SCAR: Mining and Structuring Smart Contract Security Audit Reports
Abstract
Smart contract security audit reports contain rich information about vulnerabilities and code quality issues in Web3 projects. However, these reports are scattered across different sources and formats, making large-scale analysis difficult. We present SCAR (Smart Contract Audit Repository), an open-source dataset and tool that automatically aggregates these audit reports. SCAR crawls reports from leading security firms (e.g., OpenZeppelin) and community contests (e.g., Code4rena), parses them into a structured JSON schema, and offers a queryable API for accessing the data. Its pipeline includes a crawler, a text-mining module to standardize findings (e.g., vulnerability types, severity, code references), and a web API for retrieving insights. With hundreds of audits covering thousands of issues, SCAR enables empirical studies of smart contract vulnerabilities at scale. The SCAR project repository is available on GitHub, and the screencast demo is available at this link.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.