Comprehensive Security for Your Skills & Contracts
Upload code and get instant results — automated permission audits, vulnerability detection, and stress testing to keep every line of code production-ready.
Full-lifecycle security coverage for Skills — making security a natural part of every development workflow.
One-click comprehensive scan for Skill security risks — intelligently detects permission vulnerabilities, configuration issues, and injection threats with a multi-dimensional health score.
Precise scanning of EVM / Solana contract source code — detects reentrancy attacks, integer overflows, access control issues, and other high-severity vulnerabilities.
Simulate real high-concurrency scenarios, collect P50/P95/P99 latency and throughput metrics, and fully evaluate system capacity limits.
Automatically generates structured HTML reports covering risk summaries, detailed vulnerability lists, and remediation suggestions — ready to share with your team or clients.
From code upload to report generation — fully automated, zero manual configuration.
Drag and drop your Skill zip or contract source files. Supports multiple formats with instant parsing.
Large models deeply parse code logic and combine with rule libraries to identify security risks — covering OWASP TOP 10 and on-chain-specific vulnerabilities.
Professional report generated in seconds — includes risk ratings, vulnerability details, and remediation guidance. One-click download.
Everything you need to know about CodeAutrix — clear answers, no fluff.
Skill Security Audit accepts .zip archives containing your Skill or Agent code. Contract Audit supports .sol Solidity source files (EVM chains) and Rust-based Solana programs, as well as on-chain contract addresses for live analysis. All uploads are processed server-side and never shared with third parties.
Your code is stored only for the duration of the scan task and its associated report. It is never shared with other users or used for training. You can delete any task and its artifacts at any time from the Workspace panel.
No registration is required to run scans. Connecting a wallet (MetaMask or WalletConnect) is optional — it links your session to a persistent identity so your scan history is preserved across devices. Without a wallet, your tasks are tied to your browser session only.
Yes. Each IP address may submit up to 3 scan tasks per UTC calendar day across all scan types combined (Skill Audit, Contract Audit, and Stress Test). The counter resets at midnight UTC. This limit ensures fair usage and service stability for all users.
The Skill Security Audit produces five independent dimension scores — Privacy, Privilege, Integrity, Supply Chain, and Stability — each rated 0–100. The overall score is their arithmetic mean. Scores ≥ 80 are considered healthy; scores below 60 indicate significant risk. Each dimension deducts points based on matched risk patterns weighted by severity.
Contract Audit supports all EVM-compatible chains (Ethereum, BNB Chain, Polygon, Arbitrum, Base, etc.) via Solidity source code or on-chain address, and Solana programs via Rust/Anchor source code. More chains will be added in future releases.
Yes. Every completed scan generates a structured report viewable in the browser. For Skill Security Audit, a professional PDF report can be downloaded directly from the report page — suitable for sharing with your team, clients, or auditors.
Skill Security Audit targets Skill and Agent packages (AI tool code). It checks permissions, privilege escalation, data leakage, obfuscation, supply chain risks, and more, producing a 5-dimension health score.
Contract Audit targets smart contracts — both EVM (Solidity) and Solana (Rust/Anchor). It detects reentrancy, integer overflow, access control flaws, gas inefficiencies, and other chain-specific vulnerabilities using AI-powered analysis.