ability-analysis
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static
$ npx -y skills add PlamenTSV/plamen --skill audit-prep --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/audit-prepContext preview
The summary Claude sees to decide when to auto-load this skill.
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static
name: audit-prep description: > Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static analysis. Trigger on: "prepare for audit", "audit readiness", "pre-audit check", "audit prep", "NatSpec check", or any request to review a Solidity codebase before a security review.
Orchestrate a parallelized audit-prep pipeline. Do NOT perform analysis — discover files, dispatch agents, compile the scored report.
Clean markdown. Each phase = one table with Status, Finding, and Recommendation columns. Score summary at the end. When rendered via `--report`, produces a polished `.md` file.
The report has these sections in order: 1. Header (project, framework, scope) 2. Phase 1–8, each as a titled section with a results table 3. Score summary table 4. Quick Wins table
Print the banner from the end of this file before doing anything else — in every mode (full pipeline, single phase, scan, fix). Always use this exact banner. Never generate, invent, or substitute a different banner. Also include it at the top of `--report` markdown files.
## 1. Test Coverage | Status | Finding | Recommendation | |--------|---------|----------------| | FAIL | Compiler warning — unused param in ConfigProvider:288 | Remove or rename the unused parameter | | PASS | 4/4 contracts have test files | — | | PASS | Branch coverage: 95.93% | — |
## Score Summary | Phase | Score | |-------|-------| | 1. Test Coverage | 87/100 | | 2. Test Quality | 85/100 | | ... | ... | | **Overall** | **82/100 — Almost Ready** |
## Quick Wins | # | Action | Location | |---|--------|----------| | 1 | Create deployment scripts | scripts/deploy.ts | | 2 | Create SECURITY.md with trust assumptions | project root | | 3 | Add more assertions to thin tests | test/ |
No deduction numbers, no weights, no `[-N]` annotations. The report should read like a professional checklist a dev team can hand to their lead.
First, read the VERSION file and the skill's references path in parallel:
Then print the banner (from the end of this file), followed by asking the user where the project is:
{
"question": "Where is the project you want to prepare for audit?",
"header": "Project",
"multiSelect": false,
"options": [
{
"label": "Current directory",
"description": "Use the current working directory"
},
{
"label": "Local path",
"description": "Enter a path to a local project"
},
{
"label": "GitHub repo",
"description": "Enter a GitHub URL — will clone into a temp directory"
}
]
}If **Current directory**: use the cwd as `{project_dir}`. If **Local path**: user provides a path, use it as `{project_dir}`. If **GitHub repo**: clone with `git clone <url> /tmp/audit-prep-<repo-name>` and use that as `{project_dir}`.
Make these **parallel tool calls** in ONE message: a. **Bash:** detect framework — check for `foundry.toml`, `hardhat.config.js`, `hardhat.config.ts` b. **Bash:** find in-scope `.sol` files. Exclude `test/`, `script/`, `lib/`, `node_modules/`, `interfaces/`, `mocks/`. Check both `src/` and `contracts/`. If `--diff <ref>`, use `git diff --name-only <ref> -- '*.sol'`. c. **Bash:** find test files — `find test/ -name '*.sol' -o -name '*.ts' -o -name '*.js'` d. **Bash:** count total lines in scope — `wc -l` on discovered source files g. **Bash:** `mkdir -p .audit-prep` -> `{bundle_dir}` = `.audit-prep` (project-relative, so agents can read it) h. **ToolSearch:** `mcp__sc-auditor` (for scan menu in Turn 4)
Then create agent bundles in a **single Bash call**:
# File list (one per line)
printf '%s\n' <in-scope-files> > {bundle_dir}/files.txt
# Agent A — Testing (Phases 1+2)
# Gets: framework, project dir, test metadata, source file list, instructions
{
printf 'framework: %s\nproject_dir: %s\n\n' "<fw>" "<dir>"
echo "# Test files:"
for f in <test-files>; do
printf '%s (%s lines)\n' "$f" "$(wc -l < "$f")"
done
echo ""
echo "# In-scope source files:"
cat {bundle_dir}/files.txt
echo ""
cat {ref_path}/agents/testing-agent.md
echo ""
cat {ref_path}/shared-rules.md
} > {bundle_dir}/agent-a.md
# Agent B — Source Analysis (Phases 3+4+6)
# NO SOURCE CODE — agent uses Grep/Read directly on project files
{
printf 'project_dir: %s\n\n' "<dir>"
echo "# In-scope source files:"
cat {bundle_dir}/files.txt
echo ""
cat {ref_path}/agents/source-analysis-agent.md
echo ""
cat {ref_path}/shared-rules.md
} > {bundle_dir}/agent-b.md
# Agent C — Infrastructure (Phases 5+Autonomous Web3 security auditor for Claude Code and OpenAI Codex CLI. Orchestrates 18-100 AI agents across 40+ phases to produce audit reports with verified PoC exploits — for smart contracts and L1 node-client infrastructure.
Repo: PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth…
Trigger Pattern Always (Aptos Move) - Move VM aborts on shift = bit width - Inject Into…
Trigger Protocol has privileged roles (admin, operator, governance, resource account owner) -…
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by…
Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via…