Agent skill

Solidity Auditor

by Gabson0x in Gabson0x/bountyforge

Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

No licenceAuto-check passedBackend & APIs

Install Solidity Auditor

skills CLI
$ npx skills add Gabson0x/bountyforge --skill solidity-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Gabson0x/bountyforge solidity-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pashov/solidity-auditor .claude/skills/solidity-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
solidity-auditor
GitHub stars
442
Token cost
~3.7k tokens
SKILL.md length
988 words
Files
19 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
None found

At a glance

Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

  • Works in 3 steps: Read your system prompt to detect your… → Call AskUserQuestion with → Store the runner's choice as…
  • Check this contract
  • SKILL.md covers Mode Selection and Orchestration
  • Calls curl; reaches raw.githubusercontent.com and github.com

What it does

Solidity Auditor is an agent skill from Gabson0x/bountyforge. Security audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo) or a specific filename.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including reference files (for example `README.md`, `references/hacking-agents/access-control-agent.md` and `references/hacking-agents/asymmetry-agent.md`).

It sits in Backend & APIs, covering Smart contracts, Security review and Contract review. It works with Solidity and Bash. The repository describes itself as: all round pentest skill.

When your agent uses it

  • Check this contract
  • Review for security

Example prompts

  • “check this contract”
  • “review for security”
  • “/solidity-auditor”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read your system prompt to detect your own model family (Opus, Sonnet, or Haiku). Ignore the version digits — the Agent tool's model…
  2. Call AskUserQuestion with
  3. Store the runner's choice as {agent_model}. If no answer, default to the orchestrator's own model.

What it can do on your machine

Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Solidity Auditor loads about 3.7k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 46 tokens; SKILL.md has 988 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 988 words (~3,737 tokens).

“Orchestrator of a parallelized smart contract security audit.”

— opening of SKILL.md by Gabson0x
name
solidity-auditor

Read the full SKILL.md on GitHub

Files

SKILL.md and 18 other files (references) in skills/pashov/solidity-auditor of Gabson0x/bountyforge.

  • SKILL.md
  • README.md
  • VERSION
  • references/hacking-agents/access-control-agent.md
  • references/hacking-agents/asymmetry-agent.md
  • references/hacking-agents/boundary-agent.md
  • references/hacking-agents/economic-security-agent.md
  • references/hacking-agents/execution-trace-agent.md
  • references/hacking-agents/first-principles-agent.md
  • references/hacking-agents/flow-gap-agent.md
  • references/hacking-agents/invariant-agent.md
  • references/hacking-agents/math-precision-agent.md
  • references/hacking-agents/numerical-gap-agent.md
  • references/hacking-agents/periphery-agent.md
  • references/hacking-agents/shared-rules.md
  • references/hacking-agents/trust-gap-agent.md
  • references/judging.md
  • references/report-formatting.md
  • references/senior-auditor-sop.md

Open the folder on GitHubat commit 068399d

Compare with similar skills

Solidity Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solidity Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solidity Auditor this skillGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k—~9.9kAutomated safety check: PassMIT
Defi Amm Securityaffaan-m/ECC276k1 repos~1.3kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Smart Contract Security Reviewscalus3/scalus105—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub stars~9.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    276k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus.

    105 GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Solidity Security

    wshobson/agents

    Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.

    40k GitHub starsUsed in 12 repos~892 tokens
    Backend & APIsAuto-check passed

More from Gabson0x/bountyforge

  • Hackenproof Triage Marketplace

    Gabson0x/bountyforge

    HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

    442 GitHub stars~1.2k tokensUpdated 22 days ago
    Auto-check passed
  • Security Arsenal

    Gabson0x/bountyforge

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

    442 GitHub stars~8.5k tokensUpdated 22 days ago
    Auto-check: warnings
  • Web2 Recon

    Gabson0x/bountyforge

    Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

    442 GitHub stars~1.6k tokensUpdated 22 days ago
    Auto-check passed
  • Web2 Vuln Classes

    Gabson0x/bountyforge

    Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

    442 GitHub stars~11k tokensUpdated 22 days ago
    Auto-check: warnings
  • Code Sleuth

    Gabson0x/bountyforge

    Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

    442 GitHub stars~1.5k tokensUpdated 22 days ago
    Auto-check passed

Works with

Questions about Solidity Auditor

What does Solidity Auditor do?

Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. Solidity Auditor is an agent skill from Gabson0x/bountyforge. Security audit of Solidity code while you develop.

When should I use Solidity Auditor?

Solidity Auditor fits situations like: check this contract; review for security.

How do I install Solidity Auditor in Claude Code?

Run `npx skills add Gabson0x/bountyforge --skill solidity-auditor -a claude-code`. Or copy the skill folder (skills/pashov/solidity-auditor in Gabson0x/bountyforge) into .claude/skills/solidity-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Solidity Auditor in Codex?

Run `npx skills add Gabson0x/bountyforge --skill solidity-auditor -a codex`. Or copy the skill folder (skills/pashov/solidity-auditor in Gabson0x/bountyforge) into .agents/skills/solidity-auditor in your project. Codex loads it when a task matches its description.

Can I use Solidity Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill solidity-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solidity-auditor, .gemini/skills/solidity-auditor, .github/skills/solidity-auditor and .opencode/skills/solidity-auditor in your project.

What does Solidity Auditor need to run?

Going by SKILL.md and its folder, Solidity Auditor needs the command-line tools its instructions call (curl).

Does Solidity Auditor access the network?

SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Solidity Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Solidity Auditor use?

No licence was found for Solidity Auditor or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Solidity Auditor use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Solidity Auditor?

Skills that share tags, products or a category with Solidity Auditor: Solidity Auditor (pashov/skills, 1.2k stars), Defi Amm Security (affaan-m/ECC, 276k stars), Fizz Convert (pashov/skills, 1.2k stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solidity Auditor?

Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 442 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.

Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.