Blue-team release-gate analysis for smart contract deployment and upgrade readiness.

MITAuto-check: notesDevOps & Cloud

Install Defender

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill defender -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills defender --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/defender/skills/defender .claude/skills/defender && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender
GitHub stars
130
Token cost
~1.7k tokens
SKILL.md length
683 words
Files
23 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Blue-team release-gate analysis for smart contract deployment and upgrade readiness.

  • Works in 5 steps: Project classification → Defence pass → False confidence → …
  • Tasks that involve Smart contracts
  • SKILL.md covers Use when, Non-goals, Core rule and Execution order (STRICT), plus 12 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender is an agent skill from quillai-network/quillshield_skills. Blue-team release-gate analysis for smart contract deployment and upgrade readiness. Classifies repositories, checks deploy/upgrade execution paths, CI/CD trust boundaries, config drift, secrets/signer operational security, and outputs evidence-backed release verdicts.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including reference files (for example `references/case-study-mapping.md`, `references/ci-supply-chain.md` and `references/compensating-controls.md`).

It sits in DevOps & Cloud, covering Smart contracts, CI/CD and Security operations. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Tasks that involve Smart contracts
  • Tasks that involve CI/CD
  • Tasks that involve Security operations

Example prompts

  • “/defender”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Project classification
  2. Defence pass
  3. False confidence
  4. Severity
  5. Verdict

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender loads about 1.7k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 683 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:141
    - `.env` usage for private keys
  • NoteMentions a .env fileSKILL.md:153
    Plaintext `.env` private keys are discouraged.
  • NoteMentions a .env fileSKILL.md:161
    - `.env` for non-sensitive config → acceptable

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 683 words, ~1,720 tokens.

Download SKILL.mdSave it as .claude/skills/defender/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.
name
defender
description
Blue-team release-gate analysis for smart contract deployment and upgrade readiness. Classifies repositories, checks deploy/upgrade execution paths, CI/CD trust boundaries, config drift, secrets/signer operational security, and outputs evidence-backed release verdicts.

Defender

A blue-team release-gate skill for smart contract systems.

Defender determines whether a repository is safe to deploy or upgrade. It focuses on release execution risk, not exploit discovery.

Use when

  • deploying smart contracts
  • preparing upgrades
  • reviewing deploy scripts
  • hardening CI/CD
  • rotating admin roles
  • validating ownership handoff
  • enforcing release hygiene

Non-goals

Defender does NOT replace:

  • full security audits
  • economic analysis
  • invariant discovery
  • deep proxy vulnerability analysis (proxy-upgrade-safety)

It focuses only on execution safety of release.


Core rule

Evidence first.

Only report findings from:

  • contracts
  • deploy scripts
  • CI workflows
  • dependency manifests
  • configs / address books
  • tests / fork scripts
  • docs / runbooks

Separate:

  • Detection → what repo proves
  • Policy → what should be enforced

Execution order (STRICT)

  1. Project classification
  2. Defence pass
  3. Severity scoring
  4. Release verdict

Reference packs

Always load:

  • references/finding-catalog.md
  • references/severity-model.md
  • references/evidence-query-playbook.md

Load contextually:

  • classification → project-classification.md
  • CI → ci-supply-chain.md
  • deploy drift → config-drift-checks.md
  • upgrade → upgrade-readiness.md
  • signer → signer-opsec.md
  • false confidence → false-confidence.md
  • post-deploy → post-deploy-validation.md

Templates:

  • defender-report-template.md
  • checklist templates as needed

Phase 1 — Project classification

Framework

Detect:

  • Foundry / Hardhat / hybrid / other

Evidence:

  • foundry.toml, hardhat.config.*, scripts
Language
  • Solidity / Vyper / Cairo / mixed
Upgradeability
  • upgradeable / immutable / mixed

Evidence:

  • OZ upgrade imports
  • proxies
  • initializer usage
Protocol type

Infer:

  • token / vault / AMM / lending / bridge / governance / NFT / staking / other
Deployment surface
  • manual / script / CI / multisig / upgrade-task
CI surface
  • GitHub Actions / GitLab / other / none

Output classification block.


Phase 2 — Defence pass

A. Build integrity

Check:

  • compiler version pinned
  • optimizer pinned
  • evmVersion consistency
  • lockfiles committed
  • no conflicting configs (Foundry vs Hardhat)
  • artifacts reproducible from repo
  • verification metadata aligned

Escalate if:

  • build settings differ from verification
  • configs produce ambiguous outputs

B. Dependencies, secrets, supply chain

Check:

  • committed secrets
  • .env usage for private keys
  • floating versions
  • unpinned git deps
  • install scripts
  • dependency confusion risk
  • abandoned/suspicious packages
  • OZ version mismatch
  • unsafe sidecar tooling
  • unverified binaries
Secret policy

Plaintext .env private keys are discouraged.

Preferred:

  • Foundry keystore-backed accounts

Classify:

  • private key in repo → BLOCKER/HIGH
  • deploy scripts using plaintext env keys → HIGH
  • .env for non-sensitive config → acceptable

C. CI/CD trust

Check:

  • unpinned GitHub Actions
  • secrets in untrusted workflows
  • deploys from weak branches
  • no approval gate
  • excessive secret access
  • curl/bash installs
  • unsafe runners
  • mixed trust zones

Escalate if CI can deploy unsafely.


D. Deployment config drift

CRITICAL

Check:

  • chain ID matches target
  • RPC matches chain
  • deployer is correct
  • constructor/initializer args final
  • addresses (oracle/token/admin) valid for chain
  • no test/stale addresses
  • decimals correct
  • verifier settings pinned
  • no silent fallback logic
Foundry FFI
  • default: HIGH
  • BLOCKER if affecting deploy logic/secrets

Show full SKILL.md (287 more words)Show less

E. Deploy-script safety

Check:

  • chain assertions
  • deployer assertions
  • env validation
  • correct initialization order
  • idempotency assumptions clear
  • no test config reuse
  • address outputs reviewable
  • no opaque branching
  • verification steps present

Escalate if scripts can silently misdeploy.


F. Upgrade readiness (if applicable)

Check:

  • implementation initialized or locked
  • initializer calldata reviewed
  • storage diff reviewed
  • proxy admin correct
  • multisig/timelock path exists
  • pause/rollback defined
  • fork rehearsal exists

G. Signer & admin opsec

Check:

  • deployer is dedicated
  • secure signer preferred
  • admin is multisig
  • roles separated:
    • deployer / upgrader / pauser / treasury
  • emergency roles documented
  • no hot wallet admin unless justified
  • tx review process exists

H. Address & role mapping

Extract:

  • owner/admin
  • proxy admin
  • upgrader
  • pauser
  • treasury
  • oracle
  • keeper
  • timelock

Flag:

  • role concentration
  • EOA-only control
  • zero addresses
  • missing transfer flow

I. Fork rehearsal

Require evidence of:

  • deploy scripts tested
  • initializer tested
  • role transfers tested
  • upgrade tested
  • verification tested
  • smoke tests run

Absence → HIGH (mainnet)


J. Post-deploy readiness

Check defined plan for:

  • verification
  • ownership assertions
  • pause test
  • oracle checks
  • event expectations
  • integration smoke tests
  • monitoring
  • deployment manifest

K. Unsafe deploy ergonomics

Check:

  • one-command broadcast risk
  • missing confirmations
  • hidden env defaults
  • CREATE/CREATE2 assumptions undocumented
  • nonce-sensitive flows undocumented

Phase 3 — False confidence

MANDATORY

Passing does NOT imply safety:

  • unit tests
  • forge test
  • static analysis
  • lint
  • typecheck

Require:

  • fork rehearsal
  • permission diff
  • storage diff
  • address diff
  • event checks
  • role snapshot
  • post-deploy smoke tests

Phase 4 — Severity

BLOCKER
  • wrong chain
  • lost admin
  • leaked secrets
  • broken init
  • broken upgrade
  • unverifiable deployment
HIGH
  • unsafe CI
  • missing rehearsal
  • FFI misuse
  • admin EOA risk
  • stale config
MEDIUM
  • should fix before mainnet
LOW
  • hygiene gaps

Specify scope:

  • mainnet-only / all releases / upgrades only

Phase 5 — Verdict

Always output:

  • VERDICT: BLOCK DEPLOY
  • VERDICT: PROCEED WITH RISK
  • VERDICT: READY FOR STAGED RELEASE

Include:

  • top blockers
  • required actions
  • evidence reviewed

Output format

text
DEFENDER REPORT

1. Project Classification
- Framework:
- Language:
- Upgradeability:
- Protocol Type:
- Deployment Surface:
- CI Surface:

2. Release Findings

BLOCKER:
- ...

HIGH:
- ...

MEDIUM:
- ...

LOW:
- ...

3. False Confidence Warnings
- ...

4. Release Verdict

VERDICT: ...

Top blockers:
- ...

Required actions:
- ...

Evidence reviewed:
- ...

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 22 other files (references) in plugins/defender/skills/defender of quillai-network/quillshield_skills.

  • SKILL.md
  • references/case-study-mapping.md
  • references/ci-supply-chain.md
  • references/compensating-controls.md
  • references/config-drift-checks.md
  • references/evidence-query-playbook.md
  • references/false-confidence.md
  • references/finding-catalog.md
  • references/good-vs-bad-snippets.md
  • references/post-deploy-validation.md
  • references/project-classification.md
  • references/severity-model.md
  • references/signer-opsec.md
  • references/upgrade-readiness.md
  • templates/defender-report-block-deploy-example.md
  • templates/defender-report-proceed-with-risk-example.md
  • templates/defender-report-ready-for-staged-release-example.md
  • templates/defender-report-template.md
  • templates/incident-response-checklist.md
  • … and 4 more

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

Defender next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender this skillquillai-network/quillshield_skills130—~1.7kAutomated safety check: NotesMIT
Protocol Deploymentsablier-labs/evm-monorepo353—~3.8kAutomated safety check: NotesCustom licence
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Frontmcp Deploymentagentfront/frontmcp146—~9.2kAutomated safety check: NotesApache-2.0
Canary Tripwire Responsedeonmenezes/mantishack504—~376Automated safety check: PassApache-2.0

Similar skills

  • Protocol Deployment

    sablier-labs/evm-monorepo

    Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~3.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Frontmcp Deployment

    agentfront/frontmcp

    A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.

    146 GitHub stars~9.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    504 GitHub stars~376 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Atmos CI

    cloudposse/atmos

    Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

    1.4k GitHub stars~4.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dos Griefing Analysis

    quillai-network/quillshield_skills

    Detects Denial of Service and griefing vulnerabilities in smart contracts.

    130 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed
  • External Call Safety

    quillai-network/quillshield_skills

    Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    130 GitHub stars~2.8k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    130 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Defender

What does Defender do?

Blue-team release-gate analysis for smart contract deployment and upgrade readiness. Defender is an agent skill from quillai-network/quillshield_skills. Blue-team release-gate analysis for smart contract deployment and upgrade readiness.

When should I use Defender?

Defender fits situations like: tasks that involve Smart contracts; tasks that involve CI/CD; tasks that involve Security operations.

How do I install Defender in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill defender -a claude-code`. Or copy the skill folder (plugins/defender/skills/defender in quillai-network/quillshield_skills) into .claude/skills/defender in your project. Claude Code loads it when a task matches its description.

How do I install Defender in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill defender -a codex`. Or copy the skill folder (plugins/defender/skills/defender in quillai-network/quillshield_skills) into .agents/skills/defender in your project. Codex loads it when a task matches its description.

Can I use Defender in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill defender -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender, .gemini/skills/defender, .github/skills/defender and .opencode/skills/defender in your project.

What does Defender need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender is instructions for the agent only.

Does Defender access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Defender safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Defender use?

Defender is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.4k tokens, read only when the agent opens those files.

What are the alternatives to Defender?

Skills that share tags, products or a category with Defender: Protocol Deployment (sablier-labs/evm-monorepo, 353 stars), APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars) and Frontmcp Deployment (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.