-contracts # → 0 candidate observations across 247 client .sol contracts Swap the URL for any codebase above — or your own repo — and check the numbers. That’s the whole idea: a claim you can verify, not one you have to trust. Use it on your own code Point it at a repo and get a Markdown + HTML report in seconds, or drop it into CI as a GitHub Action and get a scan on every PR: # .github/workflows/security.yml name: security on: [push, pull_request] permissions: { contents: read, pull-requests: write } jobs: audit: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: juan23z/openclaw-audit@v1 It’s free and MIT. Findings are heuristic candidates — verify before acting (the report labels every one). Shipping to mainnet and want a human on it? I do fast, honest smart-contract reviews for small protocols — a hand-verified Quick Scan is $49 (one contract, 48h, and if the report isn’t useful you don’t pay). Full calibration report and services at juan23z.github.io.