Agent skill

Semantic Guard Analysis

by quillai-network in quillai-network/quillshield_skills

Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns.

MITAuto-check: warningsBackend & APIs

Install Semantic Guard Analysis

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add quillai-network/quillshield_skills --skill semantic-guard-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install quillai-network/quillshield_skills semantic-guard-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/semantic-guard-analysis/skills/semantic-guard-analysis .claude/skills/semantic-guard-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semantic-guard-analysis
GitHub stars
130
Token cost
~2.2k tokens
SKILL.md length
564 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns.

  • Works in 3 steps: AST Extraction & State Mapping → Dependency Graph Construction → Anomaly Detection (The Solver)
  • Auditing smart contracts for missing access controls
  • SKILL.md covers When to Use, When NOT to Use, Core Principle: The… and The Three-Phase Detection…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Semantic Guard Analysis is an agent skill from quillai-network/quillshield_skills. Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns. Identifies functions that bypass security checks (require, modifiers) that other functions consistently apply. Uses the Consistency Principle — a contract is its own specification. Use when auditing smart contracts for missing access controls, inconsistent pause checks, logic bugs, forgotten modifiers, or when traditional tools report no issues but logic errors may exist.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/case-studies.md` and `references/detection-algorithm.md`).

It sits in Backend & APIs, covering Smart contracts and Authorization and RBAC. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.

When your agent uses it

  • Auditing smart contracts for missing access controls
  • Inconsistent pause checks
  • Forgotten modifiers
  • Traditional tools report no issues but logic errors may exist

Example prompts

  • “Use the semantic-guard-analysis skill to detect logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns”
  • “/semantic-guard-analysis”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. AST Extraction & State Mapping
  2. Dependency Graph Construction
  3. Anomaly Detection (The Solver)

What it can do on your machine

Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semantic Guard Analysis loads about 2.2k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 564 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:14
    th emergency/admin functions that might bypass safety mechanisms

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 564 words, ~2,200 tokens.

Download SKILL.mdSave it as .claude/skills/semantic-guard-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
semantic-guard-analysis
description
Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns. Identifies functions that bypass security checks (require, modifiers) that other functions consistently apply. Uses the Consistency Principle — a contract is its own specification. Use when auditing smart contracts for missing access controls, inconsistent pause checks, logic bugs, forgotten modifiers, or when traditional tools report no issues but logic errors may exist.

Semantic Guard Analysis

Detect logic vulnerabilities by finding functions that violate the contract's own internal guard patterns. Unlike pattern-matching tools, this approach uses the contract's consistent behavior as its specification.

When to Use

  • Auditing smart contracts where traditional tools find nothing suspicious
  • Looking for missing require checks, forgotten modifiers, inconsistent access control
  • Analyzing contracts with emergency/admin functions that might bypass safety mechanisms
  • Detecting logic bugs that are syntactically correct but semantically dangerous
  • When you suspect "forgotten check" vulnerabilities

When NOT to Use

  • Pure state-state invariant analysis (use state-invariant-detection)
  • Full multi-dimensional audit (use behavioral-state-analysis)
  • Code quality or gas optimization reviews

Core Principle: The Consistency Hypothesis

"A smart contract is its own specification."

Instead of checking against external rules, analyze what the contract claims to enforce, then find where it breaks its own rules.

If a critical state variable (like user balances) is protected by a security check (like a pause mechanism) in 90% of functions, the 10% without that check are likely vulnerabilities.

The Three-Phase Detection Architecture

Phase 1: AST Extraction & State Mapping

Parse the Solidity code and build a State Interaction Matrix.

For each state variable, track every function that touches it:

State Variable: balance
├─ deposit()        → [WRITE] + Guards: [paused, initialized]
├─ withdraw()       → [WRITE] + Guards: [paused, initialized]
├─ transfer()       → [WRITE] + Guards: [paused]
└─ emergencyWithdraw() → [WRITE] + Guards: [] ⚠️

For each function-variable interaction, record:

AttributeDescription
Write AccessDoes the function modify this variable?
Guard AccessDoes the function check this variable in require() or if()?
Read AccessDoes the function only read this variable?

Extract guard sources:

  • Modifier chains (onlyOwner, nonReentrant, whenNotPaused)
  • Explicit require statements
  • Conditional branches gating state changes
  • External calls affecting state
  • Event emissions signaling state changes
Phase 2: Dependency Graph Construction

Build a mathematical model of how variables protect each other.

Guard Relationship: If Variable A is checked before Variable B is modified:

A → B (A guards B)

Example:

paused ──────┐
             ├──→ balance
initialized ─┘

owner ───→ paused
owner ───→ totalSupply

Frequency Weighting: Each guard relationship gets a confidence score:

Confidence(guard → state) = |functions applying guard| / |functions modifying state|
  • paused guards balance in 9/10 functions → 90% confidence
  • owner guards totalSupply in 3/10 functions → 30% confidence (weak)

Composite Dependencies: Track multi-variable guards:

(owner AND timeLock) → criticalFunction
(paused OR emergency) → userAccess
Show full SKILL.md (252 more words)Show less
Phase 3: Anomaly Detection (The Solver)

Identify functions that violate established patterns.

Algorithm:

For each state variable S that can be modified:
  1. M = all functions that write to S
  2. G = common guards across those functions (above threshold)
  3. V = M \ G (functions that modify without guards)
  4. V is the vulnerability set

Threshold-Based Inference:

Guard FrequencyClassificationAction
≥ 80%Strong InvariantFlag violations as HIGH/CRITICAL
50-79%Weak InvariantFlag violations as MEDIUM
< 50%No PatternIgnore (too inconsistent)

Severity Classification:

Bypass TypeSeverity
Strong invariant on financial state (balance, totalSupply)Critical
Strong invariant on access control (owner, admin roles)High
Weak invariant on any stateMedium
Inconsistent pattern with no security implicationsLow/Info

Context-Aware Filtering:

  • Constructor and initialize() functions may legitimately bypass patterns
  • view/pure functions cannot modify state — skip
  • Proxy pattern delegatecall requires special handling
  • Emergency functions may intentionally bypass some guards

Workflow

Task Progress:
- [ ] Step 1: Parse contract AST and build State Interaction Matrix
- [ ] Step 2: Identify all state variables and their modifying functions
- [ ] Step 3: Map guards (requires, modifiers) for each function-state pair
- [ ] Step 4: Build dependency graph with frequency weighting
- [ ] Step 5: Run anomaly detection (identify V = M \ G)
- [ ] Step 6: Apply privilege overlay (filter legitimate bypasses)
- [ ] Step 7: Score and report findings

Privilege Overlay System

Not all "bypasses" are vulnerabilities. Apply role-based filtering:

Role Classification:

Role LevelScrutinyRationale
Public functionsHighestMust follow all established patterns
Owner/Admin functionsMediumMay bypass operational guards, must be consistent with each other
Emergency functionsLowerDesigned for exceptional cases
Internal functionsContext-dependentAnalyze based on callers

Filtering Rule:

For each function f in vulnerability set V:
  1. Identify function privileges (modifiers, access controls)
  2. Compare with other functions at the SAME privilege level
  3. Flag only if bypass is inconsistent WITHIN privilege tier

Output Format

markdown
## Guard-State Anomaly Report

### Finding: [Title]

**Function:** `functionName()` at `Contract.sol:L145`
**Severity:** [CRITICAL | HIGH | MEDIUM | LOW]
**Confidence:** [Percentage]

**Issue:** Modifies `[state variable]` without checking `[guard]`

**Pattern Evidence:**
- `function1()` checks `[guard]` before modifying `[state]` ✓
- `function2()` checks `[guard]` before modifying `[state]` ✓
- `functionName()` does NOT check `[guard]` before modifying `[state]` ✗

**Guard Frequency:** X out of Y functions (Z%)

**Security Impact:**
[Explanation of what an attacker can do by exploiting this inconsistency]

**Attack Scenario:**
1. [Step-by-step exploit]

**Recommendation:**
Add `require([guard], "[message]")` before modifying `[state]`,
or document why this function intentionally bypasses the check.

Case Study: The "Forgotten Check"

solidity
contract Vault {
    mapping(address => uint256) public balance;
    bool public paused;

    function deposit() public payable {
        require(!paused, "Contract paused");       // ✓ checks paused
        balance[msg.sender] += msg.value;
    }

    function withdraw(uint256 amount) public {
        require(!paused, "Contract paused");       // ✓ checks paused
        balance[msg.sender] -= amount;
        payable(msg.sender).transfer(amount);
    }

    function adminWithdraw(address user) public onlyOwner {
        // ✗ Missing paused check!
        uint256 amount = balance[user];
        balance[user] = 0;
        payable(owner).transfer(amount);
    }
}

Detection:

M_balance = {deposit, withdraw, adminWithdraw}
G_paused = {deposit, withdraw}
V = {adminWithdraw}

Result: adminWithdraw() modifies balance without checking paused
Confidence: 66.7% (2/3 functions check paused)
Severity: HIGH (financial state + admin bypass of safety mechanism)

For more case studies, see {baseDir}/references/case-studies.md. For the full detection algorithm, see {baseDir}/references/detection-algorithm.md.

Rationalizations to Reject

  • "The admin is trusted, so skipping the check is fine" → Compromised admin + missing pause check = unstoppable drain
  • "This function is only called internally" → Verify all callers; internal doesn't mean safe
  • "The pattern only appears in 2 functions" → Even 2/3 consistency is a signal worth investigating
  • "It's an emergency function" → Emergency functions should be MORE carefully guarded, not less
  • "Traditional tools said it's fine" → Traditional tools check syntax, not semantic consistency

© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/semantic-guard-analysis/skills/semantic-guard-analysis of quillai-network/quillshield_skills.

  • SKILL.md
  • references/case-studies.md
  • references/detection-algorithm.md

Open the folder on GitHubat commit 8bdd3c0

Compare with similar skills

Semantic Guard Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semantic Guard Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semantic Guard Analysis this skillquillai-network/quillshield_skills130—~2.2kAutomated safety check: WarnMIT
Entry Point Analyzeralt-research2/SolidityGuard104—~959Automated safety check: PassCustom licence
Eip7702Nethereum/Nethereum2.3k—~1.4kAutomated safety check: PassMIT
Solidity Vulnerability Scanneralt-research2/SolidityGuard104—~1.6kAutomated safety check: NotesCustom licence
Erc7702 Patternsccashwell/evm-cortex131—~1.7kAutomated safety check: PassMIT
Pashov Audit Pipelineccashwell/evm-cortex131—~5.5kAutomated safety check: PassMIT

Similar skills

  • Entry Point Analyzer

    alt-research2/SolidityGuard

    Analyzes Solidity contract entry points to map attack surface.

    104 GitHub stars~959 tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Eip7702

    Nethereum/Nethereum

    Delegate smart contract code to EOAs with EIP-7702 using Nethereum (.NET).

    2.3k GitHub stars~1.4k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Erc7702 Patterns

    ccashwell/evm-cortex

    A skill your agent uses when building with EIP-7702 account abstraction.

    131 GitHub stars~1.7k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Pashov Audit Pipeline

    ccashwell/evm-cortex

    A skill your agent uses when performing a comprehensive smart contract security audit.

    131 GitHub stars~5.5k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Solidity Security

    ccashwell/evm-cortex

    Security-focused Solidity development patterns. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.5k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed

More from quillai-network/quillshield_skills

All 11 skills in this repo
  • Behavioral State Analysis

    quillai-network/quillshield_skills

    Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

    130 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dos Griefing Analysis

    quillai-network/quillshield_skills

    Detects Denial of Service and griefing vulnerabilities in smart contracts.

    130 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed
  • External Call Safety

    quillai-network/quillshield_skills

    Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Input Arithmetic Safety

    quillai-network/quillshield_skills

    Detects input validation failures and arithmetic vulnerabilities in smart contracts.

    130 GitHub stars~3.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    130 GitHub stars~2.8k tokensUpdated 6 mo ago
    Auto-check passed
  • Proxy Upgrade Safety

    quillai-network/quillshield_skills

    Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…

    130 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Semantic Guard Analysis

What does Semantic Guard Analysis do?

Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns. Semantic Guard Analysis is an agent skill from quillai-network/quillshield_skills. Detects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns.

When should I use Semantic Guard Analysis?

Semantic Guard Analysis fits situations like: auditing smart contracts for missing access controls; inconsistent pause checks; forgotten modifiers; traditional tools report no issues but logic errors may exist.

How do I install Semantic Guard Analysis in Claude Code?

Run `npx skills add quillai-network/quillshield_skills --skill semantic-guard-analysis -a claude-code`. Or copy the skill folder (plugins/semantic-guard-analysis/skills/semantic-guard-analysis in quillai-network/quillshield_skills) into .claude/skills/semantic-guard-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Semantic Guard Analysis in Codex?

Run `npx skills add quillai-network/quillshield_skills --skill semantic-guard-analysis -a codex`. Or copy the skill folder (plugins/semantic-guard-analysis/skills/semantic-guard-analysis in quillai-network/quillshield_skills) into .agents/skills/semantic-guard-analysis in your project. Codex loads it when a task matches its description.

Can I use Semantic Guard Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill semantic-guard-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semantic-guard-analysis, .gemini/skills/semantic-guard-analysis, .github/skills/semantic-guard-analysis and .opencode/skills/semantic-guard-analysis in your project.

What does Semantic Guard Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Semantic Guard Analysis is instructions for the agent only.

Does Semantic Guard Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semantic Guard Analysis safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Semantic Guard Analysis use?

Semantic Guard Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semantic Guard Analysis use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Semantic Guard Analysis?

Skills that share tags, products or a category with Semantic Guard Analysis: Entry Point Analyzer (alt-research2/SolidityGuard, 104 stars), Eip7702 (Nethereum/Nethereum, 2.3k stars), Solidity Vulnerability Scanner (alt-research2/SolidityGuard, 104 stars) and Erc7702 Patterns (ccashwell/evm-cortex, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semantic Guard Analysis?

quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.

Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.