Ethereum Smart Contract Vulnerability Analysis
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .claude/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .claude/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .agents/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .agents/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .cursor/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .cursor/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/quillai-network/quillshield_skills.git --path plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .gemini/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .gemini/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .github/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .github/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install quillai-network/quillshield_skills reentrancy-pattern-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis .opencode/skills/reentrancy-pattern-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reentrancy-pattern-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis into .opencode/skills/reentrancy-pattern-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reentrancy-pattern-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reentrancy-pattern-analysisSystematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Reentrancy Pattern Analysis is an agent skill from quillai-network/quillshield_skills. Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy. Builds call graphs, verifies CEI (Checks-Effects-Interactions) pattern compliance, traces state changes relative to external calls, and identifies callback vectors through ERC-777/ERC-1155 hooks. Use when auditing contracts that make external calls, transfer ETH or tokens, interact with callback-enabled standards, or have complex multi-contract architectures.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/case-studies.md` and `references/reentrancy-variants.md`).
It sits in Security, covering Smart contract auditing and Codebase onboarding. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reentrancy Pattern Analysis loads about 3.4k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 817 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 817 words, ~3,435 tokens.
.claude/skills/reentrancy-pattern-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Systematically detect all variants of reentrancy vulnerabilities by mapping the relationship between external calls and state changes across the entire contract system.
Checks-Effects-Interactions (CEI) is the fundamental safety pattern:
1. CHECKS — Validate all conditions (require statements, access control)
2. EFFECTS — Update all state variables
3. INTERACTIONS — Make external calls (ETH transfers, token calls, cross-contract)Any function that performs INTERACTIONS before completing all EFFECTS is potentially vulnerable to reentrancy.
The original and most well-known pattern. A function makes an external call before updating its own state, allowing the callee to re-enter the same function.
// VULNERABLE
function withdraw(uint256 amount) public {
require(balances[msg.sender] >= amount);
(bool success, ) = msg.sender.call{value: amount}(""); // INTERACTION before EFFECT
require(success);
balances[msg.sender] -= amount; // State update AFTER external call
}Detection: Find functions where state writes to variables used in require checks occur AFTER external calls.
Two or more functions share state, and an attacker re-enters through a DIFFERENT function than the one making the external call.
function withdraw(uint256 amount) public {
require(balances[msg.sender] >= amount);
(bool success, ) = msg.sender.call{value: amount}("");
require(success);
balances[msg.sender] -= amount;
}
// Attacker re-enters HERE during withdraw's external call
function transfer(address to, uint256 amount) public {
require(balances[msg.sender] >= amount);
balances[msg.sender] -= amount;
balances[to] += amount;
}Detection: For each external call in function F, check if any OTHER public function reads/writes the same state variables that F modifies after the call.
The re-entry occurs through a different contract that shares state or trust relationships with the vulnerable contract.
// Contract A
function withdrawFromVault() public {
uint256 shares = vault.balanceOf(msg.sender);
vault.burn(msg.sender, shares);
// External call — attacker can re-enter Contract B
(bool success, ) = msg.sender.call{value: shares * pricePerShare}("");
require(success);
}
// Contract B (attacker re-enters here)
function borrow() public {
uint256 collateral = vault.balanceOf(msg.sender); // Reads stale state!
// Shares not yet burned, so collateral appears inflated
uint256 loanAmount = collateral * maxLTV;
token.transfer(msg.sender, loanAmount);
}Detection: Map all cross-contract dependencies. For each external call, identify which other contracts read the state that should have been updated.
A view/pure function returns stale state during a reentrancy callback. No state is modified during re-entry — the attacker exploits the READING of inconsistent state by a third-party contract.
// Pool contract
function removeLiquidity() external {
uint256 shares = balances[msg.sender];
// Burns LP tokens (updates internal accounting)
_burn(msg.sender, shares);
// External call BEFORE updating reserves
(bool success, ) = msg.sender.call{value: ethAmount}("");
// Reserves updated AFTER the call
totalReserves -= ethAmount;
}
// This view function returns stale data during the callback
function getRate() public view returns (uint256) {
return totalReserves / totalSupply(); // totalReserves not yet updated!
}
// Third-party contract reads the inflated rate
function priceOracle() external view returns (uint256) {
return pool.getRate(); // Returns wrong value during reentrancy
}Detection: For each external call, identify view functions that read state variables modified AFTER the call. Check if any external protocol depends on those view functions.
Token standards with built-in callback hooks that execute arbitrary code on the receiver during transfers.
// ERC-777: tokensReceived() hook called on recipient
// ERC-1155: onERC1155Received() hook called on recipient
// ERC-721: onERC721Received() hook called on recipient
function deposit(uint256 amount) public {
token.transferFrom(msg.sender, address(this), amount); // Triggers callback!
// If token is ERC-777, msg.sender's tokensReceived() runs HERE
balances[msg.sender] += amount; // State update after callback
}Detection: Identify all token transfer/transferFrom/safeTransfer calls. Check if the token could be ERC-777/ERC-1155/ERC-721. Verify state updates happen before the transfer.
Build a complete map of all external interactions.
For each function, extract:
Function: withdraw()
├── External Calls:
│ ├── msg.sender.call{value: amount}("") at line 45
│ ├── token.transfer(user, amount) at line 48
│ └── oracle.getPrice() at line 42
├── State Writes:
│ ├── balances[msg.sender] -= amount at line 50
│ └── totalWithdrawn += amount at line 51
├── State Reads (in requires):
│ └── balances[msg.sender] at line 41
└── Modifiers:
└── nonReentrant: NOCall Classification:
| Call Type | Reentrancy Risk | Examples |
|---|---|---|
ETH transfer via call | HIGH | addr.call{value: x}("") |
Token transfer/transferFrom | MEDIUM-HIGH | ERC-777 hooks, ERC-1155 callbacks |
safeTransferFrom (NFT) | MEDIUM | ERC-721 onERC721Received callback |
| Cross-contract function call | MEDIUM | otherContract.doSomething() |
staticcall / view calls | LOW | Cannot modify state but can trigger read-only reentrancy in callers |
delegatecall | HIGH | Executes in caller's context |
For each function with external calls, verify CEI ordering.
Algorithm:
For each function F with external calls:
1. E = set of all state variables written by F
2. C = set of all state variables read in require/if checks
3. I = position of each external call in F
4. For each external call at position P:
a. W_after = state writes that occur AFTER position P
b. If W_after ∩ (E ∪ C) ≠ ∅:
→ CEI VIOLATION: state modified after external call
c. Classify violation:
- W_after ∩ C ≠ ∅ → Classic reentrancy (check variable modified after call)
- W_after ∩ E ≠ ∅ → State inconsistency windowCross-Function Extension:
For each external call in function F at position P:
W_before = state variables NOT yet updated at position P
For each OTHER public function G:
R_G = state variables read by G
W_G = state variables written by G
If R_G ∩ W_before ≠ ∅ OR W_G ∩ W_before ≠ ∅:
→ CROSS-FUNCTION REENTRANCY: G can be called during F's external call
with inconsistent stateCheck that reentrancy protections are correctly applied.
Guard Types:
| Guard | Coverage | Limitations |
|---|---|---|
nonReentrant modifier (OpenZeppelin) | Single contract, all functions with modifier | Does not protect cross-contract reentrancy |
| CEI pattern compliance | Per-function | Must be verified for every function individually |
transfer() / send() (2300 gas) | Limits callback gas | NOT safe — EIP-1884 changed gas costs; don't rely on this |
| Pull payment pattern | Eliminates external calls from state changes | Requires architectural change |
Verification:
For each function F with CEI violations:
1. Check if F has nonReentrant modifier → Mitigated (single-contract only)
2. Check if ALL functions sharing state also have nonReentrant → Mitigated (cross-function)
3. Check if cross-contract consumers are protected → Requires manual review
4. If no guard → VULNERABLETask Progress:
- [ ] Step 1: Identify all external calls in every function (ETH transfers, token calls, cross-contract)
- [ ] Step 2: Build call graph with state read/write positions relative to each call
- [ ] Step 3: Detect CEI violations (state writes after external calls)
- [ ] Step 4: Detect cross-function reentrancy (shared state across functions)
- [ ] Step 5: Detect callback vectors (ERC-777, ERC-1155, ERC-721 token interactions)
- [ ] Step 6: Detect read-only reentrancy (view functions reading stale state)
- [ ] Step 7: Verify guard coverage (nonReentrant, CEI compliance, pull patterns)
- [ ] Step 8: Score findings and generate report## Reentrancy Analysis Report
### Finding: [Title]
**Function:** `functionName()` at `Contract.sol:L42`
**Variant:** [Classic | Cross-Function | Cross-Contract | Read-Only | Callback]
**Severity:** [CRITICAL | HIGH | MEDIUM]
**Guard Status:** [Unguarded | Partially Guarded | Guarded]
**CEI Violation:**
- External call at line [X]: `[call expression]`
- State write AFTER call at line [Y]: `[state variable] = [expression]`
**Re-Entry Path:**
1. Attacker calls `functionName()`
2. External call triggers callback to attacker contract
3. Attacker re-enters via `[re-entry function]`
4. State variable `[name]` still has pre-update value
5. [Exploit consequence]
**Impact:**
[Funds drained, state corrupted, price manipulated, etc.]
**Recommendation:**
[Specific fix — reorder state updates, add nonReentrant, use pull pattern]| Variant | State Modified | Funds at Risk | Severity |
|---|---|---|---|
| Classic — ETH drain | Yes | Yes | CRITICAL |
| Cross-function — balance manipulation | Yes | Yes | CRITICAL |
| Cross-contract — oracle/price manipulation | Indirectly | Yes | HIGH |
| Read-only — stale price in third-party | No (view only) | Possibly | HIGH |
| Callback — ERC-777 deposit inflation | Yes | Possibly | HIGH |
| Any variant with nonReentrant on target | Mitigated | No | LOW/INFO |
Trace reentrancy through multiple contract hops:
Contract A calls Contract B
Contract B calls Contract C
Contract C calls back to Contract A (or reads A's stale state)
Detection: Build transitive call graph across all contracts in scope.
For each call chain A → B → ... → X:
If X can call back to any contract in the chain → TRANSITIVE REENTRANCYWhen analyzing a contract, immediately check:
nonReentrant applied to ALL functions that share state with a function making external calls, not just the calling function itself?transfer() or send() for reentrancy protection? (Unsafe assumption)For detailed variant taxonomy, see {baseDir}/references/reentrancy-variants.md. For real-world case studies, see {baseDir}/references/case-studies.md.
transfer() so reentrancy is impossible" → EIP-1884 changed gas costs; transfer is no longer considered safenonReentrant" → Check cross-function and cross-contract paths; one modifier doesn't protect everything© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis of quillai-network/quillshield_skills.
Open the folder on GitHubat commit 8bdd3c0
Reentrancy Pattern Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reentrancy Pattern Analysis this skillquillai-network/quillshield_skills | 130 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Ethereum Smart Contract Vulnerability Analysistradecatlabs/vibe-coding-cn | 17k | 1 repos | ~738 | Automated safety check: Pass | Apache-2.0 | |
| Algorand Vulnerability Scannertrailofbits/skills | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Cairo Vulnerability Scannertrailofbits/skills | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Code Maturity Assessortrailofbits/skills | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Cosmos Vulnerability Scannertrailofbits/skills | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 |
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
trailofbits/skills
Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.
trailofbits/skills
Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.
trailofbits/skills
Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap.
trailofbits/skills
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.
trailofbits/skills
Guides through Trail of Bits' 5-step secure development workflow.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
quillai-network/quillshield_skills
Detects Denial of Service and griefing vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects input validation failures and arithmetic vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
quillai-network/quillshield_skills
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
Categories
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy. Reentrancy Pattern Analysis is an agent skill from quillai-network/quillshield_skills. Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Reentrancy Pattern Analysis fits situations like: auditing contracts that make external calls; interact with callback-enabled standards; have complex multi-contract architectures.
Run `npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a claude-code`. Or copy the skill folder (plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis in quillai-network/quillshield_skills) into .claude/skills/reentrancy-pattern-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a codex`. Or copy the skill folder (plugins/reentrancy-pattern-analysis/skills/reentrancy-pattern-analysis in quillai-network/quillshield_skills) into .agents/skills/reentrancy-pattern-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill reentrancy-pattern-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reentrancy-pattern-analysis, .gemini/skills/reentrancy-pattern-analysis, .github/skills/reentrancy-pattern-analysis and .opencode/skills/reentrancy-pattern-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Reentrancy Pattern Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reentrancy Pattern Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Reentrancy Pattern Analysis: Ethereum Smart Contract Vulnerability Analysis (tradecatlabs/vibe-coding-cn, 17k stars), Algorand Vulnerability Scanner (trailofbits/skills, 7.4k stars), Cairo Vulnerability Scanner (trailofbits/skills, 7.4k stars) and Code Maturity Assessor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.
Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.