Agent skill

Cm Contract Engineer

by kingxiaozhe in kingxiaozhe/cm-workflow

智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow.

MITAuto-check passedBackend & APIs

Install Cm Contract Engineer

skills CLI
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cm-contract-engineer .claude/skills/cm-contract-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cm-contract-engineer
GitHub stars
104
Token cost
~654 tokens
SKILL.md length
207 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow.

  • Works in 5 steps: 识别技术栈 → 读取上下文 → 开发 → …
  • Tasks that involve Smart contracts
  • SKILL.md covers 触发条件, 工作流程, 常见坑 and 审计准备, plus 1 more section
  • Calls npx

What it does

Cm Contract Engineer is an agent skill from kingxiaozhe/cm-workflow. 智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架

Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. It works with Solana and Solidity. The repository describes itself as: Codex-native, spec-driven AI Agent workflow with Claude Code compatibility, independent review, QA, fixes, and refactors. The licence is MIT.

When your agent uses it

  • Tasks that involve Smart contracts

Example prompts

  • “/cm-contract-engineer”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. 识别技术栈
  2. 读取上下文
  3. 开发
  4. 测试
  5. 部署准备

What it can do on your machine

Read from SKILL.md and the folder at commit 82d43f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cm Contract Engineer loads about 654 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 207 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~654

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kingxiaozhe/cm-workflow at commit 82d43f0, republished under its MIT licence (© kingxiaozhe). 207 words, ~654 tokens.

Download SKILL.mdSave it as .claude/skills/cm-contract-engineer/SKILL.md (or your agent's skills folder).
name
cm-contract-engineer
description
智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架

cm-contract-engineer — 智能合约工程师

执行智能合约开发任务。自动识别链类型和开发框架。

触发条件

由 /cm-ai 自动调用,当 task 涉及智能合约开发时触发。

工作流程

1. 识别技术栈

自动检测,不做硬编码假设:

  • 链/VM:EVM(Ethereum/Base/Arbitrum/BSC...)/ Solana / Aptos / Sui / TON / Cosmos
  • 语言:Solidity / Rust / Move / Vyper / FunC / Cairo
  • 框架:Foundry / Hardhat / Anchor / Truffle / Brownie / Ape
  • 检测方式:foundry.toml / hardhat.config.* / Anchor.toml / truffle-config.js / Move.toml / contracts/ 目录
2. 读取上下文
  • .claude/rules/smart-contract.md、.claude/rules/security.md(如存在)
  • design.md 中的合约接口设计
  • 现有合约代码和部署配置
  • 已有的测试文件和部署脚本
3. 开发

合约编写:

  • 遵循项目已有的合约组织方式(单文件/模块化/Diamond 模式等)
  • 接口(interface)先行,实现后补
  • 使用成熟的库(OpenZeppelin / Solmate / SPL 等)而非手写基础功能
  • NatSpec / Rust doc 注释覆盖所有 public 函数

安全优先(EVM/Solidity 重点):

  • 重入防护:使用 ReentrancyGuard 或 checks-effects-interactions 模式
  • 整数溢出:Solidity ≥0.8 内置检查,低版本用 SafeMath
  • 权限控制:Ownable / AccessControl / 多签,避免单点控制
  • 外部调用:不信任外部合约返回值,限制 gas 转发
  • 闪电贷攻击:价格预言机用 TWAP 而非即时价格
  • 前端运行(MEV):commit-reveal 或时间锁机制

安全优先(Solana/Anchor 重点):

  • 账户验证:每个 instruction 都要验证 account owner 和 signer
  • PDA 派生:种子要唯一,避免碰撞
  • CPI 调用:验证目标 program_id
  • 整数溢出:用 checked_add / checked_mul

Gas/资源优化:

  • 存储变量打包(EVM slot packing)
  • 减少 SSTORE/SLOAD 操作
  • 批量操作代替循环中的单次调用
  • Solana: 减少账户数量,合理使用 zero-copy
4. 测试
bash
# Foundry
forge test -vvv
forge coverage

# Hardhat
npx hardhat test
npx hardhat coverage

# Anchor
anchor test

# Move
aptos move test

测试要求:

  • 正常流程覆盖所有 public 函数
  • 边界值测试(零值、最大值、空地址)
  • 权限测试(非授权调用应 revert)
  • 攻击测试(重入、闪电贷等关键场景)
  • Fuzz 测试(Foundry forge test --fuzz-runs 1000)
5. 部署准备
  • 部署脚本使用项目约定的方式(Foundry script / Hardhat deploy / Anchor deploy)
  • 环境变量管理私钥和 RPC URL,绝不硬编码
  • 区分 testnet / mainnet 配置
  • 合约验证脚本(Etherscan / Sourcify)

部署前检查清单:

  • 所有测试通过
  • 覆盖率 > 90%
  • 权限模型正确(owner/admin/multisig)
  • 升级机制明确(如使用代理模式)
  • 紧急暂停功能(如需要)
  • 事件覆盖所有状态变更

常见坑

问题处理
Solidity 版本不一致导致编译失败检查 foundry.toml / hardhat.config 中的 solc 版本,与 pragma 一致
OpenZeppelin 版本升级 API 变化锁定依赖版本,升级前检查 changelog
Anchor IDL 生成失败确保 #[program] 和 account struct 上的宏正确
合约大小超过 24KB(EVM)拆分合约、使用 library、Diamond 模式
Gas estimation 失败检查是否有 require 条件未满足,mock 依赖合约
Solana 交易大小超限拆分 instruction,使用 lookup table

审计准备

合约开发完成后,生成审计辅助文档:

markdown
## 合约审计信息

- 合约列表: {合约名及用途}
- 依赖: {使用的库及版本}
- 权限模型: {谁能做什么}
- 资金流向: {token/ETH 的流入流出路径}
- 已知风险: {设计上的取舍及原因}

输出

  • 合约代码和接口
  • 测试结果和覆盖率
  • 部署脚本
  • 需要其他工种配合的事项(如前端需要的 ABI 和合约地址)

© kingxiaozhe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cm-contract-engineer of kingxiaozhe/cm-workflow.

Open the folder on GitHubat commit 82d43f0

Compare with similar skills

Cm Contract Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cm Contract Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cm Contract Engineer this skillkingxiaozhe/cm-workflow104—~654Automated safety check: PassMIT
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT

Similar skills

  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    243 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed

More from kingxiaozhe/cm-workflow

All 23 skills in this repo
  • Cm Fix

    kingxiaozhe/cm-workflow

    用户说“修复这个可复现 bug”或要求根据失败报告修代码时使用。执行红灯测试、根因定位、最小修复、独立审查和回归;尚未确认的问题先用 cm-test,新功能和架构重设计转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Cm Idea

    kingxiaozhe/cm-workflow

    用户说“我有个点子”“帮我梳理产品”或需要先聊清目标时使用。通过逐题访谈整理为可交给 cm-prd 的 PRD;已有明确需求文档时改用 cm-prd,不写代码、不拆开发任务。

    104 GitHub starsUsed in 1 repo~419 tokens
    Auto-check passed
  • Cm Refactor

    kingxiaozhe/cm-workflow

    用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Cm Security

    kingxiaozhe/cm-workflow

    用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

    104 GitHub starsUsed in 1 repo~744 tokens
    Auto-check passed
  • Cm AI

    kingxiaozhe/cm-workflow

    用户明确说“规格已确认,开始实现”或要求按已审批 CM specs 开发时使用。新任务默认由 JS workflow 驱动 N1-N8,完成开发、独立审查、QA 与文档同步;模糊点子、未审规格和单独一句“继续”不能触发编码批准。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Cm Check

    kingxiaozhe/cm-workflow

    用户说“检查工作流是否安装正确”“为什么找不到 cm 命令”时使用。默认查询 npm 稳定版,有新版自动升级已管理的 CM 安装,再检查插件、核心 Skills、兼容包装与模板引用;不测试或修改业务代码。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cm Contract Engineer

What does Cm Contract Engineer do?

智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow. Cm Contract Engineer is an agent skill from kingxiaozhe/cm-workflow.

When should I use Cm Contract Engineer?

Cm Contract Engineer fits situations like: tasks that involve Smart contracts.

How do I install Cm Contract Engineer in Claude Code?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a claude-code`. Or copy the skill folder (skills/cm-contract-engineer in kingxiaozhe/cm-workflow) into .claude/skills/cm-contract-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Cm Contract Engineer in Codex?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a codex`. Or copy the skill folder (skills/cm-contract-engineer in kingxiaozhe/cm-workflow) into .agents/skills/cm-contract-engineer in your project. Codex loads it when a task matches its description.

Can I use Cm Contract Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cm-contract-engineer, .gemini/skills/cm-contract-engineer, .github/skills/cm-contract-engineer and .opencode/skills/cm-contract-engineer in your project.

What does Cm Contract Engineer need to run?

Going by SKILL.md and its folder, Cm Contract Engineer needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Cm Contract Engineer access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cm Contract Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cm Contract Engineer use?

Cm Contract Engineer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cm Contract Engineer use?

About 654 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cm Contract Engineer?

Skills that share tags, products or a category with Cm Contract Engineer: Radar (Auditware/radar, 154 stars), Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars) and Fizz Convert (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cm Contract Engineer?

kingxiaozhe (a GitHub user) maintains it in kingxiaozhe/cm-workflow, which has 104 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.

Source: kingxiaozhe/cm-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.