Agent skill

Security Auditor

by Archethect in Archethect/sc-auditor

Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

No licenceAuto-check: notesSecurity

Install Security Auditor

skills CLI
$ npx skills add Archethect/sc-auditor --skill security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Archethect/sc-auditor security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Archethect/sc-auditor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-auditor .claude/skills/security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-auditor
GitHub stars
127
Token cost
~5.9k tokens
SKILL.md length
2,583 words
Files
25 (incl. assets)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

  • Works in 9 steps: RESUME CHECK → 5: RESOLVE INPUT → SETUP (1 Sub-Agent) → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers NON-NEGOTIABLE RULES, Sub-Agent Dispatch, Phase Transition Checklist and Core Protocols, plus 9 more sections
  • Runs TypeScript scripts from its folder; calls git; reaches github.com

What it does

Security Auditor is an agent skill from Archethect/sc-auditor. Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 30 other files, including assets (for example `__tests__/skill.test.ts`, `agents/openai.yaml` and `assets/attack-vectors/approval-abuse.md`).

It sits in Security, covering Static analysis and SAST, Smart contract auditing and Subagents. The repository describes itself as: Solidity smart contract auditor leveraging static analysis, Solodit findings and Map, Hunt, Attack strategy.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Smart contract auditing
  • Tasks that involve Subagents

Example prompts

  • “/security-auditor”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash, Agent, Write, Edit, mcp__sc-auditor__run-slither, mcp__sc-auditor__run-aderyn, mcp__sc-auditor__get_checklist, mcp__sc-auditor__search_findings, mcp__sc-auditor__generate-foundry-poc, mcp__sc-auditor__run-echidna, mcp__sc-auditor__run-medusa, mcp__sc-auditor__run-halmos

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. RESUME CHECK
  2. 5: RESOLVE INPUT
  3. SETUP (1 Sub-Agent)
  4. MAP (1 Sub-Agent)
  5. HUNT (5-6 Parallel Sub-Agents)
  6. ATTACK (N Parallel Sub-Agents)
  7. VERIFY (N Parallel Sub-Agents)
  8. 5: CONFLICT RESOLUTION (Proof-Based)
  9. REPORT (Inline)

What it can do on your machine

Read from SKILL.md and the folder at commit 942cc13. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash
    • Agent
    • Write
    • Edit
    • mcp__sc-auditor__run-slither
    • mcp__sc-auditor__run-aderyn
    • mcp__sc-auditor__get_checklist

    …and 5 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 5.9k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 2,583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash, Agent, Write, Edit, mcp__sc-auditor__run-slither, mcp__sc-auditor__run-adery

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,583 words (~5,877 tokens).

“You are a lean orchestrator for smart contract security audits. You coordinate sub-agents through the Map-Hunt-Attack methodology. You do NOT read contract source code yourself -- you dispatch sub-agents for all heavy phases and collect their structured JSON outputs.”

— opening of SKILL.md by Archethect
name
security-auditor
allowed-tools
Read, Glob, Grep, Bash, Agent, Write, Edit, mcp__sc-auditor__run-slither, mcp__sc-auditor__run-aderyn, mcp__sc-auditor__get_checklist, mcp__sc-auditor__search_findings, mcp__sc-auditor__generate-foundry-poc, mcp__sc-auditor__run-echidna, mcp__sc-auditor__run-medusa, mcp__sc-auditor__run-halmos
argument-hint
<solidity files or directory>

Read the full SKILL.md on GitHub

Files

SKILL.md and 24 other files (assets) in skills/security-auditor of Archethect/sc-auditor.

  • SKILL.md
  • __tests__/skill.test.ts
  • agents/openai.yaml
  • assets/attack-vectors/approval-abuse.md
  • assets/attack-vectors/callback-grief.md
  • assets/attack-vectors/entitlement-drift.md
  • assets/attack-vectors/rounding-entitlement.md
  • assets/attack-vectors/semantic-drift.md
  • assets/hard-negatives/approval-abuse-negatives.md
  • assets/hard-negatives/callback-grief-negatives.md
  • assets/hard-negatives/entitlement-drift-negatives.md
  • assets/hard-negatives/rounding-entitlement-negatives.md
  • assets/hard-negatives/semantic-drift-negatives.md
  • assets/prompts/attack.md
  • assets/prompts/da-protocol.md
  • … and 10 more

Open the folder on GitHubat commit 942cc13

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skillArchethect/sc-auditor127—~5.9kAutomated safety check: NotesNone
Orchestrate Stageseqra/opentaint162—~806Automated safety check: PassApache-2.0
Figma From Code Discovery Assetsbitovi/ai-enablement-prompts121—~1.4kAutomated safety check: PassMIT
Ethereum Smart Contract Vulnerability Analysistradecatlabs/vibe-coding-cn17k1 repos~738Automated safety check: PassApache-2.0
Auditaustintgriffith/ethskills294—~829Automated safety check: PassNone
Web3 Audit Methodology Researchtradecatlabs/vibe-coding-cn17k2 repos~9.9kAutomated safety check: PassMIT

Similar skills

  • Orchestrate Stage

    seqra/opentaint

    Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins.

    162 GitHub stars~806 tokensUpdated today
    SecurityAuto-check passed
  • Figma From Code Discovery Assets

    bitovi/ai-enablement-prompts

    Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts.

    121 GitHub stars~1.4k tokensUpdated 27 days ago
    SecurityAuto-check passed
  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    SecurityAuto-check passed
  • Audit

    austintgriffith/ethskills

    Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

    294 GitHub stars~829 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Web3 Audit Methodology Research

    tradecatlabs/vibe-coding-cn

    Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup.

    17k GitHub starsUsed in 2 repos~9.9k tokens
    SecurityAuto-check passed
  • Official

    Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.

    7.4k GitHub stars~3.1k tokensUpdated today
    SecurityAuto-check passed

Questions about Security Auditor

What does Security Auditor do?

Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting. Security Auditor is an agent skill from Archethect/sc-auditor. Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

When should I use Security Auditor?

Security Auditor fits situations like: tasks that involve Static analysis and SAST; tasks that involve Smart contract auditing; tasks that involve Subagents.

How do I install Security Auditor in Claude Code?

Run `npx skills add Archethect/sc-auditor --skill security-auditor -a claude-code`. Or copy the skill folder (skills/security-auditor in Archethect/sc-auditor) into .claude/skills/security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add Archethect/sc-auditor --skill security-auditor -a codex`. Or copy the skill folder (skills/security-auditor in Archethect/sc-auditor) into .agents/skills/security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Archethect/sc-auditor --skill security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-auditor, .gemini/skills/security-auditor, .github/skills/security-auditor and .opencode/skills/security-auditor in your project.

What does Security Auditor need to run?

Going by SKILL.md and its folder, Security Auditor needs TypeScript for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash, Agent, Write, Edit, mcp__sc-auditor__run-slither, mcp__sc-auditor__run-aderyn, mcp__sc-auditor__get_checklist, mcp__sc-auditor__search_findings, mcp__sc-auditor__generate-foundry-poc, mcp__sc-auditor__run-echidna, mcp__sc-auditor__run-medusa, mcp__sc-auditor__run-halmos.

Does Security Auditor access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Auditor use?

No licence was found for Security Auditor or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Auditor use?

About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Orchestrate Stage (seqra/opentaint, 162 stars), Figma From Code Discovery Assets (bitovi/ai-enablement-prompts, 121 stars), Ethereum Smart Contract Vulnerability Analysis (tradecatlabs/vibe-coding-cn, 17k stars) and Audit (austintgriffith/ethskills, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

Archethect (a GitHub user) maintains it in Archethect/sc-auditor, which has 127 GitHub stars. The repository was last updated on March 13, 2026.

Source: Archethect/sc-auditor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.