Solidity Vulnerability Scanner
alt-research2/SolidityGuard
Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.
A skill your agent uses when performing a comprehensive smart contract security audit.
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipeline --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pashov-audit-pipeline .claude/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .claude/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipelineType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipeline --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pashov-audit-pipeline .agents/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .agents/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipeline --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pashov-audit-pipeline .cursor/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .cursor/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ccashwell/evm-cortex.git --path skills/pashov-audit-pipeline--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipeline --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pashov-audit-pipeline .gemini/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .gemini/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipelineInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pashov-audit-pipeline .github/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .github/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ccashwell/evm-cortex pashov-audit-pipeline --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pashov-audit-pipeline .opencode/skills/pashov-audit-pipeline && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pashov-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/pashov-audit-pipeline into .opencode/skills/pashov-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pashov-audit-pipeline", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pashov-audit-pipelineA skill your agent uses when performing a comprehensive smart contract security audit.
Pashov Audit Pipeline is an agent skill from ccashwell/evm-cortex. Use when performing a comprehensive smart contract security audit. Implements the Pashov Audit Group's parallelized 12-agent attacker-framing methodology (solidity-auditor v4) — nine single-specialty lenses (math precision, access control, economic security, execution trace, invariant, periphery, first principles, asymmetry, boundary) plus three gap-hunters that find bugs living at the seams between lenses. Supports loop mode (N passes per scan, each told what earlier passes found) and a findings ledger that…
Its SKILL.md is about 5.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including reference files (for example `references/agent-prompts.md`, `references/assemble.sh` and `references/dedup-and-assembly.md`).
It sits in Backend & APIs, covering Smart contracts, Smart contract auditing and Debugging. It works with Solidity. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comraw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pashov Audit Pipeline loads about 5.5k tokens when it runs, and up to ~53k if it reads all its reference files. Until then it costs about 188 tokens; SKILL.md has 2,525 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 2,525 words, ~5,476 tokens.
.claude/skills/pashov-audit-pipeline/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.You are the orchestrator of a parallelized smart contract security audit.
Twelve specialized agents attack the same codebase at once, then their output is deduplicated, gated, and assembled into a single report. Nine work a single lens — arithmetic, permissions, economics, execution flow, invariants, periphery code, first-principles reasoning, asymmetry, and external boundaries. Three are gap-hunters that report only what lives at the seam between lenses, which is precisely the class a single-lens scan structurally cannot see.
Vendored from the Pashov Audit Group's open-source approach (github.com/pashov/skills), skill solidity-auditor, VERSION 4 (see the VERSION file alongside this one). Everything under references/ is upstream content carried over intact, with four documented EVM Cortex deviations:
references/orchestration.md is upstream's SKILL.md, vendored verbatim so the turn-by-turn procedure (memory read, prune, bundle build, run files, assembly) stays a file-by-file diff against upstream. Where any reference file says "SKILL.md Turn N", it means that file.references/judging.md carries an appended severity/PoC addendum required by this repo's finding-output-format, severity-matrix, and poc-execution rules.on-chain/off-chain are normalized to onchain/offchain across references/ prose and in the one disclaimer string assemble.sh prints, per this repo's style rule.assemble.sh carries a file-level # shellcheck disable=SC2034 directive on line 2, because this repo's CI runs ShellCheck at warning level over every .sh file and the assembler's read loops bind TSV columns it does not use. Nothing else in the script differs.Every other EVM Cortex adaptation — agent mapping, context package, Foundry pre-flight, the severity line in each finding block, and the Turn 6 annex — lives in this SKILL.md only, so an upstream re-sync replaces references/ cleanly. Check for a newer upstream revision before a high-stakes audit:
curl -sf https://raw.githubusercontent.com/pashov/skills/main/solidity-auditor/VERSIONIf that returns a number greater than 4, this skill is behind upstream.
--loop [N] runs N passes of the twelve agents in one scan. Every pass after the first is handed what the earlier passes found as "ground already walked", so it hunts new ground. One combined report at the end. When the runner asks for loop mode without a number, the default is 3 passes; the reference gives measured times (about 15 minutes per pass on a 2,200-line codebase).--memory (on automatically when passes > 1) keeps a ledger at .solidity-auditor/memory.tsv in the audited repo. Findings are tagged KNOWN (n scans) or NEW; records the scan did not raise again are listed under "Known from earlier scans" and explicitly marked not re-checked..solidity-auditor/runs/{stamp}/run-K.md while it still has context to spare; references/assemble.sh is the only producer of full-report.md. The orchestrator never composes, re-words, or summarizes the report. A real 3-pass scan that produced 71 findings once printed 14 of them and claimed full coverage; the design exists to kill that defect.references/report-language.md is appended to every agent bundle and governs every title and Description: one sentence, 25 words or fewer, active voice, names who acts and what they get.judging.md; the assembler reads it from there.script/, deploy/, *.s.sol) are in scope because they set constructor arguments and hand over ownership; explicitly named files are always scanned wherever they live.VERSION is lower than upstream, not merely different.Every agent is framed as an attacker with unlimited capital and flash loans, not as a reviewer working a checklist. Three consequences worth stating up front, because they invert the instinct:
reentrancy-patterns, flash-loan-attacks, oracle-manipulation, signature-vulnerabilities, economic-attack-vectors, denial-of-service) — load those for reference. A pure catalog sweep was an earlier generation of this pipeline; it produced volume without depth, which is why upstream dropped the dedicated vector-scan agent in v3.--memory so the report says what is newaudit-breadth-scanslither-analysis or aderyn-analysisgas-optimizercode-reviewerxray-pre-audit first, then feed its output in as the context packagesimao-audit-pipeline as well and treat overlap as signalFollow references/orchestration.md turn by turn — Mode Selection, Turn 1 through Turn 5, and its Banner — with the EVM Cortex substitutions and insertions below. The reference files it delegates to sit in the same directory: agent-prompts.md (Turn 3a prompts), dedup-and-assembly.md (Turn 4 and Turn 5 procedure), report-formatting.md (finding-block shape), report-language.md (wording), judging.md (gates, confidence, lead promotion, severity addendum), senior-auditor-sop.md and hacking-agents/ (bundle content), and assemble.sh (the assembler).
Two upstream steps are pinned here because the runtime differs:
{resolved_path} is this skill's own references/ directory. Do not glob for shared-rules.md — the installer places a copy under ~/.claude/skills/ and a repo checkout may hold another, and a glob can pick the wrong one.⚠️ Upstream solidity-auditor is at version N, this skill is vendored at 4. See https://github.com/pashov/skills. A failed fetch is skipped silently — a network failure is not an audit finding.Ask both questions in one AskUserQuestion call exactly as the reference describes. The runner's model choice {agent_model} applies to agents 1–9. The three gap-hunters (agents 10–12) run on opus regardless of the answer. Cross-lens reasoning is where model tier matters most; a weaker gap-hunter collapses into restating single-lens findings, which dedup then discards as duplicates — the most expensive way to save money in this pipeline. Say so in one line when the runner picks a lower tier.
If the audited repo's .gitignore does not list .solidity-auditor/, print a one-line reminder that the runs directory and ledger should be ignored. Do not edit .gitignore yourself.
After source.md is built and before the bundles are catted, assemble, when available: the protocol README, known issues (to avoid duplicate reports), documented design decisions, deployment context (target chains, upgrade strategy), external dependencies, and prior audit reports with resolution status. Write it to {bundle_dir}/context.md and append it to every bundle after report-language.md and before known-findings.md. Keep it under 300 lines; the agents' attention belongs to the source.
If xray-pre-audit has been run, its x-ray/x-ray.md is the best available context package — it already carries the threat model, invariant list, and entry-point classification.
Run in the audited repo, writing outputs only under the scan directory:
forge build --deny-warnings
forge test --summary
slither . --filter-paths "test|script|node_modules|lib" --json .solidity-auditor/runs/{stamp}/slither-report.json
forge tree > .solidity-auditor/runs/{stamp}/dependency-tree.txtforge build and forge test write only to out/ and cache/, which the scan excludes. A build failure is not a stopper — note it in the context package and continue; the agents read source, not artifacts. If the project is not a Foundry project, skip the forge steps and say so.
Use the two prompt templates in references/agent-prompts.md verbatim, substituting {bundle_dir}, the agent number, and the bundle's real line count. The READ-ONLY paragraph is unconditional; the "Known findings" paragraph appears only when memory is on and known-findings.md was appended. Spawn all twelve as parallel background Agent calls with these subagent_type values:
| # | Lens | subagent_type | Model |
|---|---|---|---|
| 1 | Math & Precision | depth-token-flow | opus |
| 2 | Access Control | access-control-reviewer | sonnet |
| 3 | Economic Security | mev-analyst | sonnet |
| 4 | Execution Trace | depth-state-trace | opus |
| 5 | Invariant | invariant-analyst | sonnet |
| 6 | Periphery | depth-external | opus |
| 7 | First Principles | sleuth | opus |
| 8 | Asymmetry | code-reviewer | opus |
| 9 | Boundary | depth-edge-case | sonnet |
| 10 | Numerical Gap | depth-token-flow | opus |
| 11 | Trust Gap | mev-analyst | opus |
| 12 | Flow Gap | sleuth | opus |
The subagent_type selects a base persona and tool set; the specialty file in the bundle is what determines the lens. Reused types (depth-token-flow, mev-analyst, sleuth) run as independent instances with different bundles and share no context. The Model column is the default when Turn 1b set no {agent_model}; when it did, agents 1–9 take the runner's choice and 10–12 stay on opus.
shared-rules.md binds every agent to three mental tools from senior-auditor-sop.md, each with a trigger that requires a literal marker in the agent's output: [Feynman: <name>] when it opens a new function, [Socratic: <file:line> — why?] when it stops on an unclear line, [Inversion: <function>] when a path reads as clean.
After each agent returns, grep its output for those markers. An agent that returns findings with no markers did not reason — it scanned. Note the shortfall as a workflow violation and weight that agent's findings accordingly. Do not respawn it: in loop mode the next pass covers the same lens for free, and on a 1-pass scan a retry costs an unbounded wait for one twelfth of the coverage.
Follow references/dedup-and-assembly.md Turn 4 step by step. Between step 3 (lead promotion) and step 4 (memory tag), classify every gated FINDING per the severity addendum in judging.md — impact × likelihood from the global severity matrix, assigned independently of confidence. LEADs are not classified.
In step 5a, write the severity into the finding block's body as one structured line between the Description and the Fix:
**Description**
<one sentence>
**Severity** High · Impact High · Likelihood Likely
**Fix**
...The assembler pastes the body through unchanged, so the line reaches the report without any change to assemble.sh. It is a structured field, not prose: report-language.md rule 10 (no critical, severe in sentences) governs sentences and does not reach it. Use exactly one of Critical, High, Medium, Low, Informational, and keep the **Severity** prefix and · separators exactly — Turn 6 extracts the value by shell.
Follow references/dedup-and-assembly.md Turn 5 unchanged. Do not re-word, re-order, add to, or summarize full-report.md. The --file-output copy is named {project-name}-pashov-ai-audit-report-{stamp}.md.
Runs after Turn 5, at any pass count. It reads full-report.md and never writes to it.
awk over the assembled file; the # column is the finding's number in full-report.md:REPORT=.solidity-auditor/runs/{stamp}/full-report.md
awk -v OFS='\t' '
function rank(s){ return (s=="Critical")?0:(s=="High")?1:(s=="Medium")?2:(s=="Low")?3:(s=="Informational")?4:5 }
function flush(){ if (want) { n++; print rank(sev), conf+0, "| " n " | " sev " | [" conf "] | " title " | `" loc "` |"; want=0 } }
/^\[[0-9]+\] \*\*[0-9]+\. / { flush(); match($0,/^\[[0-9]+\]/); conf=substr($0,RSTART+1,RLENGTH-2)
t=$0; sub(/^\[[0-9]+\] \*\*[0-9]+\. /,"",t); sub(/\*\*[ \t]*$/,"",t); title=t; want=1; sev="Unclassified"; loc=""; next }
want && loc=="" && /^`/ { match($0,/^`[^`]*`/); loc=substr($0,RSTART+1,RLENGTH-2); next }
want && /^\*\*Severity\*\* / { s=$0; sub(/^\*\*Severity\*\* /,"",s); sub(/ ·.*$/,"",s); sev=s; next }
/^Findings List/ { flush() }
END { flush() }
' "$REPORT" | sort -t$'\t' -k1,1n -k2,2nr | cut -f3 > .solidity-auditor/runs/{stamp}/severity-rows.md
wc -l < .solidity-auditor/runs/{stamp}/severity-rows.mdThe row count must equal F from Turn 5 step 3. If it does not, the annex says so in words and lists what it could read — it never claims to cover more than it does. A finding whose block lacks a severity line prints as Unclassified; leave it so and say why, rather than editing the assembled report.
.solidity-auditor/runs/{stamp}/severity-annex.md:# Severity annex — <project-name>
_EVM Cortex layer over `full-report.md` (same stamp). Severity is impact × likelihood per the global severity matrix and is independent of confidence. `#` is the finding's number in the report. Rows: N of F findings._
| # | Severity | Confidence | Title | Location |
|---|---|---|---|---|
<severity-rows.md, verbatim>
## Proof of concept
_Critical and High findings require a working Foundry PoC before they are reported at that severity. Medium findings need a PoC or a step-by-step reproduction._
| # | Severity | PoC | Status |
|---|---|---|---|
| 3 | Critical | `.solidity-auditor/runs/{stamp}/poc/Exploit_3.t.sol` | passes · fork block 19_000_000 |
| 7 | High | — | pending — routed to poc-writer |security-verifier or poc-writer with the finding block and the source it names. PoC tests are written only under .solidity-auditor/runs/{stamp}/poc/ — never into the project's test/ — and run with the test directory overridden so the project tree stays untouched:FOUNDRY_TEST=.solidity-auditor/runs/{stamp}/poc forge test --match-path '.solidity-auditor/runs/{stamp}/poc/*' -vvvPin the fork block in every fork-based PoC. A Critical or High finding whose PoC fails is downgraded in the annex with a one-line reason; the severity line in the run file is left as written — the run file is the pass's record, the annex is this turn's verdict.
Fix verification for findings at or above the threshold, per the judging.md addendum: trace the fix against the attack path, run the side-effect checklist, and pattern-check the rest of the codebase for the same defect.
Print a five-number summary and the annex path, nothing else:
Severity: Critical N · High N · Medium N · Low N · Informational N — annex: .solidity-auditor/runs/{stamp}/severity-annex.mdWith --file-output, also copy the annex to {project-name}-pashov-ai-audit-severity-{stamp}.md beside the report copy.
The procedure is references/dedup-and-assembly.md Turn 4 step 1 and is followed from there, not from here. The gates are hard, and the failure mode they exist for is silently deleting real bugs — twelve agents converging on one function is information, not redundancy:
known-findings.md wins, then the majority label, then the shortest label that names the defect. Without it one bug becomes three ledger records and is never recognised again.function: values. A different function is a different bug, always.bug_class, every mechanism in any constituent body survives into a final finding.Completeness: N unique (Contract, function) in raw, N covered in final.Composite chains: Chain: [A] + [B] at confidence = min(A, B) when A's output feeds B's precondition and the combined impact exceeds either alone. Most audits produce zero to two.
find command in orchestration.md (deploy scripts in, build and dependency dirs out)xray-pre-audit run, or an equivalent context package assembledVERSION (4) checked against upstream{stamp} computed once; .solidity-auditor/runs/{stamp}/scope.tsv opened with name, mode, filesAskUserQuestion; passes_planned written#solidity-auditor-memory v1, 6 columns) or the scan stoppedsource.md built once; twelve bundles built per pass, each ending with report-language.md (+ context.md, + known-findings.md when present); line counts printed and none undersized.solidity-auditor/ gitignored in the audited repo (reminder printed if not)pass_K_agents**Severity** line in its run-file block<!--F …--> / <!--/F--> markers; assemble.sh reported no structure breakfull-report.md printed word for word (20 findings or fewer) or as the counted top-3 slice (more than 20); never re-wordedmemory.tsv written atomically via .tmp; mem_after and mem_sha recordedF; Foundry PoC passing for every Critical and High, under .solidity-auditor/runs/{stamp}/poc/.solidity-auditor/ except --file-output copiesBefore doing anything else, print this exactly:
██████╗ █████╗ ███████╗██╗ ██╗ ██████╗ ██╗ ██╗ ███████╗██╗ ██╗██╗██╗ ██╗ ███████╗
██╔══██╗██╔══██╗██╔════╝██║ ██║██╔═══██╗██║ ██║ ██╔════╝██║ ██╔╝██║██║ ██║ ██╔════╝
██████╔╝███████║███████╗███████║██║ ██║██║ ██║ ███████╗█████╔╝ ██║██║ ██║ ███████╗
██╔═══╝ ██╔══██║╚════██║██╔══██║██║ ██║╚██╗ ██╔╝ ╚════██║██╔═██╗ ██║██║ ██║ ╚════██║
██║ ██║ ██║███████║██║ ██║╚██████╔╝ ╚████╔╝ ███████║██║ ██╗██║███████╗███████╗███████║
╚═╝ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ╚═════╝ ╚═══╝ ╚══════╝╚═╝ ╚═╝╚═╝╚══════╝╚══════╝╚══════╝© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 22 other files (references) in skills/pashov-audit-pipeline of ccashwell/evm-cortex.
Open the folder on GitHubat commit f8f3301
Pashov Audit Pipeline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pashov Audit Pipeline this skillccashwell/evm-cortex | 131 | — | ~5.5k | Automated safety check: Pass | MIT | |
| Solidity Vulnerability Scanneralt-research2/SolidityGuard | 104 | — | ~1.6k | Automated safety check: Notes | Custom licence | |
| Smart Contract Auditelophanto/EloPhanto | 106 | — | ~2.7k | Automated safety check: Pass | Custom licence | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Smart Contract Auditgreatpie/smart-contract-audit-skill | 101 | — | ~1.1k | Automated safety check: Pass | None | |
| Solidity AuditorGabson0x/bountyforge | 442 | — | ~3.7k | Automated safety check: Pass | None |
alt-research2/SolidityGuard
Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
pashov/skills
Security audit of Solidity code while you develop. An agent skill from pashov/skills.
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
ccashwell/evm-cortex
A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.
ccashwell/evm-cortex
Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.
ccashwell/evm-cortex
A skill your agent uses when running a local Ethereum node with Anvil.
ccashwell/evm-cortex
A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.
ccashwell/evm-cortex
A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.
Works with
Categories
A skill your agent uses when performing a comprehensive smart contract security audit. Pashov Audit Pipeline is an agent skill from ccashwell/evm-cortex. Use when performing a comprehensive smart contract security audit.
Pashov Audit Pipeline fits situations like: performing a comprehensive smart contract security audit; run the auditor in loop mode.
Run `npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a claude-code`. Or copy the skill folder (skills/pashov-audit-pipeline in ccashwell/evm-cortex) into .claude/skills/pashov-audit-pipeline in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a codex`. Or copy the skill folder (skills/pashov-audit-pipeline in ccashwell/evm-cortex) into .agents/skills/pashov-audit-pipeline in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill pashov-audit-pipeline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pashov-audit-pipeline, .gemini/skills/pashov-audit-pipeline, .github/skills/pashov-audit-pipeline and .opencode/skills/pashov-audit-pipeline in your project.
Going by SKILL.md and its folder, Pashov Audit Pipeline needs a shell for the scripts in its folder and the command-line tools its instructions call (curl). Our summary lists: A Bash shell.
SKILL.md names 2 domains. In commands or code: github.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pashov Audit Pipeline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.5k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 48k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Pashov Audit Pipeline: Solidity Vulnerability Scanner (alt-research2/SolidityGuard, 104 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars), Fizz Convert (pashov/skills, 1.2k stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.
Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.