Agent skill

Audit Reentrancy

by ben-manes in ben-manes/caffeine

Analyze user callbacks for re-entrancy defects (deadlock, corruption)

Apache-2.0Auto-check passedSecurity

Install Audit Reentrancy

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-reentrancy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-reentrancy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-reentrancy .claude/skills/audit-reentrancy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-reentrancy
GitHub stars
18k
Token cost
~643 tokens
SKILL.md length
315 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze user callbacks for re-entrancy defects (deadlock, corruption)

  • Works in 8 steps: CacheLoader.load(key) / loadAll(keys) → CacheLoader.reload(key, oldValue) → Weigher.weigh(key, value) → …
  • Tasks that involve Smart contract auditing
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Reentrancy is an agent skill from ben-manes/caffeine. Analyze user callbacks for re-entrancy defects (deadlock, corruption)

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contract auditing. The repository describes itself as: A high performance caching library for Java. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Smart contract auditing

Example prompts

  • “/audit-reentrancy”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. CacheLoader.load(key) / loadAll(keys)
  2. CacheLoader.reload(key, oldValue)
  3. Weigher.weigh(key, value)
  4. Expiry.expireAfterCreate / expireAfterUpdate / expireAfterRead
  5. RemovalListener.onRemoval(key, value, cause)
  6. EvictionListener (synchronous variant)
  7. Mapping functions passed to compute, computeIfAbsent, merge
  8. jcache: synchronous CacheEntryListener (historically caused double refresh),

What it can do on your machine

Read from SKILL.md and the folder at commit 998978c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Reentrancy loads about 643 tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 315 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~643

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit 998978c, republished under its Apache-2.0 licence (© ben-manes). 315 words, ~643 tokens.

Download SKILL.mdSave it as .claude/skills/audit-reentrancy/SKILL.md (or your agent's skills folder).
name
audit-reentrancy
description
Analyze user callbacks for re-entrancy defects (deadlock, corruption)
context
fork
agent
auditor
disable-model-invocation
true

Analyze the cache for defects caused by user callbacks re-entering the cache.

User-provided callbacks:

  1. CacheLoader.load(key) / loadAll(keys)
  2. CacheLoader.reload(key, oldValue)
  3. Weigher.weigh(key, value)
  4. Expiry.expireAfterCreate / expireAfterUpdate / expireAfterRead
  5. RemovalListener.onRemoval(key, value, cause)
  6. EvictionListener (synchronous variant)
  7. Mapping functions passed to compute, computeIfAbsent, merge
  8. jcache: synchronous CacheEntryListener (historically caused double refresh), CacheWriter, EntryProcessor.process, ExpiryPolicy

For each callback:

  1. List every lock held at the point the callback is invoked. Include: evictionLock, CHM bin lock, synchronized(node), any other.
  2. Determine what happens if the callback calls EACH of these cache methods: get, put, remove, compute, computeIfAbsent, size, clear, cleanUp, asMap().entrySet().
  3. For each (callback, cache method) pair where locks are held:
    • Can it deadlock? (Same lock re-acquired? Lock ordering violated?)
    • Can it corrupt state? (Re-entering a method mid-mutation?)
    • Can it observe partially-constructed state?
  4. If the cache defends against re-entrancy (e.g., by deferring work), explain the mechanism and verify it is complete.

For each defect: state the callback, re-entrant method, locks involved, call stack, and observable incorrect behavior.

Treat the executor as a matrix dimension. A read nudges maintenance, and an executor that runs the drain on the caller (Runnable::run, a direct executor, a saturated CallerRunsPolicy pool) runs the whole cycle inside whatever callback performed the read. Analyze each read cell under the default executor and under caller-runs separately.

Witness notes:

  • Under a caller-runs executor, any view access or read of an expired entry before the operation under test (printing asMap(), iterating) reaps it inline and removes the precondition. Print diagnostics only afterwards.
  • With the default executor, let the pool's maintenance task finish (cleanUp() or ForkJoinPool.commonPool().awaitQuiescence) before advancing a controllable ticker, or that task reaps the entry the scenario depends on.
  • Judge a lost write with an oracle that does not filter expired entries: a distinct value object per write, then check whether that value is ever notified after time advances and the key is overwritten.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-reentrancy of ben-manes/caffeine.

Open the folder on GitHubat commit 998978c

Compare with similar skills

Audit Reentrancy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Reentrancy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Reentrancy this skillben-manes/caffeine18k—~643Automated safety check: PassApache-2.0
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Web3 Smart Contract Grep Arsenaltradecatlabs/vibe-coding-cn17k2 repos~3.3kAutomated safety check: PassMIT
X Raypashov/skills1.2k1 repos~10kAutomated safety check: PassMIT
Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Web3 Smart Contract Grep Arsenal

    tradecatlabs/vibe-coding-cn

    A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

    17k GitHub starsUsed in 2 repos~3.3k tokens
    SecurityAuto-check passed
  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~855 tokensUpdated today
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated today
    Auto-check: notes

Categories

Questions about Audit Reentrancy

What does Audit Reentrancy do?

Analyze user callbacks for re-entrancy defects (deadlock, corruption). Audit Reentrancy is an agent skill from ben-manes/caffeine.

When should I use Audit Reentrancy?

Audit Reentrancy fits situations like: tasks that involve Smart contract auditing.

How do I install Audit Reentrancy in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-reentrancy -a claude-code`. Or copy the skill folder (.claude/skills/audit-reentrancy in ben-manes/caffeine) into .claude/skills/audit-reentrancy in your project. Claude Code loads it when a task matches its description.

How do I install Audit Reentrancy in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-reentrancy -a codex`. Or copy the skill folder (.claude/skills/audit-reentrancy in ben-manes/caffeine) into .agents/skills/audit-reentrancy in your project. Codex loads it when a task matches its description.

Can I use Audit Reentrancy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-reentrancy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-reentrancy, .gemini/skills/audit-reentrancy, .github/skills/audit-reentrancy and .opencode/skills/audit-reentrancy in your project.

What does Audit Reentrancy need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Reentrancy is instructions for the agent only.

Does Audit Reentrancy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Reentrancy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Reentrancy use?

Audit Reentrancy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Reentrancy use?

About 643 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Reentrancy?

Skills that share tags, products or a category with Audit Reentrancy: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Web3 Smart Contract Grep Arsenal (tradecatlabs/vibe-coding-cn, 17k stars) and X Ray (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Reentrancy?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 11, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.