Solidity Auditor
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus.
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install scalus3/scalus smart-contract-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .claude/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .claude/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install scalus3/scalus smart-contract-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .agents/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .agents/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .agents/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install scalus3/scalus smart-contract-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .cursor/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .cursor/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/scalus3/scalus.git --path scalus-skills/skills/smart-contract-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install scalus3/scalus smart-contract-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .gemini/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .gemini/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install scalus3/scalus smart-contract-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .github/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .github/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .github/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add scalus3/scalus --skill smart-contract-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install scalus3/scalus smart-contract-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scalus3/scalus.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/scalus-skills/skills/smart-contract-security-review .opencode/skills/smart-contract-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "smart-contract-security-review" agent skill from https://github.com/scalus3/scalus/tree/master/scalus-skills/skills/smart-contract-security-review into .opencode/skills/smart-contract-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "smart-contract-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
smart-contract-security-reviewSecurity review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus.
Smart Contract Security Review is an agent skill from scalus3/scalus. Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, ADA-only comparisons, rounding direction, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /smart-contract-security-review is invoked. Requires explicit path argument.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/vulnerabilities.md`).
It sits in Backend & APIs, covering Smart contracts, Smart contract auditing and Security review. The repository describes itself as: Scalus - Smart contracts & dApps Development Platform for Cardano. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f830a36. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are scala).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Smart Contract Security Review loads about 4.2k tokens when it runs, and up to ~27k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,589 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from scalus3/scalus at commit f830a36, republished under its Apache-2.0 licence (© scalus3). 1,589 words, ~4,228 tokens.
.claude/skills/smart-contract-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Analyze Scalus/Cardano smart contracts for security vulnerabilities.
Find on-chain code by searching for:
@Compile annotationValidator, DataParameterizedValidator, or ParameterizedValidatorPlutusV3.compile(), PlutusV2.compile(), or PlutusV1.compile()Search patterns:
grep -rn "@Compile" --include="*.scala" <path>
grep -rn "extends Validator" --include="*.scala" <path>
grep -rn "extends DataParameterizedValidator" --include="*.scala" <path>@Compile annotated code in specified pathBased on Cardano Developer Portal security guidelines and Scalus-specific patterns.
For detailed patterns and code examples, see references/vulnerabilities.md.
Taxonomy IDs are family-number (DS double satisfaction, VP value preservation, AU
authentication, MI minting, TI time, DT datum, IX index, PU purpose, EV evaluation, AR
arithmetic, RS resources, DE design). "Fixed by" names the Scalus operation or idiom that
closes the class; "design" means no operation can, review the design.
| ID | Taxonomy | Name | Risk | Detection | Fixed by |
|---|---|---|---|---|---|
| V001 | VP-3 | Redirect Attack | Funds stolen via output redirection | outputs.at(idx) without a whole-address check | findContinuingOutputOrFail(ownInput, msg) |
| V002 | AU-1 | Token/NFT Not Verified | State token excluded | No hasNft / hasOnly on the continuing output | out.value.hasNft(policy, name) |
| V003 | MI-1 / MI-3 | Inexact Burn/Mint | Extra tokens minted, partial burn | >= instead of ===; quantityOf alone; forall(_._2 < 0) on a possibly empty map | tx.mint.hasOnly(policy, name, signedQty); tx.onlyBurnsUnder(policy) |
| V004 | AR-1 | Rounding Direction (on-chain Integer is unbounded; there is no overflow) | Remainder harvested per split action; negative amounts | / on fees or shares without a stated direction; redeemer amounts without > 0 | a divCeil b / a divFloor b (round against the party that benefits: contract payouts down, amounts owed to the contract up) |
| V005 | DS-1 / DS-2 | Double Satisfaction | Pay once, satisfy many | outputs.exists without unique linking; >= payouts | inputs.findUniqueOrFail(_.resolved.address.credential === ownCred, msg) or hasPaidTagged(addr, value, tag) |
| V026 | VP-1 | Value Not Preserved on Continuing Output | Continuing UTxO drained while the datum looks right | Datum transition checked, .value never read; datum balance not tied to quantityOf | out.value.hasSameTokensAndAtLeastAda(expected) or out.value === expected; bind datum balances with quantityOf |
| V027 | VP-2 | ADA-Only Value Comparison | Native tokens stripped while lovelace matches | getLovelace as the only value check on a script UTxO (reading the amount with it is fine); getAdaFromOutputs / getAdaFromInputs | whole Value: valuePaidTo(addr), valueSpentFrom(addr), ===; or withoutLovelace.isZero at the boundary |
| V028 | MI-2 | One-Shot Seed Not Bound | "Unique" NFT mintable forever | TxOutRef parameter never compared with an input's outRef | findInputOrFail(seed, msg) or inputs.at(i).outRef === seed; seed.deriveTokenName; mint.hasOnly |
| V029 | IX-2 | Missed Input | A script input no index names is spent unchecked | Loop over redeemer indices, no walk over tx.inputs | walk tx.inputs; UtxoIndexer.multiOneToOneNoRedeemer |
| ID | Taxonomy | Name | Risk | Detection | Fixed by |
|---|---|---|---|---|---|
| V006 | IX-1 | Index Validation Missing | Wrong element behind an index | .at(idx) from the redeemer with no check on the element | findInputOrFail, findUniqueOrFail, singleOrFail |
| V007 | DE-3 | Self-Dealing/Shill Bidding | Price manipulation | No seller/bidder separation | design: require(!(bidder === seller)) |
| V008 | IX-1 | Double Spend via Index | Same UTxO processed twice | Index lists without uniqueness; zip truncation | strictly ascending indices; UtxoIndexer |
| V009 | VP-4 | Inexact Refund Amount | Fund manipulation, enables V005 | >= for refunds instead of === | out.value === Value.lovelace(n) (whole value); hasPaidTagged |
| V010 | PU-1 | Other Redeemer Attack | Bypass via different redeemer or purpose | Several purposes/branches with weaker checks; StakeValidator.spendMinimal alone | plugin default fail for unimplemented purposes (false positive for single-purpose objects, see below); StakeValidator.spend with a redeemer validator |
| V011 | MI-1 | Other Token Name Attack | Unauthorized token minting | quantityOf on one name, rest of the policy unchecked | tx.mint.hasOnly(policy, name, qty); mint.tokens(policy) === expected.tokens(policy) |
| V012 | AU-1 / AU-5 | Missing UTxO Authentication | Fake UTxO or planted reference-input datum | No auth token on own input or reference input | ownInput.resolved.value.hasNft(authPolicy, name); one-shot policy (V028) |
| V025 | DE-2 | Oracle Data Validation | Price manipulation, stale data | Oracle data without signature/freshness | design: verifyEd25519Signature + domain separation (V031), freshness vs validToOrFail |
| V030 | EV-1 | Evaluation-Order Trap | Security check never evaluated | Check on the right of || or in an untaken branch; pattern callback ending in a Boolean | one obligation per require; callbacks return Unit |
| V031 | AU-7 | Signature Domain Separation | Off-chain signature replayed across instances | verifyEd25519Signature over a payload without script hash and nonce | design: payload commits to domain tag, own script hash, spent TxOutRef |
| V032 | PU-3 | Certificate Purposes Unguarded | Deregistration griefing, deposit theft | certify body () or permissive case _ => () | plugin default fail; explicit TxCert match with failing default |
| ID | Taxonomy | Name | Risk | Detection | Fixed by |
|---|---|---|---|---|---|
| V013 | TI-1 / TI-2 | Time Handling | Unbounded range read as time 0; wrong inclusivity | getValidityStartTime (deprecated, returns 0 when unbounded); raw bound compared | validFromOrFail(msg) (inclusive) / validToOrFail(msg) (exclusive); isEntirelyAfter/Before |
| V014 | AU-2 | Missing Signature | Unauthorized actions; script owner cannot sign | No isSignedBy on a branch; isSignedBy on a script hash | isSignedBy / isSignedByAny for keys; for a script authority prove it ran (withdrawal or spent input) |
| V015 | DT-1 | Datum Mutation | Unauthorized state change | Field-by-field comparison with a field missing | out.hasInlineDatum(old.copy(...)) |
| V016 | AU-4 | Insufficient Staking Control | Reward redirection (franken address) | address.credential ===, === Address.fromScriptHash(h), credential-only finders on the continuing output | findContinuingOutputOrFail; or require(out.address === ownInput.resolved.address) |
| V017 | DT-3 | Arbitrary Datum | Unspendable UTxOs, datum-hash bricking | No datum validation; hash-only datum accepted | out.datum.inlineOrFail[T](msg); out.hasInlineDatum(x) |
| V024 | AU-6 | Parameterization Verification | Script substitution (varies) | ParameterizedValidator with auth params, no token | auth NFT via hasNft + one-shot policy; design |
| V033 | PU-4 | Voting / Proposing Purposes Unguarded | Governance actions approved silently | Hand-written ScriptInfo dispatcher with case _ => () | plugin default fail; explicit vote / propose with authorization |
| V034 | VP-5 | Value-Map Normalisation | Locked UTxO or false equality on a non-canonical Value | Value field in datum/redeemer compared with === | Value.valueFromDataWithValidation at the boundary; ledger values are canonical |
| V035 | VP-6 | Min-ADA Griefing | Forced output pushed below min-ADA, UTxO stuck | Whole-value preservation on a UTxO anyone can pay into | bound the token set at deposit: withoutLovelace.isZero, hasSameTokensAndAtLeastAda |
| V036 | DE-4 | Hash Grinding | Attacker grinds a hash-derived outcome | tx.id / out-ref hash used as randomness | design: commit-reveal |
| ID | Taxonomy | Name | Risk | Detection | Fixed by |
|---|---|---|---|---|---|
| V018 | RS-1 | Unbounded Value | UTxO size limit, min-ADA lever | Unlimited tokens in output | withoutLovelace.isZero; hasSameTokensAndAtLeastAda pins the token set |
| V019 | RS-2 | Unbounded Datum | Resource exhaustion | Growing datum size | design: bound every list |
| V020 | RS-3 | Unbounded Inputs | TX limit exceeded | Many required UTxOs | design: batching |
| V021 | RS-5 | UTxO Contention / Concurrency DoS | Bottleneck, DoS | Shared global state, no rate limit | design: per-user UTxOs |
| V022 | RS-6 | Cheap Spam/Dust | Operation obstruction | No minimum amounts | design: minimum require |
| V023 | DE-1 | Locked Value | Permanent lock | Missing exit paths | design: exit path per state |
| V037 | RS-7 | Reference-Script Size | Fee blow-up, size cap exceeded | Large compiled scripts, many per transaction | design: report script size, split logic |
Checklist rules:
object does not define is completed by the compiler
plugin with a body that fails, so an undefined purpose is never an entry point. Report only
purposes the object defines.Address.fromScriptHash never proves the
continuing output; only the whole address does..getLovelace, ask whether tokens can be in the
UTxO before asking whether one output can serve two inputs.getValidityStartTime is a finding; a validFromOrFail / validToOrFail is not.Before you report a vulnerability, verify that it is exploitable: trace the code with a concrete attack transaction. A pattern match alone produces false positives.
For each potential vulnerability:
Construct a concrete attack transaction
Execute the validator logic mentally with this transaction
require() statement - does it pass or fail?If a require fails, the attack fails: the finding is a false positive.
Report the finding only if every require passes with the attack transaction.
Potential vulnerability detected: handlePay sums the seller's outputs by credential without unique linking.
Construct attack transaction:
Inputs:
- EscrowA: 12 ADA, datum={seller=S, buyer=B, escrowAmount=10, initAmount=2}
- EscrowB: 12 ADA, datum={seller=S, buyer=B, escrowAmount=10, initAmount=2}
Outputs:
- 12 ADA to seller S (single output for both!)
- 1 ADA to buyer B
Signatories: [B]Trace execution for EscrowA:
// Line 58-61, before any handler:
txInfo.inputs.findUniqueOrFail(
_.resolved.address.credential === contractAddress.credential,
"Exactly one escrow input may be spent"
)
// → inputs at the script credential: [EscrowA, EscrowB] → two matches → FAILS ❌
// Line 63: never reached
val contractBalance = txInfo.valueSpentFrom(contractAddress).getLovelaceResult: Attack transaction fails at line 58-61. V005 is a FALSE POSITIVE.
Second look at the same lines (V027): contractBalance and the seller sum are compared on
.getLovelace only. Attack transaction 2: EscrowA holds 12 ADA + 500 USDM; outputs 12 ADA to S
and 500 USDM to B. Both lovelace checks pass, the tokens leave. This is a V027 finding unless
the contract proves the UTxO is ADA-only at the boundary; EscrowValidator does
(handleDeposit: txInfo.valuePaidTo(contractAddress) === Value.lovelace(escrowAmount + initializationAmount)),
so here it is not reported. Without that proof, report it.
If the attack trace is complex or you're uncertain, write an actual test:
test("V005: Double satisfaction attack should fail") {
// Setup: Create two escrow UTxOs with same seller
val escrowA = createEscrowUtxo(seller = S, buyer = B, amount = 10.ada)
val escrowB = createEscrowUtxo(seller = S, buyer = B, amount = 10.ada)
// Attack: Try to spend both with single output to seller
val attackTx = Transaction(
inputs = List(escrowA, escrowB),
outputs = List(TxOut(sellerAddress, 12.ada)), // Only pay once!
redeemers = Map(escrowA -> Pay, escrowB -> Pay)
)
// Verify: Should this pass or fail?
// If it passes → Real vulnerability
// If it fails → False positive
evaluateValidator(EscrowValidator, escrowA, attackTx) shouldBe failure
}Before reporting, answer these questions:
| Question | Answer Required |
|---|---|
| What is the specific attack transaction? | Inputs, outputs, redeemers, signatories |
| Which line would the attacker exploit? | File:line reference |
| Did you trace through EVERY require in the code path? | Yes/No |
| Does the attack pass ALL requires? | Yes (report) / No (false positive) |
| What value does the attacker gain? | Concrete amount/asset |
require() in the code path would fail the attackUse clickable file_path:line_number format for all code locations.
For each vulnerability found, output in this format:
### [SEVERITY] ID: Vulnerability Name
**Location:** `full/path/to/File.scala:LINE`
**Method:** methodName
**Issue:** Brief description of what's wrong
**Vulnerable code** (`full/path/to/File.scala:LINE-LINE`):
```scala
// actual code from fileFix:
// proposed fix
### Summary Table
At the end, provide a summary with clickable locations:
| ID | Severity | Location | Issue | Status |
|---|---|---|---|---|
| C-01 | Critical | path/File.scala:123 | Missing mint validation | Fixed |
| H-01 | High | path/File.scala:87 | Token not in output | Declined |
| M-01 | Medium | path/File.scala:200 | Missing signature | False Positive |
| ID | Location | Reason |
|---|---|---|
| M-01 | path/File.scala:200 | Authorization is done via NFT ownership in verifyAuth helper |
Security Grade: A/B/C/D/F
### Location Format Rules
1. Always use full path from project root: `scalus-examples/jvm/src/.../File.scala:123`
2. For ranges use: `File.scala:123-145`
3. For method references: `File.scala:123` (methodName)
4. Make locations clickable by using backticks
## Interactive Workflow
For each finding:
1. Display issue with location and proposed fix
2. Prompt: "Apply fix? [y/n/s/d/f]"
- y: Apply fix, mark completed, verify with `sbtn compile`
- n: Skip, log as "declined"
- s: Skip without logging
- d: Show more details (attack scenario)
- f: Mark as false positive (prompts for reason, logged to summary)
3. After all findings: run `sbtn quick` to verify fixes
4. Generate summary report including:
- Fixed issues
- Declined issues
- False positives with reasons
## Reference
For detailed vulnerability patterns and code examples, see:
- `references/vulnerabilities.md` - Full pattern documentation with Scalus-specific examples© scalus3, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in scalus-skills/skills/smart-contract-security-review of scalus3/scalus.
Open the folder on GitHubat commit f830a36
Smart Contract Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Smart Contract Security Review this skillscalus3/scalus | 105 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Solidity AuditorGabson0x/bountyforge | 442 | — | ~3.7k | Automated safety check: Pass | None | |
| Solidity Auditorpashov/skills | 1.2k | — | ~9.9k | Automated safety check: Pass | MIT | |
| Defi Amm Securityaffaan-m/ECC | 276k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Fizz Convertpashov/skills | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Solana Devsolana-foundation/solana-dev-skill | 573 | — | ~3.8k | Automated safety check: Pass | MIT |
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
pashov/skills
Security audit of Solidity code while you develop. An agent skill from pashov/skills.
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
pashov/skills
Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.
solana-foundation/solana-dev-skill
A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…
greatpie/smart-contract-audit-skill
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.
scalus3/scalus
Optimize Scalus/Cardano smart contracts for execution budget (CPU steps and memory).
scalus3/scalus
Guide for developing Scalus smart contracts. An agent skill from scalus3/scalus.
scalus3/scalus
Guide for testing Scalus smart contracts. An agent skill from scalus3/scalus.
scalus3/scalus
A skill your agent uses when developing or testing Scalus smart contracts with the local Emulator and TxBuilder.
scalus3/scalus
A skill your agent uses when writing or changing a Pretty typeclass instance (paiges Doc DSL) in scalus-core, for example in scalus/utils/Pretty.scala or the cardano/ledger types.
scalus3/scalus
Use at the start of any task in a Scalus project, to choose the Scalus skill for smart contract work.
Categories
Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus. Smart Contract Security Review is an agent skill from scalus3/scalus. Security review for Scalus/Cardano smart contracts.
Smart Contract Security Review fits situations like: reviewing on-chain code; before deploying validators; /smart-contract-security-review is invoked.
Run `npx skills add scalus3/scalus --skill smart-contract-security-review -a claude-code`. Or copy the skill folder (scalus-skills/skills/smart-contract-security-review in scalus3/scalus) into .claude/skills/smart-contract-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add scalus3/scalus --skill smart-contract-security-review -a codex`. Or copy the skill folder (scalus-skills/skills/smart-contract-security-review in scalus3/scalus) into .agents/skills/smart-contract-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add scalus3/scalus --skill smart-contract-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-contract-security-review, .gemini/skills/smart-contract-security-review, .github/skills/smart-contract-security-review and .opencode/skills/smart-contract-security-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Smart Contract Security Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Smart Contract Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Smart Contract Security Review: Solidity Auditor (Gabson0x/bountyforge, 442 stars), Solidity Auditor (pashov/skills, 1.2k stars), Defi Amm Security (affaan-m/ECC, 276k stars) and Fizz Convert (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
scalus3 (a GitHub organization) maintains it in scalus3/scalus, which has 105 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.
Source: scalus3/scalus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.