pactlint: scan a deployed contract by address
scan_contract_addresspactlint: static security scan of a deployed contract on Ethereum or Base, by address. Input: address (0x + 40 hex) and chain (ethereum | base); optional include_* flags. Fetches the verified source from Sourcify, then runs the same analysis as scan_contract_source: solc + Slither + custom detectors for recurring DeFi bug classes (unchecked ERC-20 returns, zero slippage limits, stale or spot-price oracles, ERC-4626 share inflation, signature replay and more), triaged and de-duplicated. Returns the JSON report plus a Markdown rendering. Contracts without verified source are refused (not_verified) and not charged; for those, use check_contract_before_interaction (txpeek). Price: USD 0.25 up to 3,000 normalised source lines (nSLOC), USD 0.75 up to 15,000; larger inputs are refused. Refused inputs are never charged. Free: 3 scans or 30 txpeek checks per IP per UTC day (one shared pool). Typically 3-30 s depending on the contract's size; at most 60 s per scan (past it: status timeout), one scan at a time; a request waits at most 25 s in a queue of 3 (less when paid, so every answer arrives within about 90 s), otherwise 503 with Retry-After, not charged. Automated and heuristic, not an audit: findings can be false positives and an empty report does not prove the code is free of bugs.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| chain | Yes | Chain the contract is deployed on. | |
| address | Yes | Contract address (0x + 40 hex). | |
| include_noisy | No | ||
| include_dependencies | No | ||
| include_informational | No |