Agent skill

Invariant Testing

by ccashwell in ccashwell/evm-cortex

A skill your agent uses when writing Foundry invariant (stateful fuzz) tests.

MITAuto-check passedBusiness, Finance & HR

Install Invariant Testing

skills CLI
$ npx skills add ccashwell/evm-cortex --skill invariant-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex invariant-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/invariant-testing .claude/skills/invariant-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
invariant-testing
GitHub stars
131
Token cost
~1.9k tokens
SKILL.md length
129 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when writing Foundry invariant (stateful fuzz) tests.

  • Writing Foundry invariant (stateful fuzz) tests
  • SKILL.md covers Overview, Configuration, Handler Contract Template and Invariant Test File, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Crypto and DeFi analysis

What it does

Invariant Testing is an agent skill from ccashwell/evm-cortex. Use when writing Foundry invariant (stateful fuzz) tests. Covers handler contracts, ghost variables, target configuration, common invariant patterns, and handler design for DeFi protocols.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Crypto and DeFi analysis. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Writing Foundry invariant (stateful fuzz) tests
  • Tasks that involve Crypto and DeFi analysis

Example prompts

  • “/invariant-testing”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and toml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Invariant Testing loads about 1.9k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 129 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 129 words, ~1,877 tokens.

Download SKILL.mdSave it as .claude/skills/invariant-testing/SKILL.md (or your agent's skills folder).
name
invariant-testing
description
Use when writing Foundry invariant (stateful fuzz) tests. Covers handler contracts, ghost variables, target configuration, common invariant patterns, and handler design for DeFi protocols.

Foundry Invariant Testing

Overview

Invariant tests execute random sequences of function calls against handler contracts and assert that system invariants hold after every call. Unlike stateless fuzz tests, invariant tests maintain state across calls, exploring complex state transitions.

Configuration

In foundry.toml:

toml
[invariant]
runs = 256          # number of random sequences
depth = 64          # calls per sequence
fail_on_revert = false  # don't fail on handler reverts (expected)

Handler Contract Template

solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

import {Test} from "forge-std/Test.sol";
import {CommonBase} from "forge-std/Base.sol";
import {StdCheats} from "forge-std/StdCheats.sol";
import {StdUtils} from "forge-std/StdUtils.sol";
import {Vault} from "../../src/Vault.sol";
import {IERC20} from "@openzeppelin/contracts/token/ERC20/IERC20.sol";

contract VaultHandler is CommonBase, StdCheats, StdUtils {
    Vault public vault;
    IERC20 public token;

    // Ghost variables track expected state
    uint256 public ghost_totalDeposited;
    uint256 public ghost_totalWithdrawn;
    mapping(address => uint256) public ghost_userDeposits;

    // Actors for randomized msg.sender
    address[] public actors;
    address internal currentActor;

    modifier useActor(uint256 actorIndexSeed) {
        currentActor = actors[bound(actorIndexSeed, 0, actors.length - 1)];
        vm.startPrank(currentActor);
        _;
        vm.stopPrank();
    }

    constructor(Vault _vault, IERC20 _token) {
        vault = _vault;
        token = _token;

        // Create actor pool
        for (uint256 i = 0; i < 5; i++) {
            address actor = address(uint160(0x1000 + i));
            actors.push(actor);
            deal(address(token), actor, 1_000_000e18);
            vm.prank(actor);
            token.approve(address(vault), type(uint256).max);
        }
    }

    function deposit(uint256 actorSeed, uint256 amount) external useActor(actorSeed) {
        amount = bound(amount, 1e18, 100_000e18);

        uint256 balance = token.balanceOf(currentActor);
        if (balance < amount) return; // skip if insufficient

        vault.deposit(amount);

        ghost_totalDeposited += amount;
        ghost_userDeposits[currentActor] += amount;
    }

    function withdraw(uint256 actorSeed, uint256 amount) external useActor(actorSeed) {
        uint256 staked = vault.balanceOf(currentActor);
        if (staked == 0) return; // skip if nothing to withdraw

        amount = bound(amount, 1, staked);

        vault.withdraw(amount);

        ghost_totalWithdrawn += amount;
        ghost_userDeposits[currentActor] -= amount;
    }

    function warpTime(uint256 seconds_) external {
        seconds_ = bound(seconds_, 1, 7 days);
        skip(seconds_);
    }
}

Invariant Test File

solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

import {Test} from "forge-std/Test.sol";
import {Vault} from "../src/Vault.sol";
import {MockERC20} from "./mocks/MockERC20.sol";
import {VaultHandler} from "./handlers/VaultHandler.sol";

contract VaultInvariantTest is Test {
    Vault public vault;
    MockERC20 public token;
    VaultHandler public handler;

    function setUp() public {
        token = new MockERC20("Token", "TKN", 18);
        vault = new Vault(address(token));
        handler = new VaultHandler(vault, token);

        // Only target the handler — never call vault directly
        targetContract(address(handler));
    }

    /// @dev Total shares == total deposits - total withdrawals
    function invariant_solvency() public view {
        assertGe(
            token.balanceOf(address(vault)),
            handler.ghost_totalDeposited() - handler.ghost_totalWithdrawn(),
            "vault is insolvent"
        );
    }

    /// @dev Vault token balance >= total supply of shares
    function invariant_sharesBacked() public view {
        uint256 totalShares = vault.totalSupply();
        uint256 totalAssets = token.balanceOf(address(vault));
        if (totalShares > 0) {
            assertGt(totalAssets, 0, "shares exist but no assets");
        }
    }

    /// @dev No individual user has more shares than total supply
    function invariant_noShareInflation() public view {
        address[] memory actors = _getActors();
        uint256 totalSupply = vault.totalSupply();
        for (uint256 i = 0; i < actors.length; i++) {
            assertLe(vault.balanceOf(actors[i]), totalSupply);
        }
    }

    /// @dev Ghost tracking matches actual state
    function invariant_ghostAccuracy() public view {
        uint256 expectedVaultBalance =
            handler.ghost_totalDeposited() - handler.ghost_totalWithdrawn();
        assertEq(
            token.balanceOf(address(vault)),
            expectedVaultBalance,
            "ghost tracking diverged"
        );
    }

    function _getActors() internal view returns (address[] memory) {
        address[] memory actors = new address[](5);
        for (uint256 i = 0; i < 5; i++) {
            actors[i] = handler.actors(i);
        }
        return actors;
    }
}

Common DeFi Invariants

Lending Protocol
solidity
function invariant_totalDebtLeTotalSupply() public view {
    assertLe(pool.totalDebt(), pool.totalSupply());
}
function invariant_allPositionsCollateralized() public view {
    // For each borrower, collateral * LTV >= debt
}
AMM / DEX
solidity
function invariant_constantProduct() public view {
    uint256 k = pool.reserve0() * pool.reserve1();
    assertGe(k, initialK, "k decreased"); // k should only increase (fees)
}
function invariant_lpTokensBacked() public view {
    // LP tokens redeemable for proportional reserves
}
Staking
solidity
function invariant_rewardsSolvent() public view {
    assertGe(rewardToken.balanceOf(address(staking)), staking.totalPendingRewards());
}
function invariant_totalStakedMatchesSum() public view {
    uint256 sum = 0;
    for (uint256 i = 0; i < actors.length; i++) {
        sum += staking.balanceOf(actors[i]);
    }
    assertEq(sum, staking.totalSupply());
}

Target Configuration

solidity
// Target specific contract
targetContract(address(handler));

// Target specific functions (exclude admin/setup)
bytes4[] memory selectors = new bytes4[](3);
selectors[0] = VaultHandler.deposit.selector;
selectors[1] = VaultHandler.withdraw.selector;
selectors[2] = VaultHandler.warpTime.selector;
targetSelector(FuzzSelector({addr: address(handler), selectors: selectors}));

// Exclude senders
excludeSender(address(vault)); // don't call as the vault itself

Checklist

  • Handler wraps all user-facing functions with input bounding
  • Ghost variables track expected state changes
  • Actor pool covers multiple users with pre-approved balances
  • bound() constrains all numeric inputs to valid ranges
  • Handler functions silently return on invalid preconditions (don't revert)
  • targetContract() points to handler, not the system under test
  • Invariant functions start with invariant_ prefix
  • Time progression handler included for time-dependent protocols
  • Run with sufficient depth (64+) and runs (256+) for confidence

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/invariant-testing of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Invariant Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Invariant Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Invariant Testing this skillccashwell/evm-cortex131—~1.9kAutomated safety check: PassMIT
Technical Analysttradermonty/claude-trading-skills3k5 repos~4.6kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3601 repos~2kAutomated safety check: PassApache-2.0
Longbridge Researchhelsome/folio2693 repos~2.1kAutomated safety check: PassMIT
Stock Analysis24mlight/StockClaw1012 repos~2kAutomated safety check: NotesMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT

Similar skills

  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 5 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    360 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    269 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed
  • Stock Analysis

    24mlight/StockClaw

    Analyze stocks and cryptocurrencies using Yahoo Finance data.

    101 GitHub starsUsed in 2 repos~2k tokens
    Business, Finance & HRAuto-check: notes
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    186 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 8 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 8 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed

Questions about Invariant Testing

What does Invariant Testing do?

A skill your agent uses when writing Foundry invariant (stateful fuzz) tests. Invariant Testing is an agent skill from ccashwell/evm-cortex. Use when writing Foundry invariant (stateful fuzz) tests.

When should I use Invariant Testing?

Invariant Testing fits situations like: writing Foundry invariant (stateful fuzz) tests; tasks that involve Crypto and DeFi analysis.

How do I install Invariant Testing in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill invariant-testing -a claude-code`. Or copy the skill folder (skills/invariant-testing in ccashwell/evm-cortex) into .claude/skills/invariant-testing in your project. Claude Code loads it when a task matches its description.

How do I install Invariant Testing in Codex?

Run `npx skills add ccashwell/evm-cortex --skill invariant-testing -a codex`. Or copy the skill folder (skills/invariant-testing in ccashwell/evm-cortex) into .agents/skills/invariant-testing in your project. Codex loads it when a task matches its description.

Can I use Invariant Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill invariant-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/invariant-testing, .gemini/skills/invariant-testing, .github/skills/invariant-testing and .opencode/skills/invariant-testing in your project.

What does Invariant Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: Invariant Testing is instructions for the agent only.

Does Invariant Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Invariant Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Invariant Testing use?

Invariant Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Invariant Testing use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Invariant Testing?

Skills that share tags, products or a category with Invariant Testing: Technical Analyst (tradermonty/claude-trading-skills, 3k stars), Polyclaw (chainstacklabs/polyclaw, 360 stars), Longbridge Research (helsome/folio, 269 stars) and Stock Analysis (24mlight/StockClaw, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Invariant Testing?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.