Agent skill

Smart Contract Audit

by greatpie in greatpie/smart-contract-audit-skill

Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

No licenceAuto-check passedBackend & APIs

Install Smart Contract Audit

skills CLI
$ npx skills add greatpie/smart-contract-audit-skill --skill smart-contract-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greatpie/smart-contract-audit-skill smart-contract-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greatpie/smart-contract-audit-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/smart-contract-audit .claude/skills/smart-contract-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smart-contract-audit
GitHub stars
101
Token cost
~1.1k tokens
SKILL.md length
366 words
Files
14 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

  • Asked to audit a smart contract repo from a URL
  • SKILL.md covers Overview, Quick Start, Script Behavior and Audit Standard, plus 2 more sections
  • Runs Shell scripts from its folder; calls bash
  • Auto-prepare the environment

What it does

Smart Contract Audit is an agent skill from greatpie/smart-contract-audit-skill. Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. Use when asked to audit a smart contract repo from a URL or local path, auto-prepare the environment, find high-severity loss-of-funds vulnerabilities, validate exploitability, propose safe fixes, and deliver a structured report with exact code references.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts and reference files (for example `references/benchmark-reality-checklist.md`, `references/evmbench-core.md` and `references/report-template.md`).

It sits in Backend & APIs, covering Smart contracts and Smart contract auditing. It works with Solidity.

When your agent uses it

  • Asked to audit a smart contract repo from a URL
  • Auto-prepare the environment
  • Find high-severity loss-of-funds vulnerabilities
  • Validate exploitability

Example prompts

  • “/smart-contract-audit”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 31b8142. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 9 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart Contract Audit loads about 1.1k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 366 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 366 words (~1,074 tokens).

“Run a complete security audit flow for a target EVM repository, optimized for high-impact vulnerabilities that can directly or indirectly cause loss of user or protocol assets.”

— opening of SKILL.md by greatpie
name
smart-contract-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 13 other files (scripts, references) in skills/smart-contract-audit of greatpie/smart-contract-audit-skill.

  • SKILL.md
  • references/benchmark-reality-checklist.md
  • references/evmbench-core.md
  • references/report-template.md
  • references/script-usage.md
  • scripts/audit.sh
  • scripts/bootstrap.sh
  • scripts/generate_exploit_scaffold.sh
  • scripts/lib.sh
  • scripts/run_detect.sh
  • scripts/run_exploit.sh
  • scripts/run_patch.sh
  • scripts/templates/foundry-exploit-template.sh
  • scripts/templates/hardhat-exploit-template.sh

Open the folder on GitHubat commit 31b8142

Compare with similar skills

Smart Contract Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart Contract Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart Contract Audit this skillgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k—~9.9kAutomated safety check: PassMIT
Solidity Securitywshobson/agents40k12 repos~892Automated safety check: PassMIT
Input Arithmetic Safetyquillai-network/quillshield_skills130—~3.1kAutomated safety check: PassMIT

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub stars~9.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Solidity Security

    wshobson/agents

    Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.

    40k GitHub starsUsed in 12 repos~892 tokens
    Backend & APIsAuto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes

Works with

Questions about Smart Contract Audit

What does Smart Contract Audit do?

Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. Smart Contract Audit is an agent skill from greatpie/smart-contract-audit-skill. Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

When should I use Smart Contract Audit?

Smart Contract Audit fits situations like: asked to audit a smart contract repo from a URL; auto-prepare the environment; find high-severity loss-of-funds vulnerabilities; validate exploitability.

How do I install Smart Contract Audit in Claude Code?

Run `npx skills add greatpie/smart-contract-audit-skill --skill smart-contract-audit -a claude-code`. Or copy the skill folder (skills/smart-contract-audit in greatpie/smart-contract-audit-skill) into .claude/skills/smart-contract-audit in your project. Claude Code loads it when a task matches its description.

How do I install Smart Contract Audit in Codex?

Run `npx skills add greatpie/smart-contract-audit-skill --skill smart-contract-audit -a codex`. Or copy the skill folder (skills/smart-contract-audit in greatpie/smart-contract-audit-skill) into .agents/skills/smart-contract-audit in your project. Codex loads it when a task matches its description.

Can I use Smart Contract Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greatpie/smart-contract-audit-skill --skill smart-contract-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-audit, .gemini/skills/smart-contract-audit, .github/skills/smart-contract-audit and .opencode/skills/smart-contract-audit in your project.

What does Smart Contract Audit need to run?

Going by SKILL.md and its folder, Smart Contract Audit needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell.

Does Smart Contract Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart Contract Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Smart Contract Audit use?

No licence was found for Smart Contract Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Smart Contract Audit use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Smart Contract Audit?

Skills that share tags, products or a category with Smart Contract Audit: Fizz Convert (pashov/skills, 1.2k stars), Solidity Auditor (Gabson0x/bountyforge, 442 stars), Solidity Auditor (pashov/skills, 1.2k stars) and Solidity Security (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart Contract Audit?

greatpie (a GitHub user) maintains it in greatpie/smart-contract-audit-skill, which has 101 GitHub stars. The repository was last updated on February 21, 2026.

Source: greatpie/smart-contract-audit-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.