Slither triage queue
Slither prints every detector it has, naming and style included. Drop the JSON and get the 13 detectors worth a manual pass, ranked by impact and confidence, with file and line.
Your content never leaves the browser.
Make the input
Run Slither with JSON output from the project root. The file holds every detector result with its impact, its confidence and the source lines of each element.
slither . --json slither.json
The same filter ships in the open-source kit, for a terminal or a CI step:
bounty-kit slither-focus slither.json --markdown --limit 8
What the queue holds
One section per detector result, highest impact first, then highest confidence. Each section has Slither’s description and a table of locations: file, up to four line numbers, and the function or node name.
A failed run is refused. When compilation fails, Slither writes "success": false and no results; the tool stops there and says so. An empty queue always means the 13 detectors found nothing.
The Markdown is plain: paste it into an issue, a notes file or a chat with your model.
Detectors
| Detector | Why it gets a manual pass |
|---|---|
arbitrary-send-erc20 | Why it gets a manual passtransferFrom with a from the caller chooses. Any approval given to the contract is spendable. |
arbitrary-send-eth | Why it gets a manual passETH sent to an address the caller controls. |
calls-loop | Why it gets a manual passExternal calls inside a loop. One reverting callee blocks the whole batch. |
controlled-delegatecall | Why it gets a manual passdelegatecall to a target the caller controls. |
delegatecall-loop | Why it gets a manual passdelegatecall in a loop inside a payable function. msg.value is counted on every pass. |
incorrect-equality | Why it gets a manual passStrict equality on a balance or a supply that anyone can move with a transfer. |
low-level-calls | Why it gets a manual passcall, delegatecall and staticcall sites. Each needs its target and its success check read. |
reentrancy-benign | Why it gets a manual passState written after an external call, where re-entering repeats the call. |
reentrancy-eth | Why it gets a manual passState written after an external call that sends ETH. |
reentrancy-no-eth | Why it gets a manual passState written after an external call, with no ETH sent. |
unchecked-transfer | Why it gets a manual passERC-20 transfer or transferFrom whose return value is ignored. |
uninitialized-local | Why it gets a manual passA local variable read before it is assigned. |
unused-return | Why it gets a manual passThe return value of an external call is dropped. |
Questions
Is the Slither output uploaded?
No. The file is parsed and filtered in this tab. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it. Pressing “Triage this in the workbench” moves the queue to the workbench through this browser’s session storage. It leaves the browser only when you run a review there: through our server to the provider you chose.
Why these 13 detectors?
Slither reports naming, style and gas detectors next to the ones that move funds. These 13 are the classes where a hit is worth reading line by line on a bounty target: value sent to a caller-chosen address, state written after an external call, ignored return values, controlled delegatecall.
What does the tool decide?
Nothing about validity. It filters, ranks and formats. A detector hit is a lead: the scanner triage profile in the workbench groups the leads by root cause and gives each one a next check.
A queue is a list of leads
Scanner triage groups the leads by root cause, ranks them by what each could cost, and gives every queued lead one next check.