
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@blockxai/evi-sdk
Advanced tools
EVI SDK — AI-powered smart contract development platform with wallet deployment, security auditing, compliance validation, and blockchain verification
Latest: v3.1.0 🎉
EVI SDK — Professional AI-powered smart contract development platform with wallet deployment, security auditing, compliance validation, and blockchain verification.
Default API: https://evi-wallet-production.up.railway.app
Default Network: basecamp
npm install @blockxai/evi-sdk@latest
Node 18+ is required (native fetch).
Deploy contracts with YOUR wallet - complete self-custody
import { AcadClient } from '@blockxai/evi-sdk';
const client = new AcadClient();
// Start wallet deployment
const job = await client.start_wallet_deployment({
prompt: 'ERC20 token with 1M supply',
network: 'basecamp-testnet'
});
// Get magic link for signing
const session = await client.get_wallet_magic_link(job.jobId);
console.log('Sign with MetaMask:', session.magicLink);
// Opens browser → User signs → Contract deploys
CLI:
evi wallet:deploy "ERC20 token with 1M supply"
# Generates contract → Opens MetaMask → YOU sign → Deploys
Audit Solidity files BEFORE deploying - save gas, prevent hacks
import fs from 'fs';
const code = fs.readFileSync('MyToken.sol', 'utf-8');
const report = await client.audit_source({
code,
filename: 'MyToken.sol'
});
console.log(`Security Score: ${report.report.score}/100`);
console.log(`Critical Issues: ${report.report.severity?.critical}`);
if (report.report.severity?.critical > 0) {
console.error('❌ Fix critical issues before deploying!');
process.exit(1); // Fail CI/CD build
}
CLI:
evi audit:source MyToken.sol --fail-on-critical
# Perfect for CI/CD pipelines!
Check if your token follows ERC standards
const report = await client.compliance_source({
code: tokenCode,
filename: 'MyToken.sol',
profile: 'erc20',
strict: true
});
if (!report.compliance.passed) {
console.log('Missing functions:', report.compliance.missingFunctions);
console.log('Missing events:', report.compliance.missingEvents);
}
CLI:
evi compliance:check MyToken.sol --profile erc20 --strict
# Ensure DEXs will accept your token
Monitor platform usage
const stats = await client.get_session_stats();
console.log(`Total: ${stats.total}, Active: ${stats.active}`);
CLI:
evi stats
Verify deployed contracts on block explorers (Etherscan, Basescan, etc.)
const result = await client.verify_by_job('job-id', 'basecamp');
console.log('Verified:', result.verified);
console.log('Explorer URL:', result.explorerUrl);
AI-powered vulnerability detection with severity levels
const audit = await client.audit_orchestrate({ jobId: 'job-id' });
const report = await client.get_audit_report('job-id');
console.log('Security Score:', report.score); // 0-100
console.log('Critical Issues:', report.summary?.critical);
Validate contracts against ERC standards (ERC-20, ERC-721, ERC-1155, DeFi, DAO)
const comp = await client.compliance_orchestrate({
jobId: 'job-id',
targetProfile: 'erc721',
strict: true
});
const report = await client.get_compliance_report('job-id');
console.log('Compliance Passed:', report.passed);
Complete workflow in one call: Generate → Deploy → Verify → Audit → Compliance
const result = await client.run_acv_pipeline({
prompt: 'ERC721 NFT with minting',
runVerify: true,
runAudit: true,
runCompliance: true,
complianceProfile: 'erc721'
});
See: QUICK_START_ACV.md for complete usage guide
No API key required
Optional overrides:
API_BASE_URL (or ACAD_BASE_URL)NETWORK (default: basecamp)MAX_ITERS (default: 11)NO_ANIMATION=1 (disable intro animation; colors still apply)Magical Logger (narrative logs → webhook):
MAGICAL_LOGS=1 (default on; set 0 to disable)MAGICAL_WEBHOOK_URL=https://your-bridge.example.com/magical (optional)MAGICAL_STREAM=1 (stream each event) or 0 (send one final summary)After install, you get the evi command (aliases: camp, acad for backwards compatibility).
# Generate and deploy with AI
evi deploy:prompt --prompt "ERC20 with 1M supply"
# Deploy existing Solidity file
evi deploy:file --file ./MyToken.sol
# Wallet-based deployment (sign with MetaMask)
evi wallet:deploy "ERC20 token with 1M supply" --network basecamp-testnet
# Audit Solidity file for vulnerabilities
evi audit:source MyToken.sol --fail-on-critical
# Check ERC standard compliance
evi compliance:check MyToken.sol --profile erc20 --strict
# Platform statistics
evi stats
Just run evi with no arguments to launch the interactive wizard:
evi # Opens interactive wizard
evi wizard # Alias
camp # Backwards compatibility
The wizard guides you through:
🔐 Wallet deployment
🛡️ Security auditing
✅ Compliance checking
🚀 Contract generation & deployment
📊 Platform monitoring
Run directories are named after your prompt (or filename), no timestamps:
ai_pipeline_runs/<prompt-slug>/pipeline/ for prompt-based runsai_pipeline_runs/<file-slug>/file/ for file-based runs-2, -3, … suffix is added.ai_pipeline_runs/erc721-with-minting-and-baseuri/pipeline/What you’ll see and where things are saved:
./ai_pipeline_runs/<name>/:
pipeline/ or file/job.id, final.status.jsonlogs.ndjsonartifacts/ with sources/, abis/, scripts/Examples:
# Generate and deploy from a prompt
camp deploy:prompt --prompt "ERC721 with minting and baseURI"
# Deploy from a local Solidity file
camp deploy:file --file ./contracts/MyNFT.sol --contractName MyNFT
The SDK exports AcadClient if you want to call the API directly.
import { AcadClient } from "@blockxai/camp-codegen";
const client = new AcadClient();
const jobId = await client.start_pipeline("ERC20 token", "basecamp", 11, "Token.sol", [1000000]);
const job = await client.wait_for_completion(jobId, { intervalSec: 2, timeoutSec: 2700 });
# inside camp-codegen-js/
npm install
npm run build
Outputs ESM to dist/.
In the wizard, pick “🔎 Browse preset library (search)” to choose from built-in and user-provided presets.
presets.user.json (array of { title, prompt })presets.user.txt (one preset per paragraph; first token before : is the title)src/presets.user.jsonExamples:
// presets.user.json
[
{ "title": "MessageBoard", "prompt": "MessageBoard: EMPTY CONSTRUCTOR. post(string message). Events: MessagePosted. No constructor args." },
{ "title": "SimpleBank", "prompt": "SimpleBank: EMPTY CONSTRUCTOR. deposit() payable. withdraw(uint256 amount). Events: Deposited, Withdrawn." }
]
MessageBoard: EMPTY CONSTRUCTOR. post(string message). Events: MessagePosted. No constructor args.
SimpleBank: EMPTY CONSTRUCTOR. deposit() payable. withdraw(uint256 amount). Events: Deposited, Withdrawn.
Search is fuzzy across title, description, and prompt text. If your prompts version lacks autocomplete, it falls back to a simple select list.
We emit a narrative alongside raw SSE logs to keep non-technical teammates engaged.
Categories: generation, compilation, errors, deployment, celebration, bonus, verification 🔍, audit 🛡️, compliance ✅
Configure via env vars:
MAGICAL_LOGS — enable/disable (default 1)MAGICAL_WEBHOOK_URL — optional webhook to receive eventsMAGICAL_STREAM — 1 to stream events, or 0 to receive one magical_log_summaryPayload fields include runLabel, jobId, network, prompt, filename, contractName, category, msg, and optional meta.
Tip: route the webhook to a tiny middleware (e.g., Cloudflare Worker, Vercel, Express) that transforms into Apollo.io Notes/Activities for GTM/CS visibility.
NO_ANIMATION=1)basecampNO_ANIMATION=1 is recommended for CI logsFAQs
EVI SDK — AI-powered smart contract development platform with wallet deployment, security auditing, compliance validation, and blockchain verification
The npm package @blockxai/evi-sdk receives a total of 4 weekly downloads. As such, @blockxai/evi-sdk popularity was classified as not popular.
We found that @blockxai/evi-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.