RaRust Audit AIGet started

Rust smart contract audit · Solana · Anchor · ink!

Run audit models locally, Ollama-style

Rust Audit AI packages the newest Hugging Face weights for Rust on-chain program review— CPI boundaries, account validation, reentrancy-style logic, and economic invariants — with one-line pulls and a local OpenAI-compatible API.

Quick start

curl -fsSL https://rustaudit.dev/install.sh | sh
rust-audit serve

Model library

Curated weights for Rust smart contract auditing. Each card links to its canonical Hugging Face repository; pulls are mapped to GGUF / safetensors bundles compatible with the Rust Audit runtime.

solana-analyser:8b

Featured
Hugging Face ↗

Llama 3 8B fine-tune focused on Solana on-chain program review, finding classes, and audit-style reporting.

solanaanchorauditrust
Params
8B
Quant
Q4_K_M
Context
128K
Updated
2025-03
rust-audit pull solana-analyser:8b

bifrost-sol:4b

Featured
Hugging Face ↗

Qwen3 4B Solana Vanguard SFT — Rust/Anchor security patterns, CPI/PDAs, and client integration context.

solanasecurityrustgguf
Params
4B
Quant
Q4_K_M
Context
32K
Updated
2025-06
rust-audit pull bifrost-sol:4b

Llama 3.1 ecosystem model trained on verified Rust program repos — generation plus audit-oriented reasoning.

solanaauditrustdapp
Params
8B
Quant
Q5_K_M
Context
128K
Updated
2025-01
rust-audit pull sollama:8b

deepsolana-r1:7b

Hugging Face ↗

Hybrid Solana + security scan workflow model — risk scoring and vulnerability hints for deployed programs.

solanascanrustzk
Params
7B
Quant
Q4_0
Context
64K
Updated
2024-10
rust-audit pull deepsolana-r1:7b

qwen3-coder-audit:7b

Hugging Face ↗

General code model tuned for static-review style prompts on Rust `#![no_std]` and WASM contract crates.

rustnearinkreview
Params
7B
Quant
Q4_K_M
Context
256K
Updated
2025-09
rust-audit pull qwen3-coder-audit:7b

deepseek-r1-audit:8b

Hugging Face ↗

Reasoning distill for long-form audit memos — logic bugs, access control, and economic invariant checks.

reasoningauditrustdefi
Params
8B
Quant
Q4_K_M
Context
128K
Updated
2025-05
rust-audit pull deepseek-r1-audit:8b

mistral-nemo-audit:12b

Hugging Face ↗

12B instruct model for multi-file Rust workspace review — lib.rs, state accounts, and test harness gaps.

rustmulti-fileaudit
Params
12B
Quant
Q4_K_M
Context
128K
Updated
2025-04
rust-audit pull mistral-nemo-audit:12b

llama31-security:8b

Hugging Face ↗

Llama 3.1 8B for structured SARIF-style findings on Anchor programs and native Solana entrypoints.

solanasarifanchor
Params
8B
Quant
Q4_K_M
Context
128K
Updated
2025-02
rust-audit pull llama31-security:8b

Pull · Run · Audit

Same mental model as Ollama: pull a tag, run interactively, or point your CI scanner at localhost:11435. Models stream tokens with audit-oriented system prompts baked into Modelfiles.

  • →Solana / Anchor entrypoint and account constraint review
  • →NEAR ink! and CosmWasm Rust contract static reasoning
  • →Structured findings export (Markdown, SARIF-friendly JSON)

# Pull the featured Solana auditor

rust-audit pull solana-analyser:8b

# Interactive REPL with program source

rust-audit run solana-analyser:8b

# One-shot audit from stdin

rust-audit run solana-analyser:8b --prompt "Review this Anchor program for missing signer checks"

Local API

Drop-in compatible with OpenAI SDKs. Swap the base URL and model name — ideal for custom audit pipelines and pre-deploy gates in GitHub Actions.

POST http://localhost:11435/v1/chat/completions
Content-Type: application/json

{
  "model": "solana-analyser:8b",
  "messages": [
    {
      "role": "system",
      "content": "You are a Rust smart contract auditor. Focus on on-chain Rust (Solana/Anchor). Report severity, location, and remediation."
    },
    {
      "role": "user",
      "content": "Audit the following lib.rs for missing owner checks:\n\n..."
    }
  ],
  "stream": true
}

About

Rust Audit AI is a model registry and runtime presentation layer for teams who audit Rust-written smart contracts — not general Rust application code. We prioritize Solana programs (native + Anchor), with growing support for NEAR ink! and other WASM contract targets.

Weights are hosted on Hugging Face; this site documents tags, pull commands, and recommended prompts. Always treat model output as assistive: combine with formal review, fuzzing, and static analyzers before mainnet deployment.

Stack

  • Runtime: Rust Audit daemon (Ollama-compatible CLI)
  • Weights: Hugging Face GGUF / safetensors
  • Focus: on-chain Rust security & audit workflows
  • Site: Next.js · black theme · single-page docs