Skip to content

About

AI smart-contract safety scanner on Base. Reads a contract's real code and tells you which flags are actually dangerous. Live free beta.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

TrustLens: raw scanners cry wolf. TrustLens reads the code.

Base mainnet Free beta Reads real code Follow @SafuLens

Try it live →


TrustLens: proxy-aware contract safety scanning on Base

Know before you ape. TrustLens reads a contract's real code and tells you what's safe, what's not, and how to fix it.

What it does

Paste any contract address on Base. TrustLens pulls the verified source, runs a full static analysis, then puts an AI security reviewer on top of the raw output to tell you which flags are real and which are noise.

Here is the part that matters.

Point a raw scanner at Circle's USDC and the flags light up like a fire alarm: DANGEROUS, 71 out of 100. Blocklists, upgradeable proxies, privileged roles, the works. Technically present. Completely misread.

TrustLens follows the proxy to the real FiatToken implementation and reads that code, then tells you the truth: CAUTION, 25 out of 100. This is canonical USDC. Battle-tested, the privileged functions are Circle's and are expected, and the one thing worth knowing is that its admin is a single key that can upgrade the logic. Now you know exactly what you are trusting.

That gap between "flag exists" and "flag matters" is where people get scared out of good contracts and lured into bad ones. TrustLens lives in that gap.

Why it's different

Raw scanners pattern-match. They see delegatecall, they see an owner role, they see a mint function, and they scream. Every flag looks like a five-alarm fire, so every flag gets ignored. Alert fatigue is a security hole.

TrustLens reads the code the way a security researcher would:

  • Triage, not noise. Every flag gets labeled REAL or false positive, with the reasoning.
  • Context beats keywords. A mint function on a rug is a threat. A mint function on USDC is Tuesday. TrustLens knows the difference.
  • Proof for the real ones. When a flag is genuine, you get a concrete example of how it gets exploited, plus a fix you can paste in.

You stop drowning in red. You start seeing what is actually dangerous.

How it works

  1. Paste an address. Any verified contract on Base mainnet.
  2. Get the raw scan, free and instant. Every flag a static analyzer would raise, no signup.
  3. Open the AI deep report, free in beta. Plain-English triage: what's real, what's noise, and for the real issues, how it gets attacked and how to fix it.

Try it live

trustlens-web.niftyai.workers.dev

No wallet connection required to scan. No signup to read the report. Free while we are in beta.

Start with USDC if you want to watch raw flags scream DANGEROUS on the real implementation and then get taken apart line by line.

For developers

Shipping a contract? TrustLens is a second set of eyes that never gets tired.

For every real issue it finds, you get two things a plain scanner will not give you:

  • A concrete attack example. Not "reentrancy risk detected." An actual walkthrough of how the funds leave, in the specific shape of your code.
  • A copy-paste fix. The corrected pattern, ready to drop into your contract.

Triage plus a fix, in the time it takes to read one Slither report by hand.

Tech stack

Layer Built with
Frontend React, Vite, wagmi, viem
Backend FastAPI, Slither, web3.py
AI triage Claude
On-chain Solidity PaymentGate on Base

Static analysis does the detection. The AI layer does the judgment. The frontend keeps it fast and readable.

Open source

TrustLens is four repos, the first tool in the SafuLens suite:

The four TrustLens repositories. trustlens-web posts scan and report requests to trustlens-backend, which reads Base and an AI triage API. trustlens-keepwarm requests the backend health endpoint every ten minutes. trustlens-contracts holds PaymentGate on Base Sepolia, and both payment arrows are dashed because they are switched off while the scanner is in free beta.

  • Frontend (this repo): React + wagmi/viem
  • Backend: FastAPI, Slither, web3, the proxy resolver and the AI triage layer
  • Contracts: Foundry PaymentGate, dark during the free beta
  • Keepwarm: a cron that pings the backend so Render's free tier never cold-starts

Roadmap

Free beta today.

Built and deployed, waiting on a switch:

  • Pay-per-scan. One deep report, one address, no subscription.
  • Unlimited. A monthly pass, for traders and devs who scan all day.

Both live in PaymentGate on Base Sepolia, and the backend already knows how to verify a payment against it. Turning them on is a config change, not a build. Prices are not fixed yet, so the numbers here are deliberately absent rather than invented.

Not built yet:

  • Founders Pass. A lifetime NFT for the people who showed up early. There is no contract for it, which is why the app marks it SOON rather than taking anybody's money.

License

MIT


TrustLens reads contracts, not tea leaves. Built by @SafuLens. Free beta. Not financial advice.

About

AI smart-contract safety scanner on Base. Reads a contract's real code and tells you which flags are actually dangerous. Live free beta.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages