Project Audit Report Summarizer
Free to download on every platform. Comes pre-installed on BotFone, BotPad and BotFlip — with extra free apps included.
About this app
WHAT IT DOES
Project Audit Report Summarizer analyzes a project's on-chain security signals and summarizes the security posture before you invest. The tool reads the project contract to detect audit-related patterns (audit firm names like CertiK, Halborn, Trail of Bits, OpenZeppelin, Quantstamp, etc.), owner/admin controls, mint capability, upgradeability status, trading restrictions, vesting mechanisms, and timelock mechanisms. It then calculates a security score (0-10), assigns a security grade (A-F), and determines a risk level. The tool then uses AI to generate a plain-language security summary: whether the contract appears to have been audited, what security features are present, what security risks remain, and whether the project appears to take security seriously. Results include a risk level, security grade, security score, audit indications, security features with pass/fail indicators, flags, and a comprehensive AI-generated summary. The tool operates entirely read-only — no transactions are sent, no signatures are required. The AI assessment is designed to help you identify projects with weak security or concerning patterns before you invest.
HOW TO USE
Connect your EVM wallet using the "Connect" button in the header. Select the network where the project contract is deployed from the dropdown menu. Enter the project contract address you wish to analyze. Optionally enter the project name if you know it. Click "Summarize audit signals" to begin the analysis. The tool reads the contract bytecode to detect audit patterns, owner controls, mint capability, upgradeability, trading restrictions, vesting, timelocks, and sends the data to the AI for a plain-English security summary. Results appear within seconds, showing the project contract, chain, risk level, security grade, security score, audit indications, security features with pass/fail indicators, flags, and a comprehensive AI-generated summary written in clear, conversational language.
SECURITY SIGNAL DETECTION AND SCORING
The tool uses a pattern-based approach to detect security signals from the contract bytecode. It scans for audit-related keywords — audit, certik, halborn, trailofbits, consensys, openzeppelin, peckshield, quantstamp, sigmaprime — to detect audit patterns. It detects owner/admin controls (owner, admin), mint capability (mint), upgradeability (delegatecall with implementation), trading restrictions (blacklist, whitelist, pause), vesting mechanisms (vesting, vest), and timelock mechanisms (timelock, delay). The security score (0-10) is calculated as: audit patterns (3 points), vesting (1 point), timelock (2 points), no owner controls (2 points), no mint capability (2 points), no upgradeability (1 point), no trading restrictions (1 point). The security grade is determined by the score: A (8+), B (6-7), C (4-5), D (2-3), F (0-1). The risk level is calculated based on: owner controls without timelock (1 point), mint capability (2 points), upgradeability (1 point), and no audit patterns (2 points). The AI receives all this data and is prompted to summarize the project's security posture — stating whether the contract appears to have been audited, what security features are present, what risks remain, and whether the project appears security-conscious. The AI is also instructed to state plainly what it cannot verify — that it checks on-chain patterns and known audit signatures, not off-chain audit reports, the quality of any audit, or the auditor's reputation.
WHAT IT CANNOT SEE
This tool cannot definitively verify if an audit actually exists — only checks on-chain patterns and known audit signatures. It cannot detect off-chain audit reports or verify their authenticity — a project may claim to be audited without having an on-chain record. The tool cannot determine if the audit covers all relevant contract code — an audit may only cover part of the system. Legitimate projects may have audit reports that are not reflected on-chain — some audits are not recorded on-chain. The tool cannot predict the quality or comprehensiveness of any audit — the presence of an audit pattern does not guarantee a good audit. The tool cannot detect if the audit was performed by a reputable firm. The tool cannot detect if the audit findings have been addressed. The tool cannot detect if the contract has changed since the audit. The tool cannot detect if the project has been exploited or hacked. The tool cannot verify that the security features work as intended.
PLEASE NOTE
Project Audit Report Summarizer supports EVM-compatible chains only (Ethereum, BSC, Polygon, Arbitrum, Optimism, Avalanche, and others). The tool is read-only and never requests wallet signatures or transaction approvals. Security summaries are AI-generated from on-chain data and estimated metrics — always verify audit reports through the project's official documentation and independent research before investing. The AI summary is for informational purposes only and does not constitute financial or legal advice. A project with strong security signals is not guaranteed to be safe — always conduct thorough due diligence before investing.