Agent skill

Front Running Patterns

by ccashwell in ccashwell/evm-cortex

Front-running and MEV protection patterns for Solidity protocols.

MITAuto-check passedBackend & APIs

Install Front Running Patterns

skills CLI
$ npx skills add ccashwell/evm-cortex --skill front-running-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex front-running-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/front-running-patterns .claude/skills/front-running-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
front-running-patterns
GitHub stars
131
Token cost
~1.5k tokens
SKILL.md length
269 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Front-running and MEV protection patterns for Solidity protocols.

  • Designing swaps
  • SKILL.md covers What Is MEV?, Sandwich Attacks on Swaps, Commit-Reveal Scheme and Flashbots Protect / Private…, plus 4 more sections
  • Reaches rpc.flashbots.net
  • Any transaction-ordering-dependent logic

What it does

Front Running Patterns is an agent skill from ccashwell/evm-cortex. Front-running and MEV protection patterns for Solidity protocols. Use when designing swaps, auctions, NFT mints, or any transaction-ordering-dependent logic. Covers sandwich attacks, commit-reveal, Flashbots, slippage protection, and deadline parameters.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Crypto and DeFi analysis and Smart contracts. It works with Solidity. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Designing swaps
  • Any transaction-ordering-dependent logic

Example prompts

  • “/front-running-patterns”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • rpc.flashbots.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Front Running Patterns loads about 1.5k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 269 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 269 words, ~1,514 tokens.

Download SKILL.mdSave it as .claude/skills/front-running-patterns/SKILL.md (or your agent's skills folder).
name
front-running-patterns
description
Front-running and MEV protection patterns for Solidity protocols. Use when designing swaps, auctions, NFT mints, or any transaction-ordering-dependent logic. Covers sandwich attacks, commit-reveal, Flashbots, slippage protection, and deadline parameters.

Front-Running & MEV Patterns

What Is MEV?

Maximal Extractable Value (MEV) is the profit extractable by reordering, inserting, or censoring transactions within a block. Validators and searchers extract MEV through:

  • Sandwich attacks: front-run + back-run a victim's swap
  • Front-running: copy a profitable transaction and get it mined first
  • Back-running: execute immediately after a target transaction
  • Liquidation racing: compete to liquidate undercollateralized positions
  • Just-in-Time (JIT) liquidity: add/remove concentrated liquidity around a trade

Sandwich Attacks on Swaps

1. Victim submits swap: buy 100 ETH of TOKEN
2. Attacker front-runs: buys TOKEN, pushing price up
3. Victim's swap executes at worse price
4. Attacker back-runs: sells TOKEN at inflated price
Defense: Slippage Protection
solidity
error SlippageExceeded(uint256 amountOut, uint256 minAmountOut);

function swap(
    address tokenIn,
    address tokenOut,
    uint256 amountIn,
    uint256 minAmountOut,   // user sets minimum acceptable output
    uint256 deadline
) external returns (uint256 amountOut) {
    if (block.timestamp > deadline) revert Expired();

    amountOut = _executeSwap(tokenIn, tokenOut, amountIn);

    if (amountOut < minAmountOut) {
        revert SlippageExceeded(amountOut, minAmountOut);
    }

    emit Swapped(msg.sender, tokenIn, tokenOut, amountIn, amountOut);
}
Defense: Deadline Parameters

Without deadlines, pending transactions can be held in the mempool and executed later at unfavorable prices.

solidity
modifier beforeDeadline(uint256 deadline) {
    if (block.timestamp > deadline) revert TransactionExpired(deadline, block.timestamp);
    _;
}

function addLiquidity(
    uint256 amount0,
    uint256 amount1,
    uint256 minLiquidity,
    uint256 deadline
) external beforeDeadline(deadline) returns (uint256 liquidity) {
    // ...
}

Commit-Reveal Scheme

For auctions, NFT mints, or any scenario where knowing the action gives an advantage.

solidity
uint256 public constant COMMIT_PERIOD = 1 hours;
uint256 public constant REVEAL_PERIOD = 30 minutes;
uint256 public constant MIN_COMMIT_AGE = 2 minutes; // at least 1 block gap

mapping(address => bytes32) public commitments;
mapping(address => uint256) public commitTimestamps;

function commit(bytes32 hash) external {
    commitments[msg.sender] = hash;
    commitTimestamps[msg.sender] = block.timestamp;
    emit Committed(msg.sender);
}

function reveal(uint256 bid, bytes32 salt) external {
    uint256 commitTime = commitTimestamps[msg.sender];
    if (commitTime == 0) revert NoCommitment();
    if (block.timestamp < commitTime + MIN_COMMIT_AGE) revert RevealTooEarly();
    if (block.timestamp > commitTime + COMMIT_PERIOD + REVEAL_PERIOD) revert RevealExpired();

    bytes32 expected = keccak256(abi.encodePacked(msg.sender, bid, salt));
    if (commitments[msg.sender] != expected) revert InvalidReveal();

    commitments[msg.sender] = bytes32(0);
    _processBid(msg.sender, bid);
}

Flashbots Protect / Private Mempool

Transactions submitted through Flashbots or similar services skip the public mempool, making them invisible to sandwich bots.

typescript
// Frontend integration: submit via Flashbots Protect RPC
const provider = new ethers.JsonRpcProvider("https://rpc.flashbots.net");
const tx = await signer.sendTransaction({
  to: routerAddress,
  data: encodedSwap,
  // Flashbots Protect: not visible in public mempool
});

Limitations:

  • Doesn't protect against validator-level MEV
  • Transaction may take longer to be included
  • Not all chains support Flashbots

Transaction Ordering Dependence

Any logic where the outcome depends on transaction order is vulnerable.

solidity
// VULNERABLE: first caller wins
function claim(uint256 tokenId) external {
    require(!claimed[tokenId], "Already claimed");
    claimed[tokenId] = true;
    _mint(msg.sender, tokenId);
}

// SAFER: randomized or committed selection
// Use commit-reveal or Chainlink VRF for fair selection

MEV Protection for AMMs

Concentrated Liquidity JIT Protection
solidity
// Track when liquidity was added to prevent JIT manipulation
mapping(uint256 => uint256) public positionMintBlock;

function mint(uint256 positionId, ...) external {
    positionMintBlock[positionId] = block.number;
    // ...
}

function collectFees(uint256 positionId) external {
    // Require liquidity existed for at least N blocks before fee collection
    if (block.number - positionMintBlock[positionId] < MIN_LIQUIDITY_BLOCKS) {
        revert LiquidityTooRecent();
    }
    // ...
}

Price Update Front-Running

Oracle price updates can be front-run by MEV searchers who see the update in the mempool.

1. Chainlink oracle update TX: ETH price changes from $2000 → $2100
2. Attacker front-runs: opens leveraged long at $2000
3. Oracle updates: price becomes $2100
4. Attacker closes: profit from $100 move with leverage

Defense:

  • Time-weighted or multi-block oracle consumption
  • Execution delay after position changes
  • Fee charged on rapid open/close cycles

MEV Protection Checklist

  • Slippage protection (minAmountOut) on all swap functions
  • Deadline parameter on all time-sensitive operations
  • Commit-reveal for auctions, mints, and competitive actions
  • Frontend uses private mempool (Flashbots Protect) for swaps
  • No first-come-first-served mechanisms without mitigation
  • Oracle updates not exploitable via price front-running
  • Liquidity operations protected against JIT manipulation
  • Fee structures disincentivize atomic open/close (anti-sandwich)
  • Price impact limits on single-transaction trades

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/front-running-patterns of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Front Running Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Front Running Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Front Running Patterns this skillccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT
DeFi Protocol Templateswshobson/agents40k10 repos~1.9kAutomated safety check: PassMIT
Ethskillsaustintgriffith/ethskills294—~1.4kAutomated safety check: PassNone
Chaingptinternet-court/internet-court-skill6.4k1 repos~4kAutomated safety check: PassMIT
Solidity Vulnerability Scanneralt-research2/SolidityGuard104—~1.6kAutomated safety check: NotesCustom licence
Ethskillsaustintgriffith/ethskills294—~3kAutomated safety check: PassNone

Similar skills

  • Solidity templates for DeFi building blocks: staking with reward distribution, an automated market maker, governance tokens and flash loans.

    40k GitHub starsUsed in 10 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Ethskills

    austintgriffith/ethskills

    Ethereum development knowledge for AI agents — from idea to deployed dApp.

    294 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Chaingpt

    internet-court/internet-court-skill

    Build with the ChainGPT Web3 AI developer platform. An agent skill from internet-court/internet-court-skill.

    6.4k GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Ethskills

    austintgriffith/ethskills

    A skill your agent uses when a request involves Ethereum, the EVM, or blockchain systems.

    294 GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Blockchain Developer

    Microck/ordinary-claude-skills

    Expert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols.

    401 GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 8 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 8 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed

Works with

Categories

Questions about Front Running Patterns

What does Front Running Patterns do?

Front-running and MEV protection patterns for Solidity protocols. Front Running Patterns is an agent skill from ccashwell/evm-cortex. Front-running and MEV protection patterns for Solidity protocols.

When should I use Front Running Patterns?

Front Running Patterns fits situations like: designing swaps; any transaction-ordering-dependent logic.

How do I install Front Running Patterns in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill front-running-patterns -a claude-code`. Or copy the skill folder (skills/front-running-patterns in ccashwell/evm-cortex) into .claude/skills/front-running-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Front Running Patterns in Codex?

Run `npx skills add ccashwell/evm-cortex --skill front-running-patterns -a codex`. Or copy the skill folder (skills/front-running-patterns in ccashwell/evm-cortex) into .agents/skills/front-running-patterns in your project. Codex loads it when a task matches its description.

Can I use Front Running Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill front-running-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/front-running-patterns, .gemini/skills/front-running-patterns, .github/skills/front-running-patterns and .opencode/skills/front-running-patterns in your project.

What does Front Running Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Front Running Patterns is instructions for the agent only.

Does Front Running Patterns access the network?

SKILL.md names 1 domain. In commands or code: rpc.flashbots.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Front Running Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Front Running Patterns use?

Front Running Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Front Running Patterns use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Front Running Patterns?

Skills that share tags, products or a category with Front Running Patterns: DeFi Protocol Templates (wshobson/agents, 40k stars), Ethskills (austintgriffith/ethskills, 294 stars), Chaingpt (internet-court/internet-court-skill, 6.4k stars) and Solidity Vulnerability Scanner (alt-research2/SolidityGuard, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Front Running Patterns?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.