Security audit and code review for Solidity smart contracts.

Custom licenceAuto-check passedBackend & APIs

Install Audit

skills CLI
$ npx skills add sablier-labs/evm-monorepo --skill audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sablier-labs/evm-monorepo audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sablier-labs/evm-monorepo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit .claude/skills/audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit
GitHub stars
353
Token cost
~1.8k tokens
SKILL.md length
621 words
Files
5 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
Custom licence

At a glance

Security audit and code review for Solidity smart contracts.

  • Works in 4 steps: No new code violates existing invariants → New features have corresponding… → State transitions follow documented… → …
  • Phrases - audit
  • SKILL.md covers Bundled References, Review Types, Self-Review Checklist and PR Review Issues, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit is an agent skill from sablier-labs/evm-monorepo. Security audit and code review for Solidity smart contracts. Trigger phrases - audit, check PR, security review, pre-audit preparation, vulnerability check, or when preparing code for external audit.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/audit-workflow.md` and `references/pre-audit-checklist.md`).

It sits in Backend & APIs, covering Smart contracts, Security review and Audit readiness. It works with Solidity. The repository describes itself as: Monorepo for Sablier's EVM smart contracts including Lockup, Flow, Airdrops, Bob and Utils protocols.

When your agent uses it

  • Phrases - audit
  • Security review
  • Pre-audit preparation
  • Vulnerability check

Example prompts

  • “/audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. No new code violates existing invariants
  2. New features have corresponding invariants added
  3. State transitions follow documented valid paths
  4. Aggregate amounts remain consistent

What it can do on your machine

Read from SKILL.md and the folder at commit f317dc2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit loads about 1.8k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 621 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 621 words (~1,848 tokens).

“This skill is coordination-exempt: skip the ai-coord gate for its declared work.”

— opening of SKILL.md by sablier-labs, Custom licence
name
audit
coordination
exempt

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in .agents/skills/audit of sablier-labs/evm-monorepo.

  • SKILL.md
  • agents/openai.yaml
  • references/audit-workflow.md
  • references/pre-audit-checklist.md
  • references/vulnerability-checklist.md

Open the folder on GitHubat commit f317dc2

Compare with similar skills

Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit this skillsablier-labs/evm-monorepo353—~1.8kAutomated safety check: PassCustom licence
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k—~9.9kAutomated safety check: PassMIT
Audit PrepPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Flounderadshao/flounder519—~9.2kAutomated safety check: PassAGPL-3.0
Defi Amm Securityaffaan-m/ECC276k1 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub stars~9.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Flounder

    adshao/flounder

    Operates Flounder, an autonomous white-hat security auditor.

    519 GitHub stars~9.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    276k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed

More from sablier-labs/evm-monorepo

  • Protocol Deployment

    sablier-labs/evm-monorepo

    Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Explorer Contract Verification

    sablier-labs/evm-monorepo

    Verify smart contracts on Etherscan, Routescan, and Blockscout block explorers.

    353 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Foundry Testing

    sablier-labs/evm-monorepo

    Write Foundry tests, bulloak BTT tree specs, and Solidity scripts.

    353 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Solidity Coding

    sablier-labs/evm-monorepo

    Write production-quality Solidity contracts. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Handbook

    sablier-labs/evm-monorepo

    Protocol domain knowledge - Lockup (vesting), Flow (streaming), Airdrops (merkle distribution).

    353 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Audit

What does Audit do?

Security audit and code review for Solidity smart contracts. Audit is an agent skill from sablier-labs/evm-monorepo. Security audit and code review for Solidity smart contracts.

When should I use Audit?

Audit fits situations like: phrases - audit; security review; pre-audit preparation; vulnerability check.

How do I install Audit in Claude Code?

Run `npx skills add sablier-labs/evm-monorepo --skill audit -a claude-code`. Or copy the skill folder (.agents/skills/audit in sablier-labs/evm-monorepo) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.

How do I install Audit in Codex?

Run `npx skills add sablier-labs/evm-monorepo --skill audit -a codex`. Or copy the skill folder (.agents/skills/audit in sablier-labs/evm-monorepo) into .agents/skills/audit in your project. Codex loads it when a task matches its description.

Can I use Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sablier-labs/evm-monorepo --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.

What does Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit is instructions for the agent only.

Does Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit use?

Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Audit use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Audit?

Skills that share tags, products or a category with Audit: Solidity Auditor (Gabson0x/bountyforge, 442 stars), Solidity Auditor (pashov/skills, 1.2k stars), Audit Prep (PlamenTSV/plamen, 303 stars) and Flounder (adshao/flounder, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit?

sablier-labs (a GitHub organization) maintains it in sablier-labs/evm-monorepo, which has 353 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: sablier-labs/evm-monorepo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.