Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #2,799 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
AuditPilot is a self-reported smart contract security toolkit for Solidity and Solana developers, built as a web app and an MCP server. The author states it uses Codex and GPT-5.6 in its development and offers two surfaces: a hosted web app with GitHub OAuth and OpenAI key storage, and an MCP server that enables agent-driven security analysis without consuming the project’s own API keys.
What changed
The description indicates a working prototype built during a hackathon, with core functionality including GitHub authentication, encrypted API key handling, audit history tracking, and an MCP server for deterministic reasoning. It is not evidenced whether this has progressed beyond prototype or gained users.
The single most important open question
Is there any evidence of real-world usage or adoption by developers? The description states no revenue, customers or traction data are available.
What The Product Actually Is
The description states that AuditPilot is a smart contract audit toolkit for Solidity and Solana. It has two components:
- A web app, where developers sign in with GitHub, securely store their own OpenAI API key, run audits, and view audit history.
- An MCP server, which allows Codex, IDE agents, or ChatGPT to use AuditPilot as a deterministic security toolkit.
The MCP server exposes three tools:
clone_and_parse_contractget_vulnerability_checklistsearch_solodit_findings
The author states that the MCP reasoning happens inside the developer’s own Codex session, and that the project does not spend its own OpenAI key. The web app uses GPT-5.6 when a signed-in user provides their own API key.
Inference The product is a hybrid tool combining a hosted interface with an agent-integrated backend, designed for developer workflow integration.
Positioning & Claim Evolution
The author states that smart contract teams need fast security feedback before formal audits, but existing tools are often chain-specific, expensive, or shallow. AuditPilot was built to make Codex useful as a security assistant for Solidity and Solana developers.
Claim
The product is positioned as a tool that enhances developer workflows by integrating with Codex and offering deterministic security analysis via an MCP server.
Inference The positioning reflects a niche in developer tooling, targeting early-stage smart contract development teams seeking rapid feedback. No evidence of market positioning beyond the author's own description.
Target Customer & ICP
The author states that AuditPilot is for Solidity and Solana/Anchor developers, who need fast security feedback before formal audits.
Inference The target customer segment appears to be early-stage or mid-tier smart contract developers working in Ethereum and Solana ecosystems, who are looking for lightweight, agent-integrated audit tools.
Not evidenced No specific customer personas, use cases, or adoption data are provided.
Business Model & Pricing Evidence
The description does not state a business model or pricing structure. It mentions that users sign in with GitHub, store their own OpenAI API key, and run audits via the web app.
Inference The product appears to be free-to-use, with no explicit monetization mechanism described. The web app is hosted, but there’s no indication of paid tiers or subscriptions.
Technical & Delivery Signals
The author states that the project was built using:
- Frameworks: Next.js, React, TypeScript
- Tools: Codex, GPT-5.6, Supabase, GitHub OAuth, Anchor, Solana, Solidity, Solodit, Cyfrin
- Infrastructure: Vercel, OpenAI API
Key technical decisions include:
- The MCP server is deterministic, not calling the project’s own model key.
- The web app uses GPT-5.6 with a BYOK (Bring Your Own Key) approach.
- GitHub OAuth and encrypted storage of user keys are implemented.
- Audit history is persistent.
Inference The technical stack suggests a developer-focused, lightweight tool built in a short timeframe, likely during a hackathon.
Traction & Maturity Signals
The description states that the project was submitted to the OpenAI 2026 hackathon, and includes accomplishments such as:
- A working Next.js web app
- Supabase GitHub OAuth
- Encrypted per-user OpenAI key storage
- Persistent audit history
- MCP server with local testing against foundry-rs/forge-std
- Solodit/Cyfrin historical finding lookup
Not evidenced No user base, revenue, or adoption metrics are provided. The project is described as a prototype.
Competitive Context
The author states that existing tools are often chain-specific, expensive, or shallow, and that AuditPilot aims to make Codex useful for security analysis.
Inference The competitive landscape includes traditional audit platforms (e.g., Cyfrin, Solodit) and other developer tooling. However, no specific competitors or market positioning beyond the author’s own claims are stated.
Key Risks & Red Flags
- No traction or revenue data: The project is described as a hackathon prototype with no evidence of real-world usage.
- Dependency on external tools: Reliance on GitHub OAuth, Supabase, and OpenAI API keys raises concerns about scalability and control.
- MCP server design choice: The decision to keep reasoning client-side may limit the tool’s utility or performance.
- Single-founder team: The project is built by one person, which may affect long-term development and support.
Diligence Questions To Ask The Founders
- What is the current usage of AuditPilot? Are there any users or feedback from developers?
- How does the product plan to scale beyond a hackathon prototype?
- Is there a clear path to monetization, or is it intended as an open-source tool?
- What are the limitations of the current MCP implementation and how might they be addressed?
- Are there any plans for additional chain support (e.g., Move, CosmWasm)?
- How does the project handle GitHub rate limits and API key security in a production environment?
Investment/Partnership Verdict
Not evidenced: No financials, customer data, or traction metrics are provided.
Inference The project is currently a prototype, built during a hackathon with no evidence of commercial adoption or revenue. It shows early technical capability but lacks the signals typically required for investment or partnership consideration.
The author’s own description indicates that the product is in an early stage and has not yet reached market traction. It may be a promising idea, but there is no evidence of real-world usage or commercial viability at this time.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
