Agent skill

Scv Scan

by kadenzipfel in kadenzipfel/scv-scan

Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis…

No licenceAuto-check passedBackend & APIs

Install Scv Scan

skills CLI
$ npx skills add kadenzipfel/scv-scan --skill scv-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kadenzipfel/scv-scan scv-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scv-scan
GitHub stars
109
Token cost
~1.4k tokens
SKILL.md length
586 words
Files
39 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis…

  • Works in 4 steps: Load the Cheatsheet → Codebase Sweep → Selective Deep Validation → …
  • Tasks that involve Smart contracts
  • SKILL.md covers Repository Structure, Reference File Format, Audit Workflow and Severity Guidelines, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Scv Scan is an agent skill from kadenzipfel/scv-scan. Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis, deep-validate candidates against reference files, and output a severity-ranked findings

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 39 other files, including reference files (for example `README.md`, `references/CHEATSHEET.md` and `references/arbitrary-storage-location.md`).

It sits in Backend & APIs, covering Smart contracts. It works with Solidity. The repository describes itself as: A Claude Code skill that scans Solidity codebases for security vulnerabilities by referencing 36 unique vulnerability types.

When your agent uses it

  • Tasks that involve Smart contracts

Example prompts

  • “/scv-scan”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Load the Cheatsheet
  2. Codebase Sweep
  3. Selective Deep Validation
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 1149855. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scv Scan loads about 1.4k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 586 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~29k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 586 words (~1,396 tokens).

“You are a smart contract security auditor. Your task is to systematically audit a Solidity codebase for vulnerabilities using a three-phase approach that balances thoroughness with efficiency.”

— opening of SKILL.md by kadenzipfel
name
scv-scan

Read the full SKILL.md on GitHub

Files

SKILL.md and 38 other files (references) in the repository root of kadenzipfel/scv-scan.

  • SKILL.md
  • README.md
  • references/CHEATSHEET.md
  • references/arbitrary-storage-location.md
  • references/assert-violation.md
  • references/asserting-contract-from-code-size.md
  • references/authorization-txorigin.md
  • references/delegatecall-untrusted-callee.md
  • references/dos-gas-limit.md
  • references/dos-revert.md
  • references/hash-collision.md
  • references/inadherence-to-standards.md
  • references/incorrect-constructor.md
  • references/incorrect-inheritance-order.md
  • references/insufficient-access-control.md
  • references/insufficient-gas-griefing.md
  • references/lack-of-precision.md
  • references/missing-protection-signature-replay.md
  • references/msgvalue-loop.md
  • references/off-by-one.md
  • … and 19 more

Open the folder on GitHubat commit 1149855

Compare with similar skills

Scv Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scv Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scv Scan this skillkadenzipfel/scv-scan109—~1.4kAutomated safety check: PassNone
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2431 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Add Explorer

    lidofinance/diffyscan

    Adds or repairs Diffyscan explorer API routing and response adapters for a new host, chain or payload format.

    142 GitHub stars~1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed

Works with

Categories

Questions about Scv Scan

What does Scv Scan do?

Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis…. Scv Scan is an agent skill from kadenzipfel/scv-scan.

When should I use Scv Scan?

Scv Scan fits situations like: tasks that involve Smart contracts.

How do I install Scv Scan in Claude Code?

Run `npx skills add kadenzipfel/scv-scan --skill scv-scan -a claude-code`. Or copy the skill folder (the kadenzipfel/scv-scan repository) into .claude/skills/scv-scan in your project. Claude Code loads it when a task matches its description.

How do I install Scv Scan in Codex?

Run `npx skills add kadenzipfel/scv-scan --skill scv-scan -a codex`. Or copy the skill folder (the kadenzipfel/scv-scan repository) into .agents/skills/scv-scan in your project. Codex loads it when a task matches its description.

Can I use Scv Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kadenzipfel/scv-scan --skill scv-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scv-scan, .gemini/skills/scv-scan, .github/skills/scv-scan and .opencode/skills/scv-scan in your project.

What does Scv Scan need to run?

SKILL.md names no scripts, command-line tools or credentials: Scv Scan is instructions for the agent only.

Does Scv Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Scv Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scv Scan use?

No licence was found for Scv Scan or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Scv Scan use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 27k tokens, read only when the agent opens those files.

What are the alternatives to Scv Scan?

Skills that share tags, products or a category with Scv Scan: Fizz Convert (pashov/skills, 1.2k stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars) and Radar (Auditware/radar, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scv Scan?

kadenzipfel (a GitHub user) maintains it in kadenzipfel/scv-scan, which has 109 GitHub stars. The repository was last updated on March 11, 2026.

Source: kadenzipfel/scv-scan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.