Soroban Contract Audit
sickn33/agentic-awesome-skills
Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.
Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.
$ npx skills add mblode/agent-skills --skill dx-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mblode/agent-skills dx-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dx-audit .claude/skills/dx-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .claude/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mblode/agent-skills/tree/main/skills/dx-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mblode/agent-skills --skill dx-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mblode/agent-skills dx-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dx-audit .agents/skills/dx-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .agents/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mblode/agent-skills --skill dx-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mblode/agent-skills dx-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dx-audit .cursor/skills/dx-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .cursor/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mblode/agent-skills.git --path skills/dx-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mblode/agent-skills --skill dx-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mblode/agent-skills dx-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dx-audit .gemini/skills/dx-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .gemini/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mblode/agent-skills dx-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mblode/agent-skills --skill dx-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dx-audit .github/skills/dx-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .github/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mblode/agent-skills --skill dx-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mblode/agent-skills dx-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dx-audit .opencode/skills/dx-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dx-audit" agent skill from https://github.com/mblode/agent-skills/tree/main/skills/dx-audit into .opencode/skills/dx-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dx-auditAudits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.
Dx Audit is an agent skill from mblode/agent-skills. Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 46 other files, including reference files (for example `evals/evals.json`, `evals/evaluation-scenarios.md` and `references/standards-map.md`).
The repository describes itself as: Nobody ships AI slop on purpose. These skills make sure you don’t. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cef4cfa. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxgitnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dx Audit loads about 2.4k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 1,217 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mblode/agent-skills at commit cef4cfa, republished under its MIT licence (© mblode). 1,217 words, ~2,422 tokens.
.claude/skills/dx-audit/SKILL.md (or your agent's skills folder). This skill also uses 43 other files; get the full folder from GitHub.Audit or improve what developers import, run, configure, or read when something fails.
tidy), end-user UI (ui-design Audit mode), agent trust review (ax-audit), public site or docs agent scores (agent-ready), docs prose or a README (ghostwriter), repository architecture (codebase-architecture), or building a new CLI (scaffold-cli).Pick the narrowest mode the request supports, and write a one-line scope receipt before reading code:
| Mode | When | Output |
|---|---|---|
| Targeted (default) | a named or changed public surface | findings report, read-only |
| Fix | the user says fix, improve, simplify, or implement | localized edits inside the receipt, then verification |
| Exhaustive | the user explicitly asks for the whole package or every public surface | every material finding, partitioned by surface |
Scope: <mode>; surfaces: <commands/exports/config>; prefixes: <err-, cli->; excludes: <UI, docs, architecture, private internals>"DX", "gold standard", and "review holistically" do not by themselves widen a targeted audit into exhaustive. When several skills are invoked together, this one owns only the surfaces above.
DX audit progress:
- [ ] 1. Lock the public surface and write the scope receipt
- [ ] 2. Gather local evidence and run the safe probes
- [ ] 3. Select prefixes, then open candidate rules
- [ ] 4. Rank root causes
- [ ] 5. Report, or fix when asked
- [ ] 6. Verify on the same scopeStart from git diff against the normal base and keep only changed files reachable from a public entry point: package.json exports or bin, a command registry, an exported type, a documented config loader, or an observed error path. With no useful diff, use the command, export, error, or config the user named. A private helper enters scope only through a public caller.
--help, --version, one success path, one invalid-input path, and the same command with stdout piped (| cat) to see non-TTY behavior. Never trigger a real mutation to test DX; use --dry-run where it exists.npx publint and npx @arethetypeswrong/cli --pack . after a build. These inspect packaging, but packing may invoke lifecycle scripts. Inspect those scripts first or use a disposable checkout before calling --pack.Stop when the behavior is proven, disproven, private, or out of scope. External research is for an explicit comparison request or a named uncertainty local evidence cannot resolve; references/standards-map.md carries the standards this skill already leans on.
Read rules/_sections.md, then select prefixes by surface:
| Priority | Prefix | Category | Default impact | Rules |
|---|---|---|---|---|
| 1 | api- | Public API and SDK | CRITICAL | 7 |
| 2 | err- | Developer-facing errors | CRITICAL | 5 |
| 3 | cli- | CLI UX for humans and agents | HIGH | 13 |
| 4 | types- | Exported type ergonomics | HIGH | 5 |
| 5 | onboard- | Install and first run | HIGH | 5 |
| 6 | config- | Config ergonomics | MEDIUM | 3 |
| Surface | Prefixes |
|---|---|
| Public API entry point | api-, types-, reached err- paths |
| CLI command | cli-, reached err- paths |
| Exported declarations | types-, plus api- when behavior changed |
Install, package.json, first run | onboard- |
| Config loader | config-, reached err- paths |
Applicability outranks priority: a CLI-only audit never loads api- because API rules rank higher.
Targeted mode: list the filenames for the selected prefixes (the names are the checklist), look for concrete evidence, then open only the rule files a finding needs. Exhaustive mode: read every rule in the selected prefixes.
Capability gates, applied inside a selected prefix:
stdin applies when the command semantically accepts file or stream data.impact, copied exactly. Impact is the rule's declared consequence, not a confidence score: exit 0 on failure in one subcommand is still HIGH, because the CI gate it defeats is the same. Open the rule file before citing it, since an id cited from memory drifts from the file, and drop the citation if no such file exists.--json across a surface is one finding, not one per symbol.Audit requests are read-only. A fix request authorizes localized changes inside the receipt, not a redesign of adjacent docs, UI, or architecture.
## DX Audit
Scope: `tool status` CLI; `err-`, `cli-`; 4 files inspected.
### Findings
- [HIGH] `cli-idempotent-resume` at `src/start.ts:42`: retrying the same target creates a second job.
Fix: return the existing job id and state unless the caller passes `--fresh`.
### Deferred
- 2 lower-impact config candidates were outside the locked CLI scope.List only files with findings; a clean surface gets one pass line naming the surfaces and rule files checked. In fix mode, replace Deferred with Changed and Verification (the exact commands or probes that passed). Length follows findings, not the template.
Re-open every touched or cited location, rerun the same probes and focused project checks, and reapply the same candidate rules. Match the evidence to the claim: a clean build does not prove CLI behavior, a runtime probe does not prove exported types, and only attw or a consumer-style tsc import proves a types resolution.
| File | Read when |
|---|---|
rules/_sections.md | Every audit, for prefix applicability and priority |
rules/<prefix>-*.md | A candidate has evidence, or exhaustive mode |
references/standards-map.md | A finding needs an external citation, the user asks why something is a rule, or a borderline call needs a tie-break |
rules/_template.md | Adding or editing a rule |
npx <pkg> and a global install probe the registry copy, not the working tree. --help, exit codes, and error strings then describe a released version. Build, then invoke the local entry point (node ./dist/cli.js).process.stdout.isTTY is undefined under a pipe, not false. A guard written as isTTY === false never disables color or spinners when piped, so ANSI codes reach the redirected file. Probe with | cat rather than trusting the guard.process.exit(1) right after console.log can truncate the output it was meant to explain. stdout writes are asynchronous when piped, so a CLI that prints usage and calls exit() can emit nothing under | cat. The fix is process.exitCode = 1 and a natural return (cli-exit-codes).exports map that reads correctly can still resolve wrong. "require" pointing at a .js file under "type": "module" masquerades as CJS, and a types condition listed after import is never reached. publint and attw catch both; reading the map does not (onboard-exports-resolve-typed).ui-design Audit mode: rendered end-user frontend quality and accessibilityax-audit: same files, different reader; asks whether an agent can operate and recover, where this skill asks whether a developer finds the surface ergonomicscaffold-cli: builds a new CLI with these patterns already in place; this skill audits what existstidy: general correctness and structure of a diffagent-ready: public HTTP/docs agent scores (AFDocs, Is Agentic, Is It Agent Ready); this skill audits the package once it existsghostwriter: documentation prose, README structure, and the first-reader narrativeagents-md: AGENTS.md and CLAUDE.md instruction filescodebase-architecture: repository structure and module contracts inside the repo, rather than the surface a package ships outwardMaintenance only: evals/evals.json and evals/evaluation-scenarios.md hold regression scenarios for changes to this skill; neither loads during a user task.
© mblode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 43 other files (references) in skills/dx-audit of mblode/agent-skills.
Open the folder on GitHubat commit cef4cfa
Dx Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dx Audit this skillmblode/agent-skills | 143 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Soroban Contract Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Audit Map Contractben-manes/caffeine | 18k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Cross Platform Contract Propagation Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Audit Contract Driftben-manes/caffeine | 18k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Libraryasgeirtj/system_prompts_leaks | 69k | — | ~4k | Automated safety check: Pass | CC0-1.0 |
sickn33/agentic-awesome-skills
Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.
ben-manes/caffeine
Audit ConcurrentMap and Map contract compliance for asMap() view
sickn33/agentic-awesome-skills
A skill your agent uses when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.
ben-manes/caffeine
Find places where documented API contracts and the implementation diverge
asgeirtj/system_prompts_leaks
Use ChatGPT Library when the user mentions their Library, asks to find or work with a Library-backed file, Site, or named file that may be in the Library, or wants to organize Library folders…
ben-manes/caffeine
Verify every third-party and sharp-edged JDK API usage against the contract the upstream documentation actually states
mblode/agent-skills
Implements agent-readiness on public sites and docs from Mintlify Agent Score, AFDocs, Is Agentic, Is It Agent Ready, or url-discovery-bench reports, or from server logs of agents 404ing on guessed…
mblode/agent-skills
Creates and improves portable Agent Skills with a validator, routing scenarios, and evidence-based keep, cut, merge, or retire decisions.
mblode/agent-skills
Recovers decisions, previous fixes, research, and what followed a prompt from past AI conversations, with source evidence.
mblode/agent-skills
Cuts the wait from push to green by measuring a pipeline's critical path from run timestamps, then splitting, sharding, trimming setup and sharing test module state, with a before/after ledger.
mblode/agent-skills
Monitors or repairs an open GitHub PR: CI failures, conflicts, review threads, and merge readiness, reporting state changes.
mblode/agent-skills
Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.
Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Dx Audit is an agent skill from mblode/agent-skills. Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.
Dx Audit fits situations like: asked to audit my CLI; diagnose package type resolution.
Run `npx skills add mblode/agent-skills --skill dx-audit -a claude-code`. Or copy the skill folder (skills/dx-audit in mblode/agent-skills) into .claude/skills/dx-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mblode/agent-skills --skill dx-audit -a codex`. Or copy the skill folder (skills/dx-audit in mblode/agent-skills) into .agents/skills/dx-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mblode/agent-skills --skill dx-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dx-audit, .gemini/skills/dx-audit, .github/skills/dx-audit and .opencode/skills/dx-audit in your project.
Going by SKILL.md and its folder, Dx Audit needs the command-line tools its instructions call (npx, git and node). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dx Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dx Audit: Soroban Contract Audit (sickn33/agentic-awesome-skills, 47k stars), Audit Map Contract (ben-manes/caffeine, 18k stars), Cross Platform Contract Propagation Audit (sickn33/agentic-awesome-skills, 47k stars) and Audit Contract Drift (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mblode (a GitHub user) maintains it in mblode/agent-skills, which has 143 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.
Source: mblode/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.