Agent skill

Slither Analysis

by ccashwell in ccashwell/evm-cortex

A skill your agent uses when running Slither static analysis on Solidity contracts.

MITAuto-check passedBackend & APIs

Install Slither Analysis

skills CLI
$ npx skills add ccashwell/evm-cortex --skill slither-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex slither-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/slither-analysis .claude/skills/slither-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
slither-analysis
GitHub stars
131
Token cost
~1.5k tokens
SKILL.md length
222 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when running Slither static analysis on Solidity contracts.

  • Works in 5 steps: Run full analysis: slither . --json… → Sort by severity: address High → Medium… → Filter false positives: mark known-safe… → …
  • Running Slither static analysis on Solidity contracts
  • SKILL.md covers Installation, Running Slither, Severity Levels and Key Detectors, plus 7 more sections
  • Calls pip3 and pipx

What it does

Slither Analysis is an agent skill from ccashwell/evm-cortex. Use when running Slither static analysis on Solidity contracts. Covers running slither, key detectors, false positive filtering, severity levels, upgradeability checks, CI integration, and triage methodology.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Static analysis and SAST, Smart contracts and Smart contract auditing. It works with Solidity. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Running Slither static analysis on Solidity contracts
  • Tasks that involve Static analysis and SAST
  • Tasks that involve Smart contracts

Example prompts

  • “/slither-analysis”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run full analysis: slither . --json report.json
  2. Sort by severity: address High → Medium → Low
  3. Filter false positives: mark known-safe patterns
  4. Document findings: for each real finding, note impact + fix
  5. Fix and re-run: verify findings are resolved

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip3
    • pipx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip3 and pipx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Slither Analysis loads about 1.5k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 222 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 222 words, ~1,480 tokens.

Download SKILL.mdSave it as .claude/skills/slither-analysis/SKILL.md (or your agent's skills folder).
name
slither-analysis
description
Use when running Slither static analysis on Solidity contracts. Covers running slither, key detectors, false positive filtering, severity levels, upgradeability checks, CI integration, and triage methodology.

Slither Static Analysis

Installation

bash
pip3 install slither-analyzer
# or
pipx install slither-analyzer

# Verify
slither --version

Running Slither

bash
# Basic analysis
slither .

# Target specific contract
slither src/MyContract.sol

# JSON output for CI
slither . --json slither-report.json

# Specific detectors only
slither . --detect reentrancy-eth,reentrancy-no-eth,uninitialized-state

# Exclude detectors
slither . --exclude naming-convention,pragma

# With Foundry remappings
slither . --foundry-out-directory out

Severity Levels

LevelMeaningAction
HighLikely exploitable vulnerabilityFix immediately
MediumPotential vulnerability or bad practiceFix before deploy
LowMinor issue or informationalReview and decide
InformationalStyle or optimization suggestionNice to fix
OptimizationGas optimization opportunityFix if meaningful

Key Detectors

Critical / High
DetectorDescription
reentrancy-ethReentrancy with ETH transfer
reentrancy-no-ethReentrancy without ETH
arbitrary-send-ethUnprotected ETH send
arbitrary-send-erc20Unprotected token transfer
suicidalUnprotected selfdestruct
uninitialized-stateState variable not initialized
unprotected-upgradeMissing upgrade auth check
delegatecall-loopDelegatecall in loop
Medium
DetectorDescription
divide-before-multiplyPrecision loss from order of operations
reentrancy-benignReentrancy without direct exploit
tx-originUsing tx.origin for auth
unchecked-transferReturn value not checked
locked-etherContract can receive but not send ETH
controlled-delegatecallUser-controlled delegatecall target
Low / Informational
DetectorDescription
missing-zero-checkNo zero address validation
calls-loopExternal calls in loop
timestampBlock.timestamp usage
assemblyInline assembly usage

Triage Methodology

  1. Run full analysis: slither . --json report.json
  2. Sort by severity: address High → Medium → Low
  3. Filter false positives: mark known-safe patterns
  4. Document findings: for each real finding, note impact + fix
  5. Fix and re-run: verify findings are resolved

Filtering False Positives

Create slither.config.json:

json
{
  "filter_paths": [
    "lib/",
    "test/",
    "script/",
    "node_modules/"
  ],
  "exclude_informational": true,
  "exclude_low": false,
  "exclude_optimization": true,
  "detectors_to_exclude": [
    "naming-convention",
    "pragma",
    "solc-version"
  ]
}

Or use inline annotations in Solidity:

solidity
// slither-disable-next-line reentrancy-benign
token.transfer(to, amount);

Upgradeability Checks

bash
# Check proxy/implementation compatibility
slither-check-upgradeability . MyContractV1 --proxy-name ERC1967Proxy

# Compare storage layouts between versions
slither-check-upgradeability . MyContractV2 \
  --proxy-name ERC1967Proxy \
  --new-contract-name MyContractV2

# Check for storage collisions
slither . --detect storage-collision

Printers (Code Analysis Tools)

bash
# Function summary (visibility, modifiers, state changes)
slither . --print function-summary

# Contract inheritance graph
slither . --print inheritance-graph

# Call graph
slither . --print call-graph

# Storage layout
slither . --print variable-order

# Data dependency
slither . --print data-dependency

# Human-readable summary
slither . --print human-summary

CI Integration

GitHub Actions
yaml
name: Slither Analysis
on: [push, pull_request]

jobs:
  slither:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          submodules: recursive

      - name: Install Foundry
        uses: foundry-rs/foundry-toolchain@v1

      - name: Build
        run: forge build

      - name: Run Slither
        uses: crytic/slither-action@v0.4.0
        with:
          sarif: results.sarif
          fail-on: high
          slither-args: --filter-paths "lib/|test/|script/"

      - name: Upload SARIF
        uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: results.sarif

Common Findings and Fixes

Reentrancy
solidity
// FINDING: reentrancy-eth
// FIX: checks-effects-interactions pattern
function withdraw(uint256 amount) external {
    require(balances[msg.sender] >= amount); // CHECK
    balances[msg.sender] -= amount;           // EFFECT
    (bool ok,) = msg.sender.call{value: amount}(""); // INTERACTION
    require(ok);
}
Divide Before Multiply
solidity
// FINDING: divide-before-multiply
// BAD: precision loss
uint256 result = a / b * c;

// FIX: multiply first
uint256 result = a * c / b;
// Or use FullMath / mulDiv for overflow safety
Unchecked Transfer
solidity
// FINDING: unchecked-transfer
// FIX: use SafeERC20
import {SafeERC20} from "@openzeppelin/contracts/token/ERC20/utils/SafeERC20.sol";
using SafeERC20 for IERC20;
token.safeTransfer(to, amount);

Workflow Summary

bash
# 1. Build first
forge build

# 2. Run slither with config
slither . --config slither.config.json

# 3. Generate report
slither . --json report.json --config slither.config.json

# 4. Check upgradeability (if using proxies)
slither-check-upgradeability . MyContract

# 5. Print function summary for review
slither . --print function-summary --filter-paths "lib/|test/"

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/slither-analysis of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Slither Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Slither Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Slither Analysis this skillccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Solidity AuditorGabson0x/bountyforge443—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k1 repos~9.9kAutomated safety check: PassMIT
Solidity Securitywshobson/agents40k12 repos~892Automated safety check: PassMIT

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub starsUsed in 1 repo~9.9k tokens
    Backend & APIsAuto-check passed
  • Solidity Security

    wshobson/agents

    Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.

    40k GitHub starsUsed in 12 repos~892 tokens
    Backend & APIsAuto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    129 GitHub stars~3.1k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 8 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 8 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed

Works with

Questions about Slither Analysis

What does Slither Analysis do?

A skill your agent uses when running Slither static analysis on Solidity contracts. Slither Analysis is an agent skill from ccashwell/evm-cortex. Use when running Slither static analysis on Solidity contracts.

When should I use Slither Analysis?

Slither Analysis fits situations like: running Slither static analysis on Solidity contracts; tasks that involve Static analysis and SAST; tasks that involve Smart contracts.

How do I install Slither Analysis in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill slither-analysis -a claude-code`. Or copy the skill folder (skills/slither-analysis in ccashwell/evm-cortex) into .claude/skills/slither-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Slither Analysis in Codex?

Run `npx skills add ccashwell/evm-cortex --skill slither-analysis -a codex`. Or copy the skill folder (skills/slither-analysis in ccashwell/evm-cortex) into .agents/skills/slither-analysis in your project. Codex loads it when a task matches its description.

Can I use Slither Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill slither-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/slither-analysis, .gemini/skills/slither-analysis, .github/skills/slither-analysis and .opencode/skills/slither-analysis in your project.

What does Slither Analysis need to run?

Going by SKILL.md and its folder, Slither Analysis needs the command-line tools its instructions call (pip3 and pipx). Our summary lists: Python 3.

Does Slither Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Slither Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Slither Analysis use?

Slither Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Slither Analysis use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Slither Analysis?

Skills that share tags, products or a category with Slither Analysis: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 443 stars) and Solidity Auditor (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Slither Analysis?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.