agentsastLast reviewed 2026-09-13

LLM plus symbolic execution or formal verification

Direct answerThe model generates properties, invariants or code; a solver or prover checks them, so the model's output is accepted only when a machine confirms it.

In more detail

PropertyGPT, Certora AI Composer and Olympix use this pattern for contracts. In ZK, the same idea underlies better.codes and Clean, where the Lean kernel judges AI-written proofs.

Tools that address it

Certora AI Composer, Olympix, GPTScan and PropertyGPT (research).

False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.