foundryaudit-coder:7b
속도와 정확도의 균형
일상 PR·CI용 기본 모델. Solidity와 Foundry 테스트 구조 이해도가 높습니다.
- 베이스
- qwen2.5-coder:7b
- 용량
- 4.7 GB
- 컨텍스트
- 32K
ollama create foundryaudit-coder:7bFoundry Audit AI는 Foundry·Hardhat·EVM 프로젝트용 Solidity 보안 감사 특화 오픈 LLM 모음입니다. Ollama로 로컬 실행하며 재진입, 접근 제어, 오라클 조작 등을 구조화된 JSON으로 반환합니다.
❯ curl -s -X POST https://foundryaudit.com/api/audit -H "Content-Type: text/plain" --data-binary @Vault.sol | jq .report
⠿ foundryaudit-coder:7b 분석 중… 212 lines · 2.8s
CRITICAL Reentrancy in withdraw() SWC-107 · L16
HIGH tx.origin used for authorization SWC-115 · L22
LOW Missing events for state changes L10, L18
risk_score: 94 / 100
4
감사 튜닝 모델
20+
취약점 클래스 (SWC)
0 byte
제3자로 전송되는 코드
32K
컨텍스트 토큰
Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions · Solidity ^0.8 Ollama Ethereum / EVM Foundry forge test fuzz invariant Hardhat OpenZeppelin SWC Registry Qwen2.5-Coder DeepSeek-R1 Llama 3.2 JSON Report GitHub Actions
각 모델은 Ollama Modelfile로 제공됩니다. 검증된 오픈소스 코드 LLM 위에 Foundry 감사 시스템 프롬프트와 파라미터가 올라갑니다.
속도와 정확도의 균형
일상 PR·CI용 기본 모델. Solidity와 Foundry 테스트 구조 이해도가 높습니다.
ollama create foundryaudit-coder:7b단계별 심층 분석
호출 흐름과 상태 변화를 추론해 재진입·가격 조작 등 복합 버그를 찾습니다.
ollama create foundryaudit-deep:14b메인넷 전 최종 점검
대형 프로토콜·다중 컨트랙트용 플래그십. 오탐률이 가장 낮습니다.
ollama create foundryaudit-pro:32b노트북에서도 가볍게
1차 스캔·학습용. 에디터 저장 시 빠른 점검에 적합합니다.
ollama create foundryaudit-lite:3b정확도·속도는 모델 간 비교용 참고치입니다. 실제 성능은 하드웨어와 코드베이스에 따라 달라집니다.
클라우드 API 키·종량 과금 없음. 터미널 → Ollama → 보안 리포트 — 파이프라인은 이것뿐입니다.
01
curl로 .sol 파일을 그대로 보냅니다. 로컬 Ollama(:11434) 또는 이 사이트 /api/audit 프록시 모두 가능합니다.
curl --data-binary @Vault.sol02
Ollama가 감사 모델을 실행하고, 시스템 프롬프트가 SWC 레지스트리와 Foundry 테스트 공백을 점검합니다.
ollama · temperature 0.103
심각도·위치·SWC ID·수정안이 담긴 JSON — jq·CI·대시보드에 바로 연결.
format: "json"전문 감사 전 1차 방어선입니다. 개발 루프 안에서 즉시 피드백을 받으세요.
미공개 프로토콜도 안심하고 분석. 모든 추론은 로컬 Ollama에서 실행됩니다.
토큰 과금 없음 — 커밋·파일마다 감사를 돌려도 비용 0.
JSON 모드로 동일 스키마 리포트. 파싱 지옥 없이 자동화.
curl과 jq만으로 critical/high 발견 시 GitHub Actions·GitLab CI를 실패시킬 수 있습니다.
모델과 OS를 고르면 명령이 자동으로 바뀝니다. 순서대로 복사해 실행하세요.
로컬 LLM 런타임 Ollama를 설치합니다. 서버는 :11434에서 동작합니다.
curl -fsSL https://ollama.com/install.sh | sh # Verify (if server isn't running: ollama serve) ollama --version curl http://localhost:11434/api/version
foundryaudit-coder:7b는 qwen2.5-coder:7b(4.7 GB) 기반입니다.
ollama pull qwen2.5-coder:7b
curl로 Modelfile을 받아 ollama create로 등록합니다.
curl -fsSL https://foundryaudit.com/api/modelfile/foundryaudit-coder-7b -o foundryaudit-coder-7b.Modelfile ollama create foundryaudit-coder:7b -f foundryaudit-coder-7b.Modelfile ollama list | grep foundryaudit
짧은 코드를 Ollama /api/generate로 보냅니다. format: "json"으로 구조화 출력.
curl http://localhost:11434/api/generate -d '{
"model": "foundryaudit-coder:7b",
"prompt": "contract A { function kill() public { selfdestruct(payable(msg.sender)); } }",
"format": "json",
"stream": false
}' | jq -r '.response | fromjson'jq -Rs로 파일 내용을 JSON 문자열로 감싸 /api/chat에 전달합니다.
jq -Rs '{
model: "foundryaudit-coder:7b",
stream: false,
format: "json",
messages: [{ role: "user", content: . }]
}' Vault.sol \
| curl -s http://localhost:11434/api/chat -d @- \
| jq -r '.message.content | fromjson'npm run dev 실행 시 /api/audit가 Ollama를 호출합니다 — text/plain으로 .sol 전송, JSON 이스케이프 불필요.
curl -s -X POST "https://foundryaudit.com/api/audit?model=foundryaudit-coder:7b" \ -H "Content-Type: text/plain" \ --data-binary @Vault.sol | jq . # Streaming (NDJSON) curl -N -X POST "https://foundryaudit.com/api/audit?model=foundryaudit-coder:7b&stream=true" \ -H "Content-Type: text/plain" \ --data-binary @Vault.sol
재진입·tx.origin 인증 버그가 있는 Vault를 foundryaudit-coder:7b로 감사한 예시입니다.
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
contract Vault {
mapping(address => uint256) public balances;
address public owner;
constructor() { owner = msg.sender; }
function deposit() external payable {
balances[msg.sender] += msg.value;
}
function withdraw() external {
uint256 amount = balances[msg.sender];
(bool ok, ) = msg.sender.call{value: amount}("");
require(ok, "transfer failed");
balances[msg.sender] = 0;
}
function sweep(address to) external {
require(tx.origin == owner, "not owner");
payable(to).transfer(address(this).balance);
}
}{
"model": "foundryaudit-coder:7b",
"duration_ms": 2814,
"report": {
"summary": "Vault is exposed to reentrancy and phishing-based owner takeover. Funds can be fully drained.",
"risk_score": 94,
"findings": [
{
"id": "FA-001",
"title": "Reentrancy in withdraw()",
"severity": "critical",
"swc": "SWC-107",
"location": "withdraw() L16-18",
"description": "External call is made before the balance is zeroed, allowing a malicious receiver to re-enter and withdraw repeatedly.",
"recommendation": "Apply Checks-Effects-Interactions: zero balance before the call, or use ReentrancyGuard.",
"foundry_hint": "forge test --match-test testReentrancyWithdraw"
},
{
"id": "FA-002",
"title": "tx.origin used for authorization",
"severity": "high",
"swc": "SWC-115",
"location": "sweep() L22",
"description": "A contract called by the owner can invoke sweep() and pass the tx.origin check.",
"recommendation": "Replace tx.origin with msg.sender; consider OpenZeppelin Ownable.",
"foundry_hint": "Add unit test where owner EOA calls via malicious intermediary contract"
},
{
"id": "FA-003",
"title": "Missing events for state changes",
"severity": "low",
"swc": null,
"location": "deposit() L10, withdraw() L18",
"description": "Deposits and withdrawals emit no events, hindering off-chain monitoring.",
"recommendation": "Emit Deposit and Withdraw events.",
"foundry_hint": "expectEmit in forge tests for deposit/withdraw"
}
],
"gas_optimizations": ["Declare owner as immutable", "Use custom errors instead of revert strings"],
"foundry_recommendations": ["Add invariant test: total balances <= address(this).balance", "Fuzz withdraw with random callers"]
}
}고전적 버그부터 DeFi 공격 벡터, 가스 최적화, Foundry 테스트 권고까지 한 번에.
SWC-107 critical
외부 호출 후 상태 갱신
SWC-105/106 critical
onlyOwner 누락, selfdestruct 보호 없음
SWC-112 critical
신뢰할 수 없는 대상으로 delegatecall
critical
스팟 가격 의존, 플래시론 조작
high
피싱 컨트랙트를 통한 권한 탈취
SWC-101 high
unchecked 또는 0.8 미만 컴파일러
SWC-120 medium
block.timestamp / blockhash 난수
SWC-128 medium
무한 루프, 외부 호출 revert
Ollama(localhost:11434)를 직접 호출하거나 Foundry Audit 프록시로 더 간단히 요청하세요.
/api/auditSolidity 소스를 받아 Ollama로 감사 후 JSON 리포트 반환Foundry Audit/api/models사용 가능 모델 및 Modelfile URLFoundry Audit/api/modelfile/:slugollama create용 Modelfile (text/plain)Foundry Audit/api/chat채팅 요청 — messages에 컨트랙트 전달Ollama/api/generate짧은 스니펫용 단일 프롬프트Ollama| 이름 | 타입 | 위치 | 설명 |
|---|---|---|---|
| code | string | body | Solidity 소스 (text/plain이면 본문 전체) |
| model | string | body · query | 모델명. 기본 foundryaudit-coder:7b |
| stream | boolean | body · query | true면 Ollama NDJSON 스트림 그대로 전달 |
curl -s https://foundryaudit.com/api/audit \
-H "Content-Type: application/json" \
-d '{
"model": "foundryaudit-pro:32b",
"code": "pragma solidity ^0.8.20; contract T { function f() external { selfdestruct(payable(msg.sender)); } }"
}'for f in src/*.sol; do
curl -s -X POST "https://foundryaudit.com/api/audit" \
-H "Content-Type: text/plain" --data-binary @"$f" \
| jq -e '[.report.findings[] | select(.severity=="critical" or .severity=="high")] | length == 0' \
|| { echo "❌ $f"; exit 1; }
done아니요. Foundry Audit AI는 개발 중 흔한 실수를 잡는 1차 도구입니다. LLM은 오탐·누락이 있을 수 있으므로, 실자금 컨트랙트는 Slither, Foundry fuzz/invariant, 전문 감사도 병행해야 합니다.