loading…
Search for a command to run...
loading…
Enables searching over 20,000+ smart contract audit findings from Solodit, with filters for severity, firm, tags, and more. Designed for use with AI coding agen
Enables searching over 20,000+ smart contract audit findings from Solodit, with filters for severity, firm, tags, and more. Designed for use with AI coding agents like Claude Code and Codex CLI.
Smart contract security findings for AI coding agents
Search Solodit's 20,000+ audit findings from Claude Code and Codex CLI.
npm version license node giveth

curl -fsSL https://raw.githubusercontent.com/marchev/claudit/main/install.sh | sh
The installer detects Claude Code and/or Codex CLI, prompts for your Solodit API key, and registers the MCP server.
Then just ask:
> Find 5 solo findings by 0x52 at Sherlock
claude mcp add --scope user --transport stdio solodit \
--env SOLODIT_API_KEY=sk_your_key_here \
-- npx -y @marchev/claudit@latest
# (Optional) Install companion skill
mkdir -p ~/.claude/skills/solodit
curl -fsSL https://raw.githubusercontent.com/marchev/claudit/main/.claude/skills/solodit/SKILL.md \
-o ~/.claude/skills/solodit/SKILL.md
codex mcp add solodit \
--env SOLODIT_API_KEY=sk_your_key_here \
-- npx -y @marchev/claudit@latest
search_findingsSearch across all findings with filters.
| Parameter | Type | Description |
|---|---|---|
keywords |
string |
Text search in title and content |
severity |
string[] |
HIGH MEDIUM LOW GAS (case-insensitive) |
firms |
string[] |
Audit firm names |
tags |
string[] |
Vulnerability tags |
language |
string |
Programming language |
protocol |
string |
Protocol name (partial match) |
reported |
string |
30 60 90 alltime |
sort_by |
string |
Recency Quality Rarity |
sort_direction |
string |
Desc (default) Asc |
page |
int |
Page number (default 1) |
page_size |
int |
Results per page (default 10, max 100) |
advanced_filters |
object |
See below |
| Field | Type | Description |
|---|---|---|
quality_score |
number |
Minimum quality score (0-5) |
rarity_score |
number |
Minimum rarity score (0-5) |
user |
string |
Finder/auditor handle |
min_finders |
number |
Minimum number of finders |
max_finders |
number |
Maximum number of finders |
reported_after |
string |
ISO date string |
protocol_category |
string[] |
Protocol categories |
forked |
string[] |
Forked protocol names |
get_findingGet full details for a specific finding by numeric ID, Solodit URL, or slug.
get_filter_optionsList all valid filter values — firms, tags, categories, languages — with finding counts.
Search Solodit for oracle manipulation HIGH severity findings
Find all Sherlock findings about flash loans
What reentrancy issues exist in lending protocols?
Show me solo findings by 0x52
Get recent HIGH severity Solidity findings sorted by quality
Claude Code:
claude mcp remove solodit
claude mcp add --scope user --transport stdio solodit \
--env SOLODIT_API_KEY=sk_new_key \
-- npx -y @marchev/claudit@latest
Codex CLI:
codex mcp remove solodit
codex mcp add solodit \
--env SOLODIT_API_KEY=sk_new_key \
-- npx -y @marchev/claudit@latest
Cursor MCP
{
"mcpServers": {
"solodit": {
"command": "npx",
"args": ["-y", "@marchev/claudit@latest"],
"env": {
"SOLODIT_API_KEY": "sk_new_key"
}
}
}
}
Claude Code:
claude mcp remove solodit
rm -rf ~/.claude/skills/solodit
Codex CLI:
codex mcp remove solodit
git clone https://github.com/marchev/claudit.git
cd claudit
npm install
npm run build
# Test locally
SOLODIT_API_KEY=sk_your_key node dist/index.js
Claudit is a solo-maintained public good for Ethereum security. If it saves you time or finds bugs for you, consider supporting its continued development on Giveth:
MIT License
Run in your terminal:
claude mcp add claudit -- npx Security
Low riskAutomated heuristic from public metadata — not a security guarantee.