Agent skill

Natspec Standards

by ccashwell in ccashwell/evm-cortex

NatSpec documentation standards for Solidity contracts. An agent skill from ccashwell/evm-cortex.

MITAuto-check passedBackend & APIs

Install Natspec Standards

skills CLI
$ npx skills add ccashwell/evm-cortex --skill natspec-standards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex natspec-standards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/natspec-standards .claude/skills/natspec-standards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
natspec-standards
GitHub stars
131
Token cost
~1.6k tokens
SKILL.md length
191 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

NatSpec documentation standards for Solidity contracts. An agent skill from ccashwell/evm-cortex.

  • Reviewing contract documentation
  • SKILL.md covers Required Documentation, Tags Reference, Contract-Level Documentation and Function Documentation, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Smart contracts

What it does

Natspec Standards is an agent skill from ccashwell/evm-cortex. NatSpec documentation standards for Solidity contracts. Use when writing or reviewing contract documentation. Every public and external function must have NatSpec. Covers all tags, formatting conventions, and complete examples.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. It works with Solidity. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Reviewing contract documentation
  • Tasks that involve Smart contracts

Example prompts

  • “/natspec-standards”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Natspec Standards loads about 1.6k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 191 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 191 words, ~1,633 tokens.

Download SKILL.mdSave it as .claude/skills/natspec-standards/SKILL.md (or your agent's skills folder).
name
natspec-standards
description
NatSpec documentation standards for Solidity contracts. Use when writing or reviewing contract documentation. Every public and external function must have NatSpec. Covers all tags, formatting conventions, and complete examples.

NatSpec Standards

Required Documentation

Every public and external function must have NatSpec. Internal functions that are non-trivial should also be documented.

Tags Reference

TagContextDescription
@titleContract/interfaceTitle of the contract
@authorContract/interfaceAuthor name or team
@noticeContract/function/event/errorUser-facing explanation (shown in etherscan)
@devContract/function/event/errorDeveloper-facing technical details
@paramFunction/event/errorDescribes a parameter
@returnFunctionDescribes a return value
@inheritdocFunctionInherits docs from parent contract
@custom:tagAnyCustom metadata (e.g., @custom:security-contact is mandatory)

Contract-Level Documentation

solidity
/// @title Staking Vault
/// @author Uniswap Labs
/// @notice Handles staking deposits and reward distribution for protocol governance tokens.
/// @dev Uses ERC-4626 vault standard with custom reward distribution.
///      Storage layout is proxy-compatible (see storage-layout skill).
/// @custom:security-contact security@uniswap.org
contract StakingVault is ERC4626, Ownable2Step, ReentrancyGuard {
    // ...
}

Function Documentation

solidity
/// @notice Deposits tokens into the vault and mints shares to the caller.
/// @dev Follows CEI pattern. Emits {Deposited} event. The share calculation
///      uses the current exchange rate, which may be manipulated in the same
///      block — see economic-attack-vectors for first-depositor defense.
/// @param token The address of the ERC-20 token to deposit.
/// @param amount The amount of tokens to deposit (in token's native decimals).
/// @return shares The number of vault shares minted to the caller.
function deposit(address token, uint256 amount)
    external
    nonReentrant
    whenNotPaused
    returns (uint256 shares)
{
    if (token == address(0)) revert ZeroAddress();
    if (amount == 0) revert ZeroAmount();

    shares = convertToShares(amount);
    _mint(msg.sender, shares);

    IERC20(token).safeTransferFrom(msg.sender, address(this), amount);

    emit Deposited(msg.sender, token, amount, shares);
}

Multiple Return Values

Each return value gets its own @return tag, in order.

solidity
/// @notice Returns the position details for a given position ID.
/// @param positionId The unique identifier of the position.
/// @return owner The address that owns the position.
/// @return collateral The amount of collateral deposited (in token decimals).
/// @return debt The amount of debt owed (in token decimals).
/// @return healthFactor The position's health factor (18 decimals, < 1e18 = liquidatable).
function getPosition(uint256 positionId)
    external
    view
    returns (
        address owner,
        uint256 collateral,
        uint256 debt,
        uint256 healthFactor
    )
{
    // ...
}

@inheritdoc

Use @inheritdoc to inherit documentation from a parent interface or abstract contract. Add @dev for implementation-specific details.

solidity
interface IVault {
    /// @notice Withdraws tokens by burning vault shares.
    /// @param shares The number of shares to burn.
    /// @return amount The number of tokens returned to the caller.
    function withdraw(uint256 shares) external returns (uint256 amount);
}

contract Vault is IVault {
    /// @inheritdoc IVault
    /// @dev Applies a withdrawal fee of 0.1% (10 bps). The fee is retained
    ///      in the vault, increasing the share price for remaining holders.
    function withdraw(uint256 shares) external override returns (uint256 amount) {
        // ...
    }
}

Event Documentation

solidity
/// @notice Emitted when a user deposits tokens into the vault.
/// @param user The address of the depositor.
/// @param token The address of the deposited token.
/// @param amount The amount deposited (in token's native decimals).
/// @param shares The number of vault shares minted.
event Deposited(address indexed user, address indexed token, uint256 amount, uint256 shares);

Error Documentation

solidity
/// @dev Thrown when the oracle price feed returns data older than the staleness threshold.
/// @param feed The address of the Chainlink price feed.
/// @param updatedAt The timestamp of the last price update.
/// @param threshold The maximum allowed age in seconds.
error Oracle_StalePrice(address feed, uint256 updatedAt, uint256 threshold);

Custom Tags

solidity
/// @custom:security-contact security@protocol.xyz
/// @custom:oz-upgrades-from StakingVaultV1
/// @custom:storage-location erc7201:protocol.storage.StakingVault
contract StakingVaultV2 is StakingVaultV1 {
    // ...
}

Modifier Documentation

solidity
/// @dev Restricts function access to the designated oracle updater.
///      Reverts with {Unauthorized} if caller is not the updater.
modifier onlyUpdater() {
    if (msg.sender != updater) revert Unauthorized();
    _;
}

Struct Documentation

solidity
/// @notice Represents a user's staking position.
/// @dev Packed into 2 storage slots (64 bytes). See storage-layout skill.
/// @param amount The staked token amount (18 decimals).
/// @param rewardDebt Used for reward accounting (scaled by ACC_PRECISION).
/// @param lockEnd The timestamp when the lock period expires.
/// @param boostMultiplier The user's boost factor (100 = 1x, 200 = 2x).
struct StakeInfo {
    uint256 amount;
    uint256 rewardDebt;
    uint48 lockEnd;
    uint16 boostMultiplier;
}

NatSpec Checklist

  • Every contract has @title, @author, @notice
  • Every public/external function has @notice, @param, @return
  • Complex functions have @dev with implementation details
  • Events have @notice and @param for each parameter
  • Custom errors have @dev explaining trigger conditions
  • @inheritdoc used for interface implementations
  • @custom:security-contact on all deployable contracts
  • No redundant docs (don't restate what the code obviously does)
  • Units specified in @param/@return (decimals, bps, seconds)
  • Cross-references to related skills/patterns where helpful

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/natspec-standards of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Natspec Standards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Natspec Standards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Natspec Standards this skillccashwell/evm-cortex131—~1.6kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Add Explorer

    lidofinance/diffyscan

    Adds or repairs Diffyscan explorer API routing and response adapters for a new host, chain or payload format.

    142 GitHub stars~1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 10 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 10 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 10 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Natspec Standards

What does Natspec Standards do?

NatSpec documentation standards for Solidity contracts. An agent skill from ccashwell/evm-cortex. Natspec Standards is an agent skill from ccashwell/evm-cortex. NatSpec documentation standards for Solidity contracts.

When should I use Natspec Standards?

Natspec Standards fits situations like: reviewing contract documentation; tasks that involve Smart contracts.

How do I install Natspec Standards in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill natspec-standards -a claude-code`. Or copy the skill folder (skills/natspec-standards in ccashwell/evm-cortex) into .claude/skills/natspec-standards in your project. Claude Code loads it when a task matches its description.

How do I install Natspec Standards in Codex?

Run `npx skills add ccashwell/evm-cortex --skill natspec-standards -a codex`. Or copy the skill folder (skills/natspec-standards in ccashwell/evm-cortex) into .agents/skills/natspec-standards in your project. Codex loads it when a task matches its description.

Can I use Natspec Standards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill natspec-standards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/natspec-standards, .gemini/skills/natspec-standards, .github/skills/natspec-standards and .opencode/skills/natspec-standards in your project.

What does Natspec Standards need to run?

SKILL.md names no scripts, command-line tools or credentials: Natspec Standards is instructions for the agent only.

Does Natspec Standards access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Natspec Standards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Natspec Standards use?

Natspec Standards is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Natspec Standards use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Natspec Standards?

Skills that share tags, products or a category with Natspec Standards: Fizz Convert (pashov/skills, 1.2k stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars) and Radar (Auditware/radar, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Natspec Standards?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.