Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

No licenceAuto-check passedBackend & APIs

Install Audit

skills CLI
$ npx skills add austintgriffith/ethskills --skill audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install austintgriffith/ethskills audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/austintgriffith/ethskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/audit .claude/skills/audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit
GitHub stars
294
Token cost
~829 tokens
SKILL.md length
262 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
None found

At a glance

Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

  • Works in 7 steps: Fetch the master skill (link above) — it… → Read the contract(s) → Select 5-8 skills using the routing table → …
  • Asked to audit a contract
  • SKILL.md covers The Checklists, Skills Available, How To Run An Audit and Invocation, plus 1 more section
  • Reaches raw.githubusercontent.com and github.com

What it does

Audit is an agent skill from austintgriffith/ethskills. Deep EVM smart contract security audit system. Use when asked to audit a contract, find vulnerabilities, review code for security issues, or file security issues on a GitHub repo. Covers 500+ non-obvious checklist items across 19 domains via parallel sub-agents. Different from the security skill (which teaches defensive coding) — this is for systematically auditing contracts you didn't write.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts, Smart contract auditing and Subagents. It works with GitHub. The repository describes itself as: The missing knowledge between AI agents and production Ethereum.

When your agent uses it

  • Asked to audit a contract
  • Find vulnerabilities
  • Review code for security issues
  • File security issues on a GitHub repo

Example prompts

  • “/audit”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Fetch the master skill (link above) — it has the full pipeline
  2. Read the contract(s)
  3. Select 5-8 skills using the routing table
  4. Spawn one opus sub-agent per skill (parallel)
  5. Each agent walks its checklist and writes findings-.md
  6. Synthesize all findings into AUDIT-REPORT.md
  7. File GitHub issues for Medium severity and above

What it can do on your machine

Read from SKILL.md and the folder at commit 06ea4ef. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit loads about 829 tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~829

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 262 words (~829 tokens).

“A full audit system for any EVM contract. Runs parallel specialist agents against domain-specific checklists, synthesizes findings, and files GitHub issues.”

— opening of SKILL.md by austintgriffith
name
audit

Read the full SKILL.md on GitHub

Files

Just SKILL.md in audit of austintgriffith/ethskills.

Open the folder on GitHubat commit 06ea4ef

Compare with similar skills

Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit this skillaustintgriffith/ethskills294—~829Automated safety check: PassNone
Copilot PR Autopilotgithub/awesome-copilot40k—~3.4kAutomated safety check: PassMIT
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
Local PR Reviewwindmill-labs/windmill18k—~995Automated safety check: PassCustom licence

Similar skills

  • Copilot PR Autopilot

    github/awesome-copilot

    Official

    Copilot left 14 review comments on your PR — half are nits. An agent skill from github/awesome-copilot.

    40k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Local PR Review

    windmill-labs/windmill

    Runs the same code review locally that GitHub's auto-review actions run on a PR, delegating to a fresh-context subagent so the review isn't biased by the main session's own reasoning.

    18k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed
  • Zen Comprehensive Review

    EliasOulkadi/shokunin

    Orchestrate a multi-model code review: spawn 3 review subagents, merge findings.

    114 GitHub stars~4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from austintgriffith/ethskills

All 22 skills in this repo
  • Building Blocks

    austintgriffith/ethskills

    DeFi legos and protocol composability on Ethereum and L2s. An agent skill from austintgriffith/ethskills.

    294 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Concepts

    austintgriffith/ethskills

    The essential mental models for building onchain — focused on what LLMs get wrong and what humans need explained.

    294 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Ethskills

    austintgriffith/ethskills

    Ethereum development knowledge for AI agents — from idea to deployed dApp.

    294 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Frontend Playbook

    austintgriffith/ethskills

    The complete build-to-production pipeline for Ethereum dApps.

    294 GitHub stars~3.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Frontend UX

    austintgriffith/ethskills

    Frontend UX rules for Ethereum dApps that prevent the most common AI agent UI bugs.

    294 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Gas

    austintgriffith/ethskills

    Current Ethereum gas prices, transaction costs, and the real economics of building on Ethereum today.

    294 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Audit

What does Audit do?

Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills. Audit is an agent skill from austintgriffith/ethskills. Deep EVM smart contract security audit system.

When should I use Audit?

Audit fits situations like: asked to audit a contract; find vulnerabilities; review code for security issues; file security issues on a GitHub repo.

How do I install Audit in Claude Code?

Run `npx skills add austintgriffith/ethskills --skill audit -a claude-code`. Or copy the skill folder (audit in austintgriffith/ethskills) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.

How do I install Audit in Codex?

Run `npx skills add austintgriffith/ethskills --skill audit -a codex`. Or copy the skill folder (audit in austintgriffith/ethskills) into .agents/skills/audit in your project. Codex loads it when a task matches its description.

Can I use Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add austintgriffith/ethskills --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.

What does Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit is instructions for the agent only.

Does Audit access the network?

SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit use?

No licence was found for Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Audit use?

About 829 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit?

Skills that share tags, products or a category with Audit: Copilot PR Autopilot (github/awesome-copilot, 40k stars), GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars) and PR Review (jaemk/self_update, 961 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit?

austintgriffith (a GitHub user) maintains it in austintgriffith/ethskills, which has 294 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on August 20, 2026.

Source: austintgriffith/ethskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.