Agent skill

Solidity

by Cyfrin in Cyfrin/solskill

Create production grade smart contracts. An agent skill from Cyfrin/solskill.

AGPL-3.0Auto-check passedBackend & APIs

Install Solidity

skills CLI
$ npx skills add Cyfrin/solskill --skill solidity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Cyfrin/solskill solidity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Cyfrin/solskill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/solidity .claude/skills/solidity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
solidity
GitHub stars
144
Token cost
~2.9k tokens
SKILL.md length
1,023 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Create production grade smart contracts. An agent skill from Cyfrin/solskill.

  • Works in 3 steps: Absolute and named imports only — no… → Prefer revert over require, with custom… → In tests, prefer stateless fuzz tests…
  • The user asks to write smart contracts
  • SKILL.md covers Philosophy, Code Quality and Style, Deployment and Governance, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Solidity is an agent skill from Cyfrin/solskill. Create production grade smart contracts. Use this skill when the user asks to write smart contracts, specially if they are going to be deployed to production (to a mainnet, or used in a mainnet script).

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. It works with Solidity. The licence is AGPL-3.0.

When your agent uses it

  • The user asks to write smart contracts
  • Specially if they are going to be deployed to production (to a mainnet
  • Used in a mainnet script)

Example prompts

  • “/solidity”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Absolute and named imports only — no relative (..) paths
  2. Prefer revert over require, with custom errors that are prefix'd with the contract name and 2 underscores.
  3. In tests, prefer stateless fuzz tests over unit tests

What it can do on your machine

Read from SKILL.md and the folder at commit d17bda0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • cyfrin.io
    • nascent.xyz
    • x.com
    • soliditylang.org
    • hardhat.org
    • blog.trailofbits.com
    • medium.com
    • rekt.news

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Solidity loads about 2.9k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 1,023 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Cyfrin/solskill at commit d17bda0, republished under its AGPL-3.0 licence (© Cyfrin). 1,023 words, ~2,945 tokens.

Download SKILL.mdSave it as .claude/skills/solidity/SKILL.md (or your agent's skills folder).
name
solidity
description
Create production grade smart contracts. Use this skill when the user asks to write smart contracts, specially if they are going to be deployed to production (to a mainnet, or used in a mainnet script).
disable-model-invocation
true

Solidity Development Standards

Instructions for how to write solidity code, from the Cyfrin security team.

Philosophy

  • Everything will be attacked - Assume that any code you write will be attacked and write it defensively.

Code Quality and Style

  1. Absolute and named imports only — no relative (..) paths
solidity
// good
import {MyContract} from "contracts/MyContract.sol";

// bad
import "../MyContract.sol";
  1. Prefer revert over require, with custom errors that are prefix'd with the contract name and 2 underscores.
solidity
error ContractName__MyError();

// Good
myBool = true;
if (myBool) {
    revert ContractName__MyError();
}

// bad
require(myBool, "MyError");
  1. In tests, prefer stateless fuzz tests over unit tests
solidity
// good - using foundry's built in stateless fuzzer
function testMyTest(uint256 randomNumber) { }

// bad
function testMyTest() {
    uint256 randomNumber = 0;
}

Additionally, write invariant (stateful) fuzz tests for core protocol properties. Use invariant-driven development: identify O(1) properties that must always hold and encode them directly into core functions (FREI-PI pattern). Use a multi-fuzzing setup like Chimera to run the same invariant suite across Foundry, Echidna, and Medusa — different fuzzers find different bugs.

  1. Functions should be grouped according to their visibility and ordered:
constructor
receive function (if exists)
fallback function (if exists)
user-facing state-changing functions
    (external or public, not view or pure)
user-facing read-only functions
    (external or public, view or pure)
internal state-changing functions
    (internal or private, not view or pure)
internal read-only functions
    (internal or private, view or pure)
  1. Headers should look like this:
solidity
    /*//////////////////////////////////////////////////////////////
                      INTERNAL STATE-CHANGING FUNCTIONS
    //////////////////////////////////////////////////////////////*/
  1. Layout of file
Pragma statements
Import statements
Events
Errors
Interfaces
Libraries
Contracts

Layout of contract:

Type declarations
State variables
Events
Errors
Modifiers
Functions
  1. Use the branching tree technique when creating tests Credit for this to Paul R Berg
  • Target a function
  • Create a .tree file
  • Consider all possible execution paths
  • Consider what contract state leads to what path
  • Consider what function params lead to what paths
  • Define "given state is x" nodes
  • Define "when parameter is x" node
  • Define final "it should" tests

Example:

├── when the id references a null stream
│   └── it should revert
└── when the id does not reference a null stream
    ├── given assets have been fully withdrawn
    │   └── it should return DEPLETED
    └── given assets have not been fully withdrawn
        ├── given the stream has been canceled
        │   └── it should return CANCELED
        └── given the stream has not been canceled
            ├── given the start time is in the future
            │   └── it should return PENDING
            └── given the start time is not in the future
                ├── given the refundable amount is zero
                │   └── it should return SETTLED
                └── given the refundable amount is not zero
                    └── it should return STREAMING

Example:

solidity
function test_RevertWhen_Null() external {
    uint256 nullStreamId = 1729;
    vm.expectRevert(abi.encodeWithSelector(Errors.SablierV2Lockup_Null.selector, nullStreamId));
    lockup.statusOf(nullStreamId);
}

modifier whenNotNull() {
    defaultStreamId = createDefaultStream();
    _;
}

function test_StatusOf()
    external
    whenNotNull
    givenAssetsNotFullyWithdrawn
    givenStreamNotCanceled
    givenStartTimeNotInFuture
    givenRefundableAmountNotZero
{
    LockupLinear.Status actualStatus = lockup.statusOf(defaultStreamId);
    LockupLinear.Status expectedStatus = LockupLinear.Status.STREAMING;
    assertEq(actualStatus, expectedStatus);
}
  1. Prefer strict pragma versions for contracts, and floating pragma versions for tests, libraries, abstract contracts, interfaces, and scripts. Use 0.8.34 or later as the minimum version — versions 0.8.28 through 0.8.33 have a high-severity transient storage bug where the IR pipeline (--via-ir) can emit sstore instead of tstore (and vice versa) when clearing storage, causing writes to the wrong storage domain.

  2. Add a security contact to the natspec at the top of your contracts

solidity
/**
  * @custom:security-contact mycontact@example.com
  * @custom:security-contact see https://mysite.com/ipfs-hash
  */  
  1. Remind people to get an audit if they are deploying to mainnet, or trying to deploy to mainnet

  2. NEVER. EVER. NEVER. Have private keys be in plain text. The only exception to this rule is when using a default key from something like anvil, and it must be marked as such.

    • This includes in your deploy scripts. We should always use forge script <path> --account $ACCOUNT --sender $SENDER for our deploy scripts, and never use vm.envUnit() in our scripts.
    • For hardhat, you want to use hardhat encrypted keystores
  3. Whenever a smart contract is deployed that is ownable or has admin properties (like, onlyOwner), the admin must be a multisig from the very first deployment — never use the deployer EOA as admin (testnet is the only acceptable exception). See Trail of Bits: Maturing Your Smart Contracts Beyond Private Key Risk — "Layer 1" (single EOA) governance is no longer acceptable for DeFi.

  4. Don't initialize variables to default values

solidity
// good
uint256 x;
bool y;

// bad
uint256 x = 0;
bool y = false;
  1. Prefer using named return variables if this can omit declaring local variables
solidity
// good
function getBalance() external view returns (uint256 balance) {
    balance = balances[msg.sender];
}

// bad
function getBalance() external view returns (uint256) {
    uint256 balance = balances[msg.sender];
    return balance;
}
  1. Prefer calldata instead of memory for read-only function inputs

  2. Don't cache calldata array length

solidity
// good — calldata length is cheap to read
for (uint256 i; i < items.length; ++i) { }

// bad — unnecessary caching for calldata
uint256 len = items.length;
for (uint256 i; i < len; ++i) { }
  1. Reading from storage is expensive — prevent identical storage reads by caching unchanging storage slots and passing/using cached values

  2. Revert as quickly as possible; perform input checks before checks which require storage reads or external calls

  3. Use msg.sender instead of owner inside onlyOwner functions

  4. Use SafeTransferLib::safeTransferETH instead of Solidity call() to send ETH

  5. Modify input variables instead of declaring an additional local variable when an input variable's value doesn't need to be preserved

  6. Use nonReentrant modifier before other modifiers

  7. Use ReentrancyGuardTransient for faster nonReentrant modifiers. Requires pragma solidity ^0.8.34; — do not use with 0.8.28–0.8.33 due to the transient storage clearing bug.

  8. Prefer Ownable2Step instead of Ownable

  9. Don't copy an entire struct from storage to memory if only a few slots are required

  10. Remove unnecessary "context" structs and/or remove unnecessary variables from context structs

  11. When declaring storage and structs, align the order of declarations to pack variables into the minimum number of storage slots. If variables are frequently read or written together, pack them in the same slot if possible

  12. For non-upgradeable contracts, declare variables as immutable if they are only set once in the constructor

  13. Enable the optimizer in foundry.toml

  14. If modifiers perform identical storage reads as the function body, refactor modifiers to internal functions to prevent identical storage reads

  15. Use Foundry's encrypted secure private key storage instead of plaintext environment variables

  16. Upgrades: When upgrading smart contracts, do not change the order or type of existing variables, and do not remove them. This can lead to storage collisions. Also write tests for any upgrades.

Show full SKILL.md (278 more words)Show less

Deployment

Use Foundry scripts (forge script) for both production deployments and test setup. This ensures the same deployment logic runs in development and on mainnet, making deployments more auditable and reducing the gap between test and production environments. Avoid custom test-only setup code that diverges from real deployment paths. Ideally, your deploy scripts are audited as well.

Example: use a shared base script that both tests and production inherit from, like this BaseTest using scripts pattern.

Governance

Use safe-utils or equivalent tooling for governance proposals. This makes multisig interactions testable, auditable, and reproducible through Foundry scripts rather than manual UI clicks. If you must use a UI, it's preferred to keep your transactions private, using a UI like localsafe.eth.

Write fork tests that verify expected protocol state after governance proposals execute. Fork testing against mainnet state catches misconfigurations that unit tests miss — for example, the Moonwell price feed misconfiguration would have been caught by a fork test asserting correct oracle state post-proposal.

solidity
// good - fork test verifying governance proposal outcome
function testGovernanceProposal_UpdatesPriceFeed() public {
    vm.createSelectFork(vm.envString("MAINNET_RPC_URL"));

    // Execute the governance proposal
    _executeProposal(proposalId);

    // Verify expected state after proposal
    address newFeed = oracle.priceFeed(market);
    assertEq(newFeed, EXPECTED_CHAINLINK_FEED);

    // Verify the feed returns sane values
    (, int256 price,,,) = AggregatorV3Interface(newFeed).latestRoundData();
    assertGt(price, 0);
}

CI

Every project should have a minimum CI pipeline running in parallel (use a matrix strategy). Suggested minimum:

  • solhint — Solidity linter for style and security rules
  • forge build --sizes — verify contract sizes are under the 24KB deployment limit
  • slither or aderyn — static analysis for common vulnerability patterns
    • Before committing code that you think is done, be sure to run aderyn and/or slither on the codebase and inspect the output. Even warnings may lead you to find issues in the codebase.
  • Fuzz/invariant testing — run Echidna, Medusa, or Foundry invariant tests with a reasonable time budget (~10 min per tool, in parallel via matrix)

Tool updates

Foundry

To install foundry dependencies, you don't need the --no-commit flag anymore.

© Cyfrin, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/solidity of Cyfrin/solskill.

Open the folder on GitHubat commit d17bda0

Compare with similar skills

Solidity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solidity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solidity this skillCyfrin/solskill144—~2.9kAutomated safety check: PassAGPL-3.0
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2441 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Solidity AuditorGabson0x/bountyforge443—~3.7kAutomated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    244 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed
  • Add Explorer

    lidofinance/diffyscan

    Adds or repairs Diffyscan explorer API routing and response adapters for a new host, chain or payload format.

    142 GitHub stars~1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from Cyfrin/solskill

  • Battlechain

    Cyfrin/solskill

    Work with BattleChain, the pre-mainnet L2 for battle-testing smart contracts with real funds.

    144 GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Battlechain Tutorial

    Cyfrin/solskill

    Help developers prepare their projects for BattleChain deployment.

    144 GitHub stars~5.8k tokensUpdated 3 mo ago
    Auto-check: notes

Works with

Categories

Questions about Solidity

What does Solidity do?

Create production grade smart contracts. An agent skill from Cyfrin/solskill. Solidity is an agent skill from Cyfrin/solskill. Create production grade smart contracts.

When should I use Solidity?

Solidity fits situations like: the user asks to write smart contracts; specially if they are going to be deployed to production (to a mainnet; used in a mainnet script).

How do I install Solidity in Claude Code?

Run `npx skills add Cyfrin/solskill --skill solidity -a claude-code`. Or copy the skill folder (skills/solidity in Cyfrin/solskill) into .claude/skills/solidity in your project. Claude Code loads it when a task matches its description.

How do I install Solidity in Codex?

Run `npx skills add Cyfrin/solskill --skill solidity -a codex`. Or copy the skill folder (skills/solidity in Cyfrin/solskill) into .agents/skills/solidity in your project. Codex loads it when a task matches its description.

Can I use Solidity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Cyfrin/solskill --skill solidity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solidity, .gemini/skills/solidity, .github/skills/solidity and .opencode/skills/solidity in your project.

What does Solidity need to run?

SKILL.md names no scripts, command-line tools or credentials: Solidity is instructions for the agent only.

Does Solidity access the network?

SKILL.md names 9 domains. As links in the text: github.com, cyfrin.io, nascent.xyz, x.com, soliditylang.org, hardhat.org, blog.trailofbits.com, medium.com and rekt.news. This is read from the text; nothing was executed.

Is Solidity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Solidity use?

Solidity is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Solidity use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Solidity?

Skills that share tags, products or a category with Solidity: Fizz Convert (pashov/skills, 1.2k stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 244 stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars) and Radar (Auditware/radar, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solidity?

Cyfrin (a GitHub organization) maintains it in Cyfrin/solskill, which has 144 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on June 18, 2026.

Source: Cyfrin/solskill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.