Agent skill

Radar

by Auditware in Auditware/radar

Use radar for smart contract security analysis, AST generation, and detection template development.

GPL-3.0Auto-check passedBackend & APIs

Install Radar

skills CLI
$ npx skills add Auditware/radar --skill radar -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Auditware/radar radar --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Auditware/radar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/radar .claude/skills/radar && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
radar
GitHub stars
154
Token cost
~2.1k tokens
SKILL.md length
1,110 words
Files
5 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
GPL-3.0

At a glance

Use radar for smart contract security analysis, AST generation, and detection template development.

  • Works in 3 steps: Every rule body runs inside try: …… → The DSL is a sandbox with eight… → language: and accent: gate execution. A…
  • Include scanning contracts for vulnerabilities
  • SKILL.md covers How the pipeline actually works, Three ways a template fails…, The loop and The gates, and what each one…, plus 4 more sections
  • Calls poetry and make

What it does

Radar is an agent skill from Auditware/radar. Use radar for smart contract security analysis, AST generation, and detection template development. Covers Rust (Anchor, native Solana, Stylus) and Solidity (standalone, Foundry). Triggers include scanning contracts for vulnerabilities, generating or inspecting a contract AST, writing or debugging a radar template, adding DSL utility functions, and contributing detection rules back to radar. Use when users mention radar, radar templates, the radar DSL, AST generation for Rust/Solidity/Anchor/Stylus/Foundry, or…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/ast-shape.md`, `references/contributing.md` and `references/dsl.md`). Compatibility notes: docker, radar cli

It sits in Backend & APIs, covering Smart contracts. It works with Solidity, Rust, Solana and Arbitrum. The repository describes itself as: A static analysis tool for rust, anchor, stylus, and solidity smart contracts. The licence is GPL-3.0.

When your agent uses it

  • Include scanning contracts for vulnerabilities
  • Inspecting a contract AST
  • Debugging a radar template
  • Adding DSL utility functions

Example prompts

  • “/radar”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): docker, radar cli

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Every rule body runs inside try: … except: continue. A misspelled method, wrong arity, or a Rust method called on a Solidity node raises…
  2. The DSL is a sandbox with eight builtins: print len range dict list tuple set type. No imports. any(), all(), sorted(), enumerate()…
  3. language: and accent: gate execution. A template only runs when its language matches the detected project language (default rust) and, for…

What it can do on your machine

Read from SKILL.md and the folder at commit 3439053. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • poetry
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    docker, radar cli

    From compatibility in the SKILL.md frontmatter.

Context cost

Radar loads about 2.1k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 1,110 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Auditware/radar at commit 3439053, republished under its GPL-3.0 licence (© Auditware). 1,110 words, ~2,147 tokens.

Download SKILL.mdSave it as .claude/skills/radar/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
radar
description
Use radar for smart contract security analysis, AST generation, and detection template development. Covers Rust (Anchor, native Solana, Stylus) and Solidity (standalone, Foundry). Triggers include scanning contracts for vulnerabilities, generating or inspecting a contract AST, writing or debugging a radar template, adding DSL utility functions, and contributing detection rules back to radar. Use when users mention radar, radar templates, the radar DSL, AST generation for Rust/Solidity/Anchor/Stylus/Foundry, or smart contract vulnerability scanning.
compatibility
docker, radar cli

radar

Use radar to perform a full, 100% coverage security scan for critical vulnerabilities. start with running all templates per the targeted language, take insights from them as low hanging fruits, and continue to manual audit. at the end - reflect back to templates that could've done better, or engine utility improvements - and offer to PR new improvements for the next cycle.

How the pipeline actually works

SourceParserNode class in rules
Rust - Anchor, native Solana, Stylusrust_syn (syn 2 via syn-serde)RustASTNode
Solidity, Foundrysolc-select + solcSolidityASTNode

The two node classes have different method sets. A rule gets one or the other based on its language: field - never both. Solidity is currently 68 of the 124 builtin templates, so check which side you are on before reaching for a method.

radar needs a running Docker daemon; every scan starts a compose stack. Template iteration does not - see the loop below.

Three ways a template fails silently

Nearly every "my rule doesn't work" is one of these. None of them produce an error you will see.

  1. Every rule body runs inside try: … except: continue. A misspelled method, wrong arity, or a Rust method called on a Solidity node raises, gets swallowed, and the file is skipped. No findings looks identical to no vulnerability. When a rule reports nothing, suspect a broken call before you suspect the pattern.
  2. The DSL is a sandbox with eight builtins: print len range dict list tuple set type. No imports. any(), all(), sorted(), enumerate(), str(), int() raise RuntimeError - into the except above. Use .nodes truthiness, explicit loops, and len().
  3. language: and accent: gate execution. A template only runs when its language matches the detected project language (default rust) and, for Rust, its accent matches the detected framework. Get these wrong and the template is filtered out before it runs: no error, no failing test, no output. Solidity templates use accent: "" and language: solidity. There is no accent: solidity.

The loop

0. Do not write a duplicate. 124 templates already ship. ./radar list-templates, and grep api/builtin_templates/*.yaml for the vulnerability class. If one is close, extend it or sharpen its focus - a near-duplicate is a maintenance cost with no new coverage.

1. Read the AST of a contract that has the bug. ./radar --dev -p <path> --ast -o out.json writes findings to out.json and the AST to ast.json beside it - two files. See references/ast-shape.md; the shape is not what you would guess.

2. Draft the rule against what the AST actually contains, not against the source you read. Inside a rule, some_nodes.to_raw_ast_debug() prints the enriched view (with access_path) at that point - add the call, do not wrap it in print().

3. Iterate in-process, not through Docker. For Anchor templates:

bash
cd api && poetry run python tests/check_scoping.py <template_stem>

Seconds per iteration, no daemon, and it reports detections on bad/ and good/ separately. It parses Rust live, so it needs rust_syn built once (references/contributing.md); inside the api container it is already there. It drives the Rust path only - Solidity rules iterate through the pytest suite.

4. Prove both directions before you believe it. The bad mock must detect; the good mock must be silent. One direction alone is not evidence.

5. Pin what you just proved, so the next person's tuning cannot quietly undo it - a noise fixture, a detection fixture, or both (see the gates below).

6. Register it in EXPECTED_DETECTIONS with exact file:line:startcol-endcol spans, and add the mock pair. A template with no entry is silently dropped from the accuracy suite and CI stays green. Full contract: references/contributing.md.

7. Generate the fixtures, then run the full suite - cd api && poetry run python scripts/generate_fixtures.py, then make test-all from the repo root. Plain make test skips the active_runtime suites, which are the ones that parse real source.

Show full SKILL.md (487 more words)Show less

The gates, and what each one exists to catch

Radar's test suite is a record of how detection rules have actually gone wrong here. Know which gate catches which mistake:

GateCatches
tests/check_scoping.pyRule fires on bad/ but not good/ - the fast dev loop
tests/test_templates.pyWrong span; template missing its mock pair or its EXPECTED_DETECTIONS entry
tests/noise_fixtures/False positives. Written after a benchmark found 24 of 52 findings landing on already-fixed code (#32)
tests/detection_fixtures/Lost recall. Written after narrowing rules for precision silently killed four real detections (#33/#34)
tests/corpus2_regression.pyOut-of-sample drift, scored by someone else's mapping over real bugs
tests/test_span_accuracy.pyFindings whose line does not point at the cause

Zero false positives, honestly

Zero false positives is an absolute requirement, and it has an equal and opposite failure: a rule narrowed until it detects nothing is not precise, it is empty. That is exactly how four rules regressed in #33. Every tightening pass needs a detection fixture holding the other end.

  • Say how sure you are. certainty is the auditor's judgment, not a form field. The corpus is honest about this: 121 of 124 templates declare Low or Medium; only 3 claim High. A heuristic with a plausible benign shape is Low, and that is a normal, shippable answer.
  • Point at the cause. The reported span must land on the line that is wrong - not the enclosing function, not the file, never an import.
  • Generalize the pattern, don't fit the mock. No hard-coded names, no contract-specific values. The rule should catch a variant it has never seen.
  • Never ship a rule that cannot fire. Worse than no rule, because it reads as coverage the scanner does not have. If it is architecturally undetectable, record it in ARCHITECTURALLY_UNDETECTABLE with the reason instead of leaving it silently green.

When to extend the DSL instead of the rule

A rule fighting the DSL is a signal, not a challenge. Median rule body is 23 lines; well past that usually means a missing utility. Escalate in this order:

  1. A rule-level workaround - only if it is idiomatic and clean.
  2. A new utility on RustASTNode / SolidityASTNode in api/utils/dsl/, following the traversal style of its neighbours. First check whether an existing util is merely faulty and needs a small fix - that is the better patch.
  3. The core enrichment in api/utils/ast.py - rare, and only with a span test.

A good utility aggregates a relation that several rules will want (a lookup, a traversal, a comparison shape), not one contract's quirk. references/util-authoring.md carries the full protocol.

Scanning

bash
./radar -p <path>                      # scan
./radar -p <path> -o out.json          # .json | .md | .sarif by extension
./radar -p <path> --ast -o out.json    # + ast.json beside it
./radar -p <path> -t ./my-templates    # custom templates (dir or single .yaml)
./radar -p <path> --fail-on high       # CI gate: critical|high|medium|low|none
./radar -p <path> -b baseline.json     # suppress known findings

Exit codes: 0 clean, 1 findings at or above --fail-on, 2 operational error. Severities are Critical|High|Medium|Low; --ignore takes severities plus uncertain. --ast never skips scanning - it only adds output.

References

  • references/ast-shape.md - what ast.json really contains, and how to read it
  • references/dsl.md - corrections to docs/Rule-Functions.md, and the Solidity method set
  • references/contributing.md - the template schema and the full test contract
  • references/util-authoring.md - the protocol for adding a DSL utility

© Auditware, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .claude/skills/radar of Auditware/radar.

  • SKILL.md
  • references/ast-shape.md
  • references/contributing.md
  • references/dsl.md
  • references/util-authoring.md

Open the folder on GitHubat commit 3439053

Compare with similar skills

Radar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Radar compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Radar this skillAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Feynman Auditor0xiehnnkta/nemesis-auditor2441 repos~11kAutomated safety check: PassMIT
Safe Solana BuilderFrankcastleauditor/safe-solana-builder145—~3.6kAutomated safety check: PassNone
Wiremock TestOpenZeppelin/openzeppelin-relayer153—~1.6kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    244 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Safe Solana Builder

    Frankcastleauditor/safe-solana-builder

    A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.

    145 GitHub stars~3.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Wiremock Test

    OpenZeppelin/openzeppelin-relayer

    Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.

    153 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Evm Maintainer

    RaoFoundation/subtensor

    Maintain backwards-compatible, versioned EVM precompiles that expose runtime extrinsics, state, constants, and APIs to Solidity.

    387 GitHub stars~2.5k tokensUpdated today
    Backend & APIsAuto-check passed

Categories

Questions about Radar

What does Radar do?

Use radar for smart contract security analysis, AST generation, and detection template development. Radar is an agent skill from Auditware/radar. Use radar for smart contract security analysis, AST generation, and detection template development.

When should I use Radar?

Radar fits situations like: include scanning contracts for vulnerabilities; inspecting a contract AST; debugging a radar template; adding DSL utility functions.

How do I install Radar in Claude Code?

Run `npx skills add Auditware/radar --skill radar -a claude-code`. Or copy the skill folder (.claude/skills/radar in Auditware/radar) into .claude/skills/radar in your project. Claude Code loads it when a task matches its description.

How do I install Radar in Codex?

Run `npx skills add Auditware/radar --skill radar -a codex`. Or copy the skill folder (.claude/skills/radar in Auditware/radar) into .agents/skills/radar in your project. Codex loads it when a task matches its description.

Can I use Radar in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Auditware/radar --skill radar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/radar, .gemini/skills/radar, .github/skills/radar and .opencode/skills/radar in your project.

What does Radar need to run?

Going by SKILL.md and its folder, Radar needs the command-line tools its instructions call (poetry and make). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): docker, radar cli.

Does Radar access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Radar safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Radar use?

Radar is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Radar use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Radar?

Skills that share tags, products or a category with Radar: Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 244 stars) and Safe Solana Builder (Frankcastleauditor/safe-solana-builder, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Radar?

Auditware (a GitHub organization) maintains it in Auditware/radar, which has 154 GitHub stars. The repository was last updated on September 7, 2026.

Source: Auditware/radar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.