# AuditAI — Claude Startups Application Pack (Draft)

## 1) One-liner
AuditAI is an AI smart contract security copilot that helps Web3 teams catch critical vulnerabilities early and ship safer contracts faster.

## 2) Problem
Smart contract vulnerabilities are expensive and frequent. Early-stage teams often ship without enough security review because expert audits are slow and costly. Existing scanners produce noisy output that still requires security expertise to interpret.

## 3) Product
AuditAI combines static analysis (Slither) with LLM reasoning to produce:
- concise security summary
- structured findings with severity
- exploit scenario (how attack happens)
- suggested fix (what to change in code)

Current MVP:
- Web UI for Solidity paste-and-scan
- Backend scan pipeline with stable schema output
- Slither-only fallback mode when LLM is unavailable
- Benchmark suite with reproducible outputs

## 4) Why now
Web3 teams are shipping quickly across L2s and need lightweight, continuous security feedback before costly full audits. AI quality and developer workflows now make this practical as a day-to-day tool.

## 5) Target users
- Early-stage DeFi / infra teams
- Solo founders building contracts
- Protocol engineering teams needing pre-audit triage

## 6) Differentiation
- Focus on exploitability and remediation clarity, not raw detector noise
- Built for developer workflow speed (seconds-to-result)
- Structured outputs suitable for CI/reporting integration

## 7) Validation evidence
Internal benchmark matrix on 5 contract profiles:
- Reentrancy detected: yes (Critical)
- Access control flaw detected: yes (Critical)
- Unchecked call detected: yes (Medium)
- Oracle misuse: multiple findings (Critical/High/Medium)
- Safe baseline: no critical findings

Artifact paths:
- `demo-results/matrix.md`
- `demo-results/matrix.json`
- `demo-results/results/*.json`

## 8) 8-week execution plan
### Weeks 1–2
- Improve finding precision and false-positive filtering
- Add scan history + project workspace
- Add richer error telemetry and request tracing

### Weeks 3–4
- Report export (JSON + PDF)
- Severity policy presets by protocol type
- Team sharing links

### Weeks 5–6
- GitHub/CI integration (PR comment + status check)
- Rule customization and suppression controls

### Weeks 7–8
- Pilot with 3–5 Web3 teams
- Collect usage metrics and iterate on result quality
- Prepare paid beta plans

## 9) Success metrics
- Time-to-first-useful-finding < 60 seconds
- Weekly active projects scanning contracts
- % scans producing actionable fix recommendations
- Pilot retention (week-4 active rate)

## 10) What we need from Claude Startups
- Model credits for rapid iteration and evaluation
- Product feedback loop on prompt/reliability architecture
- Potential intros to relevant Web3 startup ecosystem partners

## 11) Demo assets checklist
- 90s product demo script: `demo-results/demo-script-90s.md`
- Landing page copy: `demo-results/landing-page-copy.md`
- Benchmark evidence: `demo-results/matrix.md`
