ResearchZero - verified Web3 intelligence, delivered via MCP, for AI security agents auditing Solidity, Vyper, Cairo, and Daml smart contracts, with more domains shipping continuously
A growing corpus of empirically verified Web3 findings — compiler and language-semantics divergences across Solidity, Vyper, Cairo, and Daml today, with new domains shipping continuously — surfaced through proprietary research and verified against real, working systems before they ever reach your agent. No public API. No scraped disclosures. MCP only.
Add R0 Knowledge
Find More Vulnerabilities
Every AI security agent walks into your repo with whatever it half-remembers from training — and half-remembered misses real bugs. Keep scrolling: feed it ResearchZero mid-analysis, and it starts catching what generic pattern-matching alone would miss.
Keep scrolling…
Now finding what it would've missed
Web3 Knowledge Built for Agents
Not a vulnerability scanner, not an autonomous auditor, not a chatbot. ResearchZero is an MCP server: it analyzes your project's exact configuration and architecture, then hands your AI security agent only the verified Web3 intelligence that applies — compiler and language-semantics divergences today, with new domains shipping continuously — so it grounds findings in verified fact, not what a model happens to remember.
Two tools. No general browse or search. Nothing your agent doesn't need.
analyze_repository extracts your project's exact compiler version, optimizer/viaIR flags, dependencies, and detected architecture — no compilation, no execution, source-based static analysis only. get_relevant_intelligence then ranks the corpus against that config on two independent axes and returns only what's relevant. There's deliberately no tool to browse or search the corpus by id: that's the core IP, and "only what's relevant to your project" is a security boundary, not just a UX default.
require(cond, msg()) evaluates its message argument eagerly — solc 0.8.26 with viaIR evaluates it lazily. Verified against solc source, trigger included.
Every entry ships with a trigger, a citation, and a verification date
A large and growing corpus spanning Solidity, Vyper, Cairo, and Daml today — each entry with a reproducing trigger, a source-level citation, and the date it was last re-verified against a real build. Not summaries. Not guesses. New domains add to this corpus on a rolling basis.
See coverageNot scraped. Surfaced through methods we keep to ourselves
How we find what we find is proprietary — internal techniques we don't publish. What we do publish is the verification: every candidate is checked empirically against a real, working system before it's admitted to the corpus. A meaningful share of what surfaces this way isn't discussed or published anywhere else.
How it worksBugs that were fixed once and quietly came back
Entries carry introduced, fixed, and regressed_from metadata sourced from each compiler's own bug history, then re-verified against current builds — so your agent knows not just what's broken today, but what's broken again.
Every Discovery Becomes
Verified Intelligence
Scraping public bug trackers gets you what every other feed already has. Our discovery pipeline — internal methods we keep proprietary — surfaces candidates most teams never find, then verifies every single one empirically — a real build, a real trigger, a real citation into the source — before it ever becomes a retrievable entry.
Web3 intelligence, live today — expanding continuously
ResearchZero is built as a Web3 intelligence platform, not a single-language tool — new domains ship at the same MCP endpoint you're already using, with no integration changes required. Today's coverage: compiler and language-semantics intelligence for Solidity and Vyper across Ethereum and EVM-compatible DeFi chains, Cairo on Starknet, and Daml on Canton.
More Web3 domains are already in development — coverage expands continuously, at the same MCP endpoint.
Built for the agent doing the audit, not a human reading a report
Point Claude Code or any MCP-capable security agent at a Solidity, Vyper, Cairo, or Daml project — today's supported tech, with more shipping continuously — and it calls analyze_repository to extract the project's real configuration and architecture, then get_relevant_intelligence to pull back only the entries that actually apply, grounding its findings in verified fact instead of whatever the base model half-remembers.
Results come back as structured data, not prose — language, category, severity, affected compiler versions, trigger condition, and a citation into the compiler's own source. That's a schema an agent can act on directly, not a write-up it has to re-interpret.
Because retrieval is scoped to your own analyzed project by design, there's no general browse or search tool exposed — the curated corpus itself is the product, and that boundary is intentional, not a missing feature.
- Grounded FindingsCite a verified compiler divergence, with source-level evidence, instead of asserting a behavior from memory.
- Scoped, Not ScrapedRetrieval matches your project's exact compiler version, optimizer/viaIR flags, and detected architecture — not a generic top-N search.
- Optional AI Precision PassAn LLM re-checks top matches against your actual source before returning them.
Questions about the MCP server
Answers for auditors, audit firms, and AI agent developers evaluating ResearchZero.
What does ResearchZero actually do?
It's an MCP server your AI security agent calls while auditing a Web3 project. analyze_repository extracts the exact configuration and architecture; get_relevant_intelligence returns only the curated entries that apply — empirically verified findings, not a generic vulnerability feed.
Is this a vulnerability scanner or an autonomous auditor?
No. ResearchZero doesn't scan code or produce findings on its own — it's the knowledge layer an agent (or a human auditor's tooling) queries to ground its own analysis, not a replacement for the audit itself.
Where does the intelligence come from?
Through proprietary research and discovery techniques we don't publish. What we do publish is the verification: every candidate is checked empirically — a real build, a real trigger, a source-level citation — before it's admitted to the corpus. A meaningful share of what surfaces this way isn't documented or discussed publicly anywhere.
Is this only about compilers?
No — compiler and language-semantics intelligence is where we started, not where we stop. ResearchZero is built as a Web3 intelligence platform: new knowledge domains ship on a rolling basis at the same MCP endpoint, with no integration changes required.
Which languages and chains are covered?
Today: Solidity and Vyper for Ethereum and EVM-compatible DeFi chains, Cairo for Starknet, and Daml for Canton. Coverage expands continuously; see supported tech for the current breakdown.
Is there a public API?
No. Analysis and retrieval are MCP-only by design — there's no general browse or search tool, since that would let a caller walk the whole corpus. The dashboard and its HTTP API only handle account, API keys, and billing.
Give your agent
ground truth
Create an account, generate an API key, and point your MCP client at the server.
// Questions first? Email ResearchZero — response within 24 hours.