Fizz Convert
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…
$ npx skills add aviggiano/security --skill smart-contract-report -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aviggiano/security smart-contract-report --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/smart-contract-report .claude/skills/smart-contract-report && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .claude/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aviggiano/security/tree/main/skills/smart-contract-reportType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aviggiano/security --skill smart-contract-report -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aviggiano/security smart-contract-report --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/smart-contract-report .agents/skills/smart-contract-report && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .agents/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aviggiano/security --skill smart-contract-report -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aviggiano/security smart-contract-report --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/smart-contract-report .cursor/skills/smart-contract-report && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .cursor/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aviggiano/security.git --path skills/smart-contract-report--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aviggiano/security --skill smart-contract-report -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aviggiano/security smart-contract-report --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/smart-contract-report .gemini/skills/smart-contract-report && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .gemini/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aviggiano/security smart-contract-reportInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aviggiano/security --skill smart-contract-report -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/smart-contract-report .github/skills/smart-contract-report && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .github/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aviggiano/security --skill smart-contract-report -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aviggiano/security smart-contract-report --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/smart-contract-report .opencode/skills/smart-contract-report && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-report" agent skill from https://github.com/aviggiano/security/tree/main/skills/smart-contract-report into .opencode/skills/smart-contract-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-report", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
smart-contract-reportTurn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…
Smart Contract Report is an agent skill from aviggiano/security. Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of concept, and remediation diffs.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Smart contracts, Unit testing and Smart contract auditing. The repository describes itself as: Security Reviews and Audit Checklists. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e18ce7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Smart Contract Report loads about 2.4k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,307 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aviggiano/security at commit e18ce7d, republished under its MIT licence (© aviggiano). 1,307 words, ~2,396 tokens.
.claude/skills/smart-contract-report/SKILL.md (or your agent's skills folder).Prepare smart-contract-report.md from supplied audit findings, source context,
existing test evidence, and proposed fixes. Use another output path when requested.
This skill prepares the document; submit it externally only when the user specifies
the destination and authorizes submission.
Use this order:
Issue ID and linked Title columns, ordered H/M/L/I. Keep
the index directly after the title; do not add a separate table of contents.Do not add a separate summary/count block or severity-matrix section unless the user requests one. A report with no established issues still includes the index. Do not equate zero findings with protocol safety.
Use only Low, Medium, and High for security severity, impact, and likelihood. Do not include a severity matrix in the report. Assign severity as follows: Low impact is Low at every likelihood; Medium impact is Low at Low likelihood and Medium otherwise; High impact is Medium at Low likelihood and High otherwise.
Impact describes the supported consequence: High requires direct asset loss or compromise; Medium materially affects protocol operation, availability, accounting, or value; Low covers limited defects with minor consequences. Likelihood describes the realistic trigger conditions: High means reliably reachable by an ordinary participant or naturally occurring in realistic use; Medium requires meaningful but plausible conditions; Low requires restrictive conditions or trusted participation. Explain the actual assumptions in each issue.
Assess intended privileged operations separately from administrator mistakes and intentional misuse of trusted powers. State the protocol's trust assumptions; do not infer an unprivileged attack from an administrator-only action. Unsupported assumptions cannot establish High or Medium risk.
Informational is a separate category for established observations without a demonstrated security consequence; it is outside the matrix. Do not use it to hide unresolved vulnerability candidates.
H-001 through H-101,
including H-100, while 12 Medium issues use M-01 through M-12. Apply the
same rule to Low and Informational issues and update all references together.## [H-01] - Attacker can drain vault due to incorrect permissions.
This is a title example, not a claim about the reviewed protocol.Explain the affected behavior, root cause, necessary conditions, expected behavior, and supported consequence. Identify affected contracts or functions when known. Keep the narrative understandable without opening an external artifact. Source links may supplement the explanation, but must not replace it.
For H/M/L entries, include three bullets, each with a one-sentence explanation:
Format each as - **Label**: Rating: Explanation. Severity must follow the
severity rubric. For informational entries, omit this entire risk assessment;
the I- identifier establishes their classification.
This section applies only to H/M/L entries. Informational entries omit the entire Proof of Concept section, including numbered scenarios and test code.
Place a short human-readable numbered list of actor actions first, sorted in chronological execution order. Start each step with the actor, followed by the concrete action and its relevant result. Include the setup actions needed to understand how the final consequence occurs.
Prefer Attacker and Victim when adversarial and harmed participants are applicable. Otherwise use the protocol's usual roles, such as Depositor, Borrower, Liquidator, User, or Administrator. Keep names consistent across the scenario and test, and distinguish multiple participants as Victim A and Victim B or Depositor A and Depositor B. Avoid anonymous variables and Alice/Bob when a role is available.
Example of the required presentation, only when supported by the supplied finding:
redeem and drains the protocol.Describe setup, relevant actions in their observed order, and the resulting observable consequence. Keep the scenario faithful to the supplied evidence; do not add an unsupported attack sequence.
Immediately after the numbered scenario, include a self-contained unit-test PoC in a language-tagged code fence. Use an accurate supplied PoC when available; otherwise reconstruct it from the finding and reviewed source. Use the project's existing test framework. A self-contained test includes its imports, setup, fixtures, mocks, helpers, and meaningful assertions, and may depend on the reviewed repository and its declared dependencies. It must not depend on another finding's snippet or undisclosed local files. Do not replace code with a file link, ellipsis, or an invented passing result.
Label the PoC as supplied or reconstructed. Include the test filename, execution command, prerequisites, and recorded validation result when available. Distinguish an observed successful reproduction from unverified source. A test confirming the fix must be labeled separately. If required evidence is unavailable, identify the gap and mark the report as a draft rather than claiming it is submission-ready.
Briefly explain the proposed fix, then show it in a fenced diff block using
git unified-diff syntax, including diff --git, --- a/..., +++ b/..., and
accurate hunk headers and context. Base the diff on the reviewed revision, with
actual repository paths and code. Include documentation diffs when the fix is
documentary. Avoid pseudo-diffs, placeholder code, and unrelated refactoring.
When source is available, check patch applicability against the reviewed revision
in an isolated copy. Record validation honestly. Do not apply proposed fixes to
the user's working tree merely to prepare a report. If a fix cannot yet be
specified, describe the missing decision and mark remediation as pending.
For an informational observation requiring no change, use Not applicable with
a reason instead of an empty diff.
Before calling the report submission-ready, check:
© aviggiano, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/smart-contract-report of aviggiano/security.
Open the folder on GitHubat commit e18ce7d
Smart Contract Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Smart Contract Report this skillaviggiano/security | 144 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Smart Contract Auditgreatpie/smart-contract-audit-skill | 101 | — | ~1.1k | Automated safety check: Pass | None | |
| Solidity AuditorGabson0x/bountyforge | 442 | — | ~3.7k | Automated safety check: Pass | None | |
| Stellar DevVelaPayments/vela-payments | 131 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Auditaustintgriffith/ethskills | 295 | — | ~829 | Automated safety check: Pass | None |
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
VelaPayments/vela-payments
End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.
austintgriffith/ethskills
Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.
pashov/skills
Security audit of Solidity code while you develop. An agent skill from pashov/skills.
aviggiano/security
Create or refactor Foundry deployment fixtures for Solidity tests.
aviggiano/security
Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security.
aviggiano/security
Turn whitepapers, protocol specs, and public documentation into Foundry property tests.
aviggiano/security
Master skill for running an end-to-end multi-pass Foundry testing campaign for Solidity projects.
aviggiano/security
Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.
aviggiano/security
Create Foundry differential tests comparing production Solidity contracts against an independent reference model.
Categories
Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of…. Smart Contract Report is an agent skill from aviggiano/security. Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of concept, and remediation diffs.
Smart Contract Report fits situations like: tasks that involve Smart contracts; tasks that involve Unit testing; tasks that involve Smart contract auditing.
Run `npx skills add aviggiano/security --skill smart-contract-report -a claude-code`. Or copy the skill folder (skills/smart-contract-report in aviggiano/security) into .claude/skills/smart-contract-report in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aviggiano/security --skill smart-contract-report -a codex`. Or copy the skill folder (skills/smart-contract-report in aviggiano/security) into .agents/skills/smart-contract-report in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aviggiano/security --skill smart-contract-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-report, .gemini/skills/smart-contract-report, .github/skills/smart-contract-report and .opencode/skills/smart-contract-report in your project.
SKILL.md names no scripts, command-line tools or credentials: Smart Contract Report is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Smart Contract Report is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Smart Contract Report: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 442 stars) and Stellar Dev (VelaPayments/vela-payments, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aviggiano (a GitHub user) maintains it in aviggiano/security, which has 144 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 15, 2026.
Source: aviggiano/security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.