Identifying Solidity Smart Contract API Documentation Errors
Chenguang Zhu, Ye Liu, Xiuheng Wu, Yi Li
Abstract
Smart contracts are gaining popularity as a means to support transparent, traceable, and self-executing decentralized applications, which enable the exchange of value in a trustless environment. Developers of smart contracts rely on various libraries, such as OpenZeppelin for Solidity contracts, to improve application quality and reduce development costs. The API documentations of these libraries are important sources of information for developers who are unfamiliar with the APIs. Yet, maintaining high-quality documentations is non-trivial, and errors in documentations may place barriers for developers to learn the correct usages of APIs. In this paper, we propose a technique, DocCon, to detect inconsistencies between documentations and the corresponding code for Solidity smart contract libraries. Our fact-based approach allows inconsistencies of different severity levels to be queried, from a database containing precomputed facts about the API code and documentations. DocCon successfully detected high-priority API documentation errors in popular smart contract libraries, including mismatching parameters, missing requirements, outdated descriptions, etc. Our experiment result shows that DocCon achieves good precision and is applicable to different libraries: 29 and 22 out of our reported 40 errors have been confirmed and fixed by library developers so far.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2238e5ed-dd94-4ca4-8413-e57609c6e1bdCited by top-tier papers5
- Understanding End-User Perception of Transfer Risks in Smart ContractsYustynn Panicker, Ezekiel O. Soremekun, Sudipta Chattopadhyay, Sumei SunCHI 2025 · 2 citations
- EventSpec: Defining and Detecting Event-Semantic Issues in Blockchain EcosystemsYixuan Liu, Yuxin Dong, Ye Liu, Yin Wu et al.ISSTA 2026
- TrapHunter: Exposing Covert Pathways in Trap Token ContractsYin Wu, Yixuan Liu, Yi Li, Chenyang Peng et al.ISSTA 2026
- Identifying Multi-parameter Constraint Errors in Python Data Science Library API DocumentationXiufeng Xu, Fuman Xie, Chenguang Zhu, Guangdong Bai et al.ISSTA 2025
- SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language ModelsShihao Xia, Mengting He, Shuai Shao, Tingting Yu et al.OOPSLA 2026
Related papers
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang et al.USENIX Security 2024 · 11 citations
- Automating User Notice Generation for Smart Contract FunctionsXing Hu, Zhipeng Gao, Xin Xia, David Lo et al.ASE 2021 · 23 citations
- Demystifying OpenZeppelin's Own Vulnerabilities and Analyzing Their Propagation in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang et al.ASE 2025 · 1 citation
- DocTer: documentation-guided fuzzing for testing deep learning API functionsDanning Xie, Yitong Li, Mijung Kim, Hung Viet Pham et al.ISSTA 2022 · 72 citations
- Code Cloning in Solidity Smart Contracts: Prevalence, Evolution, and Impact on DevelopmentRan Mo, Haopeng Song, Wei Ding, Chaochao WuICSE 2025 · 1 citation
