Agent skill

Code Sleuth

by Gabson0x in Gabson0x/bountyforge

Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

No licenceAuto-check passedBackend & APIs

Install Code Sleuth

skills CLI
$ npx skills add Gabson0x/bountyforge --skill code-sleuth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Gabson0x/bountyforge code-sleuth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-sleuth .claude/skills/code-sleuth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-sleuth
GitHub stars
443
Token cost
~1.5k tokens
SKILL.md length
756 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
None found

At a glance

Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

  • Works in 5 steps: Inventory storage and storage writers → Lost write / memory-versus-storage… → Attacker-influenced storage slot writes → …
  • Tasks that involve Smart contracts
  • SKILL.md covers Applicability gates and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Sleuth is an agent skill from Gabson0x/bountyforge. Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts and Agent memory. The repository describes itself as: all round pentest skill.

When your agent uses it

  • Tasks that involve Smart contracts
  • Tasks that involve Agent memory

Example prompts

  • “/code-sleuth”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Inventory storage and storage writers
  2. Lost write / memory-versus-storage omission
  3. Attacker-influenced storage slot writes
  4. Upgradeable storage collisions and layout hazards
  5. Other storage semantics (only when security-relevant)

What it can do on your machine

Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Sleuth loads about 1.5k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 756 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 756 words (~1,475 tokens).

“Analyze EVM smart contracts for storage-safety vulnerabilities.”

— opening of SKILL.md by Gabson0x
name
code-sleuth

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/code-sleuth of Gabson0x/bountyforge.

Open the folder on GitHubat commit 068399d

Compare with similar skills

Code Sleuth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Sleuth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Sleuth this skillGabson0x/bountyforge443—~1.5kAutomated safety check: PassNone
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Durable Objectscloudflare/skills3k2 repos~1.5kAutomated safety check: PassApache-2.0
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Durable Objects

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.

    3k GitHub starsUsed in 2 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from Gabson0x/bountyforge

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Auto-check passed
  • Hackenproof Triage Marketplace

    Gabson0x/bountyforge

    HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

    443 GitHub stars~1.2k tokensUpdated 21 days ago
    Auto-check passed
  • Security Arsenal

    Gabson0x/bountyforge

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

    443 GitHub stars~8.5k tokensUpdated 21 days ago
    Auto-check: warnings
  • Web2 Recon

    Gabson0x/bountyforge

    Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

    443 GitHub stars~1.6k tokensUpdated 21 days ago
    Auto-check passed
  • Web2 Vuln Classes

    Gabson0x/bountyforge

    Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

    443 GitHub stars~11k tokensUpdated 21 days ago
    Auto-check: warnings

Categories

Questions about Code Sleuth

What does Code Sleuth do?

Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries. Code Sleuth is an agent skill from Gabson0x/bountyforge. Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

When should I use Code Sleuth?

Code Sleuth fits situations like: tasks that involve Smart contracts; tasks that involve Agent memory.

How do I install Code Sleuth in Claude Code?

Run `npx skills add Gabson0x/bountyforge --skill code-sleuth -a claude-code`. Or copy the skill folder (skills/code-sleuth in Gabson0x/bountyforge) into .claude/skills/code-sleuth in your project. Claude Code loads it when a task matches its description.

How do I install Code Sleuth in Codex?

Run `npx skills add Gabson0x/bountyforge --skill code-sleuth -a codex`. Or copy the skill folder (skills/code-sleuth in Gabson0x/bountyforge) into .agents/skills/code-sleuth in your project. Codex loads it when a task matches its description.

Can I use Code Sleuth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill code-sleuth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-sleuth, .gemini/skills/code-sleuth, .github/skills/code-sleuth and .opencode/skills/code-sleuth in your project.

What does Code Sleuth need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Sleuth is instructions for the agent only.

Does Code Sleuth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Sleuth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Sleuth use?

No licence was found for Code Sleuth or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Code Sleuth use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Sleuth?

Skills that share tags, products or a category with Code Sleuth: Fizz Convert (pashov/skills, 1.2k stars), Durable Objects (cloudflare/skills, 3k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars) and Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Sleuth?

Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 443 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.

Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.