
slither v0.11.6
Solidity 和 Vyper 的静态分析器
Slither,智能合约静态分析器
加入 Empire Hacking Slack
- 讨论与支持
Slither 是一个用 Python3 编写的 Solidity 和 Vyper 静态分析框架。它运行一套漏洞检测器,打印合约细节的可视化信息,并提供 API 以轻松编写自定义分析。Slither 使开发者能够发现漏洞,增强代码理解,并快速原型化自定义分析。
功能
- 以低误报率检测易受攻击的 Solidity 代码(查看战利品列表)
- 识别源代码中错误条件发生的位置
- 轻松集成到持续集成和 Hardhat/Foundry 构建中
- 内置的 'printers' 快速报告关键合约信息
- 检测器 API,可使用 Python 编写自定义分析
- 能够分析使用 Solidity >= 0.4 编写的合约
- 中间表示(SlithIR)实现简单、高精度的分析
- 正确解析 99.9% 的公开 Solidity 代码
- 每个合约的平均执行时间不到 1 秒
- 在 CI 中与 Github 的代码扫描集成
- 支持 Vyper 智能合约
使用
在 Hardhat/Foundry/Dapp/Brownie 应用程序上运行 Slither:```console slither .
如果你的项目有依赖项,这是首选选项,因为 Slither 依赖于底层编译框架来编译源代码。
不过,你也可以在单个不导入依赖的文件上运行 Slither:```console
slither tests/uninitialized.sol
如何安装
注意 Slither 需要 Python 3.10+。 如果您不打算使用 支持的编译框架,则需要 solc 即 Solidity 编译器;我们推荐使用 solc-select 来方便地在不同 solc 版本间切换。
使用 uv(推荐)
uv 是一个快速的 Python 包管理器,速度比 pip 快 10 到 100 倍。```console
Install uv if you haven't already
curl -LsSf https://astral.sh/uv/install.sh | sh
Install slither as a tool
uv tool install slither-analyzer
Or run slither without installation
uvx --from slither-analyzer slither
升级:```console
uv tool upgrade slither-analyzer
使用 Pip```console
python3 -m pip install slither-analyzer
要升级:```console
python3 -m pip install --upgrade slither-analyzer
使用 Brew```console
brew install slither-analyzer
### 使用 Git(开发)```bash
git clone https://github.com/crytic/slither.git && cd slither
# Install as editable for development
uv tool install -e .
# Or use uv run for testing without installation
uv run slither <target>
The -e flag installs in editable mode, meaning changes to the source code are immediately reflected without reinstalling.
使用 Docker
使用 eth-security-toolbox Docker 镜像。它在一个镜像中包含了我们所有的安全工具和每个主要版本的 Solidity。/home/share 将被挂载到容器内的 /share。```bash
docker pull trailofbits/eth-security-toolbox
为了在容器中共享一个目录:```bash
docker run -it -v /home/share:/share trailofbits/eth-security-toolbox
集成
- 对于 GitHub Action 集成,请使用 slither-action。
- 对于 pre-commit 集成,请使用(将
$GIT_TAG替换为实际标签) ```YAML- repo: https://github.com/crytic/slither
rev: $GIT_TAG
hooks:
- id: slither
- repo: https://github.com/crytic/slither
rev: $GIT_TAG
hooks:
- 要生成Markdown报告,使用
slither [target] --checklist。 - 要生成带有GitHub源代码高亮的Markdown报告,使用
slither [target] --checklist --markdown-root https://github.com/ORG/REPO/blob/COMMIT/(替换ORG、REPO、COMMIT)
检测器