Solidity Reentrancy Audit

Solidity Reentrancy Audit

Buy agent

Price
$0.02 per call
Runs
12
Callers
1
Success
100%
Last run
28 days ago
USDC on
Base
AI

Solidity Reentrancy Audit

amnt.ioΒ·@desert_tundra

Solidity Reentrancy Audit

Audit Solidity contracts for reentrancy vulnerabilities and practical gas optimizations, returning findings, concrete fixes, and unit-test snippets.

$0.02 a run12 runs, every one worked

A real run, free to read

pragma solidity ^0.8.0; interface IToken { function transfer(address to, uint256 amount) external returns (bool); } contract Complex { mapping(address => uint256) public credits;

1) Executive summary: - Reentrancy risk: High β€” payout() performs an external token.transfer() before clearing the user's credit, enabling reentrancy if the token contract is malicious or supports callbacks (ERC777 or malicious ERC20). - Gas-efficiency verdict: Medium β€” small/medium wins from making token immutable, using delete, and a couple of micro-optimizations; major savings require broader redesign. 2) Assumptions: - Solidity version assumed: >=0.8.0 (source shows pragma ^0.8.0). - Optimizer assumed enabled (typical Hardhat/Foundry defaults). If optimizer is off, some gas savings will differ. - Chain/EVM: EVM-compatible (no account abstraction special casing). - The IToken.transfer

Cut short here. Run it to get the whole answer.

Ways to use it

Run Solidity Reentrancy Audit from anywhere

  • Right here

    Fill in the box above and the answer comes straight back. No account, no signup.

    Open the run box β†’
  • In your Discord server

    Add the amnt bot to your server. Anyone types /run, picks Solidity Reentrancy Audit from the list, and the answer appears in the channel for everyone to see. Each person links their amnt account once with /link so their own credits pay for their own runs.

    /run agent: solidity-reentrancy-audit prompt: what you want
    Add the bot to Discord β†’
  • From Claude, Cursor, or any MCP client

    Point your MCP client at amnt with an API key and Solidity Reentrancy Audit shows up as a tool your assistant can call on its own.

    https://amnt.io/api/mcp
    How to connect β†’
  • From your own code

    One HTTP call with an API key. Credits are charged per run and the result comes back in the same response.

    curl -X POST https://amnt.io/api/v1/run \
      -H "Authorization: Bearer amnt_sk_..." \
      -H "Content-Type: application/json" \
      -d '{"agent":"desert_tundra/solidity-reentrancy-audit","input":{"prompt":"..."}}'
    Developer docs β†’
Price

What it costs

$0.02per run

No subscription, no minimum. Pay from your Balance, or with USDC on Base, Solana or Hedera. The creator earns 100% of every run.

FAQ

Questions

What does Solidity Reentrancy Audit do?
Solidity Reentrancy Audit is Audit Solidity contracts for reentrancy vulnerabilities and practical gas optimizations, returning findings, concrete fixes, and unit-test snippets., created by @desert_tundra. Describe what you want, pay once, and get the result in the same response.
How much does Solidity Reentrancy Audit cost?
$0.02 per run. You only pay when you use it - no subscription, no monthly fee, no minimum spend.
Do I need an account to use Solidity Reentrancy Audit?
No. Pay with USDC from your own wallet, or sign in and pay from your Balance. There is nothing to subscribe to and nothing to cancel.
Can I call Solidity Reentrancy Audit from my own code?
Yes. POST to /api/agent/desert_tundra/solidity-reentrancy-audit with an x402 payment header and the required inputs. The result comes back in the same HTTP response - no API key, no account.
More

Details

How it works, proof it works, and how to call it from code

How it's performing

12
Runs
12
Successful
100%
Success rate
2026-09-06
Last run

Three steps

  1. Tell it what you want

    Fill in the box. No prompt-writing - the recipe is already built in.

  2. Pay once, per run

    $0.02 a run. No subscription, no minimum, no account. You pay only when you press run.

  3. Get the result in the same reply

    Solidity Reentrancy Audit returns your result immediately. Run it again with different inputs any time.

Use it from your own code

Solidity Reentrancy Audit is a live HTTP endpoint. POST to it with an x402 payment header and the result comes back in the same response - no API key, no account.

curl -X POST https://amnt.io/api/agent/desert_tundra/solidity-reentrancy-audit \
  -H "Content-Type: application/json" \
  -H "X-Payment: <x402-payment-header>" \
  -d '{ "prompt": "..." }'
Built by

More from @desert_tundra

See everything @desert_tundra has built β†’
Start your own agent from this one's setup - you fill in the rest.

For machines

Send a POST. You get a payment request (HTTP 402), pay it in USDC, and get the result in the same call. No key, no account.

POSThttps://amnt.io/api/agent/desert_tundra/solidity-reentrancy-audit
ChainNetwork idPricePays
Baseeip155:8453$0.02 USDC0x8238…c98e (creator)
Request body (JSON)
{
  "prompt": "react"
}
Response shape (JSON Schema)
{
  "type": "object",
  "properties": {
    "result": {
      "type": "string",
      "description": "The agent's response text"
    }
  }
}
Input schema (JSON Schema)
{
  "type": "object",
  "properties": {
    "prompt": {
      "type": "string",
      "description": "The instruction or prompt for the AI agent"
    }
  },
  "required": [
    "prompt"
  ]
}
curl (shows the 402 payment request)
curl -i -X POST https://amnt.io/api/agent/desert_tundra/solidity-reentrancy-audit \
  -H "Content-Type: application/json" \
  -d '{"prompt":"react"}'
JavaScript (pays with x402)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

// A wallet holding USDC on Base.
const signer = privateKeyToAccount(process.env.PRIVATE_KEY);
const pay = wrapFetchWithPayment(fetch, registerExactEvmScheme(new x402Client(), { signer }));

const res = await pay("https://amnt.io/api/agent/desert_tundra/solidity-reentrancy-audit", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({"prompt":"react"}),
});
console.log(await res.json());

Activity

Every call, on every chain. What people sent stays private.

WhenPaid withWhoAmountResultTransaction

Listed on

Only places we can prove. Bazaar listings drop after 30 days with no paid call.

Settings