The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Bug Bounty Intelligence listing page.
AI-powered smart contract security analysis for AI agents and developers.
Drawn from a corpus of 27,681 submitted findings across 105 Sherlock and Code4rena contests.
Cost: $5 USDC on Base (eip155:8453) via x402.
Free tool: list_vulnerability_patterns — no payment needed.
list_vulnerability_patterns' acceptance-rate numbers are computed only from the subset where
results could be exactly reconciled against Sherlock's own published outcomes — 1,032 findings
across 10 contests. We'd rather show fewer, verified numbers than a bigger set we can't stand
behind. See METHODOLOGY.md for exactly why, and how to reproduce it.
vulnerability-acceptance-rates.json is the same data
list_vulnerability_patterns serves, as a static file. No API call, no account, no network
dependency at all — download it, or copy it into your own tool's rule set. CC0 licensed, use it
however you want, credit optional.
If you're building a local-first / offline security scanner and the paid scan_contract tool
below isn't a fit for your project's architecture, this file might still be useful on its own.
3ilm-mcp is a smaller, free-only MCP server built from
the same verified dataset. It has no paid tier at all — just pattern search
(search_vulnerabilities, get_pattern_details, list_patterns). Use this repo
(bug-bounty-intelligence-mcp) if you also want the paid scan_contract full-repo scan; use
3ilm-mcp if you only ever wanted the free lookup tools and prefer the lighter package.
On 3FLabs/grunt (ERC-4626 + Morpho vaults, 218 contracts): Slither reports 27 "High" findings. After analysis: 24 are in lib/solady (out-of-scope dependency with known Slither false positive patterns), and 3 are EIP-712 design patterns. False positive rate: 100%.
Bug Bounty Intelligence scopes to src/ only and filters through the Al-Mizaan 7-gate framework before reporting anything.
We also reported a related divide-before-multiply pattern on the same lib/solady code directly to the Slither project — crytic/slither#3039. A maintainer merged a fix for part of it (crytic/slither#3040); see BENCHMARK.md for the honest scope of what that fix does and doesn't cover, we overclaimed in the original report.
Submit a public GitHub repo containing Solidity smart contracts. Receive a full vulnerability report within 24 hours, powered by the Al-Mizaan v3 analysis framework.
| Tool | Description | Cost |
|---|---|---|
scan_contract | Submit repo for security analysis | $5 USDC |
get_scan_report | Poll status and get report URL | Free |
list_vulnerability_patterns | Show acceptance rates from exact-reconciled Sherlock contests | Free |
Add to your claude_desktop_config.json:
Or run directly:
If scan_contract returns PAYMENT REQUIRED, send exactly $5 USDC on Base to the address shown, then retry. Payment = acceptance of service terms.
x402 info:
Real scan of sherlock-audit/2025-03-crestal-network (Derivatives protocol, 29 contracts):
The Al-Mizaan v3 framework checks 7 gates:
Only findings that survive all 7 gates are reported.
This is a free, open-source MCP server maintained in my spare time. If it caught something useful before you shipped, tips are welcome and appreciated (never expected):
0xdffcC75a674257be6FE1b5549FE52e8f8a6A3A5A (USDC, Base)