Fizz Convert
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
Detects input validation failures and arithmetic vulnerabilities in smart contracts.
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .claude/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .claude/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .agents/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .agents/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .cursor/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .cursor/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/quillai-network/quillshield_skills.git --path plugins/input-arithmetic-safety/skills/input-arithmetic-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .gemini/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .gemini/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .github/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .github/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .opencode/skills/input-arithmetic-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "input-arithmetic-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/input-arithmetic-safety/skills/input-arithmetic-safety into .opencode/skills/input-arithmetic-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "input-arithmetic-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
input-arithmetic-safetyDetects input validation failures and arithmetic vulnerabilities in smart contracts.
Input Arithmetic Safety is an agent skill from quillai-network/quillshield_skills. Detects input validation failures and arithmetic vulnerabilities in smart contracts. Covers missing zero-address and zero-amount checks, division-before-multiplication precision loss, rounding direction exploitation, ERC4626 vault share inflation attacks, unsafe integer casting, dust amount exploitation, and Solidity 0.8+ unchecked block edge cases. Use when auditing contracts with fee calculations, share pricing, exchange rates, unchecked blocks, or any public-facing functions that accept user input.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/precision-patterns.md` and `references/validation-checklist.md`).
It sits in Backend & APIs, covering Smart contracts, Penetration testing and Smart contract auditing. It works with Solidity. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.
Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Input Arithmetic Safety loads about 3.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 391 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 391 words, ~3,133 tokens.
.claude/skills/input-arithmetic-safety/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Detect input validation failures (the #1 direct exploitation cause at 34.6% of all contract exploits) and arithmetic vulnerabilities that persist even with Solidity 0.8+ checked math — precision loss, rounding exploitation, unsafe casting, and share price manipulation.
unchecked blocks for overflow/underflow risksZero Address Check:
// VULNERABLE: No zero address check
function setAdmin(address newAdmin) external onlyOwner {
admin = newAdmin; // Can set admin to address(0) — locking out admin forever
}
// SAFE
function setAdmin(address newAdmin) external onlyOwner {
require(newAdmin != address(0), "Zero address");
admin = newAdmin;
}Zero Amount Check:
// VULNERABLE: Allows zero-amount operations
function deposit(uint256 amount) external {
balances[msg.sender] += amount;
emit Deposit(msg.sender, amount);
// Zero deposit: wastes gas, pollutes events, may affect accounting
}
// SAFE
function deposit(uint256 amount) external {
require(amount > 0, "Zero amount");
balances[msg.sender] += amount;
}Array Length Validation:
// VULNERABLE: No length check
function batchTransfer(address[] calldata recipients, uint256[] calldata amounts) external {
for (uint i = 0; i < recipients.length; i++) {
transfer(recipients[i], amounts[i]); // Out-of-bounds if arrays differ in length
}
}
// SAFE
function batchTransfer(address[] calldata recipients, uint256[] calldata amounts) external {
require(recipients.length == amounts.length, "Length mismatch");
require(recipients.length <= MAX_BATCH_SIZE, "Batch too large");
// ...
}Bounds Checking:
// VULNERABLE: No upper bound on fee
function setFee(uint256 newFee) external onlyOwner {
fee = newFee; // Owner can set 100% fee, stealing all user funds
}
// SAFE
function setFee(uint256 newFee) external onlyOwner {
require(newFee <= MAX_FEE, "Fee too high"); // e.g., MAX_FEE = 1000 (10%)
fee = newFee;
}For each public/external function F:
For each parameter P:
1. Is P an address? → Check for require(P != address(0))
2. Is P an amount/value? → Check for require(P > 0) if zero is invalid
3. Is P an array? → Check for length validation and max size
4. Is P a percentage/rate? → Check for upper bound
5. Is P used as an index? → Check for bounds checking
6. Is P a deadline/timestamp? → Check for require(P > block.timestamp)
Flag any parameter without appropriate validation as:
- CRITICAL if parameter controls fund flow or access
- HIGH if parameter affects protocol state
- MEDIUM if parameter affects non-critical functionality// VULNERABLE: Division first truncates, then multiplication amplifies error
uint256 result = (amount / totalShares) * price;
// If amount = 100, totalShares = 3: 100/3 = 33 (truncated from 33.33)
// 33 * price = less than expected
// SAFE: Multiply first, then divide
uint256 result = (amount * price) / totalShares;
// 100 * price / 3 = more precise (only one truncation at the end)Detection:
For each arithmetic expression:
If division (/) appears BEFORE multiplication (*) in the same expression:
→ PRECISION LOSS: division-before-multiplication
Exception: If the division result is stored and intentionally used as a floored valueIn financial protocols, rounding direction determines who benefits:
Protocol-favorable rounding:
- Deposits: round DOWN shares (user gets fewer shares)
- Withdrawals: round DOWN assets (user gets fewer assets)
- Fees: round UP fee amount (protocol collects more)
User-favorable rounding (VULNERABLE to extraction):
- Deposits: round UP shares → user gets more than entitled
- Withdrawals: round UP assets → user extracts more than entitled
- Fees: round DOWN → protocol collects less// VULNERABLE: Rounds in user's favor on withdrawal
function withdraw(uint256 shares) external returns (uint256 assets) {
assets = (shares * totalAssets()) / totalSupply(); // Rounds DOWN — correct for withdrawal
// BUT if this rounds UP somehow (e.g., via ceiling division):
assets = (shares * totalAssets() + totalSupply() - 1) / totalSupply(); // Rounds UP — BAD
}
// SAFE: Use mulDiv with explicit rounding direction
assets = shares.mulDiv(totalAssets(), totalSupply(), Math.Rounding.Down); // For withdrawals
shares = assets.mulDiv(totalSupply(), totalAssets(), Math.Rounding.Up); // For deposits// Attack on first deposit
contract VulnerableVault is ERC4626 {
function totalAssets() public view returns (uint256) {
return asset.balanceOf(address(this)); // Manipulable via donation!
}
// No virtual shares offset
function _convertToShares(uint256 assets) internal view returns (uint256) {
uint256 supply = totalSupply();
return supply == 0 ? assets : assets.mulDiv(supply, totalAssets());
}
}Attack Sequence:
1. Vault is empty (totalSupply = 0, totalAssets = 0)
2. Attacker deposits 1 wei → receives 1 share
3. Attacker donates 1000 tokens directly to vault (not via deposit)
4. totalAssets = 1000e18 + 1, totalSupply = 1
5. Victim deposits 500 tokens:
shares = 500e18 * 1 / (1000e18 + 1) = 0 (rounds to zero!)
6. Victim gets ZERO shares, their 500 tokens are trapped
7. Attacker withdraws 1 share → gets all 1500+ tokensDetection:
For ERC4626 vaults:
1. Does totalAssets() use balanceOf(address(this))? → Donation-attackable
2. Is there a virtual shares/assets offset? → Missing = VULNERABLE
3. Is there a minimum first deposit? → Missing = VULNERABLE
4. Does the vault use OpenZeppelin's _decimalsOffset()? → Present = Mitigated// VULNERABLE: Silent truncation
uint256 largeValue = 2**200;
uint128 smallValue = uint128(largeValue); // Truncated! No revert in 0.8+
// VULNERABLE: Signed/unsigned confusion
int256 negative = -1;
uint256 converted = uint256(negative); // = type(uint256).max in 0.8+
// SAFE: Use SafeCast
uint128 smallValue = SafeCast.toUint128(largeValue); // Reverts if overflowDetection:
For each type cast operation:
If casting from larger to smaller type (e.g., uint256 → uint128):
Check if preceded by bounds validation
If no bounds check → UNSAFE CASTING
If casting between signed and unsigned:
Check if value can be negative
If possible → SIGN CONFUSION// Solidity 0.8+: checked math by default, but unchecked{} disables it
unchecked {
// VULNERABLE: Overflow/underflow silently wraps
uint256 result = a - b; // If b > a: wraps to huge number
uint256 sum = a + b; // If a + b > type(uint256).max: wraps to small number
}
// SAFE use of unchecked (when overflow is impossible):
unchecked {
++i; // In a bounded for loop — i cannot overflow uint256
}Detection:
For each unchecked block:
For each arithmetic operation inside:
1. Can the operation overflow/underflow?
2. Is there a pre-condition that guarantees safety?
3. If no guarantee → UNCHECKED OVERFLOW/UNDERFLOW risk
Common safe patterns (don't flag):
- Loop counter increment: unchecked { ++i; } in for loop with bounded length
- Post-require subtraction: require(a >= b); unchecked { a - b; }// VULNERABLE: Tiny amounts bypass fee logic
function swap(uint256 amountIn) external {
uint256 fee = amountIn * FEE_BPS / 10000;
// If amountIn = 1 and FEE_BPS = 30: fee = 30/10000 = 0
// Zero fee! Attacker makes many tiny swaps to avoid fees
uint256 amountOut = amountIn - fee;
}Detection:
For each fee/tax calculation:
If fee = amount * rate / denominator:
Can amount * rate < denominator? (making fee = 0)
If yes → DUST AMOUNT EXPLOITATION: zero-fee transactions possibleTask Progress:
- [ ] Step 1: Audit all public/external function parameters for missing validation
- [ ] Step 2: Find division-before-multiplication patterns
- [ ] Step 3: Verify rounding direction in share/price calculations (protocol-favorable)
- [ ] Step 4: Check ERC4626 vaults for inflation attack protection
- [ ] Step 5: Identify all type casting operations and verify bounds
- [ ] Step 6: Analyze all unchecked blocks for overflow/underflow risks
- [ ] Step 7: Check fee calculations for dust amount exploitation
- [ ] Step 8: Score findings and generate report## Input & Arithmetic Safety Report
### Finding: [Title]
**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Missing Validation | Precision Loss | Rounding | Inflation | Unsafe Cast | Unchecked | Dust]
**Severity:** [CRITICAL | HIGH | MEDIUM | LOW]
**Issue:**
[Description of the input validation or arithmetic vulnerability]
**Vulnerable Code:**
[Code snippet showing the issue]
**Exploit Scenario:**
1. [Step-by-step exploitation]
**Mathematical Proof:**
Input: [values]
Expected: [correct result]
Actual: [incorrect result due to precision/rounding]
Difference: [loss amount]
**Recommendation:**
[Specific fix — add validation, reorder operations, use SafeCast, add rounding]address(0)?> 0 where zero is invalid?unchecked blocks only used where overflow/underflow is mathematically impossible?For precision patterns, see {baseDir}/references/precision-patterns.md. For validation checklist, see {baseDir}/references/validation-checklist.md.
unchecked blocks exist; precision loss and rounding are NOT overflow© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/input-arithmetic-safety/skills/input-arithmetic-safety of quillai-network/quillshield_skills.
Open the folder on GitHubat commit 8bdd3c0
Input Arithmetic Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Input Arithmetic Safety this skillquillai-network/quillshield_skills | 129 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Smart Contract Auditgreatpie/smart-contract-audit-skill | 101 | — | ~1.1k | Automated safety check: Pass | None | |
| Solidity AuditorGabson0x/bountyforge | 443 | — | ~3.7k | Automated safety check: Pass | None | |
| Solidity Auditorpashov/skills | 1.2k | 1 repos | ~9.9k | Automated safety check: Pass | MIT | |
| Solidity Securitywshobson/agents | 40k | 12 repos | ~892 | Automated safety check: Pass | MIT |
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
pashov/skills
Security audit of Solidity code while you develop. An agent skill from pashov/skills.
wshobson/agents
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.
alt-research2/SolidityGuard
Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
quillai-network/quillshield_skills
Detects Denial of Service and griefing vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
quillai-network/quillshield_skills
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
quillai-network/quillshield_skills
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Works with
Categories
Detects input validation failures and arithmetic vulnerabilities in smart contracts. Input Arithmetic Safety is an agent skill from quillai-network/quillshield_skills. Detects input validation failures and arithmetic vulnerabilities in smart contracts.
Input Arithmetic Safety fits situations like: auditing contracts with fee calculations; unchecked blocks; any public-facing functions that accept user input.
Run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a claude-code`. Or copy the skill folder (plugins/input-arithmetic-safety/skills/input-arithmetic-safety in quillai-network/quillshield_skills) into .claude/skills/input-arithmetic-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a codex`. Or copy the skill folder (plugins/input-arithmetic-safety/skills/input-arithmetic-safety in quillai-network/quillshield_skills) into .agents/skills/input-arithmetic-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/input-arithmetic-safety, .gemini/skills/input-arithmetic-safety, .github/skills/input-arithmetic-safety and .opencode/skills/input-arithmetic-safety in your project.
SKILL.md names no scripts, command-line tools or credentials: Input Arithmetic Safety is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Input Arithmetic Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Input Arithmetic Safety: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 443 stars) and Solidity Auditor (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 129 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.
Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.