Solidity Auditor
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
Operates Flounder, an autonomous white-hat security auditor.
$ npx skills add adshao/flounder --skill flounder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install adshao/flounder flounder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/flounder .claude/skills/flounder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .claude/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/adshao/flounder/tree/main/skills/flounderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add adshao/flounder --skill flounder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install adshao/flounder flounder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/flounder .agents/skills/flounder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .agents/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add adshao/flounder --skill flounder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install adshao/flounder flounder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/flounder .cursor/skills/flounder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .cursor/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/adshao/flounder.git --path skills/flounder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add adshao/flounder --skill flounder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install adshao/flounder flounder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/flounder .gemini/skills/flounder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .gemini/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install adshao/flounder flounderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add adshao/flounder --skill flounder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/flounder .github/skills/flounder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .github/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add adshao/flounder --skill flounder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install adshao/flounder flounder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adshao/flounder.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/flounder .opencode/skills/flounder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "flounder" agent skill from https://github.com/adshao/flounder/tree/main/skills/flounder into .opencode/skills/flounder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flounder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
flounderOperates Flounder, an autonomous white-hat security auditor.
Flounder is an agent skill from adshao/flounder. Operates Flounder, an autonomous white-hat security auditor. Use when a user asks for a security audit, bug-bounty review, vulnerability investigation, or exploit proof for a public-source or authorized repository, source tree, package, smart contract, Solidity/EVM project, ZK or proof-system code, deployed address, transaction, project link, or prior Flounder run; to run Flounder prepare, map, dig, audit, verify, confirm, or report workflows; to configure Flounder server, daemon, provider profiles, model auth…
Its SKILL.md is about 9.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `reference/commands.md`, `reference/examples.md` and `reference/maintainer-harness.md`).
It sits in Security, covering Smart contracts, Security review and Bug bounty. It works with Solidity. The repository describes itself as: Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification. The licence is AGPL-3.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 505571a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnodecurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Flounder loads about 9.2k tokens when it runs. Until then it costs about 245 tokens; SKILL.md has 4,537 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from adshao/flounder at commit 505571a, republished under its AGPL-3.0 licence (© adshao). 4,537 words, ~9,241 tokens.
.claude/skills/flounder/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.This skill is the operating manual for Flounder-driven security audits.
Flounder is an autonomous white-hat security auditor. The agent prepares the target, audits source, constructs exploit paths, runs local proof tests, confirms real findings, and packages reports. The framework provides the daemon, sandbox, command policy, run tracking, live activity, and execution gates.
| File | When to read |
|---|---|
SKILL.md | Always after this skill triggers. It is the operating playbook. |
reference/models.md | Choosing a model, OAuth versus API keys, DeepSeek/GLM setup, and missing-model troubleshooting. |
reference/commands.md | Exact CLI, REST, provider, daemon, budget, output, and pi extension details. |
reference/examples.md | Concrete Solidity/EVM and ZK examples. |
reference/product.md | Dashboard, project lifecycle, run phases, tracking, and artifact model. |
reference/safety.md | White-hat policy, sandbox boundary, evidence ladder, and public-release hygiene. |
reference/maintainer-harness.md | Maintainer-only agent workflow for Evaluation-driven source improvement and candidate PRs. |
Use progressive disclosure: open only the reference file needed for the current task. Do not duplicate long command references into the conversation when a short command and status summary is enough.
run <clue> lets Flounder prepare
the target, then map/dig/synthesize/verify, confirm, and report; run --source
is the source-provided entry path for sealed map/dig/synthesize/verify.ignored, never by deleting them.Choose the mode from the user's intent before launching anything:
| User intent | Mode | Preparation path | Guardrail |
|---|---|---|---|
| "Do a blind audit / test Flounder's capability / no hints" | Blind capability audit | Recommended: flounder run <project-or-repo-or-package-link> or a dashboard project with a factual target clue. If source is already staged or external preparation is explicitly unwanted, use flounder run --source <paths...> --build-root <root>. | Do not add incident docs, known bug names, exploit theories, or answer-bearing corpus. Official target docs are allowed only as target material, not as a hidden answer. |
| "Here is a suspicious tx/address; find the hack/root cause" | Incident investigation | flounder run <tx-or-address-or-incident-link> | Treat the clue as evidence, not as proof. Prepare may fetch chain/source data; confirm by local fork/read-only reproduction only. |
| "Audit this project/repo openly like a white-hat researcher" | Open-world public-source audit | Create a project with source paths when available plus a task/clue naming the project, bounty, repo, package, or deployment, then Run. | Let Prepare collect official docs, scope, deployments, and provenance. Do not use private or answer-bearing material. |
| "Audit this normal bounty / should we submit to this bounty?" | Normal bug bounty | Project with engagement.kind="bug-bounty", source/build/corpus paths when available, and a task/clue naming the public or private program scope. | Keep real-target Confirm when a live target exists. Submit only execution-backed findings meeting official scope, evidence, and mandatory submission terms; record private duplicate and reward uncertainty separately. |
| "Start this contest / maximize contest bounty speed" | Bug bounty contest | Project with engagement.kind="bug-bounty-contest" and contest strategy such as batchScopes, digConcurrency, skipRealTargetConfirm, and appendMapWhenExhausted. | Run short settled batches: verify/refute and report before opening the next batch. Source-only local confirmation may be enough when venue rules allow it, but suspected-only findings are not submissions. Use append-map, not remap, when expanding coverage. |
When in doubt: if the user asks to measure Flounder's unaided recall, use blind capability audit and keep the clue target-only. If the user gives live exploit evidence, use incident investigation. If the user wants broad public-source or authorized bug hunting and permits public context collection, use open-world public-source audit.
Use these when the user is not asking for a full end-to-end audit:
| User intent | Workflow |
|---|---|
| "Just map the surface / show scope inventory" | flounder map; do not produce findings. |
| "Dig this file/function/scope deeper" | flounder audit <region> or flounder audit --scope <id>. |
| "Check these suspected bugs" | flounder audit --verify <claims.json>; confirm or refute by execution. |
| "Is this locally confirmed bug real on mainnet/deployment?" | flounder confirm <run-dir> or selected project Confirm. |
| "Prepare submission package" | selected Report; include only execution-backed, non-ignored findings. |
| "Triage noisy machine findings" | update tracking: ignored for dismissed, open to recover. |
| "Run a benchmark / regression set / positive and safe controls" | Create a validated manifest and use flounder group create --manifest <file>, then `flounder group start <uuid |
| "Improve Flounder's harness / raise recall / learn from Evaluation failures" | This is maintainer work, not a normal target audit. Confirm the agent is operating in the Flounder source repository with authorization to change it, then read reference/maintainer-harness.md and drive the isolated source-change workflow. |
~/.flounder as the default product home: tracking DB, run artifacts,
durable history/build cache, daemon workspace, and daemon-local provider auth
live there unless the user explicitly passes --out or --workspace.flounder ui unless the user already has a control plane running.
CLI verbs are thin clients of that control plane.flounder ui --maintainer only when an authorized Flounder
maintainer is improving Flounder source. Ordinary Project and Evaluation work
must not enable or advertise Harness source-improvement operations.GET /api before driving the REST API directly; the catalog is the source
of truth for endpoint shape.suspected as unproven. A finding is actionable only when execution
produced confirmed-executable, confirmed-differential, or a reproduced
confirm decision.flounder run <clue> is the one-command workflow: open-world prepare,
sealed map/dig/synthesize/verify, open-world confirm, then report generation.
flounder run --source, map, and audit are sealed discovery phases.
prepare and confirm are open-world phases, still under white-hat
no-broadcast rules.When a user asks to audit, confirm, verify, report, or inspect Flounder state:
GET /api, then project UUID routes.flounder ui.--source when code is staged or no external preparation is wanted.flounder daemon provider check openai-codex on the executor machine.npm run sandbox:build if the default OCI image is missing.For repository development or local builds, use Node 24 LTS from .nvmrc /
.node-version; do not substitute newer experimental Node versions.
Check whether Flounder is available:
flounder --helpIf it is not available from PATH but the repository is checked out, build it:
npm install
npm run build
node dist/cli.js --helpUntil the package is installed or linked, replace flounder in command
examples with node dist/cli.js.
Start or reuse the local control plane:
flounder uiFor a remote executor, mint a token in Settings or with
flounder server daemon-token mint, then run:
flounder daemon start --server http://<server>:4500 --token <token>Authenticate every provider that the selected daemon will run. For model selection or credential setup, read the model setup guide. Use OAuth login only for OAuth-capable providers; API-key providers need keys in the daemon environment or an existing stored pi credential. Coding Plan subscriptions may also use API keys. Preserve the user's selected provider and plan; do not assume they need a new adapter or metered endpoint.
OAuth example:
flounder daemon provider login openai-codex
flounder daemon provider check openai-codexFor openai-codex, this is how the agent asks the user to authenticate.
Run the login command in the terminal; it prints a browser URL or device-code
instructions, the user completes the login, and then check verifies it. If
pi already has openai-codex in ~/.pi/agent/auth.json, Flounder imports
that provider entry into ~/.flounder/agent/auth.json on login/check.
Ensure the execution sandbox is available on the daemon machine. Default
auto mode prefers Apple's container runtime on Apple silicon macOS when
the selected image and sealed network are ready, then falls back to
Docker-backed OCI when the image is available. For the Docker-backed path,
install and start Docker or a Docker-compatible runtime, then build the
default sandbox image from the Flounder repo:
npm run sandbox:buildCurated target-specific images are available for common non-EVM audits:
npm run sandbox:rust:target -- --target <target-root> --execute
npm run sandbox:cairo:build # flounder-sandbox:cairo, Scarb + Starknet Foundry
npm run sandbox:ton:build # flounder-sandbox:ton, TON Blueprint + FunC/Tolk/TactOn Apple silicon macOS daemon hosts, install/start Apple's container
runtime and build or pull the selected image into that runtime to let auto
select it; --sandbox-backend apple-container requires that path explicitly.
If no sandbox engine is available, only use
--sandbox-backend host --allow-host-execution for trusted local smoke tests
after warning the user that host mode lacks kernel-level filesystem and
network isolation.
Create or reuse a provider profile in Settings. A provider profile selects
provider, model, and thinking level. Fresh stores seed openai-codex · gpt-5.6-sol · xhigh, openai-codex · gpt-6-astra · medium, and
claude-code · opus 4.8 max; the selected daemon still
needs local auth for every provider the project can use. A project can
override the profile per phase: prepare, map, dig, confirm. Set default
makes a profile the local default for new projects, evaluations, and
API/CLI launches that omit an explicit model; Use product default restores
the packaged gpt-5.6-sol fallback without changing existing projects.
The optional openai-codex · gpt-6-astra · medium starter profile does not replace
the Sol product default. Selecting Astra in the provider editor initializes
medium thinking; the operator may override it. Custom model ids use a known
same-provider Compatibility base for transport, context, tool, and reasoning
metadata. The job carries the definition to the selected daemon in memory;
credentials remain daemon-local, and no matching daemon-local pi models file is
needed. The provider must actually authorize the custom model id.
Create or reuse a project. Set:
Start the audit. Leave Run after create checked to launch immediately, or use the project Run button before the first pipeline run and Continue afterward. For a clue:
flounder run <tx-or-address-or-project-or-repo-or-link>For source already on disk:
flounder run --target <name> --source <paths...> --build-root <root> --corpus <docs...>Monitor progress from the dashboard, CLI stream, or REST API:
GET /api/runs/:id/logGET /api/projects/:uuidprepareSummary.quality is ready, limited,
preparing, needs-review, missing, or invalid; use
prepareSummary.auditReady as the automation gate. limited means the
audit can continue automatically while recorded trust boundaries or
material gaps stay visible for later confirm/report decisions. Stop only
for prepareSummary.blockingIssues, invalid, or missing usable source.GET /api/projects/:uuid/findings?tracking=activeGET /api/projects/:uuid/findings?tracking=ignoredGET /api/projects/:uuid/confirm-decisionslatestRunHealth.status is healthy,
needs-coverage, needs-resource, shallow, or infra-failedGET /api/projects/:uuid/backlog?status=open
lists coverage gaps, resource requests, and follow-up scopes with
actionability, action_owner, and recommended_action; treat open rows
as an agent-owned queue (agent-runnable, agent-resource, agent-review)
and use PATCH /api/backlog/:id to mark rows resolved, ignored,
stale, or back to openProject names are display labels. Resolve a project UUID from POST /api/projects
or GET /api/projects; do not build a project URL from the name.
Decide the next action using the rules below. Do not call the task complete just because one run ended.
Use this when the user wants no hints, no incident context, or a framework-capability check.
Recommended target-prepared path:
flounder run <project-or-repo-or-package-link>Existing source path:
flounder run --target <name> --source <paths...> --build-root <root> --corpus <user-supplied-docs...>--corpus empty unless the user supplied official docs/specs as part of
the blind package.Use this when the user gives a suspicious transaction, address, exploit link, or asks "why was this hacked?"
flounder run <tx-or-address-or-incident-link>Use this when the user wants Flounder to actively collect official public context, deployments, package metadata, docs, or bounty scope when available. Source paths are useful when already available, but they are not what defines the scenario. A public bounty is a priority and submission-path signal, not a prerequisite for local sealed audit.
flounder ui.openai-codex · gpt-5.6-sol · xhigh.GET /api/runs/:id/log and GET /api/projects/:uuid.limited prepare as audit-ready unless it has blocking issues; carry
caveats forward to verify/confirm/report decisions.Use this when the target is a normal public or private bounty program and a live target may need real-world reproduction.
config.engagement.kind="bug-bounty".Use this when the venue is a time-limited audit contest with source, rules, and a report format.
config.engagement.kind="bug-bounty-contest".batchScopes:10, digConcurrency:5, skipRealTargetConfirm:true, and
appendMapWhenExhausted:true when the rules are source-only.Resolve the project UUID from GET /api/projects.
Use the project Continue action, or from the CLI:
flounder continue --project <uuid|name>This is the same project pipeline action as the UI Continue button; it queues
verb:"run" and lets the control plane continue from stored project state.
If shelling through the REST API directly, use:
curl -X POST http://127.0.0.1:4500/api/projects/<uuid>/runs \
-H 'content-type: application/json' \
-d '{"verb":"run"}'Inspect latestRunHealth, backlogCounts, and open backlog rows before
drawing conclusions. Treat open Next Actions as work for the agent to
resolve or route before opening unrelated fresh coverage; ask the operator
only for explicit credentials, authorization, or unavailable external
resources. Continue coverage or prioritize follow-up scopes for
needs-coverage; do not treat shallow as a meaningful negative result.
If many mapped scopes are pending, prefer continuing coverage before drawing a negative conclusion.
Use this when the user asks why a project cannot run, how to clean up the project rail, or how to recover archived work.
resource-request backlog rows explain a setup limitation, first let
the agent inspect the blocker and retry safe setup work. Ask the operator only
for explicit credentials, authorization, or unavailable external resources,
then mark handled rows resolved or non-actionable rows ignored.Use this when the user is reviewing machine-reported bugs.
suspected, confirmed-*, refuted) separate from
tracking state (open, triaging, submitted, ignored, etc.).ignored; do not delete them.open if new evidence appears.flounder audit --verify <file> --source ...
or the equivalent flounder verify <file> --source ....findingId / findingIds to POST /api/projects/:uuid/runs.{"verb":"report","findingIds":[...]}.{"verb":"report","regenerateReports":true} or
flounder report --project <uuid|name> --all.findingIds generates only missing formal reports.flounder report --project <uuid|name> for missing reports and
flounder report --project <uuid|name> --finding <id> for selected
regeneration.ignored; recover it later from
tracking=ignored by changing it back to open.Open only the references needed for the current task:
| User intent | Use |
|---|---|
| "Blind audit this target / test framework capability" | Blind capability audit: prefer flounder run <target-clue>; use flounder run --source ... --build-root ... when source is already staged or no external preparation is wanted |
| "Find why this tx/address was hacked" | Incident investigation: flounder run <tx-or-address-or-incident-link> |
| "Audit this repo/source openly" | Open-world public-source audit: project with source paths plus task/clue, then Run |
| "Map the attack surface first" | flounder map, then inspect scopes and run flounder audit --scope ... |
| "Dig this file/function/region" | flounder audit <region> --source ... --build-root ... |
| "Verify this suspected bug" | Write a claims JSON and run flounder verify <file> or flounder audit --verify <file> |
| "Continue coverage" | Use project Continue or audit pending scopes from the inventory; inspect discovery backlog first for resource blockers or follow-up scopes |
| "Confirm whether this is real" | flounder confirm <run-dir> or project/finding Confirm in the UI |
| "Collect bugs for disclosure" | Read findings, selected reports, confirm decisions, and artifacts; return only execution-backed items |
| "Ignore this false positive" | Set finding tracking to ignored; do not delete it |
| "Bring back ignored findings" | Filter tracking=ignored, then set selected rows back to open |
| "Regenerate reports" | Use `flounder report --project <uuid |
| "Improve Flounder itself from evaluation evidence" | Confirm maintainer context, enable flounder ui --maintainer, then follow reference/maintainer-harness.md; never run this loop from an ordinary target Project |
flounder daemon provider login
or set daemon-local provider credentials, then check again.container runtime and build or pull the image into that runtime, or
install/start Docker on the daemon and run npm run sandbox:build. Host
fallback still needs explicit trusted-local approval.GET /api/runs/:id/log and the project phase, not only
aggregate counts.limited: continue automatically unless the user asked to
perfect materials first; preserve prepareSummary.caveats, gaps, and
realTarget for verify, confirm, and reports.needs-review, missing, or invalid: read
prepareSummary.blockingIssues, issues, gaps, and realTarget. Repair
only hard blockers such as contaminated answer-bearing material, invalid
output, empty prepared source, or no usable source; otherwise continue with
caveats instead of requiring manual review.needs-resource: inspect open resource-request rows,
have the agent retry safe toolchain, sandbox, dependency, source, or auth setup
where possible, and ask the operator only for explicit credentials,
authorization, or unavailable external resources. Mark handled rows
resolved, then rerun the blocked phase. Prepare and toolchain warm-up can
create these rows even when the model did not write resource_requests.json;
treat them as product-owned setup work, not as audit findings.needs-coverage: continue pending scopes or prioritize
follow-up scopes from the backlog. Do not ask the model to "report more bugs"
as a substitute for coverage.shallow: treat the run as inconclusive; inspect logs
and rerun or fix setup before summarizing.suspected: make the target buildable and run verify or
dig again.skipRealTargetConfirm=true: real-target Confirm may be
intentionally skipped, but verify/refute and report eligibility are still
required before submission.ignored;
recover it later from the Ignored filter by changing tracking back to open.not-reproduced: treat it as not submission-ready unless
the failure is a known environment limitation and the user approves more work.submit-candidate: collect the bug package and stop
further exploitation.| Symptom | Likely cause | Recovery |
|---|---|---|
| No daemon can claim a queued job | Project is pinned to an offline daemon | Start that daemon or edit the project daemon. |
| Provider auth missing | Credentials live on daemon, not server | Use OAuth login or daemon-local API key configuration as appropriate, then check; see reference/models.md. |
| Docker-backed OCI sandbox unavailable | Default image missing or Docker stopped | Start Docker and run npm run sandbox:build; host fallback needs explicit trusted-local approval. |
| Apple container sandbox unavailable | Apple container is not installed/started, the selected image is missing from that runtime, or the internal sealed network cannot be created | Run container system start and build or pull the image into Apple's runtime; auto falls back to Docker when that path is not ready. |
prepareSummary.quality=limited | Source is usable but has caveats | Continue unless blocking issues exist; preserve caveats for confirm/report. |
prepareSummary.quality=invalid/missing | No usable staged source or contaminated material | Repair prepare inputs before audit. |
| Verify rejects selected findings for material drift | New Prepare changed the current material boundary | Re-select current findings or pass the explicit expert override only after checking drift. |
Confirm returns not-reproduced | PoC was not attacker-real on the real target, or environment is incomplete | Treat as not submission-ready unless the user approves more reproduction work. |
| Report action says no findings are missing reports | All reportable rows already have formal reports, or selected rows are not reproduced/confirmed | Use `flounder report --project <uuid |
| Node native crash during repo tooling | Unsupported Node version | Use Node 24 LTS from .nvmrc / .node-version. |
For every bug candidate, collect:
command_idDo not present a list of model suspicions as bugs. Separate confirmed findings, suspected findings, refuted findings, and reproduced submit candidates.
The task is not complete until the agent can report:
ready or limited; if limited, every caveat needed
for verify, confirm, or report decisions is called out as a known limitation.© adshao, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files in skills/flounder of adshao/flounder.
Open the folder on GitHubat commit 505571a
Flounder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Flounder this skilladshao/flounder | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | |
| Solidity AuditorGabson0x/bountyforge | 442 | — | ~3.7k | Automated safety check: Pass | None | |
| Solidity Auditorpashov/skills | 1.2k | — | ~9.9k | Automated safety check: Pass | MIT | |
| Auditsablier-labs/evm-monorepo | 353 | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| DeFi Smart Contract Bug Classestradecatlabs/vibe-coding-cn | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | |
| Audit PrepPlamenTSV/plamen | 303 | — | ~3.7k | Automated safety check: Pass | MIT |
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
pashov/skills
Security audit of Solidity code while you develop. An agent skill from pashov/skills.
sablier-labs/evm-monorepo
Security audit and code review for Solidity smart contracts.
tradecatlabs/vibe-coding-cn
Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
Works with
Categories
Operates Flounder, an autonomous white-hat security auditor. Flounder is an agent skill from adshao/flounder. Operates Flounder, an autonomous white-hat security auditor.
Flounder fits situations like: A user asks for a security audit; bug-bounty review; vulnerability investigation; exploit proof for a public-source.
Run `npx skills add adshao/flounder --skill flounder -a claude-code`. Or copy the skill folder (skills/flounder in adshao/flounder) into .claude/skills/flounder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add adshao/flounder --skill flounder -a codex`. Or copy the skill folder (skills/flounder in adshao/flounder) into .agents/skills/flounder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adshao/flounder --skill flounder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flounder, .gemini/skills/flounder, .github/skills/flounder and .opencode/skills/flounder in your project.
Going by SKILL.md and its folder, Flounder needs the command-line tools its instructions call (npm, node and curl). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Flounder is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 9.2k tokens (SKILL.md is roughly 37k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Flounder: Solidity Auditor (Gabson0x/bountyforge, 442 stars), Solidity Auditor (pashov/skills, 1.2k stars), Audit (sablier-labs/evm-monorepo, 353 stars) and DeFi Smart Contract Bug Classes (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
adshao (a GitHub user) maintains it in adshao/flounder, which has 518 GitHub stars. The repository was last updated on October 5, 2026.
Source: adshao/flounder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.