Agent skill

Chain Construct Smart Contract

by mtarcure in mtarcure/claude-vibe-squad

A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

MITAuto-check passedBackend & APIs

Install Chain Construct Smart Contract

skills CLI
$ npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mtarcure/claude-vibe-squad chain-construct-smart-contract --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/chain-construct-smart-contract .claude/skills/chain-construct-smart-contract && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
chain-construct-smart-contract
GitHub stars
163
Token cost
~1.5k tokens
SKILL.md length
642 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

  • Works in 5 steps: Map the chain head — the first… → Select the primitive from the categories… → Author the attack contract/test in… → …
  • You have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract
  • SKILL.md covers Chain primitives — EVM, Chain primitives — Solana, Order of ops and When to pivot, plus 3 more sections
  • Calls cargo

What it does

Chain Construct Smart Contract is an agent skill from mtarcure/claude-vibe-squad. Use when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction sequence for an EVM reentrancy, flash-loan, delegatecall-overwrite, or proxy-upgrade primitive (or a Solana CPI-privilege, account-substitution, or overflow primitive) and reproduce it under Forge, LiteSVM, or Trident.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. It works with Solana. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.

When your agent uses it

  • You have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract
  • Crafted instruction sequence for an EVM reentrancy
  • Delegatecall-overwrite
  • Proxy-upgrade primitive (or a Solana CPI-privilege

Example prompts

  • “/chain-construct-smart-contract”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Map the chain head — the first externally-callable function/instruction the attacker
  2. Select the primitive from the categories above and its scaffold.
  3. Author the attack contract/test in test/attack/ (Forge) or a programs/attacker/ /
  4. Gate on state confirmation — the chain is valid only if the final state demonstrates the
  5. Document the chain — entry point → numbered intermediate steps → final impact →

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Chain Construct Smart Contract loads about 1.5k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 642 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 642 words, ~1,523 tokens.

Download SKILL.mdSave it as .claude/skills/chain-construct-smart-contract/SKILL.md (or your agent's skills folder).
name
chain-construct-smart-contract
description
Use when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction sequence for an EVM reentrancy, flash-loan, delegatecall-overwrite, or proxy-upgrade primitive (or a Solana CPI-privilege, account-substitution, or overflow primitive) and reproduce it under Forge, LiteSVM, or Trident.
audience
specialist
<!-- attack-chain-builder pattern, recreated against native CLIs; no upstream code copied -->

chain-construct-smart-contract

Smart-contract specialization of chain-construct for exploit-developer: build multi-step attack call sequences for on-chain vulnerabilities and prove them with a passing Forge (EVM) or LiteSVM/Trident (Solana) reproduction. Follow the generic chain-construct method (objective as end-state, chain head, state-feeds ordering, prove-don't-assert); this skill adds the EVM/Solana chain primitives. Where the two conflict, the contract-level guidance here wins for smart-contract targets. All tools are native host CLIs (forge, cargo test/litesvm, trident, cargo-fuzz, anchor) — no wrapper layer.

Chain primitives — EVM

Reentrancy chain: deploy an attacker contract whose receive()/fallback() re-enters the target; call the withdrawable function; re-enter before the balance is decremented; repeat until drained. Scaffold: test/attack/AttackerReentrant.sol + a Forge test.

Flash-loan chain: borrow asset X (Aave/Uniswap V3 callback); in the callback manipulate target state (price oracle, reserve ratio, collateral); extract profit; repay loan + fee. Scaffold: FlashLoanAttacker.sol implementing IERC3156FlashBorrower or a Uniswap V3 flash callback.

Delegatecall-overwrite chain: find an unprotected delegatecall to a caller-controlled address; supply a malicious implementation that overwrites slot 0 (owner/admin); call a privileged function. Scaffold: a Forge fuzz test supplying arbitrary impl_addr.

Proxy-upgrade chain: find a UUPS/Transparent proxy with a bypassable upgrade guard (missing onlyOwner, missing _authorizeUpgrade override); upgradeTo(malicious_impl); drain from the new implementation. Scaffold: a Forge test with a MaliciousImpl.

Chain primitives — Solana

CPI privilege-escalation chain: find an instruction that makes a CPI with caller-controlled signer_seeds; derive a PDA whose seeds match a privileged authority; call with the crafted seeds so the program signs on that authority's behalf. Scaffold: a Trident FuzzInstruction supplying crafted seed arrays, or a LiteSVM test.

Account-substitution chain: find an instruction accepting a generic AccountInfo for a privileged account type; pass a different account that passes owner/discriminator checks due to missing validation. Scaffold: a LiteSVM test passing a crafted account buffer.

SPL-arithmetic-overflow chain: find token arithmetic without a checked_* guard; supply an amount that overflows to a small number; withdraw more than deposited. Scaffold: a LiteSVM test with amount = u64::MAX.

Order of ops

  1. Map the chain head — the first externally-callable function/instruction the attacker controls.
  2. Select the primitive from the categories above and its scaffold.
  3. Author the attack contract/test in test/attack/ (Forge) or a programs/attacker/ / fuzz target (Solana). Validate with forge test --match-contract <Attacker> -vvvv, or cargo test / trident fuzz run <target> / cargo fuzz run <target> for Solana.
  4. Gate on state confirmation — the chain is valid only if the final state demonstrates the intended impact (balance drain, ownership change, unauthorized state write). Add explicit assertions on the expected final state; a passing test with unclear impact is not a finding.
  5. Document the chain — entry point → numbered intermediate steps → final impact → preconditions (flash loan available, specific contract state, fork block). This becomes the PoC evidence handed to impact-validator.
Show full SKILL.md (197 more words)Show less

When to pivot

  • Chain needs live mainnet state: use forge test --fork-url <rpc> --fork-block-number <n>; never submit a finding that only reproduces on a live fork without documenting the fork block and contract state.
  • Chain spans multiple blocks: use vm.warp() / vm.roll() (EVM) or advance slots on a local validator (Solana); document the required delta.

Anti-patterns

  • Do NOT author chains that require compromised admin keys or any attacker-unestablishable precondition — out of scope for smart-contract auditing.
  • Do NOT submit a chain that only works against a specific past chain state without noting the block-height constraint.
  • Do NOT conflate a theoretical chain with a demonstrated one — the Forge/LiteSVM/Trident test must actually pass.
  • Do NOT invoke dead tool_wrappers names (forge_test, litesvm_test, trident_fuzz); use the native CLIs above.

Example

solidity
// test/attack/ReentrancyAttacker.sol
contract ReentrancyAttacker {
    VulnerableVault vault;
    constructor(address _vault) { vault = VulnerableVault(_vault); }
    function attack() external payable {
        vault.deposit{value: msg.value}();
        vault.withdraw();
    }
    receive() external payable {
        if (address(vault).balance > 0) vault.withdraw(); // re-enter before balance update
    }
}
bash
forge test --match-contract ReentrancyAttacker -vvvv

Recording (chrono-vault)

The task packet's injected memory contract owns the exact call shape, sequence, and fields - see wirework-reflect. Do not copy a record(...) example or add fields (including source_task) from memory; the server binds them, and a baked example violates the run's authenticated schema. Memory is best-effort telemetry and never gates the work. What is worth recording here is the task-specific outcome: chain primitive, entry point, numbered steps, impact, preconditions, test file, reproduced?.

© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/chain-construct-smart-contract of mtarcure/claude-vibe-squad.

Open the folder on GitHubat commit 7bd69f8

Compare with similar skills

Chain Construct Smart Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Chain Construct Smart Contract compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Chain Construct Smart Contract this skillmtarcure/claude-vibe-squad163—~1.5kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMIT
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Safe Solana BuilderFrankcastleauditor/safe-solana-builder145—~3.6kAutomated safety check: PassNone
Wiremock TestOpenZeppelin/openzeppelin-relayer153—~1.6kAutomated safety check: NotesAGPL-3.0
Solana Token Extensionssolanabr/ai-kit108—~3.5kAutomated safety check: PassMIT

Similar skills

  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    574 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Safe Solana Builder

    Frankcastleauditor/safe-solana-builder

    A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.

    145 GitHub stars~3.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Wiremock Test

    OpenZeppelin/openzeppelin-relayer

    Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.

    153 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints.

    108 GitHub stars~3.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.

    113 GitHub stars~2.1k tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes

More from mtarcure/claude-vibe-squad

All 17 skills in this repo
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    163 GitHub stars~3.6k tokensUpdated 17 days ago
    Auto-check passed
  • Blind Rediscovery

    mtarcure/claude-vibe-squad

    Operational checklist + helper for blind-rediscovery fan-out work.

    163 GitHub stars~1.6k tokensUpdated 17 days ago
    Auto-check passed
  • Compact Now

    mtarcure/claude-vibe-squad

    Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…

    163 GitHub stars~1.6k tokensUpdated 17 days ago
    Auto-check passed
  • Agent Prompt Engineering

    mtarcure/claude-vibe-squad

    A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.

    163 GitHub stars~872 tokensUpdated 17 days ago
    Auto-check: warnings
  • Defi Invariant Check

    mtarcure/claude-vibe-squad

    A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

    163 GitHub stars~2.5k tokensUpdated 17 days ago
    Auto-check passed
  • Dependency Cycle Audit

    mtarcure/claude-vibe-squad

    A skill your agent uses when module, package, or build dependencies may contain cycles, especially load-order failures, broad rebuilds, or a planned extraction: derive the real graph, compute…

    163 GitHub stars~1.5k tokensUpdated 17 days ago
    Auto-check passed

Works with

Categories

Questions about Chain Construct Smart Contract

What does Chain Construct Smart Contract do?

A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…. Chain Construct Smart Contract is an agent skill from mtarcure/claude-vibe-squad. Use when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction sequence for an EVM reentrancy, flash-loan, delegatecall-overwrite, or proxy-upgrade primitive (or a Solana CPI-privilege, account-substitution, or overflow primitive) and reproduce it under Forge, LiteSVM, or Trident.

When should I use Chain Construct Smart Contract?

Chain Construct Smart Contract fits situations like: you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract; crafted instruction sequence for an EVM reentrancy; delegatecall-overwrite; proxy-upgrade primitive (or a Solana CPI-privilege.

How do I install Chain Construct Smart Contract in Claude Code?

Run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a claude-code`. Or copy the skill folder (.agents/skills/chain-construct-smart-contract in mtarcure/claude-vibe-squad) into .claude/skills/chain-construct-smart-contract in your project. Claude Code loads it when a task matches its description.

How do I install Chain Construct Smart Contract in Codex?

Run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a codex`. Or copy the skill folder (.agents/skills/chain-construct-smart-contract in mtarcure/claude-vibe-squad) into .agents/skills/chain-construct-smart-contract in your project. Codex loads it when a task matches its description.

Can I use Chain Construct Smart Contract in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill chain-construct-smart-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chain-construct-smart-contract, .gemini/skills/chain-construct-smart-contract, .github/skills/chain-construct-smart-contract and .opencode/skills/chain-construct-smart-contract in your project.

What does Chain Construct Smart Contract need to run?

Going by SKILL.md and its folder, Chain Construct Smart Contract needs the command-line tools its instructions call (cargo).

Does Chain Construct Smart Contract access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Chain Construct Smart Contract safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Chain Construct Smart Contract use?

Chain Construct Smart Contract is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Chain Construct Smart Contract use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Chain Construct Smart Contract?

Skills that share tags, products or a category with Chain Construct Smart Contract: Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Radar (Auditware/radar, 154 stars), Safe Solana Builder (Frankcastleauditor/safe-solana-builder, 145 stars) and Wiremock Test (OpenZeppelin/openzeppelin-relayer, 153 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Chain Construct Smart Contract?

mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 163 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.

Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.