
Solidity 및 Vyper용 정적 분석기
Empire Hacking Slack에 참여하세요
- 토론 및 지원
Slither는 Python3로 작성된 Solidity 및 Vyper 정적 분석 프레임워크입니다. 취약점 탐지기 모음을 실행하고, 계약 세부 정보에 대한 시각적 정보를 출력하며, 사용자 정의 분석을 쉽게 작성할 수 있는 API를 제공합니다. Slither는 개발자가 취약점을 찾고, 코드 이해도를 높이며, 사용자 정의 분석을 신속하게 프로토타입화할 수 있도록 합니다.
Hardhat/Foundry/Dapp/Brownie 애플리케이션에서 Slither 실행:```console slither .
이 방법은 프로젝트에 의존성이 있을 때 권장됩니다. Slither는 기본 컴파일 프레임워크에 의존하여 소스 코드를 컴파일하기 때문입니다.
하지만 의존성을 임포트하지 않는 단일 파일에서 Slither를 실행할 수도 있습니다:```console
slither tests/uninitialized.sol
참고 Slither는 Python 3.10+가 필요합니다. 지원되는 컴파일 프레임워크 중 하나를 사용하지 않을 경우, solc, 즉 Solidity 컴파일러가 필요합니다. solc 버전 간 편리하게 전환하려면 solc-select 사용을 권장합니다.
uv는 pip보다 10~100배 빠른 Python 패키지 관리자입니다.```console
curl -LsSf https://astral.sh/uv/install.sh | sh
uv tool install slither-analyzer
uvx --from slither-analyzer slither
업그레이드하려면:```console
uv tool upgrade slither-analyzer
python3 -m pip install slither-analyzer
업그레이드하려면:```console
python3 -m pip install --upgrade slither-analyzer
brew install slither-analyzer
### Git 사용하기 (개발)```bash
git clone https://github.com/crytic/slither.git && cd slither
# Install as editable for development
uv tool install -e .
# Or use uv run for testing without installation
uv run slither <target>
The -e 플래그는 편집 가능 모드로 설치하여, 소스 코드 변경 사항이 재설치 없이 즉시 반영됩니다.
eth-security-toolbox 도커 이미지를 사용하세요. 이 이미지에는 모든 보안 도구와 모든 주요 Solidity 버전이 단일 이미지에 포함되어 있습니다. 컨테이너에서 /home/share가 /share에 마운트됩니다.```bash
docker pull trailofbits/eth-security-toolbox
컨테이너에서 디렉터리를 공유하려면:```bash
docker run -it -v /home/share:/share trailofbits/eth-security-toolbox
$GIT_TAG를 실제 태그로 바꾸세요) 사용하세요. ```YAML
slither [target] --checklist.slither [target] --checklist --markdown-root https://github.com/ORG/REPO/blob/COMMIT/ (replace ORG, REPO, COMMIT)