Slither triage queue

Slither prints every detector it has, naming and style included. Drop the JSON and get the 13 detectors worth a manual pass, ranked by impact and confidence, with file and line.

Your content never leaves the browser.

slither-focusLocal · 13 detectors
Paste JSON instead

Each location lists up to four line numbers.

Make the input

Run Slither with JSON output from the project root. The file holds every detector result with its impact, its confidence and the source lines of each element.

shell
slither . --json slither.json

The same filter ships in the open-source kit, for a terminal or a CI step:

shell
bounty-kit slither-focus slither.json --markdown --limit 8

What the queue holds

One section per detector result, highest impact first, then highest confidence. Each section has Slither’s description and a table of locations: file, up to four line numbers, and the function or node name.

A failed run is refused. When compilation fails, Slither writes "success": false and no results; the tool stops there and says so. An empty queue always means the 13 detectors found nothing.

The Markdown is plain: paste it into an issue, a notes file or a chat with your model.

Detectors

The 13 detectors kept
DetectorWhy it gets a manual pass
arbitrary-send-erc20Why it gets a manual passtransferFrom with a from the caller chooses. Any approval given to the contract is spendable.
arbitrary-send-ethWhy it gets a manual passETH sent to an address the caller controls.
calls-loopWhy it gets a manual passExternal calls inside a loop. One reverting callee blocks the whole batch.
controlled-delegatecallWhy it gets a manual passdelegatecall to a target the caller controls.
delegatecall-loopWhy it gets a manual passdelegatecall in a loop inside a payable function. msg.value is counted on every pass.
incorrect-equalityWhy it gets a manual passStrict equality on a balance or a supply that anyone can move with a transfer.
low-level-callsWhy it gets a manual passcall, delegatecall and staticcall sites. Each needs its target and its success check read.
reentrancy-benignWhy it gets a manual passState written after an external call, where re-entering repeats the call.
reentrancy-ethWhy it gets a manual passState written after an external call that sends ETH.
reentrancy-no-ethWhy it gets a manual passState written after an external call, with no ETH sent.
unchecked-transferWhy it gets a manual passERC-20 transfer or transferFrom whose return value is ignored.
uninitialized-localWhy it gets a manual passA local variable read before it is assigned.
unused-returnWhy it gets a manual passThe return value of an external call is dropped.

Questions

Is the Slither output uploaded?

No. The file is parsed and filtered in this tab. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it. Pressing “Triage this in the workbench” moves the queue to the workbench through this browser’s session storage. It leaves the browser only when you run a review there: through our server to the provider you chose.

Why these 13 detectors?

Slither reports naming, style and gas detectors next to the ones that move funds. These 13 are the classes where a hit is worth reading line by line on a bounty target: value sent to a caller-chosen address, state written after an external call, ignored return values, controlled delegatecall.

What does the tool decide?

Nothing about validity. It filters, ranks and formats. A detector hit is a lead: the scanner triage profile in the workbench groups the leads by root cause and gives each one a next check.

A queue is a list of leads

Scanner triage groups the leads by root cause, ranks them by what each could cost, and gives every queued lead one next check.

More free tools