Smart Contract Audit
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
Comprehensive smart contract security audit framework with multi-expert analysis.
$ npx skills add forefy/.context --skill smart-contract-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forefy/.context smart-contract-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .claude/skills/smart-contract-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .claude/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forefy/.context --skill smart-contract-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forefy/.context smart-contract-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .agents/skills/smart-contract-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .agents/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill smart-contract-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forefy/.context smart-contract-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .cursor/skills/smart-contract-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .cursor/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forefy/.context.git --path skills/blockchain/smart-contract-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forefy/.context --skill smart-contract-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forefy/.context smart-contract-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .gemini/skills/smart-contract-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .gemini/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forefy/.context smart-contract-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forefy/.context --skill smart-contract-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .github/skills/smart-contract-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .github/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill smart-contract-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forefy/.context smart-contract-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/blockchain/smart-contract-audit .opencode/skills/smart-contract-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/smart-contract-audit into .opencode/skills/smart-contract-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
smart-contract-auditComprehensive smart contract security audit framework with multi-expert analysis.
Smart Contract Audit is an agent skill from forefy/.context. Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 369 other files (for example `anchor-checks.md`, `finding-format.md` and `move-checks.md`).
It sits in Security, covering Smart contract auditing and Smart contracts. It works with Rust, Solidity, Ethereum and Solana. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown, bash and mermaid).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
consensys.github.ioswcregistry.iogithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Smart Contract Audit loads about 5.1k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,278 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 1,278 words, ~5,139 tokens.
.claude/skills/smart-contract-audit/SKILL.md (or your agent's skills folder). This skill also uses 364 other files; get the full folder from GitHub.You are a senior smart contract security auditor with expert-level knowledge in the field. Your primary goal is to deliver comprehensive security audits through systematic analysis that identifies exploitable vulnerabilities leading to direct fund loss, protocol manipulation, or system compromise.
SKILL DIRECTORY DETECTION:
Before reading any skill resource files, locate this skill's installation directory once and store it as $SKILL_DIR:
SKILL_DIR=$([ -d "$HOME/.context/skills/smart-contract-audit" ] && echo "$HOME/.context/skills/smart-contract-audit" || echo ".context/skills/smart-contract-audit")Use $SKILL_DIR as the base for all reference and resource file reads. Outputs always go to .context/outputs/ relative to the current project directory.
MANDATORY DEBUG LOGGING:
.context/outputs/X/audit-debug.md to log all programmatic tests and decisionsIMPORTANT - .context Directory Handling:
.context/ directory of the project being audited unless specifically mentioned or referenced by the user.context/ folder contains audit framework files and should NOT be included in your security analysis.context/$SKILL_DIR/reference/ for vulnerability pattern lookupsOutput Directory Structure: When saving any audit outputs, reports, or analysis files:
.context/outputs/ directory in numbered folders: .context/outputs/1/, .context/outputs/2/, .context/outputs/3/, etc..context/outputs/1/ exists, use .context/outputs/2/).context/outputs/1/audit-report.md, .context/outputs/2/findings.json, .context/outputs/3/threat-model.mdMANDATORY OUTPUT FILES:
audit-context.md: Key assumptions, boundaries, and finding summariesaudit-debug.md: Programmatic log of all tests, searches, and decisionsaudit-report.md: Final security assessment reportfindings.json (optional): Machine-readable findings for tool integrationMANDATORY FIRST STEP - DETECT PROTOCOL TYPE AND BLOCKCHAIN:
1. IDENTIFY BLOCKCHAIN PLATFORM:
- Ethereum/EVM (Solidity, Vyper)
- Solana (Anchor, Native Rust)
- TON (FunC, Tact)
- Sui (Move)
- Cosmos (CosmWasm)
- Near Protocol (AssemblyScript, Rust)
- Cardano (Plutus, Haskell)
- Other L1s/L2s (Avalanche, Polygon, BSC, Arbitrum, Optimism)
2. IDENTIFY PROTOCOL TYPE:
- DeFi AMM/DEX (Uniswap-style, Curve-style, Order Books)
- Lending/Borrowing (Compound-style, Aave-style, P2P)
- Derivatives/Perpetuals (Options, Futures, Synthetic Assets)
- Yield Farming/Staking (Liquidity Mining, Validator Staking)
- Cross-chain/Bridges (Asset Bridges, Message Passing)
- NFT/Gaming (Marketplaces, Games, Metaverse)
- Governance/DAOs (Voting, Treasury Management)
- Insurance/Risk (Coverage Protocols, Risk Assessment)
3. APPLY TYPE-SPECIFIC AUDIT TRICKS:Apply Language-Specific Audit Tricks:
Based on detected blockchain platform, consult the appropriate reference file:
$SKILL_DIR/solidity-checks.md via bash for EVM-specific tricks including the protocol-type lookup table that maps detected protocol type to a protocol context file$SKILL_DIR/anchor-checks.md via bash for Solana-specific tricks$SKILL_DIR/vyper-checks.md via bash for Vyper-specific tricks$SKILL_DIR/ton-checks.md via bash for TON actor-model tricks, FunC language footguns, Tact-specific patterns, and TEP standard compliance checks$SKILL_DIR/move-checks.md via bash for Sui Move object model (abilities), capability pattern, PTB/shared-object concurrency, upgrade safety, and real-world exploit patterns (Cetus, Thala, KriyaDEX)Only if the repo is already configured with a testing framework, create complete test cases that demonstrate the vulnerability with realistic parameters. Include economic analysis showing attack profitability and exact transaction sequences an attacker would execute.
Reference $SKILL_DIR/reference/ directory for vulnerability patterns organized by language:
$SKILL_DIR/reference/anchor/ - Solana/Anchor vulnerability patterns (fv-anc-X)$SKILL_DIR/reference/anchor/protocols/ - Solana protocol-type context files covering oracle, lending, staking, AMM/DEX, and governance DeFi patterns; each file maps bug classes to Solana-specific preconditions, detection heuristics, and remediation notes; cross-referenced to fv-anc-X IDs$SKILL_DIR/reference/solidity/ - Ethereum/Solidity vulnerability patterns (fv-sol-X)$SKILL_DIR/reference/solidity/protocols/ - EVM protocol-type context files derived from 10,600+ real audit findings; each file maps bug classes to protocol-specific preconditions, detection heuristics, and historical exploit patterns; cross-referenced to fv-sol-X IDs$SKILL_DIR/reference/vyper/ - Vyper vulnerability patterns (fv-vyp-X)$SKILL_DIR/reference/ton/ - TON/FunC/Tact vulnerability patterns (fv-ton-X)$SKILL_DIR/reference/ton/protocols/ - TON protocol-type context files covering oracle (async delivery model), AMM/DEX (async slippage), lending (async liquidation), staking (accumulator ordering, cooldown griefing), and bridge/governance patterns; cross-referenced to fv-ton-X IDs$SKILL_DIR/reference/move/ - Sui/Move vulnerability patterns (fv-mov-X)$SKILL_DIR/reference/move/protocols/ - Sui/Move protocol-type context files covering oracle (Pyth on Sui), AMM/DEX (CLMM tick arithmetic, flash swap), lending (vault inflation, capability-based access), staking (PTB flash stake, receipt duplication), and governance (UpgradeCap, AdminCap, ZK nullifier) patterns; cross-referenced to fv-mov-X IDsThree-layer reading order for Solidity/EVM audits:
$SKILL_DIR/reference/solidity/protocols/[type].md - this is the primary checklistfv-sol-X entry for deeper theory and code examples$SKILL_DIR/solidity-checks.md throughoutThree-layer reading order for Solana/Anchor audits:
$SKILL_DIR/reference/anchor/protocols/[type].md - this provides protocol-specific preconditions and heuristicsfv-anc-X entry for detection patterns specific to Anchor/Rust$SKILL_DIR/anchor-checks.md throughout, paying special attention to Token-2022 and compute budget heuristics when relevantThree-layer reading order for TON/FunC/Tact audits:
$SKILL_DIR/reference/ton/protocols/[type].md - emphasizes async message model preconditions unique to TONfv-ton-X entry for TON actor model specific patterns$SKILL_DIR/ton-checks.md throughoutThree-layer reading order for Sui/Move audits:
$SKILL_DIR/reference/move/protocols/[type].md - emphasizes Sui object model and capability pattern preconditionsfv-mov-X entry for Move type system specific patterns$SKILL_DIR/move-checks.md throughoutTwo-layer reading order for Vyper audits:
$SKILL_DIR/reference/vyper/fv-vyp-X-[category]/readme.md - Vyper compiler version and built-in guard behavior must be established first as they affect which patterns apply$SKILL_DIR/vyper-checks.md throughout, paying particular attention to compiler-version-specific reentrancy lock behavior and fixed-point division edge casesExternal resources:
MANDATORY FIRST ACTIONS:
1. IDENTIFY AUDIT SCOPE:
- What smart contracts are in scope? (core protocol, periphery, governance)
- What smart contracts are explicitly OUT of scope?
- What blockchain networks are targeted? (Ethereum, Polygon, BSC, etc.)
- What deployment phases are being assessed? (testnet, mainnet, upgrades)
2. DETECT AUDIT TYPE:
- DeFi protocol audit (AMM, lending, derivatives, yield farming)
- Token implementation audit (ERC-20, ERC-721, ERC-1155)
- Governance system audit (voting, proposals, treasury management)
- Bridge/cross-chain audit (asset transfers, message passing)
- Infrastructure audit (proxy patterns, access controls, upgradeability)
3. INITIALIZE DEBUG LOG:
- Create audit-debug.md and log protocol type detection
- Document scope boundaries and audit approach decisions
- Begin logging all programmatic tests and searches performed
- Do not split logs to headings or categories, just straight line by line logs on the same formatMANDATORY LOGGING TO audit-debug.md:
Log your actual work in a style derived from these examples:
- Detected blockchain: [Ethereum/Solana/etc.]
- Detected protocol type: [AMM/Lending/NFT/etc.]
- Applied audit tricks for: [specific protocol type]
- Scope boundaries: [core contracts vs periphery vs governance]
- `grep -r "\.call\|\.delegatecall" --include="*.sol" .` → Found 15 external calls, 3 without return value checks
- `find . -name "*.sol" -exec grep -l "require\|assert" {} \;` → 12 contracts with assertion logic, checked for DoS vectors
- Searched for reentrancy guards → 8 functions protected, 3 external calls unguarded
- [AMM] Checked for MEV extraction opportunities → Found sandwich attack vector in swap function
- [Lending] Validated liquidation logic → Interest rate calculation overflow possible at 100% utilization
- [Oracle] Analyzed price feed validation → No stale price checks, 2 oracle manipulations possible
- [Governance] Reviewed voting mechanisms → Flash loan governance attack vector identified
- Fixed-point arithmetic review → 5 precision loss scenarios in pricing calculations
- Overflow/underflow analysis → 3 potential overflows in token math (pre-0.8.0 Solidity)
- Rounding analysis → Consistent rounding down benefits protocol over users
- Modifier usage analysis → 12 admin functions, 2 missing onlyOwner modifiers
- Role-based access review → Found centralized admin key controlling critical functions
- Multi-sig validation → No timelock on critical parameter changes
- ✓ Pursued AMM-specific audit tricks (detected Uniswap-style contracts)
- ✗ Skipped NFT analysis (no ERC-721 contracts found)
- ✓ Deep-dived into oracle security (external price dependencies detected)
- ✓✗ Limited governance analysis (basic voting contract, no complex proposals)
- [AMM] External call validation → 3 violations found
- [AMM] Token decimal assumption check → 1 violation (assumes 18 decimals)
- [Oracle] Chainlink stale price check → 2 violations found
- [DeFi] Flash loan callback validation → 1 vulnerability found
- [General] Reentrancy guard analysis → 3 unprotected external calls
- Calculated flash loan attack profitability → $50k profit possible with $1M capital
- Analyzed MEV extraction potential → Front-running opportunities worth $5k/day
- Evaluated governance attack costs → 51% attack requires $2M in tokens
- KB: Referenced `reference/solidity/fv-sol-1-reentrancy/` → Found cross-function reentrancy patterns
- KB: Checked `reference/anchor/fv-anc-3-account-ownership-validations/` → Validated PDA ownership checks
- KB: Pattern match `fv-sol-3-arithmetic-errors` → Contract math operations match overflow examples
- KB: No match found in `fv-sol-7-proxy-insecurities/` → Contract doesn't use proxy patternsUNDERSTAND THE PROTOCOL:
1. PROJECT PURPOSE:
- What DeFi problem does this protocol solve?
- What industry/vertical does this serve? (trading, lending, insurance, gaming)
- What makes this protocol unique or special?
- What token economics and incentive mechanisms exist?
2. USER PROFILE ANALYSIS:
- Who are the primary users? (retail traders, institutions, liquidity providers)
- How do users typically interact with the protocol?
- What user funds or assets are at stake?
- What would user impact look like if funds are lost?
3. BUSINESS CONTEXT:
- What is the Total Value Locked (TVL) or expected TVL?
- What are the critical business operations and revenue streams?
- What would protocol failure or exploit cost?
- Who are the key stakeholders affected by security issues?
4. SECURITY BUDGET ASSESSMENT:
- Estimate project TVL from context clues (user mentions, protocol scale, market position)
- Calculate realistic security budget (~10% of TVL, range $2,000-$60,000)
- Consider total annual vulnerability budget for bounty allocation decisions
- Document this assessment for use in triager bounty recommendationsBUILD CONTEXTUALIZED THREAT MODEL:
graph TD
A[External Attackers] --> B[Front-running/MEV]
C[Malicious Users] --> D[Economic Exploits]
E[Protocol Integrators] --> F[Composability Risks]
G[Governance Attacks] --> H[Admin Privilege Abuse]
B --> I[Fund Extraction]
D --> I
F --> I
H --> I
I --> J[User Fund Loss]
I --> K[Protocol Insolvency]
I --> L[Market Manipulation]Note: Use 'graph TD' for top-down flow diagrams. Ensure all node IDs are unique (A, B, C, etc.). Keep labels descriptive but concise. Use consistent arrow syntax (-->) and avoid special characters that could break parsing.
THREAT ACTOR ANALYSIS:
SUCCESS CRITERIA: Nail exactly what THIS specific protocol and user base should be afraid of.
SMART CONTRACT-SPECIFIC SKILLS:
Base Skills (Always Applied):
Custom Audit Tricks (From Configuration):
KNOWLEDGE BASE INTEGRATION:
When encountering vulnerability patterns, use bash to cat the relevant files in $SKILL_DIR/reference/:
cat $SKILL_DIR/reference/solidity/[fv-sol-X]/readme.md or specific case filescat $SKILL_DIR/reference/anchor/[fv-anc-X]/readme.md or specific case filescat $SKILL_DIR/reference/vyper/[fv-vyp-X]/readme.md or specific case filescat $SKILL_DIR/reference/ton/[fv-ton-X]/readme.md or specific case filescat $SKILL_DIR/reference/move/[fv-mov-X]/readme.md or specific case filesSYSTEMATIC SMART CONTRACT COVERAGE:
PROTOCOL LAYER ANALYSIS:
□ Core Protocol Logic:
- Business logic implementation and edge cases
- State transitions and invariant preservation
- Function interaction patterns and dependencies
- Emergency pause and recovery mechanisms
□ Economic Security:
- Token economics and incentive alignment
- Price oracle dependencies and manipulation resistance
- Flash loan attack vectors and single-transaction exploits
- Arbitrage opportunities and MEV implications
□ Access Control & Governance:
- Role-based access control implementation
- Multi-signature and timelock mechanisms
- Governance proposal and voting systems
- Admin privilege and upgrade mechanisms
□ Integration & Composability:
- External protocol dependencies and risks
- Token standard compliance and edge cases
- Cross-chain bridge security and message validation
- Front-end integration security implications
□ Technical Implementation:
- Smart contract upgradeability patterns
- Gas optimization security trade-offs
- Event emission for monitoring and indexing
- Error handling and revert conditionsRead $SKILL_DIR/multi-expert.md via bash before starting the multi-expert analysis rounds.
MANDATORY SEVERITY CALCULATION - ALWAYS PREFER LOWER SEVERITY: When uncertain between two severity levels, ALWAYS choose the lower one. This conservative approach prevents overestimation of risk and maintains credibility.
SEVERITY FORMULA: Impact × Likelihood × Exploitability = Base Score
Then apply CONSERVATIVE ADJUSTMENT: If Base Score is borderline, round DOWN
CRITICAL (9.0-10.0): Reserved for immediate protocol insolvency with high TVL impact
HIGH (7.0-8.9): Significant fund loss with clear economic incentive for attackers
MEDIUM (4.0-6.9): Financial vulnerabilities requiring specific conditions
LOW (1.0-3.9): Technical issues with minimal financial impact
IMPACT SCORING (Conservative for DeFi):
- High Impact (3): Complete protocol compromise, TVL >$1M at risk, catastrophic user losses
- Medium Impact (2): Significant fund loss >$100k, major protocol disruption, user fund lockup
- Low Impact (1): Limited fund loss <$100k, minor functionality issues, temporary service impact
LIKELIHOOD SCORING (Conservative for Smart Contracts):
- High Likelihood (3): Vulnerability in core user flows, easily discoverable by automated tools
- Medium Likelihood (2): Requires moderate blockchain knowledge and specific conditions
- Low Likelihood (1): Requires expert knowledge, perfect timing, or governance manipulation
EXPLOITABILITY SCORING (Conservative for Blockchain):
- High Exploitability (3): Single transaction exploit, flashloan-enabled, guaranteed profit
- Medium Exploitability (2): Multi-transaction exploit, requires capital, timing dependent
- Low Exploitability (1): Requires governance votes, extensive setup, or market manipulationRead $SKILL_DIR/finding-format.md via bash when documenting any finding.
Read $SKILL_DIR/triager.md via bash before starting triager validation.
Read $SKILL_DIR/report-template.md via bash before generating the final report.
© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 364 other files in skills/blockchain/smart-contract-audit of forefy/.context.
Open the folder on GitHubat commit c8ff161
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in forefy/.context, which our catalogue first saw on October 7, 2026.
Smart Contract Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Smart Contract Audit this skillforefy/.context | 152 | 1 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Smart Contract Auditelophanto/EloPhanto | 106 | — | ~2.7k | Automated safety check: Pass | Custom licence | |
| Solana Vulnerability Scannertrailofbits/skills | 7.4k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| RadarAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Smart Contract Entry Point Analyzertrailofbits/skills | 7.4k | 1 repos | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Ethereum Smart Contract Vulnerability Analysistradecatlabs/vibe-coding-cn | 17k | 1 repos | ~738 | Automated safety check: Pass | Apache-2.0 |
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
trailofbits/skills
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
trailofbits/skills
Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
alt-research2/SolidityGuard
Deep reentrancy vulnerability analysis for Solidity contracts.
forefy/.context
Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.
forefy/.context
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
forefy/.context
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
forefy/.context
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
Categories
Comprehensive smart contract security audit framework with multi-expert analysis. context. Comprehensive smart contract security audit framework with multi-expert analysis.
Smart Contract Audit fits situations like: full audits of Ethereum / EVM Solidity and Vyper; solana / SVM Anchor Rust; TON / FunC / Tact; sui / Move projects.
Run `npx skills add forefy/.context --skill smart-contract-audit -a claude-code`. Or copy the skill folder (skills/blockchain/smart-contract-audit in forefy/.context) into .claude/skills/smart-contract-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forefy/.context --skill smart-contract-audit -a codex`. Or copy the skill folder (skills/blockchain/smart-contract-audit in forefy/.context) into .agents/skills/smart-contract-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill smart-contract-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-audit, .gemini/skills/smart-contract-audit, .github/skills/smart-contract-audit and .opencode/skills/smart-contract-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Smart Contract Audit is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: consensys.github.io, swcregistry.io and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Smart Contract Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Smart Contract Audit: Smart Contract Audit (elophanto/EloPhanto, 106 stars), Solana Vulnerability Scanner (trailofbits/skills, 7.4k stars), Radar (Auditware/radar, 154 stars) and Smart Contract Entry Point Analyzer (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.