Fizz Convert
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
Detects Denial of Service and griefing vulnerabilities in smart contracts.
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .claude/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .claude/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .agents/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .agents/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .cursor/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .cursor/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/quillai-network/quillshield_skills.git --path plugins/dos-griefing-analysis/skills/dos-griefing-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .gemini/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .gemini/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .github/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .github/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install quillai-network/quillshield_skills dos-griefing-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dos-griefing-analysis/skills/dos-griefing-analysis .opencode/skills/dos-griefing-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dos-griefing-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/dos-griefing-analysis/skills/dos-griefing-analysis into .opencode/skills/dos-griefing-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dos-griefing-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dos-griefing-analysisDetects Denial of Service and griefing vulnerabilities in smart contracts.
Dos Griefing Analysis is an agent skill from quillai-network/quillshield_skills. Detects Denial of Service and griefing vulnerabilities in smart contracts. Covers unbounded loop DoS, block gas limit exhaustion, external call failure DoS, insufficient gas griefing (63/64 rule), storage bloat attacks, timestamp griefing, self-destruct force-feeding, and push vs pull payment pattern analysis. Use when auditing contracts with batch operations, loops over user data, reward distribution, dividend systems, or any logic that depends on address(this).balance or iterates over growing collections.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/dos-patterns.md` and `references/gas-griefing-vectors.md`).
It sits in Backend & APIs, covering Smart contracts and Smart contract auditing. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.
Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dos Griefing Analysis loads about 3.3k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 134 tokens; SKILL.md has 476 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 476 words, ~3,284 tokens.
.claude/skills/dos-griefing-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Detect vulnerabilities that allow attackers to make contracts unusable (Denial of Service) or harm other users at low cost (griefing). These attacks don't steal funds directly but can permanently brick contracts or block critical operations.
address(this).balance for logicLoops that iterate over collections that grow with contract usage. As the collection grows, gas cost increases until the function exceeds the block gas limit and becomes permanently uncallable.
// VULNERABLE: Loop over all users — grows forever
address[] public allUsers;
function distributeRewards() external {
for (uint i = 0; i < allUsers.length; i++) {
// If allUsers has 10,000+ entries, this exceeds block gas limit
token.transfer(allUsers[i], calculateReward(allUsers[i]));
}
}
// SAFE: Paginated processing
function distributeRewards(uint256 startIndex, uint256 batchSize) external {
uint256 end = min(startIndex + batchSize, allUsers.length);
for (uint i = startIndex; i < end; i++) {
token.transfer(allUsers[i], calculateReward(allUsers[i]));
}
}
// SAFER: Pull pattern
mapping(address => uint256) public pendingRewards;
function claimReward() external {
uint256 reward = pendingRewards[msg.sender];
pendingRewards[msg.sender] = 0;
token.transfer(msg.sender, reward);
}Detection:
For each loop in the contract:
1. What determines the loop bound?
- Fixed constant → SAFE
- Constructor parameter → SAFE (if reasonable)
- Dynamic array length → POTENTIALLY VULNERABLE
- Mapping iteration → VULNERABLE (can't iterate mappings, but workaround arrays are vulnerable)
2. Can the loop bound grow with contract usage?
3. What is the gas cost per iteration?
4. At what size does total gas exceed 30M? (block gas limit)
If loop_bound is unbounded AND gas_per_iteration > 30M / estimated_max_users:
→ UNBOUNDED LOOP DOSA single failed external call in a batch operation blocks all other operations.
// VULNERABLE: One blacklisted user blocks ALL distributions
function distributeToAll(address[] calldata users, uint256[] calldata amounts) external {
for (uint i = 0; i < users.length; i++) {
// If users[5] is USDC-blacklisted, this reverts for ALL users
require(token.transfer(users[i], amounts[i]), "Transfer failed");
}
}
// SAFE: Handle failures individually
function distributeToAll(address[] calldata users, uint256[] calldata amounts) external {
for (uint i = 0; i < users.length; i++) {
try IERC20(token).transfer(users[i], amounts[i]) returns (bool success) {
if (!success) emit TransferFailed(users[i], amounts[i]);
} catch {
emit TransferFailed(users[i], amounts[i]);
}
}
}Detection:
For each loop containing external calls:
1. Does a failed call revert the entire transaction? (require/revert)
2. Is there try/catch or success-check-and-skip?
3. Can any single address/user cause the call to fail?
- Blacklisted address
- Contract that reverts in receive()
- Address that runs out of gas
If yes → EXTERNAL CALL FAILURE DOSEIP-150's 63/64 rule: when making an external call, only 63/64 of remaining gas is forwarded. An attacker can supply just enough gas for the outer function to succeed while the inner call fails.
// VULNERABLE: Relayer pattern without gas check
function executeMetaTx(address target, bytes calldata data) external {
// Attacker (relayer) provides just enough gas for this function
// but NOT enough for target.call(data) to succeed
(bool success, ) = target.call(data);
// success = false (ran out of gas), but function doesn't revert!
// Mark meta-tx as executed even though it failed
executedTxs[txHash] = true; // Meta-tx permanently "used" but never executed
}
// SAFE: Verify sufficient gas and check success
function executeMetaTx(address target, bytes calldata data, uint256 gasLimit) external {
require(gasleft() >= gasLimit * 64 / 63 + 5000, "Insufficient gas");
(bool success, ) = target.call{gas: gasLimit}(data);
require(success, "Execution failed");
}Detection:
For each function that makes external calls:
1. Does the function check the success of the call?
2. If success is not required, does failure cause permanent state changes?
3. Is the function called by untrusted relayers?
4. Is there a minimum gas check before the external call?
If no success check AND permanent state change on failure:
→ INSUFFICIENT GAS GRIEFINGAn attacker fills storage arrays/mappings to increase gas costs for other users.
// VULNERABLE: Anyone can add entries, increasing gas for iteration
mapping(address => address[]) public userTokens;
function addToken(address token) external {
userTokens[msg.sender].push(token);
// No limit on how many tokens a user can add
// Functions that iterate userTokens[user] become expensive
}
function getUserValue(address user) external view returns (uint256) {
uint256 total = 0;
for (uint i = 0; i < userTokens[user].length; i++) {
// Gas cost grows linearly with array size
total += getTokenBalance(user, userTokens[user][i]);
}
return total;
}Detection:
For each dynamic array or mapping that grows via public/external functions:
1. Is there a size limit?
2. Is there a cost to adding entries (economic deterrent)?
3. Is the array iterated in any function?
4. Can a non-owner add entries for other users?
If unlimited growth AND iteration exists → STORAGE BLOAT DOSAttackers make minimal actions (e.g., 1 wei deposit) to reset timing mechanisms.
// VULNERABLE: Any deposit resets withdrawal timer
function deposit() external payable {
balances[msg.sender] += msg.value;
lastDepositTime[msg.sender] = block.timestamp; // Reset timer
}
function withdraw() external {
require(block.timestamp >= lastDepositTime[msg.sender] + LOCK_PERIOD, "Locked");
// Attacker deposits 1 wei to reset victim's lock period
// (if deposit function can set lastDepositTime for another user)
// Or griefs themselves by resetting their own lock with 1 wei deposits
}Detection:
For each timestamp-dependent mechanism (locks, cooldowns, vesting):
1. Can the timestamp be reset by a minimal-cost action?
2. Can the reset action be performed by someone other than the affected user?
3. Does the reset block a valuable operation (withdrawal, claim)?
If minimal cost reset AND blocks valuable operation → TIMESTAMP GRIEFINGAn attacker can force-send ETH to any contract via selfdestruct, bypassing receive/fallback functions. This breaks contracts that rely on address(this).balance for accounting.
// VULNERABLE: Relies on address(this).balance for logic
function isFullyFunded() public view returns (bool) {
return address(this).balance >= targetAmount;
// Attacker can selfdestruct another contract to force-send ETH
// Prematurely triggering "fully funded" state
}
// VULNERABLE: Uses balance for invariant
function withdraw() external {
require(address(this).balance == totalDeposits, "Balance mismatch");
// Force-fed ETH breaks this equality — function permanently DOSed
}
// SAFE: Track deposits internally, don't rely on balance
uint256 public totalDeposits;
function isFullyFunded() public view returns (bool) {
return totalDeposits >= targetAmount; // Uses internal tracking
}Detection:
For each use of address(this).balance:
1. Is it used in a strict equality check (==)?
→ CRITICAL: force-fed ETH breaks equality permanently
2. Is it used as an accounting variable?
→ HIGH: force-fed ETH inflates perceived balance
3. Is it used for informational purposes only?
→ LOW: no security impact
Flag all strict equality checks on address(this).balance as CRITICAL DoSAttackers fill entire blocks with high-gas transactions to prevent time-sensitive operations from executing.
// VULNERABLE: Time-sensitive operation without extended window
function finalizeLiquidation(uint256 id) external {
require(block.timestamp >= liquidations[id].deadline, "Not ready");
require(block.timestamp <= liquidations[id].deadline + 1 hours, "Expired");
// Attacker stuffs blocks for 1 hour to prevent finalization
}
// SAFE: Reasonable window or no upper bound
function finalizeLiquidation(uint256 id) external {
require(block.timestamp >= liquidations[id].deadline, "Not ready");
// No upper bound — can be finalized anytime after deadline
}Task Progress:
- [ ] Step 1: Find all loops and determine if bounds are dynamic/growing
- [ ] Step 2: Identify all batch operations with external calls
- [ ] Step 3: Check for insufficient gas griefing in relayer/meta-tx patterns
- [ ] Step 4: Find growing storage structures without size limits
- [ ] Step 5: Check for timestamp/cooldown reset griefing
- [ ] Step 6: Find all address(this).balance usage, especially equality checks
- [ ] Step 7: Identify time-sensitive operations vulnerable to block stuffing
- [ ] Step 8: Score findings and generate report## DoS & Griefing Analysis Report
### Finding: [Title]
**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Unbounded Loop | External Call DoS | Gas Griefing | Storage Bloat | Timestamp Grief | Force-Feed | Block Stuffing]
**Severity:** [CRITICAL | HIGH | MEDIUM]
**Issue:**
[Description of the DoS or griefing vulnerability]
**Growth Analysis:**
Current users/entries: [N]
Gas per iteration: [X gas]
Block gas limit: 30,000,000
Max iterations before DoS: [30M / X]
Estimated time to DoS: [based on growth rate]
**Attack Scenario:**
1. [Step-by-step griefing or DoS attack]
**Cost to Attacker:** [gas cost, deposit required, etc.]
**Impact on Victims:** [permanent DoS, delayed operations, lost funds]
**Recommendation:**
[Pagination, pull pattern, size limits, internal accounting, etc.]address(this).balance in a strict equality check?For DoS pattern details, see {baseDir}/references/dos-patterns.md. For gas griefing vectors, see {baseDir}/references/gas-griefing-vectors.md.
© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/dos-griefing-analysis/skills/dos-griefing-analysis of quillai-network/quillshield_skills.
Open the folder on GitHubat commit 8bdd3c0
Dos Griefing Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dos Griefing Analysis this skillquillai-network/quillshield_skills | 130 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Smart Contract Auditgreatpie/smart-contract-audit-skill | 101 | — | ~1.1k | Automated safety check: Pass | None | |
| Solidity AuditorGabson0x/bountyforge | 442 | — | ~3.7k | Automated safety check: Pass | None | |
| Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk | 132 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Stellar DevVelaPayments/vela-payments | 131 | — | ~1.8k | Automated safety check: Pass | MIT |
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
Soneso/stellar-ios-mac-sdk
Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.
VelaPayments/vela-payments
End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.
austintgriffith/ethskills
Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
quillai-network/quillshield_skills
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects input validation failures and arithmetic vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
quillai-network/quillshield_skills
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
quillai-network/quillshield_skills
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Categories
Detects Denial of Service and griefing vulnerabilities in smart contracts. Dos Griefing Analysis is an agent skill from quillai-network/quillshield_skills. Detects Denial of Service and griefing vulnerabilities in smart contracts.
Dos Griefing Analysis fits situations like: auditing contracts with batch operations; loops over user data; reward distribution; dividend systems.
Run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a claude-code`. Or copy the skill folder (plugins/dos-griefing-analysis/skills/dos-griefing-analysis in quillai-network/quillshield_skills) into .claude/skills/dos-griefing-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a codex`. Or copy the skill folder (plugins/dos-griefing-analysis/skills/dos-griefing-analysis in quillai-network/quillshield_skills) into .agents/skills/dos-griefing-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill dos-griefing-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dos-griefing-analysis, .gemini/skills/dos-griefing-analysis, .github/skills/dos-griefing-analysis and .opencode/skills/dos-griefing-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Dos Griefing Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dos Griefing Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dos Griefing Analysis: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 442 stars) and Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.
Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.