Topic · Security
Best smart contract auditing skills for Claude Code, Codex and other agents.
- skills
- 80
- official
- 8
Smart contract auditing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns. | awarexone/ | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | 2.Fizz Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects. | pashov/ | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | 2 days ago |
| 3 | A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol. | tradecatlabs/ | 17k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | 6 days ago |
| 4 | 4.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 2 days ago |
| 5 | Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. | pashov/ | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization. | tradecatlabs/ | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | 6 days ago |
| 7 | Reconcile an existing Fizz harness with a changed source tree. | pashov/ | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | 2 days ago |
| 8 | Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review. | awarexone/ | 5.3k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 9 | Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. | greatpie/ | 101 | — | ~1.1k | Automated safety check: Pass | No licence | 7 mo ago |
| 10 | Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. | Gabson0x/ | 443 | — | ~3.7k | Automated safety check: Pass | No licence | 20 days ago |
| 11 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 12 | Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk. | Soneso/ | 132 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 13 | 13.Solodit Search Solodit for similar smart contract security findings. | marchev/ | 158 | — | ~832 | Automated safety check: Pass | MIT | 5 mo ago |
| 14 | 14.Stellar Dev End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments. | VelaPayments/ | 131 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 15 | Token-efficient smart contract security auditing via Behavioral State Analysis (BSA). | quillai-network/ | 129 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 16 | 16.Audit Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills. | austintgriffith/ | 294 | — | ~829 | Automated safety check: Pass | No licence | 1 mo ago |
| 17 | Security audit of Solidity code while you develop. An agent skill from pashov/skills. | pashov/ | 1.2k | — | ~9.9k | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting. | Archethect/ | 127 | — | ~5.9k | Automated safety check: Notes | No licence | 6 mo ago |
| 19 | Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus. | scalus3/ | 105 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 20 | Detects Denial of Service and griefing vulnerabilities in smart contracts. | quillai-network/ | 129 | — | ~3.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 21 | Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. | wshobson/ | 40k | 11 repos | ~892 | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews. | tradecatlabs/ | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | 6 days ago |
| 23 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | 6 days ago |
| 24 | Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting. | tradecatlabs/ | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | 6 days ago |
| 25 | Detects unsafe external call patterns and token integration vulnerabilities in smart contracts. | quillai-network/ | 129 | — | ~3.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 26 | Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus. | tradecatlabs/ | 17k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 27 | Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring. | tradecatlabs/ | 17k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | 6 days ago |
| 28 | Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. | tradecatlabs/ | 17k | 2 repos | ~2.2k | Automated safety check: Pass | MIT | 6 days ago |
| 29 | Detects input validation failures and arithmetic vulnerabilities in smart contracts. | quillai-network/ | 129 | — | ~3.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 30 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 31 | Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy. | quillai-network/ | 129 | — | ~3.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 32 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 33 | Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. | affaan-m/ | 274k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 34 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 35 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 36 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 37 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 38 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 39 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | A skill your agent uses when reviewing Swift Concurrency performance and responsiveness, including task explosions, actor hopping, MainActor bottlenecks, cancellation, AsyncSequence cleanup… | Livsy90/ | 117 | — | ~2.9k | Automated safety check: Pass | MIT | 2 mo ago |
| 41 | Deep reentrancy vulnerability analysis for Solidity contracts. | alt-research2/ | 104 | — | ~1.8k | Automated safety check: Pass | Unknown | 3 mo ago |
| 42 | Analyze user callbacks for re-entrancy defects (deadlock, corruption) | ben-manes/ | 18k | — | ~388 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 43 | Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents | PlamenTSV/ | 303 | — | ~2.2k | Automated safety check: Pass | MIT | 11 days ago |
| 44 | Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories. | alt-research2/ | 104 | — | ~1.6k | Automated safety check: Notes | Unknown | 3 mo ago |
| 45 | Foundry and Soroban formal invariant verification register: state transition rules, boundary invariant properties, and symbolic execution checks. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 46 | Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 47 | Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 48 | Automated market maker liquidity pool register: constant-product invariant curves, swap fee tiers, and LP token shares for Soroban DeFi. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | yesterday |
Questions, answered from the data.
What is the best smart contract auditing skill?
Web3 Smart Contract Audit from awarexone/Agentic-Bug-Hunter ranks first of the 80 smart contract auditing skills listed here, with the highest score: its repository has 5.3k GitHub stars, 3 other GitHub owners carry a copy, its SKILL.md loads about 4.5k tokens and it passes the automated safety check with no findings. Next come Fizz and Web3 Smart Contract Grep Arsenal.
Which smart contract auditing skills are official?
8 of the 80 smart contract auditing skills are official, published by the vendor's own GitHub organization: Smart Contract Entry Point Analyzer, Dimensional Analysis Annotator, Solana Vulnerability Scanner, Algorand Vulnerability Scanner, Cairo Vulnerability Scanner and 3 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34