Agent skill

Ethereum Smart Contract Vulnerability Analysis

by tradecatlabs in tradecatlabs/vibe-coding-cn

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

Apache-2.0Auto-check passedSecurity

Install Ethereum Smart Contract Vulnerability Analysis

skills CLI
$ npx skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tradecatlabs/vibe-coding-cn analyzing-ethereum-smart-contract-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/smart-contract-audit/analyzing-ethereum-smart-contract-vulnerabilities .claude/skills/analyzing-ethereum-smart-contract-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-ethereum-smart-contract-vulnerabilities
GitHub stars
17k
Used in
1 other repo
Token cost
~738 tokens
SKILL.md length
296 words
Files
4 (incl. scripts, references)
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

  • Works in 4 steps: Run Slither Static Analysis → Run Mythril Symbolic Execution → Triage and Correlate Findings → …
  • Auditing a Solidity contract for known vulnerability classes before deployment
  • SKILL.md covers Overview, When to Use, Prerequisites and Steps, plus 1 more section
  • Runs Python scripts from its folder

What it does

Runs Slither's static analysis, which uses an intermediate representation to flag over 90 known vulnerability patterns in seconds, alongside Mythril's symbolic execution and SMT solving, which explores execution paths to catch deeper issues such as reentrancy and integer overflow that pattern matching alone misses. The two tools' findings are then combined, deduplicated and filtered for false positives.

Each finding is assessed for severity based on exploitability and potential financial impact, since a deployed contract is immutable and handles real assets. The final output is a structured JSON report naming each vulnerability's SWC classification, severity, affected functions and suggested fix, which becomes the basis for an audit write-up.

When your agent uses it

  • Auditing a Solidity contract for known vulnerability classes before deployment
  • Combining static and symbolic analysis results into one triaged report
  • Checking a contract for reentrancy or unchecked external calls
  • Producing a structured vulnerability report with SWC identifiers

Example prompts

  • “Run Slither and Mythril against contracts/Vault.sol and summarize the findings.”
  • “Check this staking contract for reentrancy before we deploy to mainnet.”
  • “Generate an audit report with severity ratings for everything found in src/.”

Requirements

  • Python 3.10 or newer with pip
  • Slither (`slither-analyzer`) and the solc compiler
  • Mythril with solc-select

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Run Slither Static Analysis
  2. Run Mythril Symbolic Execution
  3. Triage and Correlate Findings
  4. Generate Audit Report

What it can do on your machine

Read from SKILL.md and the folder at commit 5b76a8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ethereum Smart Contract Vulnerability Analysis loads about 738 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~738
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tradecatlabs/vibe-coding-cn at commit 5b76a8f, republished under its Apache-2.0 licence (© tradecatlabs). 296 words, ~738 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-ethereum-smart-contract-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-ethereum-smart-contract-vulnerabilities
description
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
domain
cybersecurity
subdomain
blockchain-security
tags
ethereum, solidity, smart-contract, slither, mythril, blockchain, defi, audit
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-01, PR.DS-02, ID.RA-01
mitre_attack
T1190, T1059

Analyzing Ethereum Smart Contract Vulnerabilities

Overview

Smart contract vulnerabilities have led to billions of dollars in losses across DeFi protocols. Unlike traditional software, deployed smart contracts are immutable and handle real financial assets, making pre-deployment security analysis critical. Slither performs fast static analysis using an intermediate representation to detect over 90 vulnerability patterns in seconds, while Mythril uses symbolic execution and SMT solving to discover complex execution path vulnerabilities like reentrancy and integer overflows. This skill covers running both tools against Solidity contracts, interpreting results, triaging findings by severity, and generating audit reports.

When to Use

  • When investigating security incidents that require analyzing ethereum smart contract vulnerabilities
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.10+ with pip
  • Slither (pip install slither-analyzer) and solc compiler
  • Mythril (pip install mythril) with solc-select for compiler version management
  • Solidity source code or compiled contract bytecode
  • Foundry or Hardhat development framework (optional, for project-level analysis)

Steps

Step 1: Run Slither Static Analysis

Execute Slither against the contract codebase to identify vulnerability patterns, optimization opportunities, and code quality issues using its 90+ built-in detectors.

Step 2: Run Mythril Symbolic Execution

Run Mythril deep analysis to explore execution paths and discover reentrancy, unchecked external calls, and arithmetic vulnerabilities that require path-sensitive analysis.

Step 3: Triage and Correlate Findings

Combine results from both tools, deduplicate findings, assess severity based on exploitability and financial impact, and filter false positives.

Step 4: Generate Audit Report

Produce a structured audit report with vulnerability descriptions, affected code locations, exploit scenarios, and remediation recommendations.

Expected Output

JSON report listing vulnerabilities with SWC (Smart Contract Weakness Classification) identifiers, severity ratings, affected functions, and suggested fixes.

© tradecatlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in research/vibe-cybersecurity-cn/skills/smart-contract-audit/analyzing-ethereum-smart-contract-vulnerabilities of tradecatlabs/vibe-coding-cn.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 5b76a8f

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in tradecatlabs/vibe-coding-cn, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Ethereum Smart Contract Vulnerability Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ethereum Smart Contract Vulnerability Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ethereum Smart Contract Vulnerability Analysis this skilltradecatlabs/vibe-coding-cn17k1 repos~738Automated safety check: PassApache-2.0
Algorand Vulnerability Scannertrailofbits/skills7.5k—~3.1kAutomated safety check: PassCC-BY-SA-4.0
Cairo Vulnerability Scannertrailofbits/skills7.5k—~3.3kAutomated safety check: PassCC-BY-SA-4.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT

Similar skills

  • Official

    Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.

    7.5k GitHub stars~3.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cairo Vulnerability Scanner

    trailofbits/skills

    Official

    Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.

    7.5k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated yesterday
    SecurityAuto-check: notes

More from tradecatlabs/vibe-coding-cn

All 17 skills in this repo
  • Auto Skill Builder

    tradecatlabs/vibe-coding-cn

    Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.

    17k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Web3 Smart Contract Grep Arsenal

    tradecatlabs/vibe-coding-cn

    A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

    17k GitHub starsUsed in 2 repos~3.3k tokens
    Auto-check passed
  • Auto tmux Operator

    tradecatlabs/vibe-coding-cn

    Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.

    17k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: warnings
  • Math Computation

    tradecatlabs/vibe-coding-cn

    Runs reproducible math computations and counterexample searches with SymPy, NumPy and mpmath, logging evidence without presenting results as proofs.

    17k GitHub stars~881 tokensUpdated yesterday
    Auto-check passed
  • DeFi Smart Contract Bug Classes

    tradecatlabs/vibe-coding-cn

    Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews.

    17k GitHub starsUsed in 2 repos~10k tokens
    Auto-check passed

Questions about Ethereum Smart Contract Vulnerability Analysis

What does Ethereum Smart Contract Vulnerability Analysis do?

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. Runs Slither's static analysis, which uses an intermediate representation to flag over 90 known vulnerability patterns in seconds, alongside Mythril's symbolic execution and SMT solving, which explores execution paths to catch deeper issues such as reentrancy and integer overflow that pattern matching alone misses. The two tools' findings are then combined, deduplicated and filtered for false positives.

When should I use Ethereum Smart Contract Vulnerability Analysis?

Ethereum Smart Contract Vulnerability Analysis fits situations like: auditing a Solidity contract for known vulnerability classes before deployment; combining static and symbolic analysis results into one triaged report; checking a contract for reentrancy or unchecked external calls; producing a structured vulnerability report with SWC identifiers.

How do I install Ethereum Smart Contract Vulnerability Analysis in Claude Code?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities -a claude-code`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/smart-contract-audit/analyzing-ethereum-smart-contract-vulnerabilities in tradecatlabs/vibe-coding-cn) into .claude/skills/analyzing-ethereum-smart-contract-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Ethereum Smart Contract Vulnerability Analysis in Codex?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities -a codex`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/smart-contract-audit/analyzing-ethereum-smart-contract-vulnerabilities in tradecatlabs/vibe-coding-cn) into .agents/skills/analyzing-ethereum-smart-contract-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Ethereum Smart Contract Vulnerability Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-ethereum-smart-contract-vulnerabilities, .gemini/skills/analyzing-ethereum-smart-contract-vulnerabilities, .github/skills/analyzing-ethereum-smart-contract-vulnerabilities and .opencode/skills/analyzing-ethereum-smart-contract-vulnerabilities in your project.

What does Ethereum Smart Contract Vulnerability Analysis need to run?

Going by SKILL.md and its folder, Ethereum Smart Contract Vulnerability Analysis needs Python for the scripts in its folder. Our summary lists: Python 3.10 or newer with pip; Slither (`slither-analyzer`) and the solc compiler; Mythril with solc-select.

Does Ethereum Smart Contract Vulnerability Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ethereum Smart Contract Vulnerability Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ethereum Smart Contract Vulnerability Analysis use?

Ethereum Smart Contract Vulnerability Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ethereum Smart Contract Vulnerability Analysis use?

About 738 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 661 tokens, read only when the agent opens those files.

What are the alternatives to Ethereum Smart Contract Vulnerability Analysis?

Skills that share tags, products or a category with Ethereum Smart Contract Vulnerability Analysis: Algorand Vulnerability Scanner (trailofbits/skills, 7.5k stars), Cairo Vulnerability Scanner (trailofbits/skills, 7.5k stars), Smart Contract Audit (forefy/.context, 152 stars) and CodeQL Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ethereum Smart Contract Vulnerability Analysis?

tradecatlabs (a GitHub user) maintains it in tradecatlabs/vibe-coding-cn, which has 17,386 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: tradecatlabs/vibe-coding-cn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.