Agent skill

Dos Griefing Analysis

by quillai-network in quillai-network/quillshield_skills

Detects Denial of Service and griefing vulnerabilities in smart contracts.

MITAuto-check passedBackend & APIs

Install Dos Griefing Analysis

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .claude/skills/dos-griefing-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dos-griefing-analysis
GitHub stars
130
Token cost
~3.3k tokens
SKILL.md length
476 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Detects Denial of Service and griefing vulnerabilities in smart contracts.

  • Auditing contracts with batch operations
  • SKILL.md covers When to Use, When NOT to Use, Seven DoS & Griefing… and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Loops over user data

What it does

Dos Griefing Analysis is an agent skill from quillai-network/quillshield_skills. Detects Denial of Service and griefing vulnerabilities in smart contracts. Covers unbounded loop DoS, block gas limit exhaustion, external call failure DoS, insufficient gas griefing (63/64 rule), storage bloat attacks, timestamp griefing, self-destruct force-feeding, and push vs pull payment pattern analysis. Use when auditing contracts with batch operations, loops over user data, reward distribution, dividend systems, or any logic that depends on address(this).balance or iterates over growing collections.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/dos-patterns.md` and `references/gas-griefing-vectors.md`).

It sits in Backend & APIs, covering Smart contracts and Smart contract auditing. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Auditing contracts with batch operations
  • Loops over user data
  • Reward distribution
  • Dividend systems

Example prompts

  • “Use the dos-griefing-analysis skill to detect Denial of Service and griefing vulnerabilities in smart contracts”
  • “/dos-griefing-analysis”

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dos Griefing Analysis loads about 3.3k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 134 tokens; SKILL.md has 476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 476 words, ~3,284 tokens.

Download SKILL.mdSave it as .claude/skills/dos-griefing-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
dos-griefing-analysis
description
Detects Denial of Service and griefing vulnerabilities in smart contracts. Covers unbounded loop DoS, block gas limit exhaustion, external call failure DoS, insufficient gas griefing (63/64 rule), storage bloat attacks, timestamp griefing, self-destruct force-feeding, and push vs pull payment pattern analysis. Use when auditing contracts with batch operations, loops over user data, reward distribution, dividend systems, or any logic that depends on address(this).balance or iterates over growing collections.

DoS & Griefing Analysis

Detect vulnerabilities that allow attackers to make contracts unusable (Denial of Service) or harm other users at low cost (griefing). These attacks don't steal funds directly but can permanently brick contracts or block critical operations.

When to Use

  • Auditing contracts with loops over dynamic arrays or mappings
  • Reviewing batch operations (airdrops, reward distribution, liquidation)
  • Analyzing contracts that rely on address(this).balance for logic
  • Verifying that individual user failures don't block system-wide operations
  • Checking for gas-based attack vectors (insufficient gas, storage bloat)

When NOT to Use

  • Direct fund theft analysis (use behavioral-state-analysis)
  • Access control consistency (use semantic-guard-analysis)
  • Reentrancy detection (use reentrancy-pattern-analysis)

Seven DoS & Griefing Vulnerability Classes

Class 1: Unbounded Loop DoS

Loops that iterate over collections that grow with contract usage. As the collection grows, gas cost increases until the function exceeds the block gas limit and becomes permanently uncallable.

solidity
// VULNERABLE: Loop over all users — grows forever
address[] public allUsers;

function distributeRewards() external {
    for (uint i = 0; i < allUsers.length; i++) {
        // If allUsers has 10,000+ entries, this exceeds block gas limit
        token.transfer(allUsers[i], calculateReward(allUsers[i]));
    }
}

// SAFE: Paginated processing
function distributeRewards(uint256 startIndex, uint256 batchSize) external {
    uint256 end = min(startIndex + batchSize, allUsers.length);
    for (uint i = startIndex; i < end; i++) {
        token.transfer(allUsers[i], calculateReward(allUsers[i]));
    }
}

// SAFER: Pull pattern
mapping(address => uint256) public pendingRewards;

function claimReward() external {
    uint256 reward = pendingRewards[msg.sender];
    pendingRewards[msg.sender] = 0;
    token.transfer(msg.sender, reward);
}

Detection:

For each loop in the contract:
  1. What determines the loop bound?
     - Fixed constant → SAFE
     - Constructor parameter → SAFE (if reasonable)
     - Dynamic array length → POTENTIALLY VULNERABLE
     - Mapping iteration → VULNERABLE (can't iterate mappings, but workaround arrays are vulnerable)
  2. Can the loop bound grow with contract usage?
  3. What is the gas cost per iteration?
  4. At what size does total gas exceed 30M? (block gas limit)

If loop_bound is unbounded AND gas_per_iteration > 30M / estimated_max_users:
  → UNBOUNDED LOOP DOS
Class 2: External Call Failure DoS

A single failed external call in a batch operation blocks all other operations.

solidity
// VULNERABLE: One blacklisted user blocks ALL distributions
function distributeToAll(address[] calldata users, uint256[] calldata amounts) external {
    for (uint i = 0; i < users.length; i++) {
        // If users[5] is USDC-blacklisted, this reverts for ALL users
        require(token.transfer(users[i], amounts[i]), "Transfer failed");
    }
}

// SAFE: Handle failures individually
function distributeToAll(address[] calldata users, uint256[] calldata amounts) external {
    for (uint i = 0; i < users.length; i++) {
        try IERC20(token).transfer(users[i], amounts[i]) returns (bool success) {
            if (!success) emit TransferFailed(users[i], amounts[i]);
        } catch {
            emit TransferFailed(users[i], amounts[i]);
        }
    }
}

Detection:

For each loop containing external calls:
  1. Does a failed call revert the entire transaction? (require/revert)
  2. Is there try/catch or success-check-and-skip?
  3. Can any single address/user cause the call to fail?
     - Blacklisted address
     - Contract that reverts in receive()
     - Address that runs out of gas
  If yes → EXTERNAL CALL FAILURE DOS
Class 3: Insufficient Gas Griefing (63/64 Rule)

EIP-150's 63/64 rule: when making an external call, only 63/64 of remaining gas is forwarded. An attacker can supply just enough gas for the outer function to succeed while the inner call fails.

solidity
// VULNERABLE: Relayer pattern without gas check
function executeMetaTx(address target, bytes calldata data) external {
    // Attacker (relayer) provides just enough gas for this function
    // but NOT enough for target.call(data) to succeed
    (bool success, ) = target.call(data);
    // success = false (ran out of gas), but function doesn't revert!

    // Mark meta-tx as executed even though it failed
    executedTxs[txHash] = true; // Meta-tx permanently "used" but never executed
}

// SAFE: Verify sufficient gas and check success
function executeMetaTx(address target, bytes calldata data, uint256 gasLimit) external {
    require(gasleft() >= gasLimit * 64 / 63 + 5000, "Insufficient gas");
    (bool success, ) = target.call{gas: gasLimit}(data);
    require(success, "Execution failed");
}

Detection:

For each function that makes external calls:
  1. Does the function check the success of the call?
  2. If success is not required, does failure cause permanent state changes?
  3. Is the function called by untrusted relayers?
  4. Is there a minimum gas check before the external call?

  If no success check AND permanent state change on failure:
    → INSUFFICIENT GAS GRIEFING
Class 4: Storage Bloat Attack

An attacker fills storage arrays/mappings to increase gas costs for other users.

solidity
// VULNERABLE: Anyone can add entries, increasing gas for iteration
mapping(address => address[]) public userTokens;

function addToken(address token) external {
    userTokens[msg.sender].push(token);
    // No limit on how many tokens a user can add
    // Functions that iterate userTokens[user] become expensive
}

function getUserValue(address user) external view returns (uint256) {
    uint256 total = 0;
    for (uint i = 0; i < userTokens[user].length; i++) {
        // Gas cost grows linearly with array size
        total += getTokenBalance(user, userTokens[user][i]);
    }
    return total;
}

Detection:

For each dynamic array or mapping that grows via public/external functions:
  1. Is there a size limit?
  2. Is there a cost to adding entries (economic deterrent)?
  3. Is the array iterated in any function?
  4. Can a non-owner add entries for other users?

  If unlimited growth AND iteration exists → STORAGE BLOAT DOS
Class 5: Timestamp Griefing

Attackers make minimal actions (e.g., 1 wei deposit) to reset timing mechanisms.

solidity
// VULNERABLE: Any deposit resets withdrawal timer
function deposit() external payable {
    balances[msg.sender] += msg.value;
    lastDepositTime[msg.sender] = block.timestamp; // Reset timer
}

function withdraw() external {
    require(block.timestamp >= lastDepositTime[msg.sender] + LOCK_PERIOD, "Locked");
    // Attacker deposits 1 wei to reset victim's lock period
    // (if deposit function can set lastDepositTime for another user)
    // Or griefs themselves by resetting their own lock with 1 wei deposits
}

Detection:

For each timestamp-dependent mechanism (locks, cooldowns, vesting):
  1. Can the timestamp be reset by a minimal-cost action?
  2. Can the reset action be performed by someone other than the affected user?
  3. Does the reset block a valuable operation (withdrawal, claim)?

  If minimal cost reset AND blocks valuable operation → TIMESTAMP GRIEFING
Class 6: Self-Destruct Force-Feeding

An attacker can force-send ETH to any contract via selfdestruct, bypassing receive/fallback functions. This breaks contracts that rely on address(this).balance for accounting.

solidity
// VULNERABLE: Relies on address(this).balance for logic
function isFullyFunded() public view returns (bool) {
    return address(this).balance >= targetAmount;
    // Attacker can selfdestruct another contract to force-send ETH
    // Prematurely triggering "fully funded" state
}

// VULNERABLE: Uses balance for invariant
function withdraw() external {
    require(address(this).balance == totalDeposits, "Balance mismatch");
    // Force-fed ETH breaks this equality — function permanently DOSed
}

// SAFE: Track deposits internally, don't rely on balance
uint256 public totalDeposits;

function isFullyFunded() public view returns (bool) {
    return totalDeposits >= targetAmount; // Uses internal tracking
}

Detection:

For each use of address(this).balance:
  1. Is it used in a strict equality check (==)?
     → CRITICAL: force-fed ETH breaks equality permanently
  2. Is it used as an accounting variable?
     → HIGH: force-fed ETH inflates perceived balance
  3. Is it used for informational purposes only?
     → LOW: no security impact

  Flag all strict equality checks on address(this).balance as CRITICAL DoS
Class 7: Block Stuffing

Attackers fill entire blocks with high-gas transactions to prevent time-sensitive operations from executing.

solidity
// VULNERABLE: Time-sensitive operation without extended window
function finalizeLiquidation(uint256 id) external {
    require(block.timestamp >= liquidations[id].deadline, "Not ready");
    require(block.timestamp <= liquidations[id].deadline + 1 hours, "Expired");
    // Attacker stuffs blocks for 1 hour to prevent finalization
}

// SAFE: Reasonable window or no upper bound
function finalizeLiquidation(uint256 id) external {
    require(block.timestamp >= liquidations[id].deadline, "Not ready");
    // No upper bound — can be finalized anytime after deadline
}

Workflow

Task Progress:
- [ ] Step 1: Find all loops and determine if bounds are dynamic/growing
- [ ] Step 2: Identify all batch operations with external calls
- [ ] Step 3: Check for insufficient gas griefing in relayer/meta-tx patterns
- [ ] Step 4: Find growing storage structures without size limits
- [ ] Step 5: Check for timestamp/cooldown reset griefing
- [ ] Step 6: Find all address(this).balance usage, especially equality checks
- [ ] Step 7: Identify time-sensitive operations vulnerable to block stuffing
- [ ] Step 8: Score findings and generate report

Output Format

markdown
## DoS & Griefing Analysis Report

### Finding: [Title]

**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Unbounded Loop | External Call DoS | Gas Griefing | Storage Bloat | Timestamp Grief | Force-Feed | Block Stuffing]
**Severity:** [CRITICAL | HIGH | MEDIUM]

**Issue:**
[Description of the DoS or griefing vulnerability]

**Growth Analysis:**
  Current users/entries: [N]
  Gas per iteration: [X gas]
  Block gas limit: 30,000,000
  Max iterations before DoS: [30M / X]
  Estimated time to DoS: [based on growth rate]

**Attack Scenario:**
1. [Step-by-step griefing or DoS attack]

**Cost to Attacker:** [gas cost, deposit required, etc.]
**Impact on Victims:** [permanent DoS, delayed operations, lost funds]

**Recommendation:**
[Pagination, pull pattern, size limits, internal accounting, etc.]
Show full SKILL.md (191 more words)Show less

Quick Detection Checklist

  • Do any loops iterate over arrays that grow with contract usage?
  • Do batch operations handle individual failures gracefully (try/catch)?
  • Do relayer/meta-tx functions verify gas sufficiency and call success?
  • Do growing storage structures have maximum size limits?
  • Can timing mechanisms (locks, cooldowns) be reset at minimal cost?
  • Does any logic use address(this).balance in a strict equality check?
  • Are time-sensitive operations given reasonable execution windows?
  • Do payment distributions use pull pattern instead of push?

For DoS pattern details, see {baseDir}/references/dos-patterns.md. For gas griefing vectors, see {baseDir}/references/gas-griefing-vectors.md.

Rationalizations to Reject

  • "The array will never get that large" → Growth is often exponential; what's 100 today is 10,000 next month
  • "Gas limits will increase" → Block gas limit increases are slow and unpredictable; don't depend on future changes
  • "Nobody would pay to stuff blocks" → Block stuffing cost is often less than the value of the operation being blocked
  • "The attacker gains nothing" → Griefing attacks are about harming others, not profiting; competitors and malicious actors exist
  • "We can always migrate" → Migration with locked funds or broken state is extremely difficult
  • "selfdestruct is being deprecated" → EIP-6780 limits selfdestruct but force-feeding is still possible during contract creation

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/dos-griefing-analysis/skills/dos-griefing-analysis of quillai-network/quillshield_skills.

  • SKILL.md
  • references/dos-patterns.md
  • references/gas-griefing-vectors.md

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

Dos Griefing Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dos Griefing Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dos Griefing Analysis this skillquillai-network/quillshield_skills130—~3.3kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk132—~4.3kAutomated safety check: PassApache-2.0
Stellar DevVelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • Stellar iOS Mac SDK

    Soneso/stellar-ios-mac-sdk

    Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.

    132 GitHub stars~4.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Stellar Dev

    VelaPayments/vela-payments

    End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

    131 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Audit

    austintgriffith/ethskills

    Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

    295 GitHub stars~829 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • External Call Safety

    quillai-network/quillshield_skills

    Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    130 GitHub stars~2.8k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    130 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Reentrancy Pattern Analysis

    quillai-network/quillshield_skills

    Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.

    130 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Dos Griefing Analysis

What does Dos Griefing Analysis do?

Detects Denial of Service and griefing vulnerabilities in smart contracts. Dos Griefing Analysis is an agent skill from quillai-network/quillshield_skills. Detects Denial of Service and griefing vulnerabilities in smart contracts.

When should I use Dos Griefing Analysis?

Dos Griefing Analysis fits situations like: auditing contracts with batch operations; loops over user data; reward distribution; dividend systems.

How do I install Dos Griefing Analysis in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a claude-code`. Or copy the skill folder (plugins/dos-griefing-analysis/skills/dos-griefing-analysis in quillai-network/quillshield_skills) into .claude/skills/dos-griefing-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Dos Griefing Analysis in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a codex`. Or copy the skill folder (plugins/dos-griefing-analysis/skills/dos-griefing-analysis in quillai-network/quillshield_skills) into .agents/skills/dos-griefing-analysis in your project. Codex loads it when a task matches its description.

Can I use Dos Griefing Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dos-griefing-analysis, .gemini/skills/dos-griefing-analysis, .github/skills/dos-griefing-analysis and .opencode/skills/dos-griefing-analysis in your project.

What does Dos Griefing Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Dos Griefing Analysis is instructions for the agent only.

Does Dos Griefing Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dos Griefing Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dos Griefing Analysis use?

Dos Griefing Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dos Griefing Analysis use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Dos Griefing Analysis?

Skills that share tags, products or a category with Dos Griefing Analysis: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 442 stars) and Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dos Griefing Analysis?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.