Workspace IndexKnowledge Notes › Static analysis — Slither and Semgrep read the code you skimmed

#242PoC

Static analysis — Slither and Semgrep read the code you skimmed

Static analyzers like Slither (Solidity) and Semgrep (general) flag known-bad patterns before deployment, cheap and fast but drowning in false positives that only judgment filters.

Not yet scoped.

Why

The PoC runs Slither and Semgrep on a deliberately buggy contract and triages the output, treating the true-positive rate and noise as the honest measure of the tool.

How it works

Not yet built.

Where it lands in Jayverse

  • CI: run Slither as a required check on every contracts PR across Verex, Token, Wallet and DeFi. Track its true-positive rate over time so a run of noisy findings gets triaged as "read the finding," not "disable the tool."
  • Auditor: record which static-analysis findings were triaged as false positives, and why. The methodology (what was checked, by which rule) should include the judgment calls made on top of Slither/Semgrep output, not just the raw tool report.

Key expressions

Words and phrases from this page worth keeping, with the Korean meaning and the sentence they come from.

Expression뜻 · 쓰이는 자리
flag (v.)(문제를) 표시하다, 짚어내다 · 정적 분석 도구가 의심스러운 패턴을 찾아 알려줄 때. "flag known-bad patterns before deployment"
drown in~에 파묻히다, 넘쳐나서 헤어나지 못하다 · 오탐(false positive)이 너무 많아 진짜 문제를 놓치기 쉬울 때. "drowning in false positives"
triage (v.)(우선순위를 매겨) 선별하다 · 쏟아진 경고들 중 중요한 것부터 걸러낼 때. "triages the output"
deliberately buggy일부러 결함을 심은 · 도구 성능을 테스트하려고 의도적으로 취약하게 만든 코드. "a deliberately buggy contract"
the honest measure of~에 대한 정직한(과장 없는) 척도 · 도구의 실제 성능을 있는 그대로 평가하는 기준. "the honest measure of the tool"
SlitherSolidity 전용 정적분석 도구 · 스마트 컨트랙트 코드에서 알려진 취약 패턴을 자동으로 찾아주는 오픈소스 분석기. "Static analyzers like Slither (Solidity) and Semgrep (general)"
Semgrep범용 정적분석 도구 · 여러 언어에 쓸 수 있는 패턴 기반 코드 스캐너, 배포 전 알려진 위험 패턴을 표시. "flag known-bad patterns before deployment"

← All Knowledge Notes · Workspace Index · Top ↑

정적 분석 — Slither와 Semgrep은 훑고 지나간 코드를 읽는다

Slither(Solidity)와 Semgrep(범용) 같은 정적 분석기는 배포 전에 알려진 나쁜 패턴을 표시하며, 싸고 빠르지만 판단만이 걸러내는 거짓양성에 잠깁니다.

아직 범위 미정.

이 PoC는 의도적으로 버그가 있는 컨트랙트에 Slither와 Semgrep을 돌려 출력을 분류하며, 진양성률과 잡음을 도구의 정직한 척도로 다룹니다.

동작 방식

아직 만들지 않음.

Jayverse에서의 위치

  • CI: Verex, Token, Wallet, DeFi 전체의 모든 컨트랙트 PR에 Slither를 필수 체크로 돌린다. 참양성률을 시간에 따라 추적해서, 잡음 섞인 결과가 나오면 "도구를 끈다"가 아니라 "결과를 읽는다"로 대응하게 한다.
  • Auditor: 어떤 정적 분석 결과를 오탐으로 판단했는지, 왜 그런지 기록한다. 방법론(무엇을 어떤 규칙으로 확인했는지)에는 Slither·Semgrep 원시 출력뿐 아니라 그 위에서 내린 판단도 포함되어야 한다.

핵심 표현

이 페이지의 영어 본문에서 배울 만한 단어와 표현, 뜻과 나온 자리.

Expression뜻 · 쓰이는 자리
flag (v.)(문제를) 표시하다, 짚어내다 · 정적 분석 도구가 의심스러운 패턴을 찾아 알려줄 때. "flag known-bad patterns before deployment"
drown in~에 파묻히다, 넘쳐나서 헤어나지 못하다 · 오탐(false positive)이 너무 많아 진짜 문제를 놓치기 쉬울 때. "drowning in false positives"
triage (v.)(우선순위를 매겨) 선별하다 · 쏟아진 경고들 중 중요한 것부터 걸러낼 때. "triages the output"
deliberately buggy일부러 결함을 심은 · 도구 성능을 테스트하려고 의도적으로 취약하게 만든 코드. "a deliberately buggy contract"
the honest measure of~에 대한 정직한(과장 없는) 척도 · 도구의 실제 성능을 있는 그대로 평가하는 기준. "the honest measure of the tool"
SlitherSolidity 전용 정적분석 도구 · 스마트 컨트랙트 코드에서 알려진 취약 패턴을 자동으로 찾아주는 오픈소스 분석기. "Static analyzers like Slither (Solidity) and Semgrep (general)"
Semgrep범용 정적분석 도구 · 여러 언어에 쓸 수 있는 패턴 기반 코드 스캐너, 배포 전 알려진 위험 패턴을 표시. "flag known-bad patterns before deployment"

← 전체 기술 노트 · 워크스페이스 인덱스 · 맨 위 ↑