Agent skill

Smart Contract Audit

by elophanto in elophanto/EloPhanto

A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

Custom licenceAuto-check passedSecurity

Install Smart Contract Audit

skills CLI
$ npx skills add elophanto/EloPhanto --skill smart-contract-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elophanto/EloPhanto smart-contract-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elophanto/EloPhanto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/smart-contract-audit .claude/skills/smart-contract-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smart-contract-audit
GitHub stars
106
Token cost
~2.7k tokens
SKILL.md length
1,242 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

  • Works in 5 steps: scoping & engagement (before reading any… → orientation (10–20% of budget) → vulnerability sweep (60–70% of budget) → …
  • Reviewing a Solidity
  • SKILL.md covers Triggers, Overview, Phase 1 — scoping & engagement… and Phase 2 — orientation (10–20%…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Smart Contract Audit is an agent skill from elophanto/EloPhanto. Use when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check. Covers reentrancy, oracle manipulation, access control, signature replay, integer/precision, donation/share-inflation, and protocol-specific risks. Outputs a findings report with severity, impact, PoC sketch, and remediation. Includes outreach templates for direct-to-protocol paid engagements.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Smart contract auditing, Smart contracts and Authorization and RBAC. It works with Solana, Solidity and Rust. The repository describes itself as: Source-available autonomous AI agent with a self-model that actually changes as it runs - ego, affect and identity grounded in real psychology (Higgins, PAD/OCC). Writes its own…

When your agent uses it

  • Reviewing a Solidity
  • Rust (Solana/Anchor) smart contract for paid audit work
  • Pre-launch sanity check

Example prompts

  • “/smart-contract-audit”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. scoping & engagement (before reading any code)
  2. orientation (10–20% of budget)
  3. vulnerability sweep (60–70% of budget)
  4. exploitation & PoC (10–15% of budget)
  5. report (10% of budget)

What it can do on your machine

Read from SKILL.md and the folder at commit 7bfc65d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart Contract Audit loads about 2.7k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 1,242 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,242 words (~2,675 tokens).

“Smart contract bugs are expensive: the average DeFi exploit in the last cycle moved $5M+, and the average protocol team is overworked and underspecialized in security. There is real, recurring demand for a fast, paid second set of eyes between…”

— opening of SKILL.md by elophanto, Custom licence
name
smart-contract-audit

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/smart-contract-audit of elophanto/EloPhanto.

Open the folder on GitHubat commit 7bfc65d

Compare with similar skills

Smart Contract Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart Contract Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart Contract Audit this skillelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Solana Vulnerability Scannertrailofbits/skills7.4k—~3.6kAutomated safety check: PassCC-BY-SA-4.0
Solidity Vulnerability Scanneralt-research2/SolidityGuard104—~1.6kAutomated safety check: NotesCustom licence
Solidity Securityccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Official

    Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

    7.4k GitHub stars~3.6k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Solidity Security

    ccashwell/evm-cortex

    Security-focused Solidity development patterns. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.5k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Official

    Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

    7.4k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes

More from elophanto/EloPhanto

All 11 skills in this repo
  • Pikastream Video Meeting

    elophanto/EloPhanto

    Join a Google Meet or Zoom call as a video meeting agent via PikaStreaming.

    106 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Metaplex

    elophanto/EloPhanto

    Metaplex development on Solana — NFTs, tokens, compressed NFTs, candy machines, token launches.

    106 GitHub stars~1.6k tokensUpdated 9 days ago
    Auto-check passed
  • 12 Principles Of Animation

    elophanto/EloPhanto

    Audit animation code against Disney's 12 principles adapted for web.

    106 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Deep Research

    elophanto/EloPhanto

    A skill your agent uses when investigating any claim, question, or topic where the easy first answer is likely insufficient.

    106 GitHub stars~2.4k tokensUpdated 9 days ago
    Auto-check passed
  • Kid Agents

    elophanto/EloPhanto

    A skill your agent uses when running dangerous shell commands, installing untrusted packages, or testing untrusted code that could damage the host.

    106 GitHub stars~1.6k tokensUpdated 9 days ago
    Auto-check passed
  • Nextjs16 Skills

    elophanto/EloPhanto

    Key facts and links for Next.js 16. An agent skill from elophanto/EloPhanto.

    106 GitHub stars~1.4k tokensUpdated 9 days ago
    Auto-check passed

Questions about Smart Contract Audit

What does Smart Contract Audit do?

A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check. Smart Contract Audit is an agent skill from elophanto/EloPhanto. Use when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

When should I use Smart Contract Audit?

Smart Contract Audit fits situations like: reviewing a Solidity; rust (Solana/Anchor) smart contract for paid audit work; pre-launch sanity check.

How do I install Smart Contract Audit in Claude Code?

Run `npx skills add elophanto/EloPhanto --skill smart-contract-audit -a claude-code`. Or copy the skill folder (skills/smart-contract-audit in elophanto/EloPhanto) into .claude/skills/smart-contract-audit in your project. Claude Code loads it when a task matches its description.

How do I install Smart Contract Audit in Codex?

Run `npx skills add elophanto/EloPhanto --skill smart-contract-audit -a codex`. Or copy the skill folder (skills/smart-contract-audit in elophanto/EloPhanto) into .agents/skills/smart-contract-audit in your project. Codex loads it when a task matches its description.

Can I use Smart Contract Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elophanto/EloPhanto --skill smart-contract-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-audit, .gemini/skills/smart-contract-audit, .github/skills/smart-contract-audit and .opencode/skills/smart-contract-audit in your project.

What does Smart Contract Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Smart Contract Audit is instructions for the agent only.

Does Smart Contract Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart Contract Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Smart Contract Audit use?

Smart Contract Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Smart Contract Audit use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Smart Contract Audit?

Skills that share tags, products or a category with Smart Contract Audit: Smart Contract Audit (forefy/.context, 152 stars), Solana Vulnerability Scanner (trailofbits/skills, 7.4k stars), Solidity Vulnerability Scanner (alt-research2/SolidityGuard, 104 stars) and Solidity Security (ccashwell/evm-cortex, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart Contract Audit?

elophanto (a GitHub user) maintains it in elophanto/EloPhanto, which has 106 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 1, 2026.

Source: elophanto/EloPhanto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.