$npx skillfedfor your agent

slither-analyzer

Slither is a Solidity and Vyper static analysis framework written in Python 3.

With conditionsPyPI Quality AssuranceReleased Jul 2026184.5K downloads / moAGPL-3.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — slither_analyzer-0.11.6-py3-none-any.whl
v0.11.6 · released 2026-07-28 · Python >=3.10 · 8 runtime deps: crytic-compile, eth-abi, eth-typing, eth-utils, packaging, prettytable, pycryptodome, web3

Yes, with conditions. Slither is actively maintained, has low install friction, and is widely used in the Ethereum ecosystem for contract security analysis. However, the AGPL-3.0 license requires that any modifications or derivative works be released under the same license—ensure this aligns with your project's licensing model before integrating it into proprietary software. For open-source projects or internal security tooling, it is a solid choice.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10+.
  • If not using a supported compilation framework (Hardhat, Foundry, Dapp, Brownie), you must have solc (Solidity compiler) installed; solc-select is recommended for version management.
  • Low friction: pure Python wheel with 8 runtime dependencies including crytic-compile, web3, and eth-utils.

License · maintenance · safety

AGPL-3.0 (agpl) — Licensed under AGPL-3.0, which requires that any modifications or derivative works distributed must also be released under AGPL-3.0. This is a copyleft license; using it in proprietary software requires careful consideration of how the code is deployed.

last release 2026-07-28 (17 days) · last repo commit 2026-08-12 · 6,343 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 184,500 downloads/mo, #10,035 on PyPI

Verify before relying

pip install slither-analyzer
slither .
# or on a single file:
slither tests/uninitialized.sol
  • Whether the false-positive rate and detector accuracy claims in the description are independently validated
  • Current coverage of Vyper detector rules relative to Solidity detectors
  • Performance characteristics on large or complex contract suites beyond the stated 'less than 1 second per contract'
Same gist for agents: .md · .json

What it is and what it does

Slither is a Python-based static analysis framework designed to scan Solidity and Vyper smart contracts for security vulnerabilities and code quality issues. It runs a suite of built-in detectors that identify common patterns like uninitialized state variables, arbitrary fund transfers, and storage array misuse, then reports findings with source code locations. The framework also includes 'printers' that generate visual summaries of contract structure and behavior, and exposes an API for developers to write custom analyses in Python.

The tool integrates into development workflows through CI/CD systems, pre-commit hooks, and build frameworks like Hardhat and Foundry. It depends on crytic-compile to handle contract compilation, web3 and eth-utils for blockchain interaction, and pycryptodome for cryptographic operations. Installation is straightforward via pip, though you need Python 3.10+ and a Solidity compiler (solc) if analyzing standalone files outside a supported build framework.

Use it for

  • Scan a Solidity codebase during development to catch high-impact vulnerabilities before deployment
  • Integrate Slither into a GitHub Actions workflow to flag security issues on every pull request
  • Analyze a Vyper contract for state variable shadowing, uninitialized storage, and other common mistakes
  • Write a custom detector in Python to enforce project-specific contract coding rules or patterns
  • Generate a markdown checklist report of contract findings for security review or audit documentation

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Slither is actively maintained, has low install friction, and is widely used in the Ethereum ecosystem for contract security analysis. However, the AGPL-3.0 license requires that any modifications or derivative works be released under the same license—ensure this aligns with your project's licensing model before integrating it into proprietary software. For open-source projects or internal security tooling, it is a solid choice.

Install

slither-analyzer on PyPI

Before you install

Low friction: pure Python wheel with 8 runtime dependencies including crytic-compile, web3, and eth-utils. Actively maintained with a release 17 days ago and 6343 repository stars. Requires Python 3.10+.

Requires Python 3.10+. If not using a supported compilation framework (Hardhat, Foundry, Dapp, Brownie), you must have solc (Solidity compiler) installed; solc-select is recommended for version management.

License in practice

Licensed under AGPL-3.0, which requires that any modifications or derivative works distributed must also be released under AGPL-3.0. This is a copyleft license; using it in proprietary software requires careful consideration of how the code is deployed.

Quickstart

pip install slither-analyzer
slither .
# or on a single file:
slither tests/uninitialized.sol

Verify before relying

  • Whether the false-positive rate and detector accuracy claims in the description are independently validated
  • Current coverage of Vyper detector rules relative to Solidity detectors
  • Performance characteristics on large or complex contract suites beyond the stated 'less than 1 second per contract'

Package facts

LicenseAGPL-3.0 agpl
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
crytic-compileeth-abieth-typingeth-utilspackagingprettytablepycryptodomeweb3
MaintenanceActively maintained 17 days since the last release
Last repo commit
First released
Downloads184,500 / month, #10,035 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Affero General Public License v3Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: slither_analyzer-0.11.6-py3-none-any.whl

Tags

Capabilities
solidity static analysissmart contract vulnerability detectionvyper code analyzerethereum security scannersolidity lintercontract code review toolblockchain security analysis
Topics
smart-contractssecurity-analysissolidity
PyPI keywords
ethereumsecuritysmart-contractssoliditystatic-analysisvyper

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “solidity static analysis”

  • slither-analyzerSlither is a static analysis framework for Solidity and Vyper smart…
  • mythrilMythril analyzes EVM bytecode for security vulnerabilities in smart…
  • crytic-compileCrytic-compile abstracts smart contract compilation across multiple…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also mythril · eth-brownie · crytic-compile · flawfinder · vyper · ethereum-dasm · checkov · clvm · scan-build · solc-select