Radar
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow.
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cm-contract-engineer .claude/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .claude/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cm-contract-engineer .agents/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .agents/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cm-contract-engineer .cursor/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .cursor/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kingxiaozhe/cm-workflow.git --path skills/cm-contract-engineer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cm-contract-engineer .gemini/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .gemini/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cm-contract-engineer .github/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .github/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kingxiaozhe/cm-workflow cm-contract-engineer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cm-contract-engineer .opencode/skills/cm-contract-engineer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cm-contract-engineer" agent skill from https://github.com/kingxiaozhe/cm-workflow/tree/main/skills/cm-contract-engineer into .opencode/skills/cm-contract-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cm-contract-engineer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cm-contract-engineer智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow.
Cm Contract Engineer is an agent skill from kingxiaozhe/cm-workflow. 智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架
Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Smart contracts. It works with Solana and Solidity. The repository describes itself as: Codex-native, spec-driven AI Agent workflow with Claude Code compatibility, independent review, QA, fixes, and refactors. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82d43f0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cm Contract Engineer loads about 654 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 207 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kingxiaozhe/cm-workflow at commit 82d43f0, republished under its MIT licence (© kingxiaozhe). 207 words, ~654 tokens.
.claude/skills/cm-contract-engineer/SKILL.md (or your agent's skills folder).执行智能合约开发任务。自动识别链类型和开发框架。
由 /cm-ai 自动调用,当 task 涉及智能合约开发时触发。
自动检测,不做硬编码假设:
foundry.toml / hardhat.config.* / Anchor.toml / truffle-config.js / Move.toml / contracts/ 目录.claude/rules/smart-contract.md、.claude/rules/security.md(如存在)合约编写:
安全优先(EVM/Solidity 重点):
安全优先(Solana/Anchor 重点):
Gas/资源优化:
# Foundry
forge test -vvv
forge coverage
# Hardhat
npx hardhat test
npx hardhat coverage
# Anchor
anchor test
# Move
aptos move test测试要求:
forge test --fuzz-runs 1000)部署前检查清单:
| 问题 | 处理 |
|---|---|
| Solidity 版本不一致导致编译失败 | 检查 foundry.toml / hardhat.config 中的 solc 版本,与 pragma 一致 |
| OpenZeppelin 版本升级 API 变化 | 锁定依赖版本,升级前检查 changelog |
| Anchor IDL 生成失败 | 确保 #[program] 和 account struct 上的宏正确 |
| 合约大小超过 24KB(EVM) | 拆分合约、使用 library、Diamond 模式 |
| Gas estimation 失败 | 检查是否有 require 条件未满足,mock 依赖合约 |
| Solana 交易大小超限 | 拆分 instruction,使用 lookup table |
合约开发完成后,生成审计辅助文档:
## 合约审计信息
- 合约列表: {合约名及用途}
- 依赖: {使用的库及版本}
- 权限模型: {谁能做什么}
- 资金流向: {token/ETH 的流入流出路径}
- 已知风险: {设计上的取舍及原因}© kingxiaozhe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cm-contract-engineer of kingxiaozhe/cm-workflow.
Open the folder on GitHubat commit 82d43f0
Cm Contract Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cm Contract Engineer this skillkingxiaozhe/cm-workflow | 104 | — | ~654 | Automated safety check: Pass | MIT | |
| RadarAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Smart Contract Auditforefy/.context | 152 | 1 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Smart Contract Auditelophanto/EloPhanto | 106 | — | ~2.7k | Automated safety check: Pass | Custom licence | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Solana Devsolana-foundation/solana-dev-skill | 574 | — | ~3.8k | Automated safety check: Pass | MIT |
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
0xiehnnkta/nemesis-auditor
Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.
kingxiaozhe/cm-workflow
用户说“修复这个可复现 bug”或要求根据失败报告修代码时使用。执行红灯测试、根因定位、最小修复、独立审查和回归;尚未确认的问题先用 cm-test,新功能和架构重设计转交 cm-prd。
kingxiaozhe/cm-workflow
用户说“我有个点子”“帮我梳理产品”或需要先聊清目标时使用。通过逐题访谈整理为可交给 cm-prd 的 PRD;已有明确需求文档时改用 cm-prd,不写代码、不拆开发任务。
kingxiaozhe/cm-workflow
用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。
kingxiaozhe/cm-workflow
用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。
kingxiaozhe/cm-workflow
用户明确说“规格已确认,开始实现”或要求按已审批 CM specs 开发时使用。新任务默认由 JS workflow 驱动 N1-N8,完成开发、独立审查、QA 与文档同步;模糊点子、未审规格和单独一句“继续”不能触发编码批准。
kingxiaozhe/cm-workflow
用户说“检查工作流是否安装正确”“为什么找不到 cm 命令”时使用。默认查询 npm 稳定版,有新版自动升级已管理的 CM 安装,再检查插件、核心 Skills、兼容包装与模板引用;不测试或修改业务代码。
Categories
智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架. An agent skill from kingxiaozhe/cm-workflow. Cm Contract Engineer is an agent skill from kingxiaozhe/cm-workflow.
Cm Contract Engineer fits situations like: tasks that involve Smart contracts.
Run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a claude-code`. Or copy the skill folder (skills/cm-contract-engineer in kingxiaozhe/cm-workflow) into .claude/skills/cm-contract-engineer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a codex`. Or copy the skill folder (skills/cm-contract-engineer in kingxiaozhe/cm-workflow) into .agents/skills/cm-contract-engineer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kingxiaozhe/cm-workflow --skill cm-contract-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cm-contract-engineer, .gemini/skills/cm-contract-engineer, .github/skills/cm-contract-engineer and .opencode/skills/cm-contract-engineer in your project.
Going by SKILL.md and its folder, Cm Contract Engineer needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cm Contract Engineer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 654 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cm Contract Engineer: Radar (Auditware/radar, 154 stars), Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars) and Fizz Convert (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kingxiaozhe (a GitHub user) maintains it in kingxiaozhe/cm-workflow, which has 104 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.
Source: kingxiaozhe/cm-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.