The hard part of a security scanner isn’t finding things. It’s not drowning the real issues in noise.
A tool that flags forty non-issues trains you to ignore it — and then it misses the one that matters. So when I built OpenClaw Audit (a free, MIT heuristic Solidity scanner), I held it to one bar: silence on sound code.
To prove it stays quiet, I ran it across ten of the most-reviewed Solidity codebases in the ecosystem — libraries that thousands of protocols depend on and that have been audited many times over — and hand-verified every flag. Here’s exactly what came out.
The numbers
Run on each library’s source (tests, mocks and dependencies excluded), latest main:
createPair — worth a human’s eyes, not a false alarm.
Uniswap v3-core
40
1
initialize() flagged — false positive: pool init is permissionless by design.
Uniswap v4-core
46
1
Same as v3 — permissionless initialize(), false positive.
Solmate
20
2
One real, known flag (ERC-4626 first-depositor inflation, omitted by design); one rounding false positive.
Morpho Blue
17
2
Two reentrancy false positives — formally verified, correct effects-before-interactions.
Solady
140
7
All false positives: documented tx.origin rescue, UUPS auth the heuristic can’t parse, intentional math ordering.
Total
608
14
~2.3% of files flag anything; 4 of 10 codebases perfectly clean.
What this actually shows
It stays silent on sound code. Zero findings across OpenZeppelin, forge-std, Permit2 and PRBMath — the most-audited code in web3, where naive tools carpet-bomb false positives.
When it does flag, the flags are explainable — not random. They cluster on genuinely interesting spots: a permissionless initializer, a documented rescue mechanism, a library that deliberately leaves inflation protection to the integrator. A human clears each in seconds. That’s the point.
It catches real, known design gaps. The Solmate first-depositor-inflation flag is a true observation: that ERC-4626 implementation omits the virtual-share defense OpenZeppelin’s adds. The scanner surfaces the difference.
My favorite result is Solady: zero flags across 140 files of hand-written, gas-golfed assembly — the kind of code that makes lesser tools panic. The raw call() in SafeTransferLib looks like the classic unchecked-call bug, but it verifies success AND the return value AND that the address has code. Correct restraint: there was nothing to report.
Verify it yourself — one command
Every number above is reproducible. You don’t have to trust me:
pipx run --spec git+https://github.com/juan23z/openclaw-audit openclaw-audit \
https://github.com/OpenZeppelin/openzeppelin-contracts
# → 0 candidate observations across 247 client .sol contracts
Enter fullscreen mode Exit fullscreen mode
Swap the URL for any codebase above — or your own repo — and check the numbers. That’s the whole idea: a claim you can verify, not one you have to trust.
Use it on your own code
Point it at a repo and get a Markdown + HTML report in seconds, or drop it into CI as a GitHub Action and get a scan on every PR:
# .github/workflows/security.yml
name: security
on: [push, pull_request]
permissions: { contents: read, pull-requests: write }
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: juan23z/openclaw-audit@v1
Enter fullscreen mode Exit fullscreen mode
It’s free and MIT. Findings are heuristic candidates — verify before acting (the report labels every one).
Shipping to mainnet and want a human on it? I do fast, honest smart-contract reviews for small protocols — a hand-verified Quick Scan is $49 (one contract, 48h, and if the report isn’t useful you don’t pay). Full calibration report and services at juan23z.github.io.