Overview
slither-chat is a smart-contract audit copilot that transforms raw Slither detector output into a reviewable security report. It normalizes each finding, explains the issue in plain English, orders findings by severity, and provides a suggested fix with a line-specific patch hint.
The project is intended as a review aid rather than a replacement for a professional auditor. Its explanations and generated patches should be verified before any contract is deployed.
Key Features
- Runs Slither in JSON mode and captures the rule identifier, severity, confidence, contract or function, exact lines, and source snippet for each finding.
- Supports an offline rule-based knowledge base that requires no model, network connection, or API key.
- Offers an on-device Hugging Face zero-shot backend that classifies findings by vulnerability type and confidence.
- Connects to OpenAI-compatible APIs for LLM-generated explanations, with graceful fallback to the rule backend.
- Produces unified-diff patch hints tied to precise lines for every normalized finding.
- Renders rich terminal output, Markdown reports, exportable SVG, and JSON suitable for CI pipelines.
Audit Workflow
Users run the command-line tool against a Solidity contract and select the desired explanation backend. The default offline path remains available when a key, model, or network connection is unavailable, while optional local model support requires the corresponding transformer dependencies.
Reports combine normalized static-analysis results with explanations and remediation guidance. Machine-readable JSON can be emitted alongside a Markdown report for automated workflows and later review.
Benchmarking
slither-chat can benchmark the audit pipeline against real audited contracts and Slither ground truth from the Hugging Face Hub. Results include precision, recall, and F1 scores for individual rules, making it possible to assess detector and explanation performance against labeled examples.
The repository also includes a deliberately vulnerable reentrancy vault and a generated sample audit report for demonstrating the end-to-end output.
Technical Requirements
The tool is written for Python 3.10 or newer and uses Slither with its Solidity compilation tooling for static analysis. The command-line and reporting stack includes Click and Rich, while Hugging Face datasets and Transformers support local classification and benchmark data.