Agent skill

Input Arithmetic Safety

by quillai-network in quillai-network/quillshield_skills

Detects input validation failures and arithmetic vulnerabilities in smart contracts.

MITAuto-check passedBackend & APIs

Install Input Arithmetic Safety

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills input-arithmetic-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/input-arithmetic-safety/skills/input-arithmetic-safety .claude/skills/input-arithmetic-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
input-arithmetic-safety
GitHub stars
129
Token cost
~3.1k tokens
SKILL.md length
391 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Detects input validation failures and arithmetic vulnerabilities in smart contracts.

  • Auditing contracts with fee calculations
  • SKILL.md covers When to Use, When NOT to Use, Part 1: Input Validation… and Part 2: Arithmetic…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Unchecked blocks

What it does

Input Arithmetic Safety is an agent skill from quillai-network/quillshield_skills. Detects input validation failures and arithmetic vulnerabilities in smart contracts. Covers missing zero-address and zero-amount checks, division-before-multiplication precision loss, rounding direction exploitation, ERC4626 vault share inflation attacks, unsafe integer casting, dust amount exploitation, and Solidity 0.8+ unchecked block edge cases. Use when auditing contracts with fee calculations, share pricing, exchange rates, unchecked blocks, or any public-facing functions that accept user input.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/precision-patterns.md` and `references/validation-checklist.md`).

It sits in Backend & APIs, covering Smart contracts, Penetration testing and Smart contract auditing. It works with Solidity. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Auditing contracts with fee calculations
  • Unchecked blocks
  • Any public-facing functions that accept user input

Example prompts

  • “Use the input-arithmetic-safety skill to detect input validation failures and arithmetic vulnerabilities in smart contracts”
  • “/input-arithmetic-safety”

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Input Arithmetic Safety loads about 3.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 391 words, ~3,133 tokens.

Download SKILL.mdSave it as .claude/skills/input-arithmetic-safety/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
input-arithmetic-safety
description
Detects input validation failures and arithmetic vulnerabilities in smart contracts. Covers missing zero-address and zero-amount checks, division-before-multiplication precision loss, rounding direction exploitation, ERC4626 vault share inflation attacks, unsafe integer casting, dust amount exploitation, and Solidity 0.8+ unchecked block edge cases. Use when auditing contracts with fee calculations, share pricing, exchange rates, unchecked blocks, or any public-facing functions that accept user input.

Input & Arithmetic Safety

Detect input validation failures (the #1 direct exploitation cause at 34.6% of all contract exploits) and arithmetic vulnerabilities that persist even with Solidity 0.8+ checked math — precision loss, rounding exploitation, unsafe casting, and share price manipulation.

When to Use

  • Auditing any contract with public/external functions accepting user-supplied parameters
  • Reviewing DeFi protocols with fee calculations, share pricing, or exchange rates
  • Analyzing vault/staking contracts for rounding or first-depositor attacks
  • Checking contracts with unchecked blocks for overflow/underflow risks
  • Verifying arithmetic in token minting, burning, and distribution logic

When NOT to Use

  • Access control analysis (use semantic-guard-analysis)
  • Reentrancy detection (use reentrancy-pattern-analysis)
  • Full multi-dimensional audit (use behavioral-state-analysis)

Part 1: Input Validation Analysis

Critical Missing Validations

Zero Address Check:

solidity
// VULNERABLE: No zero address check
function setAdmin(address newAdmin) external onlyOwner {
    admin = newAdmin; // Can set admin to address(0) — locking out admin forever
}

// SAFE
function setAdmin(address newAdmin) external onlyOwner {
    require(newAdmin != address(0), "Zero address");
    admin = newAdmin;
}

Zero Amount Check:

solidity
// VULNERABLE: Allows zero-amount operations
function deposit(uint256 amount) external {
    balances[msg.sender] += amount;
    emit Deposit(msg.sender, amount);
    // Zero deposit: wastes gas, pollutes events, may affect accounting
}

// SAFE
function deposit(uint256 amount) external {
    require(amount > 0, "Zero amount");
    balances[msg.sender] += amount;
}

Array Length Validation:

solidity
// VULNERABLE: No length check
function batchTransfer(address[] calldata recipients, uint256[] calldata amounts) external {
    for (uint i = 0; i < recipients.length; i++) {
        transfer(recipients[i], amounts[i]); // Out-of-bounds if arrays differ in length
    }
}

// SAFE
function batchTransfer(address[] calldata recipients, uint256[] calldata amounts) external {
    require(recipients.length == amounts.length, "Length mismatch");
    require(recipients.length <= MAX_BATCH_SIZE, "Batch too large");
    // ...
}

Bounds Checking:

solidity
// VULNERABLE: No upper bound on fee
function setFee(uint256 newFee) external onlyOwner {
    fee = newFee; // Owner can set 100% fee, stealing all user funds
}

// SAFE
function setFee(uint256 newFee) external onlyOwner {
    require(newFee <= MAX_FEE, "Fee too high"); // e.g., MAX_FEE = 1000 (10%)
    fee = newFee;
}
Input Validation Detection Algorithm
For each public/external function F:
  For each parameter P:
    1. Is P an address? → Check for require(P != address(0))
    2. Is P an amount/value? → Check for require(P > 0) if zero is invalid
    3. Is P an array? → Check for length validation and max size
    4. Is P a percentage/rate? → Check for upper bound
    5. Is P used as an index? → Check for bounds checking
    6. Is P a deadline/timestamp? → Check for require(P > block.timestamp)

  Flag any parameter without appropriate validation as:
    - CRITICAL if parameter controls fund flow or access
    - HIGH if parameter affects protocol state
    - MEDIUM if parameter affects non-critical functionality

Part 2: Arithmetic Vulnerability Analysis

Pattern 1: Division-Before-Multiplication (Precision Loss)
solidity
// VULNERABLE: Division first truncates, then multiplication amplifies error
uint256 result = (amount / totalShares) * price;
// If amount = 100, totalShares = 3: 100/3 = 33 (truncated from 33.33)
// 33 * price = less than expected

// SAFE: Multiply first, then divide
uint256 result = (amount * price) / totalShares;
// 100 * price / 3 = more precise (only one truncation at the end)

Detection:

For each arithmetic expression:
  If division (/) appears BEFORE multiplication (*) in the same expression:
    → PRECISION LOSS: division-before-multiplication
  Exception: If the division result is stored and intentionally used as a floored value
Pattern 2: Rounding Direction Exploitation

In financial protocols, rounding direction determines who benefits:

Protocol-favorable rounding:
  - Deposits: round DOWN shares (user gets fewer shares)
  - Withdrawals: round DOWN assets (user gets fewer assets)
  - Fees: round UP fee amount (protocol collects more)

User-favorable rounding (VULNERABLE to extraction):
  - Deposits: round UP shares → user gets more than entitled
  - Withdrawals: round UP assets → user extracts more than entitled
  - Fees: round DOWN → protocol collects less
solidity
// VULNERABLE: Rounds in user's favor on withdrawal
function withdraw(uint256 shares) external returns (uint256 assets) {
    assets = (shares * totalAssets()) / totalSupply(); // Rounds DOWN — correct for withdrawal
    // BUT if this rounds UP somehow (e.g., via ceiling division):
    assets = (shares * totalAssets() + totalSupply() - 1) / totalSupply(); // Rounds UP — BAD
}

// SAFE: Use mulDiv with explicit rounding direction
assets = shares.mulDiv(totalAssets(), totalSupply(), Math.Rounding.Down); // For withdrawals
shares = assets.mulDiv(totalSupply(), totalAssets(), Math.Rounding.Up);   // For deposits
Pattern 3: ERC4626 Vault Share Inflation Attack
solidity
// Attack on first deposit
contract VulnerableVault is ERC4626 {
    function totalAssets() public view returns (uint256) {
        return asset.balanceOf(address(this)); // Manipulable via donation!
    }

    // No virtual shares offset
    function _convertToShares(uint256 assets) internal view returns (uint256) {
        uint256 supply = totalSupply();
        return supply == 0 ? assets : assets.mulDiv(supply, totalAssets());
    }
}

Attack Sequence:

1. Vault is empty (totalSupply = 0, totalAssets = 0)
2. Attacker deposits 1 wei → receives 1 share
3. Attacker donates 1000 tokens directly to vault (not via deposit)
4. totalAssets = 1000e18 + 1, totalSupply = 1
5. Victim deposits 500 tokens:
   shares = 500e18 * 1 / (1000e18 + 1) = 0 (rounds to zero!)
6. Victim gets ZERO shares, their 500 tokens are trapped
7. Attacker withdraws 1 share → gets all 1500+ tokens

Detection:

For ERC4626 vaults:
  1. Does totalAssets() use balanceOf(address(this))? → Donation-attackable
  2. Is there a virtual shares/assets offset? → Missing = VULNERABLE
  3. Is there a minimum first deposit? → Missing = VULNERABLE
  4. Does the vault use OpenZeppelin's _decimalsOffset()? → Present = Mitigated
Pattern 4: Unsafe Integer Casting
solidity
// VULNERABLE: Silent truncation
uint256 largeValue = 2**200;
uint128 smallValue = uint128(largeValue); // Truncated! No revert in 0.8+

// VULNERABLE: Signed/unsigned confusion
int256 negative = -1;
uint256 converted = uint256(negative); // = type(uint256).max in 0.8+

// SAFE: Use SafeCast
uint128 smallValue = SafeCast.toUint128(largeValue); // Reverts if overflow

Detection:

For each type cast operation:
  If casting from larger to smaller type (e.g., uint256 → uint128):
    Check if preceded by bounds validation
    If no bounds check → UNSAFE CASTING
  If casting between signed and unsigned:
    Check if value can be negative
    If possible → SIGN CONFUSION
Pattern 5: Unchecked Block Risks
solidity
// Solidity 0.8+: checked math by default, but unchecked{} disables it
unchecked {
    // VULNERABLE: Overflow/underflow silently wraps
    uint256 result = a - b; // If b > a: wraps to huge number
    uint256 sum = a + b;    // If a + b > type(uint256).max: wraps to small number
}

// SAFE use of unchecked (when overflow is impossible):
unchecked {
    ++i; // In a bounded for loop — i cannot overflow uint256
}

Detection:

For each unchecked block:
  For each arithmetic operation inside:
    1. Can the operation overflow/underflow?
    2. Is there a pre-condition that guarantees safety?
    3. If no guarantee → UNCHECKED OVERFLOW/UNDERFLOW risk

  Common safe patterns (don't flag):
    - Loop counter increment: unchecked { ++i; } in for loop with bounded length
    - Post-require subtraction: require(a >= b); unchecked { a - b; }
Pattern 6: Dust Amount Exploitation
solidity
// VULNERABLE: Tiny amounts bypass fee logic
function swap(uint256 amountIn) external {
    uint256 fee = amountIn * FEE_BPS / 10000;
    // If amountIn = 1 and FEE_BPS = 30: fee = 30/10000 = 0
    // Zero fee! Attacker makes many tiny swaps to avoid fees
    uint256 amountOut = amountIn - fee;
}

Detection:

For each fee/tax calculation:
  If fee = amount * rate / denominator:
    Can amount * rate < denominator? (making fee = 0)
    If yes → DUST AMOUNT EXPLOITATION: zero-fee transactions possible

Workflow

Task Progress:
- [ ] Step 1: Audit all public/external function parameters for missing validation
- [ ] Step 2: Find division-before-multiplication patterns
- [ ] Step 3: Verify rounding direction in share/price calculations (protocol-favorable)
- [ ] Step 4: Check ERC4626 vaults for inflation attack protection
- [ ] Step 5: Identify all type casting operations and verify bounds
- [ ] Step 6: Analyze all unchecked blocks for overflow/underflow risks
- [ ] Step 7: Check fee calculations for dust amount exploitation
- [ ] Step 8: Score findings and generate report

Output Format

markdown
## Input & Arithmetic Safety Report

### Finding: [Title]

**Function:** `functionName()` at `Contract.sol:L42`
**Category:** [Missing Validation | Precision Loss | Rounding | Inflation | Unsafe Cast | Unchecked | Dust]
**Severity:** [CRITICAL | HIGH | MEDIUM | LOW]

**Issue:**
[Description of the input validation or arithmetic vulnerability]

**Vulnerable Code:**
[Code snippet showing the issue]

**Exploit Scenario:**
1. [Step-by-step exploitation]

**Mathematical Proof:**
  Input: [values]
  Expected: [correct result]
  Actual: [incorrect result due to precision/rounding]
  Difference: [loss amount]

**Recommendation:**
[Specific fix — add validation, reorder operations, use SafeCast, add rounding]
Show full SKILL.md (208 more words)Show less

Quick Detection Checklist

  • Do all public functions validate address parameters against address(0)?
  • Do all amount parameters check for > 0 where zero is invalid?
  • Are array parameters checked for equal lengths and maximum size?
  • Do all percentage/rate parameters have upper bounds?
  • Is division always performed AFTER multiplication (not before)?
  • Does rounding favor the protocol (down on deposits, down on withdrawals of assets)?
  • Do ERC4626 vaults use virtual shares/assets offset against inflation?
  • Are all downcasts (uint256 → smaller) protected by SafeCast or bounds checks?
  • Are unchecked blocks only used where overflow/underflow is mathematically impossible?
  • Can fee calculations produce zero for small but valid amounts?

For precision patterns, see {baseDir}/references/precision-patterns.md. For validation checklist, see {baseDir}/references/validation-checklist.md.

Rationalizations to Reject

  • "Solidity 0.8+ has checked math" → unchecked blocks exist; precision loss and rounding are NOT overflow
  • "The fee is too small to matter" → Millions of small transactions compound; zero-fee dust swaps are profitable
  • "No one would deposit 1 wei" → ERC4626 inflation attack uses exactly this; front-runners are automated
  • "The admin wouldn't set a bad value" → Admin key compromise + no bounds = instant parameter manipulation
  • "Rounding errors are just 1 wei" → 1 wei per transaction × millions of transactions = significant loss
  • "Zero address can't sign transactions" → But setting admin to zero address locks out all admin functions permanently

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/input-arithmetic-safety/skills/input-arithmetic-safety of quillai-network/quillshield_skills.

  • SKILL.md
  • references/precision-patterns.md
  • references/validation-checklist.md

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

Input Arithmetic Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Input Arithmetic Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Input Arithmetic Safety this skillquillai-network/quillshield_skills129—~3.1kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
Solidity AuditorGabson0x/bountyforge443—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k1 repos~9.9kAutomated safety check: PassMIT
Solidity Securitywshobson/agents40k12 repos~892Automated safety check: PassMIT

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub starsUsed in 1 repo~9.9k tokens
    Backend & APIsAuto-check passed
  • Solidity Security

    wshobson/agents

    Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.

    40k GitHub starsUsed in 12 repos~892 tokens
    Backend & APIsAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    129 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dos Griefing Analysis

    quillai-network/quillshield_skills

    Detects Denial of Service and griefing vulnerabilities in smart contracts.

    129 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed
  • External Call Safety

    quillai-network/quillshield_skills

    Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

    129 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    129 GitHub stars~2.8k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    129 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Reentrancy Pattern Analysis

    quillai-network/quillshield_skills

    Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.

    129 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Input Arithmetic Safety

What does Input Arithmetic Safety do?

Detects input validation failures and arithmetic vulnerabilities in smart contracts. Input Arithmetic Safety is an agent skill from quillai-network/quillshield_skills. Detects input validation failures and arithmetic vulnerabilities in smart contracts.

When should I use Input Arithmetic Safety?

Input Arithmetic Safety fits situations like: auditing contracts with fee calculations; unchecked blocks; any public-facing functions that accept user input.

How do I install Input Arithmetic Safety in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a claude-code`. Or copy the skill folder (plugins/input-arithmetic-safety/skills/input-arithmetic-safety in quillai-network/quillshield_skills) into .claude/skills/input-arithmetic-safety in your project. Claude Code loads it when a task matches its description.

How do I install Input Arithmetic Safety in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a codex`. Or copy the skill folder (plugins/input-arithmetic-safety/skills/input-arithmetic-safety in quillai-network/quillshield_skills) into .agents/skills/input-arithmetic-safety in your project. Codex loads it when a task matches its description.

Can I use Input Arithmetic Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill input-arithmetic-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/input-arithmetic-safety, .gemini/skills/input-arithmetic-safety, .github/skills/input-arithmetic-safety and .opencode/skills/input-arithmetic-safety in your project.

What does Input Arithmetic Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Input Arithmetic Safety is instructions for the agent only.

Does Input Arithmetic Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Input Arithmetic Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Input Arithmetic Safety use?

Input Arithmetic Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Input Arithmetic Safety use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Input Arithmetic Safety?

Skills that share tags, products or a category with Input Arithmetic Safety: Fizz Convert (pashov/skills, 1.2k stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars), Solidity Auditor (Gabson0x/bountyforge, 443 stars) and Solidity Auditor (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Input Arithmetic Safety?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 129 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.