Official agent skill

Smart Contract Entry Point Analyzer

by trailofbits in trailofbits/skills

Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Smart Contract Entry Point Analyzer

skills CLI
$ npx skills add trailofbits/skills --skill entry-point-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills entry-point-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/entry-point-analyzer/skills/entry-point-analyzer .claude/skills/entry-point-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
entry-point-analyzer
GitHub stars
7.4k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
789 words
Files
10 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

  • Works in 7 steps: Check if Slither is Available → If Slither is Detected, Run Entry Points… → Use Slither Output as Foundation → …
  • Starting a smart contract audit and mapping the attack surface
  • SKILL.md covers When to Use, When NOT to Use, Scope: State-Changing… and Workflow, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The agent detects the contract language from file extensions, finds the contract or module files (optionally limited to a directory) and extracts every externally callable function that can change state. Each one is classified as public, admin, role-restricted or contract-only. The goal is an attack-surface map to start an audit from, delivered as a structured Markdown report.

Read-only functions are skipped on purpose: view and pure in Solidity, the view decorator in Vyper, get methods in TON and the query entry point in CosmWasm. For Solidity the agent checks whether Slither is installed and, if so, starts from its entry-points printer table of contract, function, visibility and modifiers. Language notes cover Solidity, Vyper, Solana, Move on Aptos and Sui, TON and CosmWasm. It does not detect vulnerabilities, write exploits or review gas use.

When your agent uses it

  • Starting a smart contract audit and mapping the attack surface
  • Listing admin and role-restricted functions in a codebase
  • Reviewing access control patterns across contracts
  • Finding which functions can modify contract state

Example prompts

  • “List every state-changing entry point in ./contracts and group them by access level.”
  • “Which privileged functions does the Solana program in programs/vault expose?”
  • “Map the admin-only functions in our Vyper contracts before the audit starts.”

Requirements

  • Slither, optional, for Solidity codebases
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Check if Slither is Available
  2. If Slither is Detected, Run Entry Points Printer
  3. Use Slither Output as Foundation
  4. When Slither is NOT Available
  5. Public (Unrestricted)
  6. Role-Restricted
  7. Contract-Only (Internal Integration Points)

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart Contract Entry Point Analyzer loads about 2.4k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 789 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 789 words, ~2,394 tokens.

Download SKILL.mdSave it as .claude/skills/entry-point-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
entry-point-analyzer
description
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level (public, admin, role-restricted, contract-only), and generates structured audit reports. Excludes view/pure/read-only functions. Use when auditing smart contracts (Solidity, Vyper, Solana/Rust, Move, TON, CosmWasm) or when asked to find entry points, audit flows, external functions, access control patterns, or privileged operations.
allowed-tools
Read, Grep, Glob, Bash

Entry Point Analyzer

Systematically identify all state-changing entry points in a smart contract codebase to guide security audits.

When to Use

Use this skill when:

  • Starting a smart contract security audit to map the attack surface
  • Asked to find entry points, external functions, or audit flows
  • Analyzing access control patterns across a codebase
  • Identifying privileged operations and role-restricted functions
  • Building an understanding of which functions can modify contract state

When NOT to Use

Do NOT use this skill for:

  • Vulnerability detection (use audit-context-building or domain-specific-audits)
  • Writing exploit POCs (use solidity-poc-builder)
  • Code quality or gas optimization analysis
  • Non-smart-contract codebases
  • Analyzing read-only functions (this skill excludes them)

Scope: State-Changing Functions Only

This skill focuses exclusively on functions that can modify state. Excluded:

LanguageExcluded Patterns
Solidityview, pure functions
Vyper@view, @pure functions
SolanaFunctions without mut account references
MoveNon-entry public fun (module-callable only)
TONget methods (FunC), read-only receivers (Tact)
CosmWasmquery entry point and its handlers

Why exclude read-only functions? They cannot directly cause loss of funds or state corruption. While they may leak information, the primary audit focus is on functions that can change state.

Workflow

  1. Detect Language - Identify contract language(s) from file extensions and syntax
  2. Use Tooling (if available) - For Solidity, check if Slither is available and use it
  3. Locate Contracts - Find all contract/module files (apply directory filter if specified)
  4. Extract Entry Points - Parse each file for externally callable, state-changing functions
  5. Classify Access - Categorize each function by access level
  6. Generate Report - Output structured markdown report

Slither Integration (Solidity)

For Solidity codebases, Slither can automatically extract entry points. Before manual analysis:

1. Check if Slither is Available
bash
which slither
2. If Slither is Detected, Run Entry Points Printer
bash
slither . --print entry-points

This outputs a table of all state-changing entry points with:

  • Contract name
  • Function name
  • Visibility
  • Modifiers applied
3. Use Slither Output as Foundation
  • Parse the Slither output table to populate your analysis
  • Cross-reference with manual inspection for access control classification
  • Slither may miss some patterns (callbacks, dynamic access control)—supplement with manual review
  • If Slither fails (compilation errors, unsupported features), fall back to manual analysis
4. When Slither is NOT Available

If which slither returns nothing, proceed with manual analysis using the language-specific reference files.

Language Detection

ExtensionLanguageReference
.solSolidity{baseDir}/references/solidity.md
.vyVyper{baseDir}/references/vyper.md
.rs + Cargo.toml with solana-programSolana (Rust){baseDir}/references/solana.md
.move + Move.toml with edition{baseDir}/references/move-sui.md
.move + Move.toml with Aptos{baseDir}/references/move-aptos.md
.fc, .func, .tactTON (FunC/Tact){baseDir}/references/ton.md
.rs + Cargo.toml with cosmwasm-stdCosmWasm{baseDir}/references/cosmwasm.md

Load the appropriate reference file(s) based on detected language before analysis.

Access Classification

Classify each state-changing entry point into one of these categories:

1. Public (Unrestricted)

Functions callable by anyone without restrictions.

2. Role-Restricted

Functions limited to specific roles. Common patterns to detect:

  • Explicit role names: admin, owner, governance, guardian, operator, manager, minter, pauser, keeper, relayer, lender, borrower
  • Role-checking patterns: onlyRole, hasRole, require(msg.sender == X), assert_owner, #[access_control]
  • When role is ambiguous, flag as "Restricted (review required)" with the restriction pattern noted
Show full SKILL.md (301 more words)Show less
3. Contract-Only (Internal Integration Points)

Functions callable only by other contracts, not by EOAs. Indicators:

  • Callbacks: onERC721Received, uniswapV3SwapCallback, flashLoanCallback
  • Interface implementations with contract-caller checks
  • Functions that revert if tx.origin == msg.sender
  • Cross-contract hooks

Output Format

Generate a markdown report with this structure:

markdown
# Entry Point Analysis: [Project Name]

**Analyzed**: [timestamp]
**Scope**: [directories analyzed or "full codebase"]
**Languages**: [detected languages]
**Focus**: State-changing functions only (view/pure excluded)

## Summary

| Category | Count |
|----------|-------|
| Public (Unrestricted) | X |
| Role-Restricted | X |
| Restricted (Review Required) | X |
| Contract-Only | X |
| **Total** | **X** |

---

## Public Entry Points (Unrestricted)

State-changing functions callable by anyone—prioritize for attack surface analysis.

| Function | File | Notes |
|----------|------|-------|
| `functionName(params)` | `path/to/file.sol:L42` | Brief note if relevant |

---

## Role-Restricted Entry Points

### Admin / Owner
| Function | File | Restriction |
|----------|------|-------------|
| `setFee(uint256)` | `Config.sol:L15` | `onlyOwner` |

### Governance
| Function | File | Restriction |
|----------|------|-------------|

### Guardian / Pauser
| Function | File | Restriction |
|----------|------|-------------|

### Other Roles
| Function | File | Restriction | Role |
|----------|------|-------------|------|

---

## Restricted (Review Required)

Functions with access control patterns that need manual verification.

| Function | File | Pattern | Why Review |
|----------|------|---------|------------|
| `execute(bytes)` | `Executor.sol:L88` | `require(trusted[msg.sender])` | Dynamic trust list |

---

## Contract-Only (Internal Integration Points)

Functions only callable by other contracts—useful for understanding trust boundaries.

| Function | File | Expected Caller |
|----------|------|-----------------|
| `onFlashLoan(...)` | `Vault.sol:L200` | Flash loan provider |

---

## Files Analyzed

- `path/to/file1.sol` (X state-changing entry points)
- `path/to/file2.sol` (X state-changing entry points)

Filtering

When user specifies a directory filter:

  • Only analyze files within that path
  • Note the filter in the report header
  • Example: "Analyze only src/core/" → scope = src/core/

Analysis Guidelines

  1. Be thorough: Don't skip files. Every state-changing externally callable function matters.
  2. Be conservative: When uncertain about access level, flag for review rather than miscategorize.
  3. Skip read-only: Exclude view, pure, and equivalent read-only functions.
  4. Note inheritance: If a function's access control comes from a parent contract, note this.
  5. Track modifiers: List all access-related modifiers/decorators applied to each function.
  6. Identify patterns: Look for common patterns like:
    • Initializer functions (often unrestricted on first call)
    • Upgrade functions (high-privilege)
    • Emergency/pause functions (guardian-level)
    • Fee/parameter setters (admin-level)
    • Token transfers and approvals (often public)

Common Role Patterns by Protocol Type

Protocol TypeCommon Roles
DEXowner, feeManager, pairCreator
Lendingadmin, guardian, liquidator, oracle
Governanceproposer, executor, canceller, timelock
NFTminter, admin, royaltyReceiver
Bridgerelayer, guardian, validator, operator
Vault/Yieldstrategist, keeper, harvester, manager

Rationalizations to Reject

When analyzing entry points, reject these shortcuts:

  • "This function looks standard" → Still classify it; standard functions can have non-standard access control
  • "The modifier name is clear" → Verify the modifier's actual implementation
  • "This is obviously admin-only" → Trace the actual restriction; "obvious" assumptions miss subtle bypasses
  • "I'll skip the callbacks" → Callbacks define trust boundaries; always include them
  • "It doesn't modify much state" → Any state change can be exploited; include all non-view functions

Error Handling

If a file cannot be parsed:

  1. Note it in the report under "Analysis Warnings"
  2. Continue with remaining files
  3. Suggest manual review for unparsable files

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references, assets) in plugins/entry-point-analyzer/skills/entry-point-analyzer of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/cosmwasm.md
  • references/move-aptos.md
  • references/move-sui.md
  • references/solana.md
  • references/solidity.md
  • references/ton.md
  • references/vyper.md

Open the folder on GitHubat commit 82fe822

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in trailofbits/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Smart Contract Entry Point Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart Contract Entry Point Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart Contract Entry Point Analyzer this skilltrailofbits/skills7.4k1 repos~2.4kAutomated safety check: NotesCC-BY-SA-4.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Meme Coin Security Auditawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Pump Securitynirholas/pump-fun-sdk133—~892Automated safety check: PassCustom licence

Similar skills

  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Pump Security

    nirholas/pump-fun-sdk

    Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

    133 GitHub stars~892 tokensUpdated 18 days ago
    SecurityAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Categories

Questions about Smart Contract Entry Point Analyzer

What does Smart Contract Entry Point Analyzer do?

Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. The agent detects the contract language from file extensions, finds the contract or module files (optionally limited to a directory) and extracts every externally callable function that can change state. Each one is classified as public, admin, role-restricted or contract-only.

When should I use Smart Contract Entry Point Analyzer?

Smart Contract Entry Point Analyzer fits situations like: starting a smart contract audit and mapping the attack surface; listing admin and role-restricted functions in a codebase; reviewing access control patterns across contracts; finding which functions can modify contract state.

How do I install Smart Contract Entry Point Analyzer in Claude Code?

Run `npx skills add trailofbits/skills --skill entry-point-analyzer -a claude-code`. Or copy the skill folder (plugins/entry-point-analyzer/skills/entry-point-analyzer in trailofbits/skills) into .claude/skills/entry-point-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Smart Contract Entry Point Analyzer in Codex?

Run `npx skills add trailofbits/skills --skill entry-point-analyzer -a codex`. Or copy the skill folder (plugins/entry-point-analyzer/skills/entry-point-analyzer in trailofbits/skills) into .agents/skills/entry-point-analyzer in your project. Codex loads it when a task matches its description.

Can I use Smart Contract Entry Point Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill entry-point-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/entry-point-analyzer, .gemini/skills/entry-point-analyzer, .github/skills/entry-point-analyzer and .opencode/skills/entry-point-analyzer in your project.

What does Smart Contract Entry Point Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Smart Contract Entry Point Analyzer is instructions for the agent only. Our summary lists: Slither, optional, for Solidity codebases. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Smart Contract Entry Point Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart Contract Entry Point Analyzer safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Smart Contract Entry Point Analyzer use?

Smart Contract Entry Point Analyzer is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Smart Contract Entry Point Analyzer use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.8k tokens, read only when the agent opens those files.

What are the alternatives to Smart Contract Entry Point Analyzer?

Skills that share tags, products or a category with Smart Contract Entry Point Analyzer: Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars), Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Meme Coin Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart Contract Entry Point Analyzer?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.