Use Smart Contract Platform
circlefin/skills
Deploy, import, interact with, and monitor smart contracts using Circle Smart Contract Platform APIs.
Detects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts.
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .claude/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .claude/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .agents/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .agents/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .cursor/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .cursor/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/quillai-network/quillshield_skills.git --path plugins/signature-replay-analysis/skills/signature-replay-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .gemini/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .gemini/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .github/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .github/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install quillai-network/quillshield_skills signature-replay-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/quillai-network/quillshield_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/signature-replay-analysis/skills/signature-replay-analysis .opencode/skills/signature-replay-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "signature-replay-analysis" agent skill from https://github.com/quillai-network/quillshield_skills/tree/main/plugins/signature-replay-analysis/skills/signature-replay-analysis into .opencode/skills/signature-replay-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signature-replay-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
signature-replay-analysisDetects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts.
Signature Replay Analysis is an agent skill from quillai-network/quillshield_skills. Detects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts. Covers five replay types (same-chain, cross-chain, cross-contract, nonce-skip, expired-signature), EIP-712 domain separator verification, nonce management analysis, ecrecover edge cases (address(0), malleability, s-value), permit/permit2 safety, ERC-1271 contract wallet support, and meta-transaction security. Use when auditing contracts with ecrecover, ECDSA, EIP-712, permit, meta-transactions, multi-sig…
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/eip712-checklist.md` and `references/replay-taxonomy.md`).
It sits in Backend & APIs, covering Webhooks and Smart contracts. It works with Ethereum. The repository describes itself as: Structured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8bdd3c0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Signature Replay Analysis loads about 3.2k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 597 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from quillai-network/quillshield_skills at commit 8bdd3c0, republished under its MIT licence (© quillai-network). 597 words, ~3,241 tokens.
.claude/skills/signature-replay-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Detect vulnerabilities where cryptographic signatures can be reused, replayed across chains/contracts, or exploited through implementation flaws. Research shows 19.63% of Ethereum contracts using signatures contain replay vulnerabilities.
ecrecover, ECDSA, EIP-712)permit() / Uniswap Permit2 implementationsA signature proves that a specific private key holder authorized a specific action. For this to be secure, the signature must be:
Any gap in this model creates a replay vulnerability.
The exact same signature is submitted multiple times to the same contract on the same chain.
// VULNERABLE: No nonce — same signature works forever
function executeWithSig(address to, uint256 amount, bytes memory signature) external {
bytes32 hash = keccak256(abi.encodePacked(to, amount));
address signer = ECDSA.recover(hash, signature);
require(signer == admin, "Invalid signer");
token.transfer(to, amount);
// Attacker can submit this same signature again and again!
}
// SAFE: Use nonce
mapping(address => uint256) public nonces;
function executeWithSig(address to, uint256 amount, uint256 nonce, bytes memory signature) external {
require(nonce == nonces[admin], "Invalid nonce");
bytes32 hash = keccak256(abi.encodePacked(to, amount, nonce));
address signer = ECDSA.recover(hash, signature);
require(signer == admin, "Invalid signer");
nonces[admin]++;
token.transfer(to, amount);
}A signature valid on one chain (e.g., Ethereum) is replayed on another chain (e.g., Polygon, Arbitrum) where the same contract is deployed.
// VULNERABLE: No chainId in signed message
bytes32 hash = keccak256(abi.encodePacked(to, amount, nonce));
// This hash is identical on Ethereum, Polygon, Arbitrum, etc.
// SAFE: Include chainId (via EIP-712 domain separator)
bytes32 DOMAIN_SEPARATOR = keccak256(abi.encode(
keccak256("EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"),
keccak256(bytes("MyContract")),
keccak256(bytes("1")),
block.chainid,
address(this)
));A signature for Contract A is replayed on Contract B (same chain) if both accept the same message format without contract-specific binding.
// VULNERABLE: No contract address in signed message
bytes32 hash = keccak256(abi.encodePacked(to, amount, nonce, block.chainid));
// Same hash for any contract on this chain
// SAFE: Include verifyingContract (via EIP-712)
// The domain separator includes address(this), binding to this specific contractNonce implementation allows gaps or out-of-order execution, enabling skipped nonces to be replayed later.
// VULNERABLE: Bitmap nonce without invalidation
mapping(uint256 => bool) public usedNonces;
function execute(uint256 nonce, ...) external {
require(!usedNonces[nonce], "Used");
usedNonces[nonce] = true;
// If nonces 1, 2, 3 are used but 4 is skipped,
// nonce 4 can be used anytime in the future
// This may be intentional OR a vulnerability depending on context
}
// SAFER for strict ordering: Sequential nonce
mapping(address => uint256) public nonces;
function execute(uint256 nonce, ...) external {
require(nonce == nonces[signer], "Invalid nonce");
nonces[signer]++;
}A signature without a deadline can be held and executed at an arbitrary future time when conditions have changed.
// VULNERABLE: No deadline — signature valid forever
function permit(address owner, address spender, uint256 value, uint8 v, bytes32 r, bytes32 s) external {
bytes32 hash = keccak256(abi.encodePacked(owner, spender, value, nonces[owner]++));
require(ecrecover(hash, v, r, s) == owner, "Invalid");
allowance[owner][spender] = value;
// This permit can be executed weeks later when user doesn't expect it
}
// SAFE: Include deadline
function permit(address owner, address spender, uint256 value, uint256 deadline, uint8 v, bytes32 r, bytes32 s) external {
require(block.timestamp <= deadline, "Expired");
// ... rest of verification
}ecrecover returns address(0) for invalid signatures instead of reverting.
// VULNERABLE: address(0) accepted as valid signer
address signer = ecrecover(hash, v, r, s);
require(signer == owner, "Invalid");
// If owner == address(0) AND signature is invalid → passes!
// SAFE: Explicit zero check
address signer = ecrecover(hash, v, r, s);
require(signer != address(0), "Invalid signature");
require(signer == owner, "Wrong signer");
// SAFEST: Use OpenZeppelin's ECDSA.recover() — reverts on address(0)
address signer = ECDSA.recover(hash, signature);For every valid ECDSA signature (r, s, v), there exists a second valid signature (r, s', v') for the same message. This allows anyone to create an alternate valid signature without the private key.
// The Ethereum standard: s must be in the lower half of the curve
// s' = secp256k1n - s (the "flipped" signature)
// VULNERABLE: Accepts both s values
address signer = ecrecover(hash, v, r, s); // Works for both s and s'
// If used as a unique identifier, the same message has TWO valid signatures
// SAFE: Enforce lower-s (OpenZeppelin's ECDSA library does this)
require(uint256(s) <= 0x7FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF5D576E7357A4501DDFE92F46681B20A0, "Invalid s");// v should be 27 or 28 (Ethereum standard)
// Some implementations use 0 or 1 (subtract 27)
// Not normalizing v can cause signature verification to fail
require(v == 27 || v == 28, "Invalid v");bytes32 constant DOMAIN_TYPEHASH = keccak256(
"EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"
);
bytes32 DOMAIN_SEPARATOR = keccak256(abi.encode(
DOMAIN_TYPEHASH,
keccak256(bytes(name)), // Contract name
keccak256(bytes(version)), // Version string
block.chainid, // Chain ID — prevents cross-chain replay
address(this) // Contract address — prevents cross-contract replay
));| Field | Purpose | Missing = |
|---|---|---|
name | Identifies the signing domain | MEDIUM risk |
version | Prevents replay across upgrades | MEDIUM risk |
chainId | Prevents cross-chain replay | HIGH risk |
verifyingContract | Prevents cross-contract replay | HIGH risk |
salt (optional) | Additional disambiguation | LOW risk |
// MISTAKE 1: Hardcoded chainId (doesn't update on chain forks)
uint256 immutable CHAIN_ID = 1;
// After a fork, signatures valid on both chains!
// SAFE: Use block.chainid at verification time, or recalculate domain separator
function DOMAIN_SEPARATOR() public view returns (bytes32) {
if (block.chainid == INITIAL_CHAIN_ID) return _DOMAIN_SEPARATOR;
return _calculateDomainSeparator(); // Recalculate for new chain
}
// MISTAKE 2: Empty name/version
keccak256(bytes("")) // Valid but weak — same across all contracts with empty name
// MISTAKE 3: Missing struct type hash in message
// EIP-712 requires: hashStruct(message) = keccak256(typeHash + encodeData(message))
// Omitting typeHash weakens the domain binding- [ ] Uses EIP-712 domain separator with chainId and verifyingContract
- [ ] Includes per-user sequential nonce
- [ ] Includes deadline with block.timestamp check
- [ ] Uses ECDSA.recover (not raw ecrecover)
- [ ] Checks recovered address != address(0)
- [ ] Checks recovered address == owner parameter
- [ ] Nonce incremented BEFORE any state change
- [ ] Domain separator recalculated on chain fork- Permit2 uses nonce-bitmap approach (unordered nonces)
- Supports batch permits and transfer-with-permit
- Still requires deadline, domain separator, nonce management
- Contracts integrating Permit2 must verify the permit2 contract addressTask Progress:
- [ ] Step 1: Find all signature verification code (ecrecover, ECDSA.recover, EIP-712)
- [ ] Step 2: Check for same-chain replay protection (nonce management)
- [ ] Step 3: Check for cross-chain replay protection (chainId in domain/message)
- [ ] Step 4: Check for cross-contract replay protection (address(this) in domain/message)
- [ ] Step 5: Check deadline/expiry enforcement
- [ ] Step 6: Verify ecrecover safety (address(0) check, s-value, v-value)
- [ ] Step 7: Verify EIP-712 domain separator completeness
- [ ] Step 8: Check ERC-1271 support for contract wallets (if applicable)
- [ ] Step 9: Score findings and generate report## Signature & Replay Analysis Report
### Finding: [Title]
**Function:** `functionName()` at `Contract.sol:L42`
**Replay Type:** [Same-Chain | Cross-Chain | Cross-Contract | Nonce-Skip | Expired]
**Severity:** [CRITICAL | HIGH | MEDIUM]
**Issue:**
[Description of the replay vulnerability or signature verification flaw]
**Signed Message Fields:**
- [x] to/from addresses
- [x] amount/value
- [ ] chainId ← MISSING
- [ ] verifyingContract ← MISSING
- [x] nonce
- [ ] deadline ← MISSING
**Attack Scenario:**
1. User signs message for [intended purpose]
2. Attacker captures signature from [source]
3. Attacker replays on [target chain/contract/time]
4. [Unauthorized action occurs]
**Recommendation:**
[Add EIP-712 domain separator, add nonce, add deadline, use ECDSA.recover]chainId? (Prevents cross-chain replay)address(this)? (Prevents cross-contract replay)block.timestamp check? (Prevents late execution)ecrecover result checked against address(0)?ecrecover?isValidSignature supported?For replay type details, see {baseDir}/references/replay-taxonomy.md. For EIP-712 checklist, see {baseDir}/references/eip712-checklist.md.
© quillai-network, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/signature-replay-analysis/skills/signature-replay-analysis of quillai-network/quillshield_skills.
Open the folder on GitHubat commit 8bdd3c0
Signature Replay Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Signature Replay Analysis this skillquillai-network/quillshield_skills | 130 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Use Smart Contract Platformcirclefin/skills | 155 | — | ~2.9k | Automated safety check: Notes | Apache-2.0 | |
| AlchemyBankrBot/skills | 1.2k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Explorer Contract Verificationsablier-labs/evm-monorepo | 353 | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Developing Smart ContractsLFDT-Lineth/lineth-monorepo | 126 | — | ~1.4k | Automated safety check: Pass | AGPL-3.0 | |
| Deposit QrSuperior-Trade/superior-skills | 215 | — | ~1.1k | Automated safety check: Pass | MIT |
circlefin/skills
Deploy, import, interact with, and monitor smart contracts using Circle Smart Contract Platform APIs.
BankrBot/skills
Blockchain API access via Alchemy. An agent skill from BankrBot/skills.
sablier-labs/evm-monorepo
Verify smart contracts on Etherscan, Routescan, and Blockscout block explorers.
LFDT-Lineth/lineth-monorepo
Solidity smart contract development guidelines for Lineth blockchain.
Superior-Trade/superior-skills
A skill your agent uses when a user needs a QR code or wallet payment URI to fund a Superior-managed EVM wallet on a specific chain before using Lighter, Polymarket, Hyperliquid, or other Superior…
LFDT-Lineth/lineth-monorepo
Triage unresolved bot review comments on a GitHub PR. An agent skill from LFDT-Lineth/lineth-monorepo.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
quillai-network/quillshield_skills
Detects Denial of Service and griefing vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects unsafe external call patterns and token integration vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects input validation failures and arithmetic vulnerabilities in smart contracts.
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
quillai-network/quillshield_skills
Detects vulnerabilities in upgradeable proxy smart contracts including storage layout collisions, uninitialized implementations, function selector clashing, delegatecall context issues, and upgrade…
Works with
Categories
Detects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts. Signature Replay Analysis is an agent skill from quillai-network/quillshield_skills.63% of signature-using contracts.
Signature Replay Analysis fits situations like: auditing contracts with ecrecover; meta-transactions; any off-chain signature verification.
Run `npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a claude-code`. Or copy the skill folder (plugins/signature-replay-analysis/skills/signature-replay-analysis in quillai-network/quillshield_skills) into .claude/skills/signature-replay-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a codex`. Or copy the skill folder (plugins/signature-replay-analysis/skills/signature-replay-analysis in quillai-network/quillshield_skills) into .agents/skills/signature-replay-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add quillai-network/quillshield_skills --skill signature-replay-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/signature-replay-analysis, .gemini/skills/signature-replay-analysis, .github/skills/signature-replay-analysis and .opencode/skills/signature-replay-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Signature Replay Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Signature Replay Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Signature Replay Analysis: Use Smart Contract Platform (circlefin/skills, 155 stars), Alchemy (BankrBot/skills, 1.2k stars), Explorer Contract Verification (sablier-labs/evm-monorepo, 353 stars) and Developing Smart Contracts (LFDT-Lineth/lineth-monorepo, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
quillai-network (a GitHub organization) maintains it in quillai-network/quillshield_skills, which has 130 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on March 30, 2026.
Source: quillai-network/quillshield_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.