Smart Contract Audit
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
Use radar for smart contract security analysis, AST generation, and detection template development.
$ npx skills add Auditware/radar --skill radar -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Auditware/radar radar --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/radar .claude/skills/radar && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .claude/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Auditware/radar/tree/main/.claude/skills/radarType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Auditware/radar --skill radar -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Auditware/radar radar --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/radar .agents/skills/radar && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .agents/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Auditware/radar --skill radar -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Auditware/radar radar --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/radar .cursor/skills/radar && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .cursor/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Auditware/radar.git --path .claude/skills/radar--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Auditware/radar --skill radar -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Auditware/radar radar --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/radar .gemini/skills/radar && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .gemini/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Auditware/radar radarInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Auditware/radar --skill radar -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/radar .github/skills/radar && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .github/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Auditware/radar --skill radar -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Auditware/radar radar --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/radar .opencode/skills/radar && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "radar" agent skill from https://github.com/Auditware/radar/tree/main/.claude/skills/radar into .opencode/skills/radar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "radar", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
radarUse radar for smart contract security analysis, AST generation, and detection template development.
Radar is an agent skill from Auditware/radar. Use radar for smart contract security analysis, AST generation, and detection template development. Covers Rust (Anchor, native Solana, Stylus) and Solidity (standalone, Foundry). Triggers include scanning contracts for vulnerabilities, generating or inspecting a contract AST, writing or debugging a radar template, adding DSL utility functions, and contributing detection rules back to radar. Use when users mention radar, radar templates, the radar DSL, AST generation for Rust/Solidity/Anchor/Stylus/Foundry, or…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/ast-shape.md`, `references/contributing.md` and `references/dsl.md`). Compatibility notes: docker, radar cli
It sits in Backend & APIs, covering Smart contracts. It works with Solidity, Rust, Solana and Arbitrum. The repository describes itself as: A static analysis tool for rust, anchor, stylus, and solidity smart contracts. The licence is GPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3439053. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
poetrymakeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
docker, radar cli
From compatibility in the SKILL.md frontmatter.
Radar loads about 2.1k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 1,110 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Auditware/radar at commit 3439053, republished under its GPL-3.0 licence (© Auditware). 1,110 words, ~2,147 tokens.
.claude/skills/radar/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Use radar to perform a full, 100% coverage security scan for critical vulnerabilities. start with running all templates per the targeted language, take insights from them as low hanging fruits, and continue to manual audit. at the end - reflect back to templates that could've done better, or engine utility improvements - and offer to PR new improvements for the next cycle.
| Source | Parser | Node class in rules |
|---|---|---|
| Rust - Anchor, native Solana, Stylus | rust_syn (syn 2 via syn-serde) | RustASTNode |
| Solidity, Foundry | solc-select + solc | SolidityASTNode |
The two node classes have different method sets. A rule gets one or the other based on its language: field - never both. Solidity is currently 68 of the 124 builtin templates, so check which side you are on before reaching for a method.
radar needs a running Docker daemon; every scan starts a compose stack. Template iteration does not - see the loop below.
Nearly every "my rule doesn't work" is one of these. None of them produce an error you will see.
try: … except: continue. A misspelled method, wrong arity, or a Rust method called on a Solidity node raises, gets swallowed, and the file is skipped. No findings looks identical to no vulnerability. When a rule reports nothing, suspect a broken call before you suspect the pattern.print len range dict list tuple set type. No imports. any(), all(), sorted(), enumerate(), str(), int() raise RuntimeError - into the except above. Use .nodes truthiness, explicit loops, and len().language: and accent: gate execution. A template only runs when its language matches the detected project language (default rust) and, for Rust, its accent matches the detected framework. Get these wrong and the template is filtered out before it runs: no error, no failing test, no output. Solidity templates use accent: "" and language: solidity. There is no accent: solidity.0. Do not write a duplicate. 124 templates already ship. ./radar list-templates, and grep api/builtin_templates/*.yaml for the vulnerability class. If one is close, extend it or sharpen its focus - a near-duplicate is a maintenance cost with no new coverage.
1. Read the AST of a contract that has the bug. ./radar --dev -p <path> --ast -o out.json writes findings to out.json and the AST to ast.json beside it - two files. See references/ast-shape.md; the shape is not what you would guess.
2. Draft the rule against what the AST actually contains, not against the source you read. Inside a rule, some_nodes.to_raw_ast_debug() prints the enriched view (with access_path) at that point - add the call, do not wrap it in print().
3. Iterate in-process, not through Docker. For Anchor templates:
cd api && poetry run python tests/check_scoping.py <template_stem>Seconds per iteration, no daemon, and it reports detections on bad/ and good/ separately. It parses Rust live, so it needs rust_syn built once (references/contributing.md); inside the api container it is already there. It drives the Rust path only - Solidity rules iterate through the pytest suite.
4. Prove both directions before you believe it. The bad mock must detect; the good mock must be silent. One direction alone is not evidence.
5. Pin what you just proved, so the next person's tuning cannot quietly undo it - a noise fixture, a detection fixture, or both (see the gates below).
6. Register it in EXPECTED_DETECTIONS with exact file:line:startcol-endcol spans, and add the mock pair. A template with no entry is silently dropped from the accuracy suite and CI stays green. Full contract: references/contributing.md.
7. Generate the fixtures, then run the full suite - cd api && poetry run python scripts/generate_fixtures.py, then make test-all from the repo root. Plain make test skips the active_runtime suites, which are the ones that parse real source.
Radar's test suite is a record of how detection rules have actually gone wrong here. Know which gate catches which mistake:
| Gate | Catches |
|---|---|
tests/check_scoping.py | Rule fires on bad/ but not good/ - the fast dev loop |
tests/test_templates.py | Wrong span; template missing its mock pair or its EXPECTED_DETECTIONS entry |
tests/noise_fixtures/ | False positives. Written after a benchmark found 24 of 52 findings landing on already-fixed code (#32) |
tests/detection_fixtures/ | Lost recall. Written after narrowing rules for precision silently killed four real detections (#33/#34) |
tests/corpus2_regression.py | Out-of-sample drift, scored by someone else's mapping over real bugs |
tests/test_span_accuracy.py | Findings whose line does not point at the cause |
Zero false positives is an absolute requirement, and it has an equal and opposite failure: a rule narrowed until it detects nothing is not precise, it is empty. That is exactly how four rules regressed in #33. Every tightening pass needs a detection fixture holding the other end.
certainty is the auditor's judgment, not a form field. The corpus is honest about this: 121 of 124 templates declare Low or Medium; only 3 claim High. A heuristic with a plausible benign shape is Low, and that is a normal, shippable answer.ARCHITECTURALLY_UNDETECTABLE with the reason instead of leaving it silently green.A rule fighting the DSL is a signal, not a challenge. Median rule body is 23 lines; well past that usually means a missing utility. Escalate in this order:
RustASTNode / SolidityASTNode in api/utils/dsl/, following the traversal style of its neighbours. First check whether an existing util is merely faulty and needs a small fix - that is the better patch.api/utils/ast.py - rare, and only with a span test.A good utility aggregates a relation that several rules will want (a lookup, a traversal, a comparison shape), not one contract's quirk. references/util-authoring.md carries the full protocol.
./radar -p <path> # scan
./radar -p <path> -o out.json # .json | .md | .sarif by extension
./radar -p <path> --ast -o out.json # + ast.json beside it
./radar -p <path> -t ./my-templates # custom templates (dir or single .yaml)
./radar -p <path> --fail-on high # CI gate: critical|high|medium|low|none
./radar -p <path> -b baseline.json # suppress known findingsExit codes: 0 clean, 1 findings at or above --fail-on, 2 operational error. Severities are Critical|High|Medium|Low; --ignore takes severities plus uncertain. --ast never skips scanning - it only adds output.
references/ast-shape.md - what ast.json really contains, and how to read itreferences/dsl.md - corrections to docs/Rule-Functions.md, and the Solidity method setreferences/contributing.md - the template schema and the full test contractreferences/util-authoring.md - the protocol for adding a DSL utility© Auditware, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in .claude/skills/radar of Auditware/radar.
Open the folder on GitHubat commit 3439053
Radar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Radar this skillAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Smart Contract Auditforefy/.context | 152 | 1 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Smart Contract Auditelophanto/EloPhanto | 106 | — | ~2.7k | Automated safety check: Pass | Custom licence | |
| Feynman Auditor0xiehnnkta/nemesis-auditor | 244 | 1 repos | ~11k | Automated safety check: Pass | MIT | |
| Safe Solana BuilderFrankcastleauditor/safe-solana-builder | 145 | — | ~3.6k | Automated safety check: Pass | None | |
| Wiremock TestOpenZeppelin/openzeppelin-relayer | 153 | — | ~1.6k | Automated safety check: Notes | AGPL-3.0 |
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
0xiehnnkta/nemesis-auditor
Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.
Frankcastleauditor/safe-solana-builder
A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.
OpenZeppelin/openzeppelin-relayer
Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.
RaoFoundation/subtensor
Maintain backwards-compatible, versioned EVM precompiles that expose runtime extrinsics, state, constants, and APIs to Solidity.
Categories
Use radar for smart contract security analysis, AST generation, and detection template development. Radar is an agent skill from Auditware/radar. Use radar for smart contract security analysis, AST generation, and detection template development.
Radar fits situations like: include scanning contracts for vulnerabilities; inspecting a contract AST; debugging a radar template; adding DSL utility functions.
Run `npx skills add Auditware/radar --skill radar -a claude-code`. Or copy the skill folder (.claude/skills/radar in Auditware/radar) into .claude/skills/radar in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Auditware/radar --skill radar -a codex`. Or copy the skill folder (.claude/skills/radar in Auditware/radar) into .agents/skills/radar in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Auditware/radar --skill radar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/radar, .gemini/skills/radar, .github/skills/radar and .opencode/skills/radar in your project.
Going by SKILL.md and its folder, Radar needs the command-line tools its instructions call (poetry and make). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): docker, radar cli.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Radar is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Radar: Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 244 stars) and Safe Solana Builder (Frankcastleauditor/safe-solana-builder, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Auditware (a GitHub organization) maintains it in Auditware/radar, which has 154 GitHub stars. The repository was last updated on September 7, 2026.
Source: Auditware/radar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.