Fizz Convert
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .claude/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .claude/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .agents/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .agents/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .cursor/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .cursor/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/quillai-network/quillshield_skills.git --path plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .gemini/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .gemini/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .github/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .github/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install quillai-network/quillshield_skills proxy-upgrade-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety .opencode/skills/proxy-upgrade-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "proxy-upgrade-safety" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety into .opencode/skills/proxy-upgrade-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "proxy-upgrade-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
proxy-upgrade-safetyDetects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
Proxy Upgrade Safety is an agent skill from quillai-network/quillshield_skills. Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade path safety. Covers Transparent Proxy, UUPS (EIP-1822), Beacon, Diamond (EIP-2535), and Minimal Proxy (EIP-1167) patterns. Use when auditing upgradeable contracts, reviewing implementation upgrades, analyzing delegatecall architectures, or verifying proxy pattern compliance.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/proxy-patterns.md` and `references/storage-collision-detection.md`).
It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Proxy Upgrade Safety loads about 3.2k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 616 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 616 words, ~3,245 tokens.
.claude/skills/proxy-upgrade-safety/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Detect vulnerabilities specific to upgradeable proxy architectures — the most widely deployed contract pattern on Ethereum (54.2% of contracts). Proxy bugs cause storage corruption, unauthorized upgrades, and complete contract takeover.
delegatecall-based architectures and library usageinitialize() be front-run?)When Proxy calls Implementation via delegatecall:
┌─────────────────────┐ delegatecall ┌─────────────────────┐
│ PROXY │ ──────────────────→ │ IMPLEMENTATION │
│ │ │ │
│ Storage: │ Implementation code │ Code only: │
│ slot 0: admin │ executes in proxy's │ No persistent │
│ slot 1: impl addr │ storage context │ storage │
│ slot 2: user data │ │ │
│ slot 3: user data │ │ │
└─────────────────────┘ └─────────────────────┘Key Rule: The implementation's code reads/writes the PROXY's storage slots. If storage layouts don't match, data corruption occurs.
Between Proxy and Implementation:
// Proxy contract
contract Proxy {
address public admin; // slot 0
address public implementation; // slot 1
fallback() external payable {
delegatecall(implementation);
}
}
// Implementation contract
contract ImplementationV1 {
uint256 public totalSupply; // slot 0 — COLLIDES with admin!
mapping(address => uint256) public balances; // slot 1 — COLLIDES with implementation!
}Detection: Compare storage slot assignments between proxy and implementation. Any overlap = CRITICAL vulnerability.
Between Implementation Versions:
// V1
contract ImplementationV1 {
uint256 public totalSupply; // slot 0
address public owner; // slot 1
mapping(address => uint256) balances; // slot 2
}
// V2 — DANGEROUS: inserted variable before existing ones
contract ImplementationV2 {
bool public paused; // slot 0 — COLLIDES with totalSupply!
uint256 public totalSupply; // slot 1 — COLLIDES with owner!
address public owner; // slot 2 — COLLIDES with balances!
mapping(address => uint256) balances; // slot 3
}Safe V2:
contract ImplementationV2 {
uint256 public totalSupply; // slot 0 — same
address public owner; // slot 1 — same
mapping(address => uint256) balances; // slot 2 — same
bool public paused; // slot 3 — NEW, appended at end
}Proxy pattern uses initialize() instead of constructor(). If the implementation contract itself is not initialized, an attacker can call initialize() directly on it.
contract ImplementationV1 is Initializable {
address public owner;
function initialize(address _owner) external initializer {
owner = _owner;
}
function selfDestruct() external {
require(msg.sender == owner);
selfdestruct(payable(msg.sender));
}
}Attack:
1. Implementation deployed but initialize() not called on impl itself
2. Attacker calls implementation.initialize(attacker_address)
3. Attacker is now owner of the IMPLEMENTATION contract
4. Attacker calls selfDestruct() on implementation
5. Proxy now delegatecalls to destroyed contract
6. ALL proxy calls return empty data — contract brickedDetection:
For each implementation contract:
1. Does it have initialize() or any initializer function?
2. Was initialize() called on the implementation address (not just the proxy)?
3. Does the constructor call _disableInitializers()?
4. If no → UNINITIALIZED IMPLEMENTATION vulnerabilitySolidity function selectors are only 4 bytes. Collisions between proxy admin functions and implementation functions cause unexpected behavior.
// Proxy has admin function
function upgrade(address newImpl) external; // selector: 0x0900f010
// Implementation has user function with SAME selector
function collide(uint256 amount) external; // selector: 0x0900f010
// When user calls collide(), proxy intercepts it as upgrade()!Transparent Proxy Mitigation: Admin can only call admin functions; users can only call implementation functions. But this must be correctly implemented.
Detection:
For each function in the proxy:
selector_proxy = keccak256(signature)[:4]
For each function in the implementation:
selector_impl = keccak256(signature)[:4]
If selector_proxy == selector_impl:
→ FUNCTION SELECTOR CLASHUUPS Pattern: The upgrade logic lives in the implementation, not the proxy. If _authorizeUpgrade() is not properly protected, anyone can upgrade.
// VULNERABLE: Missing access control on upgrade
contract ImplementationV1 is UUPSUpgradeable {
function _authorizeUpgrade(address newImplementation) internal override {
// NO ACCESS CHECK! Anyone can upgrade!
}
}
// SAFE
contract ImplementationV1 is UUPSUpgradeable, OwnableUpgradeable {
function _authorizeUpgrade(address newImplementation) internal override onlyOwner {
// Only owner can upgrade
}
}Detection:
For UUPS proxies:
1. Find _authorizeUpgrade() function
2. Check for access control (onlyOwner, onlyRole, require(msg.sender == admin))
3. If no access control → CRITICAL: unauthorized upgrade
4. Also check: Can _authorizeUpgrade be removed in a new version?
→ If V2 doesn't inherit UUPSUpgradeable → proxy becomes non-upgradeable (bricked)Code executing via delegatecall runs with the caller's msg.sender, msg.value, and storage. Misunderstanding this context creates vulnerabilities.
// Implementation stores admin in its own constructor
contract Implementation {
address public admin;
constructor() {
admin = msg.sender; // Sets admin in IMPLEMENTATION storage
// When called via delegatecall, this is proxy's storage
// BUT constructor only runs during deployment, not via proxy!
}
}Key Rule: Constructors NEVER run via delegatecall. Any state set in the constructor exists only in the implementation's own storage, not the proxy's.
Identify which proxy pattern is used.
| Pattern | Key Indicator | Upgrade Location |
|---|---|---|
| Transparent (EIP-1967) | _IMPLEMENTATION_SLOT at keccak256('eip1967.proxy.implementation') - 1 | Proxy contract |
| UUPS (EIP-1822) | proxiableUUID() in implementation | Implementation contract |
| Beacon | _BEACON_SLOT at keccak256('eip1967.proxy.beacon') - 1 | Beacon contract |
| Diamond (EIP-2535) | diamondCut() function, facet registry | Diamond contract |
| Minimal (EIP-1167) | Clone bytecode pattern 363d3d373d3d3d363d73... | Not upgradeable |
Build the complete storage map for proxy and all implementation versions.
Algorithm:
For each contract C (proxy, impl_v1, impl_v2, ...):
storage_map[C] = {}
slot = 0
For each state variable V in C (in declaration order):
storage_map[C][slot] = V
slot += size_of(V) // Consider packing for <32 byte types
For each slot S:
If storage_map[proxy][S] conflicts with storage_map[impl][S]:
→ PROXY-IMPL COLLISION at slot S
If storage_map[impl_v1][S] != storage_map[impl_v2][S]:
→ UPGRADE COLLISION at slot SSpecial Cases:
uint256[50] private __gap): reserved space for upgradesInitialization Checks:
1. Does implementation use Initializable?
2. Is initialize() protected by initializer modifier?
3. Does constructor call _disableInitializers()?
4. Can initialize() be called more than once? (reinitializer)
5. Was initialize() called on impl address directly?
Upgrade Path Checks:
1. Is upgrade function access-controlled?
2. Does new impl maintain storage layout compatibility?
3. Does new impl still support upgrades? (UUPS: must inherit UUPSUpgradeable)
4. Is there a timelock on upgrades?
5. Can upgrade + initialize race condition occur?Task Progress:
- [ ] Step 1: Identify proxy pattern (Transparent, UUPS, Beacon, Diamond, Minimal)
- [ ] Step 2: Map storage layout of proxy contract
- [ ] Step 3: Map storage layout of all implementation versions
- [ ] Step 4: Check for storage collisions (proxy-impl and version-version)
- [ ] Step 5: Verify initialization safety (disableInitializers, initializer modifier)
- [ ] Step 6: Check function selector clashing (proxy admin vs impl functions)
- [ ] Step 7: Verify upgrade authorization (access control on upgrade path)
- [ ] Step 8: Check delegatecall context safety
- [ ] Step 9: Score findings and generate report## Proxy & Upgrade Safety Report
### Finding: [Title]
**Contract:** `ContractName` at `Contract.sol:L42`
**Proxy Pattern:** [Transparent | UUPS | Beacon | Diamond | Minimal]
**Class:** [Storage Collision | Uninitialized Impl | Selector Clash | Missing Auth | Context Confusion]
**Severity:** [CRITICAL | HIGH | MEDIUM]
**Issue:**
[Description of the proxy-specific vulnerability]
**Storage Layout:**
Proxy slot 0: `[proxy variable]`
Impl slot 0: `[impl variable]` ← COLLISION
**Attack Scenario:**
1. [Step-by-step exploit]
**Impact:**
[Storage corruption, unauthorized upgrade, contract bricked, etc.]
**Recommendation:**
[Use EIP-1967 slots, add _disableInitializers, add access control, append-only storage]constructor() call _disableInitializers()?initialize() use the initializer modifier?__gap variable for future storage expansion in base contracts?_authorizeUpgrade() have proper access control?UUPSUpgradeable?For proxy pattern details, see {baseDir}/references/proxy-patterns.md. For storage collision detection, see {baseDir}/references/storage-collision-detection.md.
_authorizeUpgrade is properly protected AND maintained across upgrades© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety of quillai-network/quillshield_skills.
Open the folder on GitHubat commit 8bdd3c0
Proxy Upgrade Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Proxy Upgrade Safety this skillquillai-network/quillshield_skills | 130 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Solana Devsolana-foundation/solana-dev-skill | 574 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Feynman Auditor0xiehnnkta/nemesis-auditor | 243 | 1 repos | ~11k | Automated safety check: Pass | MIT | |
| Smart Contract Auditgreatpie/smart-contract-audit-skill | 101 | — | ~1.1k | Automated safety check: Pass | None | |
| RadarAuditware/radar | 154 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 |
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
0xiehnnkta/nemesis-auditor
Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
Auditware/radar
Use radar for smart contract security analysis, AST generation, and detection template development.
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
quillai-network/quillshield_skills
Detects Denial of Service and griefing vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects input validation failures and arithmetic vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
quillai-network/quillshield_skills
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Categories
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…. Proxy Upgrade Safety is an agent skill from quillai-network/quillshield_skills. Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade path safety.
Proxy Upgrade Safety fits situations like: auditing upgradeable contracts; reviewing implementation upgrades; analyzing delegatecall architectures; verifying proxy pattern compliance.
Run `npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a claude-code`. Or copy the skill folder (plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety in quillai-network/quillshield_skills) into .claude/skills/proxy-upgrade-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a codex`. Or copy the skill folder (plugins/proxy-upgrade-safety/skills/proxy-upgrade-safety in quillai-network/quillshield_skills) into .agents/skills/proxy-upgrade-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill proxy-upgrade-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/proxy-upgrade-safety, .gemini/skills/proxy-upgrade-safety, .github/skills/proxy-upgrade-safety and .opencode/skills/proxy-upgrade-safety in your project.
SKILL.md names no scripts, command-line tools or credentials: Proxy Upgrade Safety is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Proxy Upgrade Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Proxy Upgrade Safety: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 574 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 243 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.
Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.