Tool 10 · Reference · Free

Sample Audit Report

A complete report rendered in the browser — threat model, findings with impact and likelihood, vulnerable-versus-fixed diffs, runnable Foundry proofs of concept and verification status. This is exactly what a real engagement delivers.

At a glance

Findings8 across 5 severities
IncludesThreat model, PoCs, diffs, verification
FormatWhat we actually ship
CostFree
StatusIllustrative example

Sample Audit Report

Run it

Illustrative example — not a client engagement

“Aurora Vault” is a constructed ERC-4626 vault written to demonstrate the finding classes and the report format we deliver. The structure below — threat model, findings with impact and likelihood, proof of concept, remediation, verification status — is exactly what a real engagement produces.

How it works

What this tool does, and what it can't.

Every report opens with the threat model, not the findings. Who are the actors, what privileges do they hold, which contracts are trusted, what external dependencies exist, and what assets are at risk. Almost every serious finding is a gap between that document and the code.

Each finding carries a location, the mechanism, the impact, the likelihood, a runnable proof of concept for anything Critical or High, and a specific remediation — not “consider adding validation” but the actual change, in your code. The vulnerable and fixed versions sit side by side so a reviewer can see the delta.

The section most reports omit is verification. After the client fixes, we re-review every changed line, re-run each PoC and the invariant suite, and mark every finding Fixed, Acknowledged or Open — including the ones the team decided to accept, with their reasoning. That final report is the publishable one.

FAQ

Questions about this tool.

More in the methodology and the glossary.

No, and it is labelled as such throughout. “Aurora Vault” is a constructed teaching example. The finding classes are real and the format is exactly what we deliver, but no client engagement is represented here.

An executive summary, the threat model and trust assumptions, every finding with severity, impact, likelihood and location, a proof of concept for each Critical and High, specific remediation guidance, and the verification status of every finding after fixes. Delivered as PDF and Markdown, plus the findings register as JSON.

Because it keeps severity honest and it removes the need to trust us. A runnable Foundry test against a fork, with the attacker's profit measured in the assertion, is something your engineers can verify themselves — and re-run after the fix.

Yes. The format is not proprietary and the industry benefits from reports being comparable. If you are a team writing up an internal review, this is a reasonable template.

Yes, whenever the client permits it — they appear on the reports page. SENTRYX is a new brand, so that page is honest about how few there are rather than padded with logos we cannot link to a report.

Beyond automation

No tool reads your specification. We do.

The findings that drain protocols come from state assumptions, economic design and cross-contract interaction — none of which a scanner sees. Free scoping in under two working days.