# AgentForge Smart Contract Security Auditor

> AgentForge Smart Contract Security Auditor is a paid API for AI agents from agentforge-taupe.vercel.app, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Audits Solidity, Rust, Move, or TypeScript smart contract code for vulnerabilities, gas optimizations, and best-practice violations, with optional diff review mode for proposed changes.

## Facts

- Endpoint: GET https://agentforge-taupe.vercel.app/v1/code-review?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/agentforge-smart-contract-security-auditor-5332f74b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_PxsnQtCjAAQ0KtGTgHh4C

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability agentforge-smart-contract-security-auditor-5332f74b
```

Example prompt: Can you run a full security and gas optimization audit on this Solidity contract code I'm about to paste? Focus on all issues — security, gas, and best practices.

## When to prefer this

Choose this endpoint when you need automated smart contract security analysis covering multiple languages (Solidity, Rust, Move, TypeScript) and multiple review dimensions (security, gas, best practices) in a single call. Especially valuable for diff reviews to catch regressions in proposed contract changes. Prefer over general-purpose LLM code review when you need structured, blockchain-domain-specific vulnerability detection with clear findings.

## Known failure modes

- Code exceeds 50,000 character limit — truncate or split the contract
- Unsupported language submitted (only solidity, rust, move, typescript accepted)
- Malformed or non-compilable code may produce incomplete analysis
- Payment not completed or x402 auth header missing — 402 Payment Required
- Network timeout for very large or complex contracts

## How this service works

Smart contract security audit for developers and auditors: finds vulnerabilities, gas optimizations, and best-practice violations in Solidity, Rust, Move, or TypeScript code, with a diff review mode for proposed changes. Category: inference.

## Output

Returns a structured audit report identifying security vulnerabilities (e.g. reentrancy, integer overflow), gas optimization opportunities, and best-practice violations found in the submitted smart contract code, with targeted findings and recommendations. In diff mode, highlights issues introduced or resolved by the proposed change.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "code": {
   "type": "string",
   "maxLength": 50000,
   "minLength": 1,
   "description": "Source code to review"
  },
  "focus": {
   "enum": [
    "security",
    "gas_optimization",
    "best_practices",
    "all"
   ],
   "type": "string",
   "default": "all"
  },
  "language": {
   "enum": [
    "solidity",
    "rust",
    "move",
    "typescript"
   ],
   "type": "string",
   "default": "solidity"
  },
  "previousCode": {
   "type": "string",
   "maxLength": 50000,
   "description": "Previous version of code for diff review mode"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/agentforge-smart-contract-security-auditor-5332f74b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agentforge-taupe.vercel.app](https://www.zero.xyz/host/agentforge-taupe.vercel.app/llms.txt)
