audit-assist
Flow B — AI-assisted iterative audit with a human in the loop. Same lifecycle as audit-cycle, but pauses at checkpoints to surface confirmed findings, the…
Deep single-instruction / single-function security review using the instruction worksheet, context reconstruction, and adversarial exploit modeling.
> /plugin marketplace add solanabr/auditor-skill > /plugin install auditor@auditor
How it fires
How this command gets triggered: by you, by Claude, or both.
/deep-reviewContext preview
What this command does when you run it.
Deep single-instruction / single-function security review using the instruction worksheet, context reconstruction, and adversarial exploit modeling.
name: auditor:deep-review description: Deep single-instruction / single-function security review using the instruction worksheet, context reconstruction, and adversarial exploit modeling. argument-hint: "<file> [function|instruction]" allowed-tools: Read, Grep, Glob, Bash, Task
**Arguments:** $ARGUMENTS
1. Read the target file completely. 2. Run Phase 0.5 Context Reconstruction on the target function (`templates/context-worksheet.md`): purpose, inputs, invariants (≥3), assumptions (≥5), external-interaction risks (≥3) — each cited to `L#`. 3. Fill `templates/instruction-worksheet.md`; cross-reference code that shares state. 4. Adversarially model exploitation. Any high-severity finding (N≥6) must pass the Rule 5b validation gate. 5. Report per-item verdicts + findings for this unit only.
Production-grade security audit for any codebase, powered by AI agents. 20 checklists · 1,413 verification items · 136 known attack vectors · executable PoCs + fix patches A full audit-firm lifecycle (automated + interactive) · Benchmarked against CertiK, SOC
Repo: solanabr/auditor-skill
Flow B — AI-assisted iterative audit with a human in the loop. Same lifecycle as audit-cycle, but pauses at checkpoints to surface confirmed findings, the…
Flow A — fully automated audit-firm lifecycle. Runs scope → context → tool-assisted first pass → domain-partitioned manual review → independent reconciliation…
Aggregate audit checkpoints into the final report — executive summary, Scope Coverage, findings by severity, maturity scorecard, and remediation roadmap.
Full scope-gated security audit of a Solana / full-stack repository — discovery, context reconstruction, per-item checklist verdicts, false-positive…
PR / commit-scoped differential audit — audits only changed functions (plus 1-hop callers), flags removed security checks, and prioritizes by risk × blast…
Quantify a candidate economic finding — compute attack cost vs extractable value and, when possible, reproduce deposit→manipulate→withdraw against a Surfpool…