Bringing Scout to Solana
Dear Solana community,
We’re excited to present our proposal for this RFP, Scout, our open-source vulnerability detection tool. Whether you’re an entry-level developer or an expert, Scout is the perfect tool to improve the secure development lifecycle of your smart contract projects. Designed with ease of use in mind, Scout offers a seamless installation process, allowing you to focus on what matters most: creating innovative and secure smart contracts.
We are CoinFabrik, a leading research, development, and security auditing company specializing in Web3 technologies. This year marks our 10-year anniversary, and for the past 3 years, we’ve added value to the Solana ecosystem. CoinFabrik’s technical team has performed development and auditing for projects like Codigo.AI, Genopets, SmartChain, and Fitchin. Furthermore, we co-hosted the first Solana Hackathon in Argentina (Summer Sol Sessions Buenos Aires) and also had our booth at Breakpoint Amsterdam in 2023, presenting our smart contract testing tool SolBricks. Our commitment is to continue contributing to Solana’s developer growth and retention, and to foster the entry of new talent to help maintain and improve the network.
Our team has an academic background in computer science and mathematics, adding up to decades of experience in cybersecurity and software development, including academic publications, patents turned into products, and conference presentations. Furthermore, we have an ongoing collaboration on knowledge transfer and open-source projects with the University of Buenos Aires.
Tool Overview
Scout is an open-source bug detection tool designed to assist developers and auditors in identifying potential security threats and applying best practices to smart contracts. It enhances contract security by detecting issues and suggesting remediations during development, thus ensuring the security of contracts before deployment.
Scout is a static analyzer equipped with specialized lints or detectors that pinpoint specific vulnerabilities. These lints are designed for easy integration, enabling contributors to add new detectors seamlessly. Scout includes a command-line interface (CLI) offering various output formats, along with a VSCode extension that highlights vulnerable code segments and provides explanations and remediation suggestions.
As a security companion, Scout’s comprehensive documentation and open-source approach encourage community contributions, elevating ecosystem security standards and best practices.
Help us bring Scout to Solana!
We want to hear from you! We look forward to any feedback the Solana developer community wants to share concerning our proposal to bring Scout into the ecosystem.
Which types of Solana vulnerabilities would you like our bug detection tool to focus on identifying? Your suggestions will help us refine our tool’s capabilities to better meet the community’s requirements and improve the network’s security.