Platform
Smart contract review
Understand your Solidity source before a deeper security audit.
Start a source review
Open Tools, then Smart Contract Review. Paste a Solidity contract or choose a .sol file up to 100 KB. Flattened source can include several contract declarations. No account or token purchase is required.
Read the evidence
Expand a function to see declared visibility, modifier definitions, checks, possible local call paths and direct state writes. Internal functions are shown through resolved local calls. Inherited behavior, overloads, external calls and storage aliases need separate review.
Treat leads as questions
The starter checks highlight transaction-origin usage, delegated execution and self-destruct instructions. These are possible false positives, not confirmed vulnerabilities. A useful finding needs a reachable external call, caller permissions, achievable state and demonstrated harm to a victim.
Your AI review allowance
Each signed-in account can complete up to 3 AI reviews per UTC day, 7 per UTC week and 14 per UTC calendar month. All three limits apply. Weekly allowances reset Monday at 00:00 UTC. Grail shows remaining reviews and reset times in your local timezone. Failed reviews return their reserved allowance; basic source maps, viewing reports and downloads are unlimited.
Privacy and exports
Basic source maps run in your browser without uploading source. AI review requires explicit consent to send source to ZeroScout and its configured 0G provider. Grail keeps a private report recovery copy for 24 hours and allowance metadata for up to 35 days. Reports contain source snippets and a SHA-256 fingerprint; share them only with people who should see your code.
Methodology
The workflow adapts the entry-point mapping and finding-validation approach from Pashov?s open-source skills. This is a Grail starter tool, not an audit by Pashov or an endorsement. A full audit requires complete dependencies, deployment context and reproducible tests.