Agent skill

Audit Prep

by ccashwell in ccashwell/evm-cortex

A skill your agent uses when preparing a codebase for security audit.

MITAuto-check passedSecurity

Install Audit Prep

skills CLI
$ npx skills add ccashwell/evm-cortex --skill audit-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex audit-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-prep .claude/skills/audit-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-prep
GitHub stars
131
Token cost
~1.4k tokens
SKILL.md length
155 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when preparing a codebase for security audit.

  • Works in 8 steps: Scope Definition → Architecture Documentation → Invariants Documentation → …
  • Preparing a codebase for security audit
  • SKILL.md covers Overview, Audit Preparation Checklist, Deliverables to Auditors and Checklist
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Prep is an agent skill from ccashwell/evm-cortex. Use when preparing a codebase for security audit. Covers scope definition, documentation review, dependency analysis, invariant documentation, known issues lists, prior audit review, test coverage verification, and static analysis.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Test coverage, Static analysis and SAST and Security review. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Preparing a codebase for security audit
  • Tasks that involve Test coverage
  • Tasks that involve Static analysis and SAST

Example prompts

  • “/audit-prep”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Scope Definition
  2. Architecture Documentation
  3. Invariants Documentation
  4. Known Issues / Design Decisions
  5. Prior Audit Review
  6. Test Coverage Verification
  7. Static Analysis
  8. Build Verification

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Prep loads about 1.4k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 155 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 155 words, ~1,400 tokens.

Download SKILL.mdSave it as .claude/skills/audit-prep/SKILL.md (or your agent's skills folder).
name
audit-prep
description
Use when preparing a codebase for security audit. Covers scope definition, documentation review, dependency analysis, invariant documentation, known issues lists, prior audit review, test coverage verification, and static analysis.

Pre-Audit Preparation

Overview

Audit preparation maximizes audit value. A well-prepared codebase lets auditors focus on finding real vulnerabilities instead of deciphering intent or fighting build issues.

Audit Preparation Checklist

1. Scope Definition
markdown
## Audit Scope

### In Scope
| File | SLOC | Description |
|------|------|-------------|
| src/Vault.sol | 245 | Core vault logic, deposits/withdrawals |
| src/Strategy.sol | 189 | Yield strategy integration |
| src/Oracle.sol | 78 | Price feed wrapper |
| **Total** | **512** | |

### Out of Scope
- OpenZeppelin imports (v5.0.1) — audited separately
- Test files and deployment scripts
- Frontend / offchain components

### Deployment Chain(s)
- Ethereum Mainnet
- Arbitrum One

### EVM Version
- Shanghai (solc 0.8.24)
2. Architecture Documentation

Provide auditors with:

markdown
## Architecture

### Contract Relationships
Vault -> Strategy -> ExternalProtocol (Aave V3)
Vault -> Oracle -> Chainlink ETH/USD Feed
Governor -> Timelock -> Vault (parameter changes)

### Access Control
- Owner (2/3 multisig): pause, setFee, setStrategy
- Keeper (EOA): harvest, rebalance
- Users: deposit, withdraw, claim

### External Dependencies
| Dependency | Address | Trust Assumption |
|-----------|---------|-----------------|
| Aave V3 Pool | 0x8787... | Fully trusted |
| Chainlink ETH/USD | 0x5f4e... | Staleness checked |
| USDC | 0xA0b8... | Standard ERC20 |

### Value Flow
1. User deposits USDC -> Vault mints shares
2. Vault deploys USDC to Aave via Strategy
3. Strategy harvests yield -> increases share price
4. User redeems shares -> receives USDC + yield
3. Invariants Documentation
markdown
## Protocol Invariants

### Core Invariants (must NEVER be violated)
1. `vault.totalAssets() >= vault.totalSupply() * minSharePrice`
   - Shares are always redeemable for at least their initial value
2. `sum(userShares) == vault.totalSupply()`
   - No share inflation/deflation outside deposit/withdraw
3. `strategy.totalDeployed() + vault.idleAssets() == vault.totalAssets()`
   - All assets accounted for

### Economic Invariants
4. Share price monotonically increases (no value extraction)
5. Withdrawal amount <= deposit amount + accumulated yield
6. Fees never exceed configured maximum (10%)

### Access Control Invariants
7. Only owner can change strategy/oracle/fees
8. Only keeper can trigger harvest
9. Users can always withdraw (no permanent lock, even if paused)
4. Known Issues / Design Decisions
markdown
## Known Issues & Accepted Risks

### K-01: First depositor receives favorable exchange rate
- **Severity**: Low
- **Mitigation**: Virtual shares offset (1e3) prevents manipulation
- **Status**: Accepted with mitigation

### K-02: Oracle can return stale prices during Chainlink outage
- **Severity**: Medium
- **Mitigation**: 1-hour staleness check; fallback oracle planned for v2
- **Status**: Accepted for v1

### Design Decisions
- D-01: Emergency withdraw bypasses strategy — users get idle assets only
- D-02: Fee-on-transfer tokens NOT supported (by design)
- D-03: Rebasing tokens NOT supported (by design)
5. Prior Audit Review

If previously audited:

  • Link to prior audit report
  • List resolved vs unresolved findings
  • Describe changes since last audit
  • Highlight new code vs unchanged code
6. Test Coverage Verification
bash
# Run full test suite
forge test -vvv

# Generate coverage report
forge coverage --report lcov
genhtml lcov.info -o coverage-report

# Verify coverage thresholds
# Core logic: > 95% branch coverage
# Periphery: > 85% branch coverage
7. Static Analysis
bash
# Slither
slither . --filter-paths "test|script|node_modules" \
         --exclude naming-convention,solc-version

# Aderyn
aderyn . --exclude test/ script/

# Review and triage findings
# - Fix genuine issues before audit
# - Document accepted findings with rationale
8. Build Verification
bash
# Clean build
forge clean && forge build

# Verify all tests pass
forge test

# Check for compiler warnings
forge build 2>&1 | grep -i warning

# Verify contract sizes
forge build --sizes

Deliverables to Auditors

project/
├── src/                     # Source contracts (in scope)
├── test/                    # Full test suite
├── docs/
│   ├── ARCHITECTURE.md      # System design
│   ├── INVARIANTS.md        # Protocol invariants
│   ├── KNOWN_ISSUES.md      # Accepted risks
│   └── DEPLOYMENT.md        # Deployment plan and addresses
├── audit/
│   ├── scope.md             # Scope definition
│   ├── prior-audits/        # Previous audit reports
│   └── slither-output.json  # Static analysis results
├── foundry.toml
└── README.md                # Build and test instructions

Checklist

  • Scope document with SLOC counts and file descriptions
  • Architecture diagram with contract relationships
  • External dependency list with addresses and trust assumptions
  • Protocol invariants documented and tested
  • Known issues list with severity and mitigation
  • Test suite passes with 90%+ branch coverage on in-scope code
  • Slither/Aderyn run with findings triaged
  • Clean build with no warnings
  • README with build, test, and deployment instructions
  • Git commit hash pinned for audit scope

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-prep of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Audit Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Prep this skillccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT
Audit PrepPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
CodeCrucible Security Scansblock/codecrucible117—~1.2kAutomated safety check: PassApache-2.0
Auditvigolium/piolium138—~8.7kAutomated safety check: PassMIT
Codeqlwaybarrios/opencode-power-pack5332 repos~3.7kAutomated safety check: PassMIT

Similar skills

  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Audit

    vigolium/piolium

    A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

    138 GitHub stars~8.7k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Codeql

    waybarrios/opencode-power-pack

    Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

    533 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 7 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 7 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed

Questions about Audit Prep

What does Audit Prep do?

A skill your agent uses when preparing a codebase for security audit. Audit Prep is an agent skill from ccashwell/evm-cortex. Use when preparing a codebase for security audit.

When should I use Audit Prep?

Audit Prep fits situations like: preparing a codebase for security audit; tasks that involve Test coverage; tasks that involve Static analysis and SAST.

How do I install Audit Prep in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill audit-prep -a claude-code`. Or copy the skill folder (skills/audit-prep in ccashwell/evm-cortex) into .claude/skills/audit-prep in your project. Claude Code loads it when a task matches its description.

How do I install Audit Prep in Codex?

Run `npx skills add ccashwell/evm-cortex --skill audit-prep -a codex`. Or copy the skill folder (skills/audit-prep in ccashwell/evm-cortex) into .agents/skills/audit-prep in your project. Codex loads it when a task matches its description.

Can I use Audit Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill audit-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-prep, .gemini/skills/audit-prep, .github/skills/audit-prep and .opencode/skills/audit-prep in your project.

What does Audit Prep need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Prep is instructions for the agent only.

Does Audit Prep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Prep use?

Audit Prep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Prep use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Prep?

Skills that share tags, products or a category with Audit Prep: Audit Prep (PlamenTSV/plamen, 303 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars), CodeCrucible Security Scans (block/codecrucible, 117 stars) and Audit (vigolium/piolium, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Prep?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.