Solana Dev
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .claude/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .claude/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contractType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .agents/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .agents/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .cursor/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .cursor/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mtarcure/claude-vibe-squad.git --path .agents/skills/chain-construct-smart-contract--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .gemini/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .gemini/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contractInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .github/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .github/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .opencode/skills/chain-construct-smart-contract && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "chain-construct-smart-contract" agent skill from https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/chain-construct-smart-contract into .opencode/skills/chain-construct-smart-contract/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chain-construct-smart-contract", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
chain-construct-smart-contractA skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…
Chain Construct Smart Contract is an agent skill from mtarcure/claude-vibe-squad. Use when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction sequence for an EVM reentrancy, flash-loan, delegatecall-overwrite, or proxy-upgrade primitive (or a Solana CPI-privilege, account-substitution, or overflow primitive) and reproduce it under Forge, LiteSVM, or Trident.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Smart contracts. It works with Solana. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Chain Construct Smart Contract loads about 1.5k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 642 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 642 words, ~1,523 tokens.
.claude/skills/chain-construct-smart-contract/SKILL.md (or your agent's skills folder).<!-- attack-chain-builder pattern, recreated against native CLIs; no upstream code copied -->
Smart-contract specialization of chain-construct for exploit-developer: build multi-step
attack call sequences for on-chain vulnerabilities and prove them with a passing Forge (EVM) or
LiteSVM/Trident (Solana) reproduction. Follow the generic chain-construct method (objective as
end-state, chain head, state-feeds ordering, prove-don't-assert); this skill adds the
EVM/Solana chain primitives. Where the two conflict, the contract-level guidance here wins for
smart-contract targets. All tools are native host CLIs (forge, cargo test/litesvm,
trident, cargo-fuzz, anchor) — no wrapper layer.
Reentrancy chain: deploy an attacker contract whose receive()/fallback() re-enters the
target; call the withdrawable function; re-enter before the balance is decremented; repeat
until drained. Scaffold: test/attack/AttackerReentrant.sol + a Forge test.
Flash-loan chain: borrow asset X (Aave/Uniswap V3 callback); in the callback manipulate
target state (price oracle, reserve ratio, collateral); extract profit; repay loan + fee.
Scaffold: FlashLoanAttacker.sol implementing IERC3156FlashBorrower or a Uniswap V3
flash callback.
Delegatecall-overwrite chain: find an unprotected delegatecall to a caller-controlled
address; supply a malicious implementation that overwrites slot 0 (owner/admin); call a
privileged function. Scaffold: a Forge fuzz test supplying arbitrary impl_addr.
Proxy-upgrade chain: find a UUPS/Transparent proxy with a bypassable upgrade guard (missing
onlyOwner, missing _authorizeUpgrade override); upgradeTo(malicious_impl); drain from the
new implementation. Scaffold: a Forge test with a MaliciousImpl.
CPI privilege-escalation chain: find an instruction that makes a CPI with caller-controlled
signer_seeds; derive a PDA whose seeds match a privileged authority; call with the crafted
seeds so the program signs on that authority's behalf. Scaffold: a Trident FuzzInstruction
supplying crafted seed arrays, or a LiteSVM test.
Account-substitution chain: find an instruction accepting a generic AccountInfo for a
privileged account type; pass a different account that passes owner/discriminator checks due to
missing validation. Scaffold: a LiteSVM test passing a crafted account buffer.
SPL-arithmetic-overflow chain: find token arithmetic without a checked_* guard; supply an
amount that overflows to a small number; withdraw more than deposited. Scaffold: a LiteSVM test
with amount = u64::MAX.
test/attack/ (Forge) or a programs/attacker/ /
fuzz target (Solana). Validate with forge test --match-contract <Attacker> -vvvv, or
cargo test / trident fuzz run <target> / cargo fuzz run <target> for Solana.impact-validator.forge test --fork-url <rpc> --fork-block-number <n>;
never submit a finding that only reproduces on a live fork without documenting the fork block
and contract state.vm.warp() / vm.roll() (EVM) or advance slots on a
local validator (Solana); document the required delta.tool_wrappers names (forge_test, litesvm_test, trident_fuzz); use
the native CLIs above.// test/attack/ReentrancyAttacker.sol
contract ReentrancyAttacker {
VulnerableVault vault;
constructor(address _vault) { vault = VulnerableVault(_vault); }
function attack() external payable {
vault.deposit{value: msg.value}();
vault.withdraw();
}
receive() external payable {
if (address(vault).balance > 0) vault.withdraw(); // re-enter before balance update
}
}forge test --match-contract ReentrancyAttacker -vvvvThe task packet's injected memory contract owns the exact call shape, sequence, and fields - see
wirework-reflect. Do not copy a record(...) example or add fields (including source_task) from
memory; the server binds them, and a baked example violates the run's authenticated schema. Memory is
best-effort telemetry and never gates the work. What is worth recording here is the task-specific
outcome: chain primitive, entry point, numbered steps, impact, preconditions, test file, reproduced?.
© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/chain-construct-smart-contract of mtarcure/claude-vibe-squad.
Open the folder on GitHubat commit 7bd69f8
Chain Construct Smart Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Chain Construct Smart Contract this skillmtarcure/claude-vibe-squad | 163 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Solana Devsolana-foundation/solana-dev-skill | 574 | — | ~3.8k | Automated safety check: Pass | MIT | |
| RadarAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | |
| Safe Solana BuilderFrankcastleauditor/safe-solana-builder | 145 | — | ~3.6k | Automated safety check: Pass | None | |
| Wiremock TestOpenZeppelin/openzeppelin-relayer | 153 | — | ~1.6k | Automated safety check: Notes | AGPL-3.0 | |
| Solana Token Extensionssolanabr/ai-kit | 108 | — | ~3.5k | Automated safety check: Pass | MIT |
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
Frankcastleauditor/safe-solana-builder
A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.
OpenZeppelin/openzeppelin-relayer
Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.
solanabr/ai-kit
Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints.
moonpay/skills
A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.
mtarcure/claude-vibe-squad
A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…
mtarcure/claude-vibe-squad
Operational checklist + helper for blind-rediscovery fan-out work.
mtarcure/claude-vibe-squad
Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…
mtarcure/claude-vibe-squad
A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.
mtarcure/claude-vibe-squad
A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…
mtarcure/claude-vibe-squad
A skill your agent uses when module, package, or build dependencies may contain cycles, especially load-order failures, broad rebuilds, or a planned extraction: derive the real graph, compute…
Works with
Categories
A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…. Chain Construct Smart Contract is an agent skill from mtarcure/claude-vibe-squad. Use when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction sequence for an EVM reentrancy, flash-loan, delegatecall-overwrite, or proxy-upgrade primitive (or a Solana CPI-privilege, account-substitution, or overflow primitive) and reproduce it under Forge, LiteSVM, or Trident.
Chain Construct Smart Contract fits situations like: you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract; crafted instruction sequence for an EVM reentrancy; delegatecall-overwrite; proxy-upgrade primitive (or a Solana CPI-privilege.
Run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a claude-code`. Or copy the skill folder (.agents/skills/chain-construct-smart-contract in mtarcure/claude-vibe-squad) into .claude/skills/chain-construct-smart-contract in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a codex`. Or copy the skill folder (.agents/skills/chain-construct-smart-contract in mtarcure/claude-vibe-squad) into .agents/skills/chain-construct-smart-contract in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chain-construct-smart-contract, .gemini/skills/chain-construct-smart-contract, .github/skills/chain-construct-smart-contract and .opencode/skills/chain-construct-smart-contract in your project.
Going by SKILL.md and its folder, Chain Construct Smart Contract needs the command-line tools its instructions call (cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Chain Construct Smart Contract is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Chain Construct Smart Contract: Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Radar (Auditware/radar, 154 stars), Safe Solana Builder (Frankcastleauditor/safe-solana-builder, 145 stars) and Wiremock Test (OpenZeppelin/openzeppelin-relayer, 153 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 163 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.
Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.