partial-coverage-probe.sol
VSS-20260923-21NOQY2S · generated Sep 23, 2026, 3:31 PM
Verdict is derived from severity counts via the same deterministic formula every VegaSec report uses. partial-coverage-probe.sol was scanned from pasted source. This is static-analysis triage, not a certification or formal audit attestation.
Partial coverage, not a clean-surface verdict. At least one required analyzer (slither, semgrep) did not complete this scan, so the score is capped at 50/100 and the verdict above can never be Strong/Clear surface. Cause: slither coverage degraded: no installed solc satisfies pragma "^0.3.0" (installed: 0.4.26, 0.5.17, 0.6.12, 0.7.6, 0.8.19). Install a matching solc via solc-select. (+1 more coverage note).
PDF artifact
Queued artifact pipeline · not blocking on the scan
No PDF artifact has been requested for this report yet. The HTML report and the Markdown export already carry the full disclaimer and limitations inline. PDF synthesis is a queued artifact, not part of the scan path.
Status endpoint
GET /report/solidity/VSS-20260923-21NOQY2S/export.pdf
Solidity evidence report
0 audit findings
Executive summary
- No detector raised a finding against the submitted source. This is not a guarantee of safety; manual review remains required.
- Automated static analysis only. A human operator review has not been attached to this report.
Warnings (2)
- · slither coverage degraded: no installed solc satisfies pragma "^0.3.0" (installed: 0.4.26, 0.5.17, 0.6.12, 0.7.6, 0.8.19). Install a matching solc via solc-select.
- · slither exit 1:
Exploit reasoning
No high-confidence exploit narratives
The analyzers did not produce findings at critical, high, or medium severity that map to a deterministic exploit narrative. This does not mean the contract is free of bugs; it means this scan path did not produce evidence strong enough to publish a narrative without operator review.
Audit pipeline
Audit cockpit
Honest stage-by-stage view of what VegaSec ran against this contract. Automated stages do not replace a human operator review.
Audit intake
Passed320ms replay3:31 PMNormalize the submitted contract target and confirm it can enter the Solidity audit lane.
Source acquisition
Passed1.4s replay3:31 PMResolve pasted source or verified explorer source without treating malformed input as demo data.
Toolchain validation
Partial2.3s replay3:31 PMConfirm the configured static analyzers can run and produce parseable output.
- One or more analyzers emitted warnings; report findings remain usable but should be read with limitations.
Static analysis
Partial0 findings8.8s replay3:31 PMRun static analyzers against the sandboxed source and collect raw detector evidence.
- One or more analyzers emitted warnings; report findings remain usable but should be read with limitations.
Finding normalization
Passed0 findings1.1s replay3:31 PMDedupe detectors, classify vulnerability classes and compute severity-weighted risk.
Exploitability review
Partial0 findings1.9s replay3:31 PMFrame automated findings with conservative exploitability and limitation notes.
- Automated exploitability review is conservative and does not replace a manual exploitability assessment.
Remediation draft
Partial0 findings1.5s replay3:31 PMPrepare remediation-oriented evidence for the shareable report artifact.
- Remediation notes are generated from detector evidence and require project-specific engineering review.
Operator review
Blocked0ms replay3:31 PMRecord whether a human operator artifact exists before buyer escalation.
- No operator review artifact is attached to this automated scan.
- Human operator review has not been attached to this automated scan yet.
Finalization
Partial0 findings620ms replay3:31 PMPublish the automated report artifact or explain why the scan failed closed.
Artifact: Automated Solidity report · solidity-2f746d702f766567
- Final report is an automated static-analysis artifact; no operator review artifact is attached.
How to read this report
Score, confidence, ranking: four moving parts, no hand-tuning.
Generated Sep 23, 2026, 3:31 PM · Solidity · partial-coverage-probe.sol
Score bands
0-19
AVOID-style triage
Multiple high or critical findings, low source confidence, or unverified context. Public action should pause until a Private Review or a re-scan with better evidence.
20-49
High caution
Notable findings or thin evidence. Worth a Private Review before relying on the artifact.
50-69
Watch · this report
Mixed signals: some evidence, some gaps. Re-scan after material changes to the target.
70-89
Clear surface (automated)
No critical or high findings via static analysis. Not a safety claim: human review is still recommended for diligence work.
90-100
Strong surface (automated)
No critical or high findings, verified source, and high source confidence. Not a safety claim: human review is still recommended for diligence work.
- Score
- Deterministic 0-100 derived from severity counts. Same formula across every report. Lower means more risk.
- Confidence
- Separate axis. Measures how much VegaSec trusts the input data. Low confidence pushes the verdict toward UNKNOWN; the two are never collapsed into one number.
- Ranking / percentile
- Only meaningful within the eligible Trust Index set. Shown on /trust-index when the eligible pool is large enough. Today the public index is a controlled preview.
Private Review is separate
A paid Private Review does not raise the public score on this report. Public score reflects public-source evidence only. Private Review adds operator attestation and a confidential memo, never a score bump.