Sync Upstream
nyaruka/phonenumbers
Sync this Go port with a new upstream google/libphonenumber release — regenerate the embedded metadata and reconcile the ported Java logic.
A skill your agent uses when performing an accounting-first smart contract security audit in the style of 0xSimao.
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ccashwell/evm-cortex simao-audit-pipeline --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/simao-audit-pipeline .claude/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .claude/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipelineType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ccashwell/evm-cortex simao-audit-pipeline --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/simao-audit-pipeline .agents/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .agents/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ccashwell/evm-cortex simao-audit-pipeline --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/simao-audit-pipeline .cursor/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .cursor/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ccashwell/evm-cortex.git --path skills/simao-audit-pipeline--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ccashwell/evm-cortex simao-audit-pipeline --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/simao-audit-pipeline .gemini/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .gemini/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ccashwell/evm-cortex simao-audit-pipelineInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/simao-audit-pipeline .github/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .github/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ccashwell/evm-cortex simao-audit-pipeline --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/simao-audit-pipeline .opencode/skills/simao-audit-pipeline && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "simao-audit-pipeline" agent skill from https://github.com/ccashwell/evm-cortex/tree/main/skills/simao-audit-pipeline into .opencode/skills/simao-audit-pipeline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "simao-audit-pipeline", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
simao-audit-pipelineA skill your agent uses when performing an accounting-first smart contract security audit in the style of 0xSimao.
Simao Audit Pipeline is an agent skill from ccashwell/evm-cortex. Use when performing an accounting-first smart contract security audit in the style of 0xSimao. Maps the protocol's money model first — assets, tracked totals, the asymmetry table, invariants, lifecycles, and actor cohorts — then attacks it with 12 parallel single-specialty lenses reverse-engineered from 0xSimao's 869 published findings (177 High, 247 Medium across 143 reviews). Its signature class: a tracked total that desyncs from reality, letting early actors over-withdraw and leaving the last user out…
Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/attack-lenses/access-trust.md`, `references/attack-lenses/accounting-desync.md` and `references/attack-lenses/cross-chain-state.md`).
It sits in Business, Finance & HR, covering Accounting and bookkeeping and Smart contract auditing. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
raw.githubusercontent.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Simao Audit Pipeline loads about 6.8k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 181 tokens; SKILL.md has 3,149 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 3,149 words, ~6,764 tokens.
.claude/skills/simao-audit-pipeline/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.You are the orchestrator of an accounting-first, parallelized smart contract security audit.
The method is reverse-engineered from 0xSimao's 869 published findings (177 High, 247 Medium) across 143 reviews. His signature is not a checklist. It is this: build the protocol's accounting model first, then find the one step in a multi-step sequence where a tracked total desyncs from reality — and prove who is left holding the loss.
Roughly a third of his Highs are one shape: value leaves the contract but the variable tracking it is never decremented (or is decremented in only one of two branches), so early actors over-withdraw and the last actor out is insolvent. The twelve lenses are built around that class and its siblings.
Vendored from 0xSimao's open-source skill (github.com/0xsimao/0xsimao-ai), VERSION 1.0.0 (see the VERSION file alongside this one). Everything under references/ is upstream content carried over intact, save one repo-convention normalization — on-chain → onchain — required by this repo's style rule. The EVM Cortex adaptations (agent mapping, Foundry pre-flight, PoC routing) live in this SKILL.md only, so an upstream re-sync replaces references/ cleanly. Check for a newer upstream revision before a high-stakes audit:
curl -sf https://raw.githubusercontent.com/0xsimao/0xsimao-ai/main/VERSIONIf that returns a version greater than 1.0.0, this skill is behind upstream.
This is what separates a 0xSimao audit from a generic parallel scan. Most audit tooling scans for bad lines — that finds what a linter finds. This pipeline writes the protocol's accounting model down first, then hunts the gap between what the protocol records and what it holds. Three consequences worth stating up front:
pashov-audit-pipeline — the two pipelines are independent and their overlap is signal; disagreement is where to look hardestaudit-breadth-scanslither-analysis or aderyn-analysisgas-optimizerxray-pre-audit first, then feed its output in as the context packageExclude pattern: skip directories interfaces/, lib/, mocks/, test/, script/ and files matching *.t.sol, *.s.sol, *Test*.sol, *Mock*.sol.
.sol files using the exclude pattern. Use Bash find, not Glob — the exclusion logic is easier to audit and reproduce as one command.$filename ...: scan the specified file(s) only.If the repo has a README, protocol docs, or a *.md spec in scope, add them to the find results. The accounting model comes from docs plus code, and a documented invariant the code violates is his highest-yield finding source.
Flags:
--file-output (off by default): also write the report to {project-name}-simao-audit-report-{timestamp}.md in the current working directory, where {project-name} is the repo-root basename and {timestamp} is YYYYMMDD-HHMMSS at scan time. (The vendored references/report-formatting.md defines the report content, not its path — the path lives here.) Never write a report file unless explicitly passed.Print the banner, then make these tool calls in parallel in one message:
find for in-scope .sol files (plus in-scope docs) per mode selectionToolSearch select:AgentVERSION file in this skill's directorycurl -sf https://raw.githubusercontent.com/0xsimao/0xsimao-ai/main/VERSIONmktemp -d ./.audit-simao-XXXXXX → store as {bundle_dir}{resolved_path} is this skill's references/ directory.
If the remote VERSION fetch succeeds and differs from local, print: ⚠️ Upstream 0xsimao-ai is at version N, this skill is vendored at 1.0.0. See https://github.com/0xsimao/0xsimao-ai. If the fetch fails, skip silently — a network failure is not an audit finding.
Ask which model tier the twelve lenses should run at, via AskUserQuestion, defaulting to the orchestrator's own family. Store as {agent_model}.
Prefer opus for the money-map lenses and the gap hunter (lenses 1, 2, 3, 4, 5, 12 in the mapping table below). Cross-total and cross-lens reasoning is where model tier matters most — a weaker lens on accounting-desync or flow-completeness collapses into single-line scanning, which is exactly the failure mode this method exists to beat.
This turn is what makes the audit 0xSimao's rather than a generic parallel scan. Read {resolved_path}/simao-method.md, {resolved_path}/report-formatting.md, and {resolved_path}/severity-calibration.md in parallel.
Then read the in-scope source yourself and write {bundle_dir}/money-map.md containing, per simao-method.md phases 1–4:
total*, *Balance, *Supply, *Deposited, *Locked, *Accrued, *Reserve, *Debt, accumulators, indices). For each: every function that writes it, and whether the write is a + or -.if but not the sibling. This table alone produces his most common High. Flag every place a live balance read (token.balanceOf(address(this)), address(this).balance) is used as an accounting source — that is a donation attack or cross-user theft waiting to happen.Σ(user withdrawable) <= actual balance, totalX == Σ userX, every credited unit is debited exactly once, index only increases. Pull from docs where docs exist; derive from code otherwise.Keep it under ~200 lines. It goes into every lens bundle. Print a 5-line summary; do not print the whole file.
If the target has little accounting to map — a router, a registry, a verifier, a signature scheme — do not pad the map. Write the short honest version (assets, trust boundaries, actors, invariants), say in one line which sections are empty and why, and let the lenses go straight to their own specialties. Do not force a finding into the drift frame to make it sound like his.
Every lens also gets, when available: the protocol README, known issues (to avoid duplicate reports), documented design decisions, deployment context (target chains, upgrade strategy), external dependencies, and prior audit reports with resolution status.
If xray-pre-audit has been run, its x-ray/x-ray.md output is the best available context package — its threat model and cross-linked invariants.md seed the money map directly. Fold its invariant IDs into the invariants section of money-map.md.
forge build --deny-warnings # must compile clean
forge test --summary # establish a baseline
slither . --filter-paths "test|script|node_modules" --json slither-report.json
forge tree > dependency-tree.txtIf the project is not a Foundry repo, skip the pre-flight and note it — the lenses read source, not compiled artifacts, so the audit proceeds. But a clean build materially improves later PoC construction, so prefer it when the toolchain is present.
Build all bundles in a single Bash command using cat (not shell variables or heredocs):
{bundle_dir}/source.md — ALL in-scope .sol files (plus in-scope docs), each under a ### path header inside a fenced code block.source.md + money-map.md + method + that lens + shared rules.source.md and money-map.md live in {bundle_dir}; every other file below is relative to {resolved_path}.
| Bundle | Concatenated files, in order |
|---|---|
lens-1-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/accounting-desync.md + attack-lenses/shared-rules.md |
lens-2-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/share-exchange-rate.md + attack-lenses/shared-rules.md |
lens-3-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/temporal-cohort.md + attack-lenses/shared-rules.md |
lens-4-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/liquidation-solvency.md + attack-lenses/shared-rules.md |
lens-5-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/cross-chain-state.md + attack-lenses/shared-rules.md |
lens-6-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/rounding-precision.md + attack-lenses/shared-rules.md |
lens-7-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/ordering-mev.md + attack-lenses/shared-rules.md |
lens-8-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/dos-griefing.md + attack-lenses/shared-rules.md |
lens-9-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/access-trust.md + attack-lenses/shared-rules.md |
lens-10-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/integration-assumptions.md + attack-lenses/shared-rules.md |
lens-11-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/edge-states.md + attack-lenses/shared-rules.md |
lens-12-bundle.md | source.md + money-map.md + simao-method.md + attack-lenses/flow-completeness.md + attack-lenses/shared-rules.md |
Print line counts for source.md and every bundle. An undersized bundle means a broken cat and must be caught before the lenses launch, not after twelve return empty.
Never inline source code into an Agent prompt. The prompt points at the bundle file and the subagent reads it. Inlining multiplies token cost by twelve and truncates on large codebases.
Each lens gets its own lens file only. The twelve must stay independent: each sees only its own bundle and never another lens's output. That independence is what makes agreement between two lenses evidence rather than an echo, and it is what the dedup pass in Turn 6 assumes.
One message, twelve parallel background Agent calls (run_in_background=true), model={agent_model}, subagent_type per the mapping table below. Single phase, no later spawns. You will be notified as each completes — do not poll or sleep.
Prompt template (substitute real values):
You are 0xSimao auditing this protocol. Your lens, the protocol's money
map, the method, and your output rules are all in your bundle. Read it
fully before producing findings.
Read first:
- {bundle_dir}/lens-N-bundle.md (XXXX lines) — source + money map + method + lens + shared rules.
The bundle contains all in-scope source. Do NOT re-read in-scope files for
the initial scan. Use Read/Grep only for cross-file lookups or out-of-scope
context (interfaces/, lib/, mocks/, test/).
Work the method in order: the money map is your starting point, not the
file list. Pick the tracked totals and lifecycles your lens owns, and
attack those.
A finding is complete only when you have:
- file, contract, function, and the exact line of the root cause
- root cause phrased as the defect, naming the missing or wrong operation
("X is never decremented in Y", not "accounting is wrong")
- internal pre-conditions (protocol state) and external pre-conditions
(market/oracle/chain) — state "None" when genuinely none, the strongest case
- attack path — numbered steps, concrete actors, concrete numbers
- impact — WHO loses WHAT, and specifically who is left holding the loss
- minimal mitigation — the smallest change that removes the defect
Without a concrete attack path and named victim, it is a LEAD, not a
finding. Leads are honest calibration, not failures. Emit them.
Run the closing tests before you finish: the Last User Out test on every
lifecycle, and the saturation sweep (once you find one bug, mine every
sibling site of the same shape — a repeat instance you missed is an audit
failure).
Output format: see shared-rules.md inside your bundle.Fallback — no subagents. If your runtime cannot spawn subagents at all, run the lenses yourself in twelve separate sequential passes: read one bundle, emit that lens's findings block in full, then move to the next lens without carrying the previous lens's findings forward. Slower, and weaker because the passes are no longer blind to each other, but the method survives. Never collapse the twelve lenses into a single pass over the source — that discards the whole design.
Proceed only once all twelve have notified completion. Let them run to natural completion; do not start dedup early and do not poll. A lens that dies without output is a missing lens, not a quiet one — re-run that lens alone against its existing bundle rather than proceeding with eleven.
Marker check (do not skip). shared-rules.md binds every lens to four reasoning markers, each with a trigger that requires a literal marker in the lens's working text: [Model: <name>] when it opens a function that moves value, [Why: <file:line>] when it stops on an unclear line, [Defeat: <function>] when a path reads as clean, and [LastOut: <lifecycle>] when it finishes a lifecycle. After each lens returns, grep its output for those four markers. A lens that returns findings with zero markers did not reason — it scanned, which is the exact failure mode the method exists to beat. A lens with no [LastOut:] never ran the solvency test on any lifecycle. Treat either as noncompliant: re-run that lens alone against its existing bundle before dedup, and if it still returns bare, weight its findings down and note the shortfall in the report's methodology line. Do not carry an unverified lens into Turn 6.
Single pass: dedup, gate, and produce the final report in one turn. Do not print an intermediate dedup list.
severity-calibration.md, in order, no skipping and no revisiting after a verdict. UNCERTAIN = ALLOWS.[lenses: 2+] independently reached it. [lenses: 2+] does NOT override a code path that actually interrupts the attack before harm — demote instead. Judge what the code allows, never what the deployer intends.severity-calibration.md.{bundle_dir} still exists. Route every High (and any Medium where a runnable test is cheap) to security-verifier or poc-writer per the EVM Cortex addendum below, then run the High-finding fix verification. This step MUST precede the print and the cleanup: a printed report cannot gain a PoC after the fact, and Turn 6 deletes the bundle at the end. A High without a landed PoC is not ready — resolve it here, not after.report-formatting.md (Description + Recommended Mitigation per finding), embedding each High's verified PoC. With --file-output, also write the file.rm -rf {bundle_dir}. It is transient build state, not an artifact. For debugging, copy it elsewhere before re-running.Group findings by group_key (Contract | function | bug_class). Exact match first, then merge synonymous bug_class within the same (Contract, function). Keep the best per group, number sequentially, annotate [lenses: N].
Four gates govern this phase. They exist because the failure mode of naive merging is silently deleting real bugs — twelve lenses converging on one function is information, not redundancy.
Gate A — Function isolation (HARD). NEVER merge across different function: values. Dedup only within (Contract, function). A different function is a different bug, always.
Gate B — Mechanism preservation. A merged group whose members describe distinct mechanisms — different root-cause line, different mitigation, different attack path — MUST list every mechanism. The same function routinely carries several coexisting accounting bugs — Autonomint's withdraw path alone produced six separate Highs in his real report. Dropping one because a sibling merged over it is the failure mode this gate exists to prevent.
Gate C — Function-level second pass. After group_key dedup, run a second pass at (Contract, function) ignoring bug_class entirely. Lenses often tag coexisting bugs with different bug_class values while referencing multiple mechanisms in the body. For every (Contract, function) with multiple final findings, scan every constituent's description, path, proof, and mitigation for distinct mechanisms crossing bug_class boundaries. Every mechanism in any constituent body must survive into at least one final finding. Stay within (Contract, function) — never across, per Gate A.
Gate D — Mitigation preservation (HARD). Before writing a merged mitigation: for a (Contract, function) with multiple findings, collect every raw mitigation and group by the actual change (added require / added decrement / reordered call / changed rounding / restricted target). Two mitigations are distinct if they change different operations or different directions. ≥2 distinct → present as Option A, B… verbatim from the lens text, labelled by kind (add-missing-write / validate / reorder / round-other-way / restrict).
Completeness gate (HARD). Before printing, enumerate every unique (Contract, function) in any raw FINDING or LEAD across all twelve lenses. Every one MUST be accounted for — never silently dropped — but "accounted for" is not the same as "reported". Each resolves to exactly one of three fates:
## Unverified leads section;(Contract, function) per Gates B/C.A (Contract, function) with zero fate is the silent drop this gate exists to catch. Print inline before the report:
Completeness: N unique (Contract, function) in raw — R reported, X rejected (with reasons), M merged.Composite chains. If finding A's output feeds finding B's precondition AND the combined impact exceeds either alone, add Chain: [A] + [B]. He reports these as their own finding when the chain crosses a trust boundary. Most audits produce zero to two.
The vendored severity-calibration.md assigns High / Medium / Low / Info and this skill keeps that scale intact — do not remap it onto a Critical band. Severity is impact × likelihood, assigned after all four judging gates pass. When genuinely torn between two severities, choose the lower and say why in one line — over-claiming costs credibility, and credibility is the whole product.
| Severity | PoC |
|---|---|
| High | Working Foundry PoC — mandatory |
| Medium | PoC or clear step-by-step reproduction |
| Low / Info | Description only |
Route PoC construction for every High (and any Medium where a runnable test is cheap) to the security-verifier or poc-writer agent in Turn 6 step 5 — before the report is formatted and before {bundle_dir} is deleted, never after. Pin the fork block number in every fork-based PoC so it stays reproducible. A High finding with no PoC is not ready to report.
Trace the proposed mitigation against the original attack path and confirm the path terminates, then check for side effects:
| # | Lens | Owns | subagent_type | Model |
|---|---|---|---|---|
| 1 | accounting-desync | tracked totals drifting from reality, the largest class | depth-token-flow | opus |
| 2 | share-exchange-rate | claims vs value, round-trip profit, redemption in terminal states | depth-token-flow | opus |
| 3 | temporal-cohort | who gets the distribution, join-before / leave-before, index checkpoints | depth-state-trace | opus |
| 4 | liquidation-solvency | health math, blocked liquidations, bad-debt clearing | sleuth | opus |
| 5 | cross-chain-state | LayerZero/CCIP global-state overwrite, debited-here-credited-nowhere | depth-external | opus |
| 6 | rounding-precision | direction, truncation, decimals, casts, overflow | depth-token-flow | sonnet |
| 7 | ordering-mev | init races, unprotected protocol swaps, discrete-jump arbitrage | mev-analyst | sonnet |
| 8 | dos-griefing | unbounded loops, poisoned batches, pause interactions | depth-edge-case | sonnet |
| 9 | access-trust | callbacks, approval abuse, unvalidated targets, composed privilege | access-control-reviewer | sonnet |
| 10 | integration-assumptions | token quirks, oracles, external protocols, chain environment | oracle-analyst | sonnet |
| 11 | edge-states | zero, one, first, last, expired, paused, capped | depth-edge-case | sonnet |
| 12 | flow-completeness | the gap hunter: missing calls, asymmetric branches, absent siblings | code-reviewer | opus |
The subagent_type selects a base persona and tool set; the lens file in the bundle is what determines the lens. Reused types (depth-token-flow, depth-edge-case) run as independent instances with different bundles and share no context. When Turn 1b sets {agent_model}, it overrides the per-lens Model column above.
xray-pre-audit run, or an equivalent context package assembledmoney-map.md written — assets, tracked totals, asymmetry table, invariants, lifecycles, cohortssource.md plus twelve lens bundles builtsource.md and every bundle, and none is undersizedforge build --deny-warnings passes clean (or Foundry-absent noted)forge test passes with no failuresVERSION checked against upstreamgroup_key; function isolation respected (Gate A)bug_class boundaries (Gate C)Completeness: N / N line printed and reconciledseverity-calibration.mdDescription + Recommended Mitigation per findingBefore doing anything else, print this exactly:
██████╗ ██╗ ██╗███████╗██╗███╗ ███╗ █████╗ ██████╗
██╔═████╗╚██╗██╔╝██╔════╝██║████╗ ████║██╔══██╗██╔═══██╗
██║██╔██║ ╚███╔╝ ███████╗██║██╔████╔██║███████║██║ ██║
████╔╝██║ ██╔██╗ ╚════██║██║██║╚██╔╝██║██╔══██║██║ ██║
╚██████╔╝██╔╝ ██╗███████║██║██║ ╚═╝ ██║██║ ██║╚██████╔╝
╚═════╝ ╚═╝ ╚═╝╚══════╝╚═╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚═════╝
follow the money, then find who eats the loss
© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (references) in skills/simao-audit-pipeline of ccashwell/evm-cortex.
Open the folder on GitHubat commit f8f3301
Simao Audit Pipeline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Simao Audit Pipeline this skillccashwell/evm-cortex | 131 | — | ~6.8k | Automated safety check: Pass | MIT | |
| Sync Upstreamnyaruka/phonenumbers | 1.6k | — | ~2.8k | Automated safety check: Pass | MIT | |
| Radiology Tablehuang-sir1/radiology-skills | 1.9k | — | ~1.3k | Automated safety check: Pass | Custom licence | |
| ERPClaw ERP Controlleravansaber/erpclaw | 116 | — | ~18k | Automated safety check: Pass | GPL-3.0 | |
| Odoo Agency Fleet Reviewerpipe-org/mcp-odoo | 421 | — | ~699 | Automated safety check: Pass | MIT | |
| Beancount Closebex-co/beancount-io | 296 | — | ~1.4k | Automated safety check: Pass | MIT |
nyaruka/phonenumbers
Sync this Go port with a new upstream google/libphonenumber release — regenerate the embedded metadata and reconcile the ported Java logic.
huang-sir1/radiology-skills
Create/audit editable publication tables with source reconciliation; not figures or statistical inference.
avansaber/erpclaw
Operates the ERPClaw self-hosted ERP in plain language: accounting, invoicing, inventory, purchasing, tax, HR, payroll and reports, treating the ERP as the single source of truth.
erpipe-org/mcp-odoo
Review many client Odoo databases at once through odoo-mcp's cross-instance tools — fleet-wide accounting health, per-client aging, partial-failure triage — for agencies and partners managing 5–50…
bex-co/beancount-io
Close an accounting period in a Beancount ledger by reconciling each active account through beancount-reconcile, checking assertions and recurring gaps, reviewing flags, then proposing a commit with…
Vuk97/forward-implementation-first
Keeps an agent building and validating real output instead of servicing its own bookkeeping.
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
ccashwell/evm-cortex
A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.
ccashwell/evm-cortex
Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.
ccashwell/evm-cortex
A skill your agent uses when running a local Ethereum node with Anvil.
ccashwell/evm-cortex
A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.
ccashwell/evm-cortex
A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.
Categories
A skill your agent uses when performing an accounting-first smart contract security audit in the style of 0xSimao. Simao Audit Pipeline is an agent skill from ccashwell/evm-cortex. Use when performing an accounting-first smart contract security audit in the style of 0xSimao.
Simao Audit Pipeline fits situations like: performing an accounting-first smart contract security audit in the style of 0xSimao; accounting-first audit; follow the money audit.
Run `npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a claude-code`. Or copy the skill folder (skills/simao-audit-pipeline in ccashwell/evm-cortex) into .claude/skills/simao-audit-pipeline in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a codex`. Or copy the skill folder (skills/simao-audit-pipeline in ccashwell/evm-cortex) into .agents/skills/simao-audit-pipeline in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill simao-audit-pipeline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/simao-audit-pipeline, .gemini/skills/simao-audit-pipeline, .github/skills/simao-audit-pipeline and .opencode/skills/simao-audit-pipeline in your project.
Going by SKILL.md and its folder, Simao Audit Pipeline needs the command-line tools its instructions call (curl).
SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Simao Audit Pipeline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Simao Audit Pipeline: Sync Upstream (nyaruka/phonenumbers, 1.6k stars), Radiology Table (huang-sir1/radiology-skills, 1.9k stars), ERPClaw ERP Controller (avansaber/erpclaw, 116 stars) and Odoo Agency Fleet Review (erpipe-org/mcp-odoo, 421 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.
Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.