← SkillSafe / Wei Desk

Find the bugs that are off by 1012 and never throw

Paste the off-chain code that moves token amounts or hashes Ethereum data - a bot, a backend, a dashboard, an indexer. Your browser checks it for the silent decimal and hashing bugs for free, and nothing is uploaded. A paid run then audits it line by line or patches it.

Each example has a saved model run, so you can see the whole page for free.

Read in your browser. Only a paid run sends the code to the model. Leave out keys and secrets.

Drop a .ts, .js, .py, .sol or .txt file, or a set .json saved from this page, or
Paste your code to price the run.

Free tools (exact, in your browser)

Units

Type an amount.

Selector and topic

Type a signature.

Your recent audits

What this does, and what it does not

The prescan reads only the text you paste, with pattern checks drawn from the two source skills: query decimals() at runtime, cache by chain and token address rather than symbol, use exact math rather than floats, keep fallbacks visible, and never hash Ethereum data with NIST SHA3-256 - Keccak-256 pads with 0x01 where SHA3-256 pads with 0x06, so the two digests never match. Pattern checks can miss or over-read; the paid run answers each flag and may dismiss one with a reason. Selectors and topics are computed here, in your browser, and the model is told never to compute one.

The decimals shown for USDC, USDT, WBTC and DAI were read on-chain with decimals() on 2026-09-26 (USDC and USDT are 6 on Ethereum, Arbitrum and Polygon, and 18 as Binance-Peg USDC and BSC-USD on BNB Chain). Tokens change; your code should still ask the chain. Nothing here calls a chain or runs your code. Derived from the agent skills @affaan-m/evm-token-decimals and @affaan-m/nodejs-keccak256 (affaan-m/everything-claude-code, MIT). The example modules are fictional.