Agent skill

Smart Contract Report

by aviggiano in aviggiano/security

Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…

MITAuto-check passedBackend & APIs

Install Smart Contract Report

skills CLI
$ npx skills add aviggiano/security --skill smart-contract-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aviggiano/security smart-contract-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/smart-contract-report .claude/skills/smart-contract-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smart-contract-report
GitHub stars
144
Token cost
~2.4k tokens
SKILL.md length
1,307 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…

  • Works in 4 steps: Report title. → Issue index with Issue ID and linked… → Issue entries, ordered H/M/L/I. → …
  • Tasks that involve Smart contracts
  • SKILL.md covers Evidence and scope, Report opening, Severity ratings and Issue identity and titles, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Smart Contract Report is an agent skill from aviggiano/security. Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of concept, and remediation diffs.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts, Unit testing and Smart contract auditing. The repository describes itself as: Security Reviews and Audit Checklists. The licence is MIT.

When your agent uses it

  • Tasks that involve Smart contracts
  • Tasks that involve Unit testing
  • Tasks that involve Smart contract auditing

Example prompts

  • “/smart-contract-report”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Report title.
  2. Issue index with Issue ID and linked Title columns, ordered H/M/L/I. Keep
  3. Issue entries, ordered H/M/L/I.
  4. An optional appendix for unresolved candidates or material review limitations.

What it can do on your machine

Read from SKILL.md and the folder at commit e18ce7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart Contract Report loads about 2.4k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,307 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aviggiano/security at commit e18ce7d, republished under its MIT licence (© aviggiano). 1,307 words, ~2,396 tokens.

Download SKILL.mdSave it as .claude/skills/smart-contract-report/SKILL.md (or your agent's skills folder).
name
smart-contract-report
description
Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of concept, and remediation diffs.

Smart Contract Report

Prepare smart-contract-report.md from supplied audit findings, source context, existing test evidence, and proposed fixes. Use another output path when requested. This skill prepares the document; submit it externally only when the user specifies the destination and authorizes submission.

Evidence and scope

  • Identify the reviewed repository, revision, scope, protocol roles, and supplied findings. Mark unavailable context explicitly; never invent test results, affected locations, assumptions, or validation status.
  • Report established issues separately from unresolved candidates. Preserve source finding identities in working notes when assigning presentation IDs. Merge duplicates only when they share the same root cause and remediation.
  • Preserve supplied PoCs when they accurately reproduce the finding. When a PoC is missing, reconstruct the smallest self-contained unit test that demonstrates the reported behavior against the reviewed revision. Keep it within the supplied finding's actors, preconditions, and consequence; do not target live systems or expand into unrelated exploit discovery. Validate it in an isolated copy when feasible and record the command and observed result. If execution is unavailable or the test does not reproduce the issue, state that clearly and keep the report as a draft.
  • Preserve the distinction between observed behavior and inferred consequences. If a supplied classification conflicts with the severity rubric, surface the conflict instead of silently changing an authoritative assessment.

Report opening

Use this order:

  1. Report title.
  2. Issue index with Issue ID and linked Title columns, ordered H/M/L/I. Keep the index directly after the title; do not add a separate table of contents.
  3. Issue entries, ordered H/M/L/I.
  4. An optional appendix for unresolved candidates or material review limitations.

Do not add a separate summary/count block or severity-matrix section unless the user requests one. A report with no established issues still includes the index. Do not equate zero findings with protocol safety.

Severity ratings

Use only Low, Medium, and High for security severity, impact, and likelihood. Do not include a severity matrix in the report. Assign severity as follows: Low impact is Low at every likelihood; Medium impact is Low at Low likelihood and Medium otherwise; High impact is Medium at Low likelihood and High otherwise.

Impact describes the supported consequence: High requires direct asset loss or compromise; Medium materially affects protocol operation, availability, accounting, or value; Low covers limited defects with minor consequences. Likelihood describes the realistic trigger conditions: High means reliably reachable by an ordinary participant or naturally occurring in realistic use; Medium requires meaningful but plausible conditions; Low requires restrictive conditions or trusted participation. Explain the actual assumptions in each issue.

Assess intended privileged operations separately from administrator mistakes and intentional misuse of trusted powers. State the protocol's trust assumptions; do not infer an unprivileged attack from an administrator-only action. Unsupported assumptions cannot establish High or Medium risk.

Informational is a separate category for established observations without a demonstrated security consequence; it is outside the matrix. Do not use it to hide unresolved vulnerability candidates.

Issue identity and titles

  • Stable-sort entries High, Medium, Low, Informational; preserve input order within each category.
  • Assign independent, consecutive counters for each severity. Choose one digit width per severity from its total issue count: the greater of two digits or the digits needed to represent that count. Zero-pad every ID in that severity to the same width. For example, 101 High issues use H-001 through H-101, including H-100, while 12 Medium issues use M-01 through M-12. Apply the same rule to Low and Informational issues and update all references together.
  • Use headings shaped as ## [H-01] - Attacker can drain vault due to incorrect permissions. This is a title example, not a claim about the reviewed protocol.
  • Write the concrete outcome and its cause. Prefer an actor when one is relevant. Avoid titles that merely name a bug class or exaggerate the supported consequence.
  • Keep IDs and titles identical in the index and entry headings.

Each issue

Description

Explain the affected behavior, root cause, necessary conditions, expected behavior, and supported consequence. Identify affected contracts or functions when known. Keep the narrative understandable without opening an external artifact. Source links may supplement the explanation, but must not replace it.

Risk assessment

For H/M/L entries, include three bullets, each with a one-sentence explanation:

  • Severity: rating followed by why this impact/likelihood combination produces it.
  • Likelihood: rating followed by the actors, permissions, and conditions needed.
  • Impact: rating followed by the concrete effect on assets or protocol behavior.

Format each as - **Label**: Rating: Explanation. Severity must follow the severity rubric. For informational entries, omit this entire risk assessment; the I- identifier establishes their classification.

Show full SKILL.md (556 more words)Show less
Proof of Concept

This section applies only to H/M/L entries. Informational entries omit the entire Proof of Concept section, including numbered scenarios and test code.

Place a short human-readable numbered list of actor actions first, sorted in chronological execution order. Start each step with the actor, followed by the concrete action and its relevant result. Include the setup actions needed to understand how the final consequence occurs.

Prefer Attacker and Victim when adversarial and harmed participants are applicable. Otherwise use the protocol's usual roles, such as Depositor, Borrower, Liquidator, User, or Administrator. Keep names consistent across the scenario and test, and distinguish multiple participants as Victim A and Victim B or Depositor A and Depositor B. Avoid anonymous variables and Alice/Bob when a role is available.

Example of the required presentation, only when supported by the supplied finding:

  1. Victim deposits 100 MON into the protocol.
  2. Attacker calls redeem and drains the protocol.

Describe setup, relevant actions in their observed order, and the resulting observable consequence. Keep the scenario faithful to the supplied evidence; do not add an unsupported attack sequence.

Immediately after the numbered scenario, include a self-contained unit-test PoC in a language-tagged code fence. Use an accurate supplied PoC when available; otherwise reconstruct it from the finding and reviewed source. Use the project's existing test framework. A self-contained test includes its imports, setup, fixtures, mocks, helpers, and meaningful assertions, and may depend on the reviewed repository and its declared dependencies. It must not depend on another finding's snippet or undisclosed local files. Do not replace code with a file link, ellipsis, or an invented passing result.

Label the PoC as supplied or reconstructed. Include the test filename, execution command, prerequisites, and recorded validation result when available. Distinguish an observed successful reproduction from unverified source. A test confirming the fix must be labeled separately. If required evidence is unavailable, identify the gap and mark the report as a draft rather than claiming it is submission-ready.

Remediation

Briefly explain the proposed fix, then show it in a fenced diff block using git unified-diff syntax, including diff --git, --- a/..., +++ b/..., and accurate hunk headers and context. Base the diff on the reviewed revision, with actual repository paths and code. Include documentation diffs when the fix is documentary. Avoid pseudo-diffs, placeholder code, and unrelated refactoring.

When source is available, check patch applicability against the reviewed revision in an isolated copy. Record validation honestly. Do not apply proposed fixes to the user's working tree merely to prepare a report. If a fix cannot yet be specified, describe the missing decision and mark remediation as pending. For an informational observation requiring no change, use Not applicable with a reason instead of an empty diff.

Final review

Before calling the report submission-ready, check:

  • Index links resolve to actual headings.
  • IDs are unique, consecutive, and uniformly zero-padded within each severity according to its total count; order is H/M/L/I.
  • Each H/M/L entry has a supported outcome-based title and three concise risk explanations, with severity following the rubric.
  • Every H/M/L issue has its numbered scenario before its self-contained unit-test evidence, followed by remediation. Informational entries have neither a risk assessment nor a Proof of Concept section; they proceed from description to remediation.
  • Supplied or reconstructed tests and patches are complete, and validation claims match recorded evidence. Missing evidence and pending remediation remain visible.

© aviggiano, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/smart-contract-report of aviggiano/security.

Open the folder on GitHubat commit e18ce7d

Compare with similar skills

Smart Contract Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart Contract Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart Contract Report this skillaviggiano/security144—~2.4kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Stellar DevVelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT
Auditaustintgriffith/ethskills295—~829Automated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • Stellar Dev

    VelaPayments/vela-payments

    End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

    131 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Audit

    austintgriffith/ethskills

    Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

    295 GitHub stars~829 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub stars~9.9k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from aviggiano/security

All 10 skills in this repo
  • Foundry Deploy Fixtures

    aviggiano/security

    Create or refactor Foundry deployment fixtures for Solidity tests.

    144 GitHub stars~634 tokensUpdated 25 days ago
    Auto-check passed
  • Foundry Fuzz Mirrors

    aviggiano/security

    Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security.

    144 GitHub stars~584 tokensUpdated 25 days ago
    Auto-check passed
  • Foundry Spec Properties

    aviggiano/security

    Turn whitepapers, protocol specs, and public documentation into Foundry property tests.

    144 GitHub stars~489 tokensUpdated 25 days ago
    Auto-check passed
  • Foundry Test Campaign

    aviggiano/security

    Master skill for running an end-to-end multi-pass Foundry testing campaign for Solidity projects.

    144 GitHub stars~1.6k tokensUpdated 25 days ago
    Auto-check passed
  • Stateful Invariant Testing

    aviggiano/security

    Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

    144 GitHub stars~2.8k tokensUpdated 25 days ago
    Auto-check passed
  • Foundry Differential Tests

    aviggiano/security

    Create Foundry differential tests comparing production Solidity contracts against an independent reference model.

    144 GitHub stars~613 tokensUpdated 25 days ago
    Auto-check passed

Questions about Smart Contract Report

What does Smart Contract Report do?

Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…. Smart Contract Report is an agent skill from aviggiano/security. Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of concept, and remediation diffs.

When should I use Smart Contract Report?

Smart Contract Report fits situations like: tasks that involve Smart contracts; tasks that involve Unit testing; tasks that involve Smart contract auditing.

How do I install Smart Contract Report in Claude Code?

Run `npx skills add aviggiano/security --skill smart-contract-report -a claude-code`. Or copy the skill folder (skills/smart-contract-report in aviggiano/security) into .claude/skills/smart-contract-report in your project. Claude Code loads it when a task matches its description.

How do I install Smart Contract Report in Codex?

Run `npx skills add aviggiano/security --skill smart-contract-report -a codex`. Or copy the skill folder (skills/smart-contract-report in aviggiano/security) into .agents/skills/smart-contract-report in your project. Codex loads it when a task matches its description.

Can I use Smart Contract Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aviggiano/security --skill smart-contract-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-report, .gemini/skills/smart-contract-report, .github/skills/smart-contract-report and .opencode/skills/smart-contract-report in your project.

What does Smart Contract Report need to run?

SKILL.md names no scripts, command-line tools or credentials: Smart Contract Report is instructions for the agent only.

Does Smart Contract Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart Contract Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Smart Contract Report use?

Smart Contract Report is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Smart Contract Report use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Smart Contract Report?

Skills that share tags, products or a category with Smart Contract Report: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 442 stars) and Stellar Dev (VelaPayments/vela-payments, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart Contract Report?

aviggiano (a GitHub user) maintains it in aviggiano/security, which has 144 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 15, 2026.

Source: aviggiano/security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.