Static-analyzer high-severity count
Sanctum's assessment for RD-F-010 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Slither/Mythril/Semgrep are EVM tools and do not run on Solana BPF bytecode. No published cargo-audit or Clippy report is publicly available. Audit summaries claim full remediation for V1 but no tooling output is verifiable for the current V2 state or Router program.
Sources #
- GitHubNon-EVM tooling gap — Solana substrateSolana BPF programs require cargo-audit/Clippy/Soteria; no published static analysis output foundretrieved 2026-05-04
Methodology #
Count the number of unique high-severity detector findings from Slither + Mythril + Semgrep run against the deployed verified source (after deduplication across tools).
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol sanctum factor RD-F-010 score gray collected_at 2026-05-04 18:49:23