sealevel-insight
v0.8.2
Published
Local, deterministic architecture and code-metrics CLI for Solana programs.
Maintainers
Readme
Sealevel Insight CLI
Sealevel Insight is a local, deterministic architecture and code-metrics CLI for Solana programs. It turns an unfamiliar repository into an evidence-backed map of programs, instructions, functions, accounts, state, CPIs, PDAs, dependencies, token and asset flows, and review scope.
The CLI understands Anchor, native Rust, Pinocchio, Steel, Quasar, custom Rust, Solang Solidity, and hand-written sBPF assembly. It does not execute the analyzed program, upload source code, contact Solana RPC, use telemetry, or invoke AI services.
Install
npm install --global sealevel-insight
sealevel-insight analyze . --format json --output report.jsonFor a one-off run:
npx sealevel-insight analyze . --format markdown --output report.mdNode.js 18 or newer is required. npm or npx may access the registry to obtain
the package; analysis after installation is local and offline, with all parser
grammars shipped in the package.
Commands
sealevel-insight analyze [root] [options]
sealevel-insight scope [root] [options]
sealevel-insight diff <before.json> <after.json> [--format json|markdown|html]
sealevel-insight baseline save [root] [--output baseline.json]
sealevel-insight cache clear [root]Useful options include --enable-idl, --cargo-metadata, --target, repeated
--cfg, --cfg-complete, --no-cache, --format, and --output.
Exit codes are stable for scripting: 0 means success, 1 means an
analysis/configuration failure, and 2 means a configured quality policy
failed.
Reports
Reports are available as JSON, Markdown, or standalone HTML. They include metrics, program and package structure, instruction reachability, deterministic function/call paths, account and state relationships, CPIs, PDA signing, token/asset-flow evidence, IDL reconciliation, semantic coverage, review complexity, and explicit unresolved conditions. Review signals are not vulnerability findings or a security verdict.
Cargo workspaces
The analyzer reads Cargo manifests without running Cargo. For reproducible CI, provide saved metadata:
cargo metadata --format-version 1 --locked --offline > cargo-metadata.json
sealevel-insight analyze . --cargo-metadata cargo-metadata.json --no-cacheThe repository also contains an optional Cargo launcher around this same bundled Node.js/WASM engine. It is a thin launcher, not a native Rust rewrite, and requires Node.js 18 or newer. Install it with Cargo when the crate is available in your registry:
cargo install sealevel-insight
sealevel-insight analyze . --format markdown --output report.mdPublishing (maintainers)
The source repository also contains the VS Code extension, so its root manifest is private. The public CLI is generated and validated separately:
npm run package:cli
npm run test:cli-package
npm publish ./dist-cli-package --access publicPublish only the generated dist-cli-package/ directory. The package includes
DISCLOSURE, dependency notices, and no development dependencies.
Privacy and safety
Normal execution reads the selected local files and writes the requested report/cache. It does not upload source code, access wallets or private keys, call Solana RPC, collect telemetry, invoke AI APIs, or execute the analyzed program.
See the repository SECURITY.md, SUPPORT.md, and
THIRD_PARTY_NOTICES.md for reporting and dependency information.
