Property Based Testing
trailofbits/skills
Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.
Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aviggiano/security stateful-invariant-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/stateful-invariant-testing .claude/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .claude/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aviggiano/security stateful-invariant-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/stateful-invariant-testing .agents/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .agents/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aviggiano/security stateful-invariant-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/stateful-invariant-testing .cursor/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .cursor/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aviggiano/security.git --path skills/stateful-invariant-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aviggiano/security stateful-invariant-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/stateful-invariant-testing .gemini/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .gemini/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aviggiano/security stateful-invariant-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/stateful-invariant-testing .github/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .github/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aviggiano/security --skill stateful-invariant-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aviggiano/security stateful-invariant-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aviggiano/security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/stateful-invariant-testing .opencode/skills/stateful-invariant-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "stateful-invariant-testing" agent skill from https://github.com/aviggiano/security/tree/main/skills/stateful-invariant-testing into .opencode/skills/stateful-invariant-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stateful-invariant-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
stateful-invariant-testingBuild metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.
Stateful Invariant Testing is an agent skill from aviggiano/security. Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects. Use when Codex needs a Recon-style invariant harness with Setup, TargetFunctions, Properties, BeforeAfter, CryticTester, CryticToFoundry, actor and manager setup, Echidna/Medusa/recon-fuzzer smoke runs, and standardized Recon coverage gates.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Fuzzing and Smart contracts. It works with Solidity. The repository describes itself as: Security Reviews and Audit Checklists. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e18ce7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Stateful Invariant Testing loads about 2.8k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,314 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aviggiano/security at commit e18ce7d, republished under its MIT licence (© aviggiano). 1,314 words, ~2,848 tokens.
.claude/skills/stateful-invariant-testing/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill to create a real stateful invariant fuzzing campaign using the Recon Chimera style. In this context, stateful invariant testing is property-based testing over sequences of protocol actions, not a separate campaign type. The fuzzer should choose action sequences. The harness should expose protocol entrypoints with minimal preprocessing, track actors and state, and report bugs instead of papering over them.
Default to the create-chimera-app layout and adapt it to the target repo. Do not hand-roll a generic StdInvariant campaign, a single monolithic handler, or a differential-only state machine unless the user explicitly asks for that instead of Chimera.
For a full campaign, explicitly ask the user to run it as a Codex /goal if they did not already. Use a measurable objective such as:
/goal Build and validate a stateful invariant testing campaign with 5-minute smoke runs on recon-fuzzer, Echidna, and Medusa, no unclassified failures, and at least 90% standardized line coverage of core production contracts.Use 90% standardized line coverage as the default initial target. The user may choose a higher target or a different production scope.
AGENTS.md, repo testing docs, and existing Foundry test patterns before editing.contracts/ or src/ unchanged unless the user explicitly asks for contract fixes.Recon-Fuzz/create-chimera-app and Recon-Fuzz/chimera as the normative scaffold for new campaigns. Treat repo-local fixture helpers as inputs to Setup, not as a reason to abandon the Chimera file structure.try/catch to force artificial coverage. Let expected reverts be explored naturally by fuzzing unless the call is an intentional quote-then-execute or setup boundary.asActor and actor-manager helpers over direct vm.prank(actor) in target functions. Explicit pranks belong in deterministic setup or narrow shortcut scenarios.Use these repositories as implementation references for every new Chimera campaign:
Before the first edit, read the current create-chimera-app AGENT.md or README.md, its test/recon skeleton, and the relevant recon-magic prompts for scout, setup, properties, and coverage. If local clones exist, prefer them; otherwise fetch the public upstream files. Summarize the scaffold and command choices in the first implementation update.
If create-chimera-app or recon-magic-framework exists as a local checkout in the workspace or home directory, use those local references. Helpful files include:
<create-chimera-app>/AGENT.md<create-chimera-app>/test/recon/Setup.sol<create-chimera-app>/test/recon/TargetFunctions.sol<create-chimera-app>/test/recon/Properties.sol<create-chimera-app>/test/recon/BeforeAfter.sol<create-chimera-app>/test/recon/CryticTester.sol<create-chimera-app>/test/recon/CryticToFoundry.sol<recon-magic-framework>/prompts/agent/scout-v2-phase-0.md<recon-magic-framework>/prompts/agent/setup-v2-phase-0.md<recon-magic-framework>/prompts/agent/properties-v4-phase-0.md<recon-magic-framework>/prompts/agent/coverage-phase-0.md<recon-magic-framework>/prompts/agent/chimera-test-linter.md@recon/=lib/chimera/src/.Setup.sol, TargetFunctions.sol, Properties.sol, BeforeAfter.sol, CryticTester.sol, and CryticToFoundry.sol.forge build and a short Foundry invariant or reproducer check before longer fuzzer runs.The fuzzer entrypoint should normally be CryticTester. The Foundry debug entrypoint should normally be CryticToFoundry.
Prefer assertion mode for Chimera campaigns: properties should use Chimera assertions such as t, eq, gte, or lte through CryticAsserts/FoundryAsserts. Use echidna_ property mode only when the local toolchain or repo convention clearly requires it.
require lines, impossible states, or intentionally invalid payloads.snapshot_liquidate that performs supply_1, supply_2, borrow_1, change_price, and liquidate_2 with different actors.view/pure functions before covg_eval analyzes recon-coverage.json. Keep important read-only behavior as focused invariant checks or no-revert canaries, and move introspection sweeps, intentionally invalid calls, and revert-branch exercises out of primary stateful targets.Good targets look like public user actions. Suspicious targets look like scripts that force a protocol story from start to finish.
Use standardized coverage from recon-magic-framework/tools/covg_eval, not ad hoc line counts. The goal is not complete until the covg_eval-style number meets the requested target for the requested production scope.
Prefer recon-fuzzer for coverage iteration because it is usually faster than Echidna. Use recon-fuzzer LCOV/corpus output to decide which real actions to add or split. Do not chase coverage with handlers whose only value is forcing lines through setup.
Track:
When a fuzzer finds a broken invariant or property violation, create a deterministic CryticToFoundry reproducer, following the pattern of hardcoded failing sequences in examples like rheo-xyz/rheo-solidity's CryticToFoundry.t.sol.
The reproducer should:
For an end-to-end request, do not stop at "it compiles." A normal completion gate is:
forge build passes.If a fuzzer exits because a wrapper timeout stops it after the requested duration but it wrote corpus/LCOV and reports passing invariants, record that clearly rather than treating it as an unexplained failure.
When a smoke run or regression test fails:
End with the files changed, commands run, fuzzer results, coverage numbers, remaining classified findings, and whether the requested campaign gate is complete. Mention any untouched dirty worktree changes separately.
© aviggiano, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/stateful-invariant-testing of aviggiano/security.
Open the folder on GitHubat commit e18ce7d
Stateful Invariant Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Stateful Invariant Testing this skillaviggiano/security | 144 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Property Based Testingtrailofbits/skills | 7.5k | — | ~1.1k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Fuzz Generatoralt-research2/SolidityGuard | 104 | — | ~763 | Automated safety check: Notes | Custom licence | |
| Fuzzing Patternsccashwell/evm-cortex | 131 | — | ~1.6k | Automated safety check: Pass | MIT |
trailofbits/skills
Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
alt-research2/SolidityGuard
Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts.
ccashwell/evm-cortex
A skill your agent uses when writing fuzz tests for Solidity contracts.
adshao/flounder
Operates Flounder, an autonomous white-hat security auditor.
aviggiano/security
Create or refactor Foundry deployment fixtures for Solidity tests.
aviggiano/security
Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security.
aviggiano/security
Turn whitepapers, protocol specs, and public documentation into Foundry property tests.
aviggiano/security
Master skill for running an end-to-end multi-pass Foundry testing campaign for Solidity projects.
aviggiano/security
Create Foundry differential tests comparing production Solidity contracts against an independent reference model.
aviggiano/security
Classify failing Foundry fuzz, property, invariant, and differential tests.
Works with
Categories
Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects. Stateful Invariant Testing is an agent skill from aviggiano/security. Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.
Stateful Invariant Testing fits situations like: Codex needs a Recon-style invariant harness with Setup; targetFunctions; cryticToFoundry; actor and manager setup.
Run `npx skills add aviggiano/security --skill stateful-invariant-testing -a claude-code`. Or copy the skill folder (skills/stateful-invariant-testing in aviggiano/security) into .claude/skills/stateful-invariant-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aviggiano/security --skill stateful-invariant-testing -a codex`. Or copy the skill folder (skills/stateful-invariant-testing in aviggiano/security) into .agents/skills/stateful-invariant-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aviggiano/security --skill stateful-invariant-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stateful-invariant-testing, .gemini/skills/stateful-invariant-testing, .github/skills/stateful-invariant-testing and .opencode/skills/stateful-invariant-testing in your project.
SKILL.md names no scripts, command-line tools or credentials: Stateful Invariant Testing is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Stateful Invariant Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Stateful Invariant Testing: Property Based Testing (trailofbits/skills, 7.5k stars), Fizz (pashov/skills, 1.2k stars), Fizz Convert (pashov/skills, 1.2k stars) and Fuzz Generator (alt-research2/SolidityGuard, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aviggiano (a GitHub user) maintains it in aviggiano/security, which has 144 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 15, 2026.
Source: aviggiano/security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.