
slither v0.11.6
Static Analyzer for Solidity and Vyper
Slither, the smart contract static analyzer
Join the Empire Hacking Slack
- Discussions and Support
Slither is a Solidity & Vyper static analysis framework written in Python3. It runs a suite of vulnerability detectors, prints visual information about contract details, and provides an API to easily write custom analyses. Slither enables developers to find vulnerabilities, enhance their code comprehension, and quickly prototype custom analyses.
- Features
- Usage
- How to install
- Detectors
- Printers
- Tools
- API Documentation
- Getting Help
- FAQ
- License
- Publications
Features
- Detects vulnerable Solidity code with low false positives (see the list of trophies)
- Identifies where the error condition occurs in the source code
- Easily integrates into continuous integration and Hardhat/Foundry builds
- Built-in 'printers' quickly report crucial contract information
- Detector API to write custom analyses in Python
- Ability to analyze contracts written with Solidity >= 0.4
- Intermediate representation (SlithIR) enables simple, high-precision analyses
- Correctly parses 99.9% of all public Solidity code
- Average execution time of less than 1 second per contract
- Integrates with Github's code scanning in CI
- Support for Vyper smart contracts
Usage
Run Slither on a Hardhat/Foundry/Dapp/Brownie application:
slither .
This is the preferred option if your project has dependencies as Slither relies on the underlying compilation framework to compile source code.
However, you can run Slither on a single file that does not import dependencies:
slither tests/uninitialized.sol
How to install
Note Slither requires Python 3.10+. If you're not going to use one of the supported compilation frameworks, you need solc, the Solidity compiler; we recommend using solc-select to conveniently switch between solc versions.
Using uv (Recommended)
uv is a fast Python package manager that's 10-100x faster than pip.
# Install uv if you haven't already
curl -LsSf https://astral.sh/uv/install.sh | sh
# Install slither as a tool
uv tool install slither-analyzer
# Or run slither without installation
uvx --from slither-analyzer slither <target>
To upgrade:
uv tool upgrade slither-analyzer
Using Pip
python3 -m pip install slither-analyzer
To upgrade:
python3 -m pip install --upgrade slither-analyzer
Using Brew
brew install slither-analyzer
Using Git (Development)
git clone https://github.com/crytic/slither.git && cd slither
# Install as editable for development
uv tool install -e .
# Or use uv run for testing without installation
uv run slither <target>
The -e flag installs in editable mode, meaning changes to the source code are immediately reflected without reinstalling.
Using Docker
Use the eth-security-toolbox docker image. It includes all of our security tools and every major version of Solidity in a single image. /home/share will be mounted to /share in the container.
docker pull trailofbits/eth-security-toolbox
To share a directory in the container:
docker run -it -v /home/share:/share trailofbits/eth-security-toolbox
Integration
- For GitHub action integration, use slither-action.
- For pre-commit integration, use (replace
$GIT_TAGwith real tag)- repo: https://github.com/crytic/slither rev: $GIT_TAG hooks: - id: slither - To generate a Markdown report, use
slither [target] --checklist. - To generate a Markdown with GitHub source code highlighting, use
slither [target] --checklist --markdown-root https://github.com/ORG/REPO/blob/COMMIT/(replaceORG,REPO,COMMIT)