FULL-REPOSITORY SOLANA AUDITS

Other scanners hand you a list. SPECTRE gives you a path to closure.

SPECTRE combines programmatic analysis with grounded model adjudication to trace findings across supported files and programs. A full audit turns that evidence into remediation guidance, a patch and regression proof where suitable, and a complete audit pack.

Find the issue · Trace the path · Prove the fix

Product preview of a SPECTRE finding with connected source context, regression evidence, a verified patch state, and the full audit pack.

From scan to solution

Finding the issue is only the first gate.

Programmatic analysis creates repeatable coverage. Repository context and grounded adjudication explain what matters. Full-audit delivery gives engineering the evidence and the next move.

  1. STEP 01

    Audit the repository

    Solana-aware programmatic analysis scans supported source, accounts, instructions, authorities, dependencies, and cryptographic use. Coverage begins with code analysis—not a prompt.

  2. STEP 02

    Trace the relevant path

    SPECTRE follows evidence across files and program boundaries so a finding arrives with the surrounding code that gives it meaning.

  3. STEP 03

    Adjudicate in context

    A grounded model evaluates the cited source and relevant relationships, recording a verdict, rationale, confidence, and provenance. Uncertain candidates stay visible.

  4. STEP 04

    Remediate and prove

    A full audit provides concrete remediation guidance and can include a patch plus regression proof that fails before the fix and passes after it.

The model adjudicates. The evidence remains inspectable.

Separating candidate discovery from judgment makes the scan repeatable while preserving the contextual reasoning needed for protocol risk. Uncertain results fail open for review.

Coverage
Programmatic
Context
Cross-file
Delivery
Actionable

One full audit

The finding, the fix path, and the complete record.

A SPECTRE full audit gives engineering enough context to act and a portable audit pack that security, governance, and procurement can carry forward.

Finding delivery

A path to closure, not another triage queue.

Finding context

The rule, exact source location, rationale, and relevant paths stay attached to the finding instead of collapsing into an alert ID.

Path to remediation

Every delivered finding explains the next engineering action. Suitable full-audit findings can also include a ready-to-apply patch.

Regression proof

Where executable verification is appropriate, the reproducer fails before the fix and passes after the remediation.

Complete audit pack

One analysis. Five durable artifacts.

  • Human-readable audit report
  • Structured findings JSON
  • CycloneDX software bill of materials
  • CycloneDX cryptography bill of materials
  • NIST IR 8547 transition record

Detected, adjudicated, reproduced, and patched are separate evidence states. SPECTRE only presents the stronger state when the supporting evidence exists. Patch and test artifacts accompany suitable findings; the audit pack remains the stable record of the analysis.

Why SPECTRE

Most tools stop at the finding.

Conventional SAST provides repeatable detection. LLM-first review provides flexible reasoning. SPECTRE connects programmatic analysis to grounded adjudication and a full-audit workflow built around engineering action.

Swipe horizontally to compare approaches →

Comparison of conventional SAST, LLM-first review, and SPECTRE.
Approach
Conventional SAST

Broad, repeatable coverage of known patterns

LLM-first review

Exploratory review and novel hypotheses

SPECTRE

Repository audit with a path to closure

Candidate discoveryRules, queries, control flow, and data flowModel reasoning over supplied or gathered contextProgrammatic Solana and cryptography analysis
Repository contextAdvanced products can reason across files and functionsCan gather broad repository context, but remains probabilisticRelevant relationships across supported files and programs
Model roleUsually absent or used for enrichmentPrimary detector and reviewerGrounded adjudication after candidate discovery
Typical outputAlerts, traces, and remediation guidanceReview comments, explanations, and suggested changesFinding, evidence state, remediation path, and full audit pack
Fix proofBefore/after regression proof is not a standard deliverableSuggested changes still require independent verificationPatch and before/after regression proof where suitable

Category capabilities vary by vendor and deployment. SPECTRE is designed to complement—not replace—manual review for novel protocol behavior, runtime conditions, and economic invariants.

Full-repository scope

See the program as a system.

SPECTRE looks beyond isolated findings to the supported source, state, authorities, dependencies, cryptography, and program relationships that determine real impact.

Solana program semantics

Review supported account constraints, signers, PDA derivation, CPI safety, state invariants, and instruction behavior with Solana-specific meaning.

Cross-file and program paths

Follow relevant definitions, handlers, authorities, calls, and program boundaries instead of judging an isolated call site alone.

Dependencies and supply chain

Resolve software inventory and dependency relationships alongside the source paths and program assumptions that rely on them.

Cryptographic posture

Inventory primitives, libraries, key-material use, and authorities, with CBOM output and migration-impact context attached to the audit.

Cryptography is one first-class audit surface, not a separate product. SPECTRE can emit a CycloneDX CBOM and standards-linked migration-impact context, but protocol-layer replacement choices remain with the relevant standards, runtimes, and engineering teams.

Supported source

Rust and TypeScript are the primary Solana surfaces.

A Solana repository is rarely one language. SPECTRE extracts the on-chain program and its off-chain clients as one graph, then extends that same analysis to whatever else lives in the repository.

Rust — Anchor & native Solana

Tree-sitter extraction over programs, instruction handlers, Accounts structs, constraints, and PDA derivation, checked against the Solana rule pack for governance, authority, and CPI safety.

TypeScript & JavaScript — off-chain clients

Client call sites, SDKs, and test suites are extracted and bound back to the on-chain instructions they invoke, so a finding carries both sides of the program boundary.

Also detected in mixed-language repositories

Python
Go
Java
Kotlin
Swift
PHP
Solidity
C
C++
C#
Ruby
SQL
COBOL
HTML
CSS

Language detection is automatic. When a repository mixes languages, SPECTRE processes each of them and merges the results into a single unified graph rather than scanning files in isolation.

Your repository, with a way forward

Bring us the code. Leave with the next move.

SPECTRE for Solana is rolling out to select teams. Request a full-repository audit or early access to the unified dashboard.

Selective rollout for Solana teamsNo spam, ever.