Audit your transaction paths
Find missing, wrong, or unresolved Builder Code evidence in supported TypeScript source.
Run Attribution Doctor
The AST-backed analyzer identifies supported call sites and connects them to nearby or project-level attribution evidence. It reports paths, protected paths, coverage, and findings. It does not execute application code.
pnpm exec bao init --builder-code bc_abc123
pnpm exec bao doctorChoose a profile deliberately
The ci profile reports environment-driven evidence as an unresolved warning. strict treats unresolved evidence as an error. Keep the profile and severity rules in your project policy so your team reviews the same result.
pnpm exec bao doctor --profile strictUse the output where you work
Human output suits local inspection. JSON provides automation data. SARIF can be uploaded to GitHub Code Scanning. Use a new output path for artifacts you intend to retain.
pnpm exec bao doctor --format human
pnpm exec bao doctor --format json
pnpm exec bao doctor --format sarif --output bao.sarifRead the scope with the finding
Supported families include viem, wagmi, ethers, Privy, raw RPC, EIP-5792, ERC-4337, x402, and agent transaction tools. Coverage describes supported paths in the supplied source. It does not establish runtime behavior or coverage over code the analyzer did not inspect.