Inspiration

Every developer who has run a security linter knows the feeling: fifty warnings, forty-nine of them noise, so you stop reading and ship the one real bug anyway. Reentrancy and access-control bugs have drained billions from smart contracts, and most of them were "flagged" by some tool nobody was listening to. An agent that helps with this repetitive, judgment-heavy task can't be one more thing that pings. It has to be quiet until it is right.

What it does

Aegis watches your Solidity as you work. When you save a contract, it reviews the change in the background and surfaces a finding only when the bug is genuinely present and exploitable. On safe or already-patched code, it stays silent.

  • aegis review <path> gives a one-shot review of a file or folder.
  • aegis watch <path> runs as a background monitor that pings you only on a real, exploitable finding, right before you deploy.

Same vault contract, two versions: it flags the vulnerable one and clears the patched one. That gap, no false alarms, is the whole product.

How I built it

Built on the Strands Agents SDK, running on a local model via Ollama so unaudited contracts never leave the developer's machine. The pipeline is designed so the model is only ever asked questions it can answer reliably:

  1. A fast static scanner produces high-recall candidate findings with line numbers (deliberately noisy).
  2. For reentrancy, whether it is real is a structural fact (is a state update made after the external call?), so Aegis computes it deterministically instead of asking the model.
  3. For the other classes, each candidate is verified with a category-specific, step-by-step guide and returned as a Strands structured-output verdict, with a reasoning field placed first in the schema so the model reasons before it commits.

Challenges I ran into

Small local models are unreliable at security judgment: they flip-flop on the same contract, misread line ordering, and flag safe code. The entire build was about not trusting the model blindly. Two turning points: forcing a JSON verdict was silently killing the model's chain-of-thought (fixed by moving a reasoning field to the front of the schema), and reentrancy ordering should be computed in code, not asked of the model.

Accomplishments that I'm proud of

It clears every patched contract in its scope. A security tool that only makes claims it can stand behind is the entire point, and it holds up: flag the vulnerable, clear the fix, stay silent otherwise.

What I learned

Ground the model, do not trust it blind. Compute the structural facts in code. Make the model reason before it judges. And scope honestly: Aegis only claims the classes it can both catch and clear (reentrancy, access control, unchecked low-level calls), and openly lists what is out of scope.

What's next for Aegis

More vulnerability classes as they become reliable (unsafe randomness, cross-function reentrancy), an editor extension so the alerts appear inline, and an optional larger model (Amazon Bedrock) for deeper analysis on demand.

Built With

Share this project:

Updates

Submission history