Agent skill

Contract Decode

by sd0xdev in sd0xdev/sd0x-harness

EVM contract error and calldata decoder. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check: notesBackend & APIs

Install Contract Decode

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill contract-decode -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness contract-decode --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/contract-decode .claude/skills/contract-decode && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contract-decode
GitHub stars
192
Token cost
~1.3k tokens
SKILL.md length
372 words
Files
2 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

EVM contract error and calldata decoder. An agent skill from sd0xdev/sd0x-harness.

  • Works in 4 steps: Classify Input → Local Fast Decode (no external… → External API Query → …
  • : user pastes hex revert data
  • SKILL.md covers Trigger, When NOT to Use, Input Parsing and Workflow, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Contract Decode is an agent skill from sd0xdev/sd0x-harness. EVM contract error and calldata decoder. Use when: user pastes hex revert data, calldata, function selector, or mentions custom error, execution reverted, 4byte, decode. Input contains 0x + 8+ hex chars.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/apis.md`).

It sits in Backend & APIs, covering Smart contracts. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : user pastes hex revert data
  • Function selector
  • Mentions custom error
  • Execution reverted

Example prompts

  • “/contract-decode”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebFetch

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Classify Input
  2. Local Fast Decode (no external dependencies)
  3. External API Query
  4. Precise Decode

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contract Decode loads about 1.3k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 372 words, ~1,314 tokens.

Download SKILL.mdSave it as .claude/skills/contract-decode/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
contract-decode
description
EVM contract error and calldata decoder. Use when: user pastes hex revert data, calldata, function selector, or mentions custom error, execution reverted, 4byte, decode. Input contains 0x + 8+ hex chars.
allowed-tools
Read, Grep, Glob, Bash, WebFetch
context
fork

Contract Decode — EVM Error & Calldata Decoder

Decode EVM contract function selectors, custom errors, calldata, and revert data.

Trigger

  • Keywords: revert, selector, 4byte, calldata, decode, custom error, execution reverted, abi decode
  • Message contains 0x + 8+ hex chars (selector or revert data)

When NOT to Use

  • Standard Error(string) revert already handled by your codebase
  • Non-EVM chain errors
  • Only need error code definitions (not hex decoding)

Input Parsing

Extract from user input:

FieldSourceExample
revertDataError data or user-pasted hex0xaca553e4
calldataTransaction data0x5e15c749000...1c05
contractAddrContract address0x5874...f064
chainIdChain identifier1 (Ethereum mainnet)

Workflow

Step 1: Classify input → Step 2: Local fast decode → Step 3: ABI query → Step 4: Precise decode → Report
Step 1: Classify Input
LengthClassificationNext Step
4 bytes (0x + 8 hex)Pure selectorStep 2
> 4 bytes, with selector prefixCalldata or revert dataStep 2 + Step 3
Contract addressNeed ABI firstStep 3
Step 2: Local Fast Decode (no external dependencies)

Try in order:

2a. Standard error decode

SelectorTypeDecode Method
0x08c379a0Error(string)cast abi-decode "Error(string)" <data>
0x4e487b71Panic(uint256)cast abi-decode "Panic(uint256)" <data> → lookup panic code

Panic code reference:

CodeMeaning
0x00generic compiler panic
0x01assert failure
0x11arithmetic overflow
0x12division by zero
0x21enum conversion
0x22storage encoding
0x31pop empty array
0x32array out of bounds
0x41too much memory
0x51zero function pointer

2b. Selector lookup (cast) — optional, skip if cast not installed

bash
timeout 5 cast 4byte <selector>

If cast is unavailable or crashes, fall back to Step 3 API query.

Show full SKILL.md (142 more words)Show less
Step 3: External API Query

See references/apis.md for full endpoints and parameters.

Query strategy:

Has contract address? → 3a. ABI path (precise) → get ABI → Step 4
No contract address?  → 3b. Selector DB path (candidates) → get signature candidates

3a. ABI path (has contract address + chainId)

  1. Sourcify (free, no key) → get full ABI JSON
  2. Etherscan v2 (needs key, free tier 3 req/s) → get ABI JSON
  3. If proxy → get implementation address → re-query ABI

3b. Selector DB path (no contract address or ABI query failed)

  1. 4byte.directory API → may return multiple candidates
  2. Multiple candidates → mark confidence: low, list all possibilities
Step 4: Precise Decode

With ABI, use cast (if available):

bash
# Decode revert data (needs ABI file)
cast decode-error <revert_data> --abi <abi_file>

# Decode calldata
cast decode-calldata <calldata> --abi <abi_file>

# Or decode with signature directly
cast calldata-decode "functionName(type1,type2)" <calldata>

Without ABI but with signature candidates:

bash
cast abi-decode "functionName(type1,type2)" <data_without_selector>

Output Format

markdown
## Contract Decode Report

| Field | Value |
|-------|-------|
| Type | function call / revert error / event |
| Selector | `0x5e15c749` |
| Signature | `finalizeWithdrawal(uint256)` |
| Decoded Args | `tokenId: 7173` |
| Confidence | High (verified ABI) / Medium (selector DB) / Low (multiple candidates) |
| Source | Sourcify / Etherscan / 4byte.directory / cast |
| Contract | `0x5874...f064` |
| Chain | Ethereum Mainnet (chainId: 1) |

### Raw Data

- Revert: `0xaca553e4`
- Calldata: `0x5e15c749000...1c05`

Multiple candidates:

markdown
### Ambiguous Candidates

| # | Signature | Confidence |
|---|-----------|------------|
| 1 | `WithdrawalRequestDoesNotExist()` | Likely (context match) |
| 2 | `SomeOtherError()` | Unlikely |

References

FilePurposeWhen to Read
references/apis.mdAPI endpoints, parameters, rate limitsBefore Step 3

Verification

  • Input correctly classified (selector / calldata / revert data)
  • Local fast decode attempted (Error/Panic/cast)
  • External query returned results or marked as failed
  • Confidence level indicated
  • Multiple candidates listed (if any)

Examples

Input: Decode 0xaca553e4
Action: 4 bytes → selector → cast 4byte → 4byte.directory → return candidate signatures
Input: What is this revert data 0x08c379a0000...
Action: selector = Error(string) → local cast abi-decode → return error message
Input: Decode this with contract 0x5874..., chainId 1, revert data 0xaca553e4
Action: Has contract + chainId → Sourcify ABI → cast decode-error → precise decode

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/contract-decode of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/apis.md

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Contract Decode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contract Decode compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contract Decode this skillsd0xdev/sd0x-harness192—~1.3kAutomated safety check: NotesMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Solana Devsolana-foundation/solana-dev-skill571—~3.8kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2441 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Solana Dev

    solana-foundation/solana-dev-skill

    A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

    571 GitHub stars~3.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    244 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Contract Decode

What does Contract Decode do?

EVM contract error and calldata decoder. An agent skill from sd0xdev/sd0x-harness. Contract Decode is an agent skill from sd0xdev/sd0x-harness. EVM contract error and calldata decoder.

When should I use Contract Decode?

Contract Decode fits situations like: : user pastes hex revert data; function selector; mentions custom error; execution reverted.

How do I install Contract Decode in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill contract-decode -a claude-code`. Or copy the skill folder (skills/contract-decode in sd0xdev/sd0x-harness) into .claude/skills/contract-decode in your project. Claude Code loads it when a task matches its description.

How do I install Contract Decode in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill contract-decode -a codex`. Or copy the skill folder (skills/contract-decode in sd0xdev/sd0x-harness) into .agents/skills/contract-decode in your project. Codex loads it when a task matches its description.

Can I use Contract Decode in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill contract-decode -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contract-decode, .gemini/skills/contract-decode, .github/skills/contract-decode and .opencode/skills/contract-decode in your project.

What does Contract Decode need to run?

SKILL.md names no scripts, command-line tools or credentials: Contract Decode is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebFetch.

Does Contract Decode access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Contract Decode safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Contract Decode use?

Contract Decode is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Contract Decode use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Contract Decode?

Skills that share tags, products or a category with Contract Decode: Fizz Convert (pashov/skills, 1.2k stars), Solana Dev (solana-foundation/solana-dev-skill, 571 stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 244 stars) and Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contract Decode?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.