Agent skill

Smart Contract Security Review

by scalus3 in scalus3/scalus

Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus.

Apache-2.0Auto-check passedBackend & APIs

Install Smart Contract Security Review

skills CLI
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install scalus3/scalus smart-contract-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .claude/skills/smart-contract-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smart-contract-security-review
GitHub stars
105
Token cost
~4.2k tokens
SKILL.md length
1,589 words
Files
2 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus.

  • Works in 3 steps: Objects/classes with @Compile annotation → Objects extending Validator,… → Objects compiled with…
  • Reviewing on-chain code
  • SKILL.md covers Target Code Identification, Workflow, Vulnerability Checklist and False Positive Verification, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Smart Contract Security Review is an agent skill from scalus3/scalus. Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, ADA-only comparisons, rounding direction, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /smart-contract-security-review is invoked. Requires explicit path argument.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/vulnerabilities.md`).

It sits in Backend & APIs, covering Smart contracts, Smart contract auditing and Security review. The repository describes itself as: Scalus - Smart contracts & dApps Development Platform for Cardano. The licence is Apache-2.0.

When your agent uses it

  • Reviewing on-chain code
  • Before deploying validators
  • /smart-contract-security-review is invoked

Example prompts

  • “/smart-contract-security-review”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Objects/classes with @Compile annotation
  2. Objects extending Validator, DataParameterizedValidator, or ParameterizedValidator
  3. Objects compiled with PlutusV3.compile(), PlutusV2.compile(), or PlutusV1.compile()

What it can do on your machine

Read from SKILL.md and the folder at commit f830a36. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are scala).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart Contract Security Review loads about 4.2k tokens when it runs, and up to ~27k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,589 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~27k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from scalus3/scalus at commit f830a36, republished under its Apache-2.0 licence (© scalus3). 1,589 words, ~4,228 tokens.

Download SKILL.mdSave it as .claude/skills/smart-contract-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
smart-contract-security-review
description
Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, ADA-only comparisons, rounding direction, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /smart-contract-security-review is invoked. Requires explicit path argument.

Smart Contract Security Review

Analyze Scalus/Cardano smart contracts for security vulnerabilities.

Target Code Identification

Find on-chain code by searching for:

  1. Objects/classes with @Compile annotation
  2. Objects extending Validator, DataParameterizedValidator, or ParameterizedValidator
  3. Objects compiled with PlutusV3.compile(), PlutusV2.compile(), or PlutusV1.compile()

Search patterns:

grep -rn "@Compile" --include="*.scala" <path>
grep -rn "extends Validator" --include="*.scala" <path>
grep -rn "extends DataParameterizedValidator" --include="*.scala" <path>

Workflow

  1. Discovery: Find all @Compile annotated code in specified path
  2. Classification: Identify validator type (spend/mint/reward/certify/vote/propose)
  3. Analysis: Check each validator against vulnerability checklist
  4. False Positive Verification: For each potential issue, verify it's not a false positive
  5. Reporting: Generate structured report with severity levels (only verified issues)
  6. Remediation: Use TodoWrite to track issues, fix one-by-one with user confirmation

Vulnerability Checklist

Based on Cardano Developer Portal security guidelines and Scalus-specific patterns. For detailed patterns and code examples, see references/vulnerabilities.md. Taxonomy IDs are family-number (DS double satisfaction, VP value preservation, AU authentication, MI minting, TI time, DT datum, IX index, PU purpose, EV evaluation, AR arithmetic, RS resources, DE design). "Fixed by" names the Scalus operation or idiom that closes the class; "design" means no operation can, review the design.

Critical Severity
IDTaxonomyNameRiskDetectionFixed by
V001VP-3Redirect AttackFunds stolen via output redirectionoutputs.at(idx) without a whole-address checkfindContinuingOutputOrFail(ownInput, msg)
V002AU-1Token/NFT Not VerifiedState token excludedNo hasNft / hasOnly on the continuing outputout.value.hasNft(policy, name)
V003MI-1 / MI-3Inexact Burn/MintExtra tokens minted, partial burn>= instead of ===; quantityOf alone; forall(_._2 < 0) on a possibly empty maptx.mint.hasOnly(policy, name, signedQty); tx.onlyBurnsUnder(policy)
V004AR-1Rounding Direction (on-chain Integer is unbounded; there is no overflow)Remainder harvested per split action; negative amounts/ on fees or shares without a stated direction; redeemer amounts without > 0a divCeil b / a divFloor b (round against the party that benefits: contract payouts down, amounts owed to the contract up)
V005DS-1 / DS-2Double SatisfactionPay once, satisfy manyoutputs.exists without unique linking; >= payoutsinputs.findUniqueOrFail(_.resolved.address.credential === ownCred, msg) or hasPaidTagged(addr, value, tag)
V026VP-1Value Not Preserved on Continuing OutputContinuing UTxO drained while the datum looks rightDatum transition checked, .value never read; datum balance not tied to quantityOfout.value.hasSameTokensAndAtLeastAda(expected) or out.value === expected; bind datum balances with quantityOf
V027VP-2ADA-Only Value ComparisonNative tokens stripped while lovelace matchesgetLovelace as the only value check on a script UTxO (reading the amount with it is fine); getAdaFromOutputs / getAdaFromInputswhole Value: valuePaidTo(addr), valueSpentFrom(addr), ===; or withoutLovelace.isZero at the boundary
V028MI-2One-Shot Seed Not Bound"Unique" NFT mintable foreverTxOutRef parameter never compared with an input's outReffindInputOrFail(seed, msg) or inputs.at(i).outRef === seed; seed.deriveTokenName; mint.hasOnly
V029IX-2Missed InputA script input no index names is spent uncheckedLoop over redeemer indices, no walk over tx.inputswalk tx.inputs; UtxoIndexer.multiOneToOneNoRedeemer
High Severity
IDTaxonomyNameRiskDetectionFixed by
V006IX-1Index Validation MissingWrong element behind an index.at(idx) from the redeemer with no check on the elementfindInputOrFail, findUniqueOrFail, singleOrFail
V007DE-3Self-Dealing/Shill BiddingPrice manipulationNo seller/bidder separationdesign: require(!(bidder === seller))
V008IX-1Double Spend via IndexSame UTxO processed twiceIndex lists without uniqueness; zip truncationstrictly ascending indices; UtxoIndexer
V009VP-4Inexact Refund AmountFund manipulation, enables V005>= for refunds instead of ===out.value === Value.lovelace(n) (whole value); hasPaidTagged
V010PU-1Other Redeemer AttackBypass via different redeemer or purposeSeveral purposes/branches with weaker checks; StakeValidator.spendMinimal aloneplugin default fail for unimplemented purposes (false positive for single-purpose objects, see below); StakeValidator.spend with a redeemer validator
V011MI-1Other Token Name AttackUnauthorized token mintingquantityOf on one name, rest of the policy uncheckedtx.mint.hasOnly(policy, name, qty); mint.tokens(policy) === expected.tokens(policy)
V012AU-1 / AU-5Missing UTxO AuthenticationFake UTxO or planted reference-input datumNo auth token on own input or reference inputownInput.resolved.value.hasNft(authPolicy, name); one-shot policy (V028)
V025DE-2Oracle Data ValidationPrice manipulation, stale dataOracle data without signature/freshnessdesign: verifyEd25519Signature + domain separation (V031), freshness vs validToOrFail
V030EV-1Evaluation-Order TrapSecurity check never evaluatedCheck on the right of || or in an untaken branch; pattern callback ending in a Booleanone obligation per require; callbacks return Unit
V031AU-7Signature Domain SeparationOff-chain signature replayed across instancesverifyEd25519Signature over a payload without script hash and noncedesign: payload commits to domain tag, own script hash, spent TxOutRef
V032PU-3Certificate Purposes UnguardedDeregistration griefing, deposit theftcertify body () or permissive case _ => ()plugin default fail; explicit TxCert match with failing default
Medium Severity
IDTaxonomyNameRiskDetectionFixed by
V013TI-1 / TI-2Time HandlingUnbounded range read as time 0; wrong inclusivitygetValidityStartTime (deprecated, returns 0 when unbounded); raw bound comparedvalidFromOrFail(msg) (inclusive) / validToOrFail(msg) (exclusive); isEntirelyAfter/Before
V014AU-2Missing SignatureUnauthorized actions; script owner cannot signNo isSignedBy on a branch; isSignedBy on a script hashisSignedBy / isSignedByAny for keys; for a script authority prove it ran (withdrawal or spent input)
V015DT-1Datum MutationUnauthorized state changeField-by-field comparison with a field missingout.hasInlineDatum(old.copy(...))
V016AU-4Insufficient Staking ControlReward redirection (franken address)address.credential ===, === Address.fromScriptHash(h), credential-only finders on the continuing outputfindContinuingOutputOrFail; or require(out.address === ownInput.resolved.address)
V017DT-3Arbitrary DatumUnspendable UTxOs, datum-hash brickingNo datum validation; hash-only datum acceptedout.datum.inlineOrFail[T](msg); out.hasInlineDatum(x)
V024AU-6Parameterization VerificationScript substitution (varies)ParameterizedValidator with auth params, no tokenauth NFT via hasNft + one-shot policy; design
V033PU-4Voting / Proposing Purposes UnguardedGovernance actions approved silentlyHand-written ScriptInfo dispatcher with case _ => ()plugin default fail; explicit vote / propose with authorization
V034VP-5Value-Map NormalisationLocked UTxO or false equality on a non-canonical ValueValue field in datum/redeemer compared with ===Value.valueFromDataWithValidation at the boundary; ledger values are canonical
V035VP-6Min-ADA GriefingForced output pushed below min-ADA, UTxO stuckWhole-value preservation on a UTxO anyone can pay intobound the token set at deposit: withoutLovelace.isZero, hasSameTokensAndAtLeastAda
V036DE-4Hash GrindingAttacker grinds a hash-derived outcometx.id / out-ref hash used as randomnessdesign: commit-reveal
Show full SKILL.md (641 more words)Show less
Low Severity / Design Issues
IDTaxonomyNameRiskDetectionFixed by
V018RS-1Unbounded ValueUTxO size limit, min-ADA leverUnlimited tokens in outputwithoutLovelace.isZero; hasSameTokensAndAtLeastAda pins the token set
V019RS-2Unbounded DatumResource exhaustionGrowing datum sizedesign: bound every list
V020RS-3Unbounded InputsTX limit exceededMany required UTxOsdesign: batching
V021RS-5UTxO Contention / Concurrency DoSBottleneck, DoSShared global state, no rate limitdesign: per-user UTxOs
V022RS-6Cheap Spam/DustOperation obstructionNo minimum amountsdesign: minimum require
V023DE-1Locked ValuePermanent lockMissing exit pathsdesign: exit path per state
V037RS-7Reference-Script SizeFee blow-up, size cap exceededLarge compiled scripts, many per transactiondesign: report script size, split logic

Checklist rules:

  1. V010, V032, V033: a purpose the validator object does not define is completed by the compiler plugin with a body that fails, so an undefined purpose is never an entry point. Report only purposes the object defines.
  2. V001 and V016 together: a credential-only finder or Address.fromScriptHash never proves the continuing output; only the whole address does.
  3. V027 before V005: when a value check reads .getLovelace, ask whether tokens can be in the UTxO before asking whether one output can serve two inputs.
  4. V013: any getValidityStartTime is a finding; a validFromOrFail / validToOrFail is not.

False Positive Verification

Before you report a vulnerability, verify that it is exploitable: trace the code with a concrete attack transaction. A pattern match alone produces false positives.

Verification Method: Attack Transaction Tracing

For each potential vulnerability:

  1. Construct a concrete attack transaction

    • Define specific inputs (UTxOs with concrete values/datums)
    • Define the redeemer values
    • Define the outputs the attacker would create
    • Define signatories
  2. Execute the validator logic mentally with this transaction

    • Go line-by-line through the validator code
    • Track what each variable evaluates to with your attack tx
    • Check each require() statement - does it pass or fail?
  3. If a require fails, the attack fails: the finding is a false positive.

  4. Report the finding only if every require passes with the attack transaction.

Example: V005 Double Satisfaction Verification

Potential vulnerability detected: handlePay sums the seller's outputs by credential without unique linking.

Construct attack transaction:

Inputs:
  - EscrowA: 12 ADA, datum={seller=S, buyer=B, escrowAmount=10, initAmount=2}
  - EscrowB: 12 ADA, datum={seller=S, buyer=B, escrowAmount=10, initAmount=2}
Outputs:
  - 12 ADA to seller S (single output for both!)
  - 1 ADA to buyer B
Signatories: [B]

Trace execution for EscrowA:

scala
// Line 58-61, before any handler:
txInfo.inputs.findUniqueOrFail(
  _.resolved.address.credential === contractAddress.credential,
  "Exactly one escrow input may be spent"
)
// → inputs at the script credential: [EscrowA, EscrowB] → two matches → FAILS ❌

// Line 63: never reached
val contractBalance = txInfo.valueSpentFrom(contractAddress).getLovelace

Result: Attack transaction fails at line 58-61. V005 is a FALSE POSITIVE.

Second look at the same lines (V027): contractBalance and the seller sum are compared on .getLovelace only. Attack transaction 2: EscrowA holds 12 ADA + 500 USDM; outputs 12 ADA to S and 500 USDM to B. Both lovelace checks pass, the tokens leave. This is a V027 finding unless the contract proves the UTxO is ADA-only at the boundary; EscrowValidator does (handleDeposit: txInfo.valuePaidTo(contractAddress) === Value.lovelace(escrowAmount + initializationAmount)), so here it is not reported. Without that proof, report it.

When to Write a Test

If the attack trace is complex or you're uncertain, write an actual test:

scala
test("V005: Double satisfaction attack should fail") {
  // Setup: Create two escrow UTxOs with same seller
  val escrowA = createEscrowUtxo(seller = S, buyer = B, amount = 10.ada)
  val escrowB = createEscrowUtxo(seller = S, buyer = B, amount = 10.ada)

  // Attack: Try to spend both with single output to seller
  val attackTx = Transaction(
    inputs = List(escrowA, escrowB),
    outputs = List(TxOut(sellerAddress, 12.ada)),  // Only pay once!
    redeemers = Map(escrowA -> Pay, escrowB -> Pay)
  )

  // Verify: Should this pass or fail?
  // If it passes → Real vulnerability
  // If it fails → False positive
  evaluateValidator(EscrowValidator, escrowA, attackTx) shouldBe failure
}
Verification Checklist

Before reporting, answer these questions:

QuestionAnswer Required
What is the specific attack transaction?Inputs, outputs, redeemers, signatories
Which line would the attacker exploit?File:line reference
Did you trace through EVERY require in the code path?Yes/No
Does the attack pass ALL requires?Yes (report) / No (false positive)
What value does the attacker gain?Concrete amount/asset
Do NOT Report If
  • You only found a pattern match without tracing execution
  • You haven't constructed a specific attack transaction
  • Any require() in the code path would fail the attack
  • You're unsure whether the attack works (investigate more or write a test)

Output Format

Use clickable file_path:line_number format for all code locations.

Finding Format

For each vulnerability found, output in this format:

### [SEVERITY] ID: Vulnerability Name

**Location:** `full/path/to/File.scala:LINE`
**Method:** methodName

**Issue:** Brief description of what's wrong

**Vulnerable code** (`full/path/to/File.scala:LINE-LINE`):
```scala
// actual code from file

Fix:

scala
// proposed fix


### Summary Table

At the end, provide a summary with clickable locations:

Summary

IDSeverityLocationIssueStatus
C-01Criticalpath/File.scala:123Missing mint validationFixed
H-01Highpath/File.scala:87Token not in outputDeclined
M-01Mediumpath/File.scala:200Missing signatureFalse Positive

False Positives

IDLocationReason
M-01path/File.scala:200Authorization is done via NFT ownership in verifyAuth helper

Security Grade: A/B/C/D/F


### Location Format Rules

1. Always use full path from project root: `scalus-examples/jvm/src/.../File.scala:123`
2. For ranges use: `File.scala:123-145`
3. For method references: `File.scala:123` (methodName)
4. Make locations clickable by using backticks

## Interactive Workflow

For each finding:
1. Display issue with location and proposed fix
2. Prompt: "Apply fix? [y/n/s/d/f]"
   - y: Apply fix, mark completed, verify with `sbtn compile`
   - n: Skip, log as "declined"
   - s: Skip without logging
   - d: Show more details (attack scenario)
   - f: Mark as false positive (prompts for reason, logged to summary)
3. After all findings: run `sbtn quick` to verify fixes
4. Generate summary report including:
   - Fixed issues
   - Declined issues
   - False positives with reasons

## Reference

For detailed vulnerability patterns and code examples, see:
- `references/vulnerabilities.md` - Full pattern documentation with Scalus-specific examples

© scalus3, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in scalus-skills/skills/smart-contract-security-review of scalus3/scalus.

  • SKILL.md
  • references/vulnerabilities.md

Open the folder on GitHubat commit f830a36

Compare with similar skills

Smart Contract Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart Contract Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart Contract Security Review this skillscalus3/scalus105—~4.2kAutomated safety check: PassApache-2.0
Solidity AuditorGabson0x/bountyforge442—~3.7kAutomated safety check: PassNone
Solidity Auditorpashov/skills1.2k—~9.9kAutomated safety check: PassMIT
Defi Amm Securityaffaan-m/ECC276k1 repos~1.3kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill573—~3.8kAutomated safety check: PassMIT

Similar skills

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    pashov/skills

    Security audit of Solidity code while you develop. An agent skill from pashov/skills.

    1.2k GitHub stars~9.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    276k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    573 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed

More from scalus3/scalus

  • Optimize Contract

    scalus3/scalus

    Optimize Scalus/Cardano smart contracts for execution budget (CPU steps and memory).

    105 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Contract

    scalus3/scalus

    Guide for developing Scalus smart contracts. An agent skill from scalus3/scalus.

    105 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Contract Test

    scalus3/scalus

    Guide for testing Scalus smart contracts. An agent skill from scalus3/scalus.

    105 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Local Development

    scalus3/scalus

    A skill your agent uses when developing or testing Scalus smart contracts with the local Emulator and TxBuilder.

    105 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Pretty

    scalus3/scalus

    A skill your agent uses when writing or changing a Pretty typeclass instance (paiges Doc DSL) in scalus-core, for example in scalus/utils/Pretty.scala or the cardano/ledger types.

    105 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Using Scalus

    scalus3/scalus

    Use at the start of any task in a Scalus project, to choose the Scalus skill for smart contract work.

    105 GitHub stars~321 tokensUpdated today
    Auto-check passed

Questions about Smart Contract Security Review

What does Smart Contract Security Review do?

Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus. Smart Contract Security Review is an agent skill from scalus3/scalus. Security review for Scalus/Cardano smart contracts.

When should I use Smart Contract Security Review?

Smart Contract Security Review fits situations like: reviewing on-chain code; before deploying validators; /smart-contract-security-review is invoked.

How do I install Smart Contract Security Review in Claude Code?

Run `npx skills add scalus3/scalus --skill smart-contract-security-review -a claude-code`. Or copy the skill folder (scalus-skills/skills/smart-contract-security-review in scalus3/scalus) into .claude/skills/smart-contract-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Smart Contract Security Review in Codex?

Run `npx skills add scalus3/scalus --skill smart-contract-security-review -a codex`. Or copy the skill folder (scalus-skills/skills/smart-contract-security-review in scalus3/scalus) into .agents/skills/smart-contract-security-review in your project. Codex loads it when a task matches its description.

Can I use Smart Contract Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add scalus3/scalus --skill smart-contract-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-security-review, .gemini/skills/smart-contract-security-review, .github/skills/smart-contract-security-review and .opencode/skills/smart-contract-security-review in your project.

What does Smart Contract Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Smart Contract Security Review is instructions for the agent only.

Does Smart Contract Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart Contract Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Smart Contract Security Review use?

Smart Contract Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Smart Contract Security Review use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Smart Contract Security Review?

Skills that share tags, products or a category with Smart Contract Security Review: Solidity Auditor (Gabson0x/bountyforge, 442 stars), Solidity Auditor (pashov/skills, 1.2k stars), Defi Amm Security (affaan-m/ECC, 276k stars) and Fizz Convert (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart Contract Security Review?

scalus3 (a GitHub organization) maintains it in scalus3/scalus, which has 105 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.

Source: scalus3/scalus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.