auditing-foundry-smart…
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines…
Perform static and symbolic analysis of Solidity smart contracts using
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-ethereum-smart-contract-vulnerabilitiesContext preview
The summary Claude sees to decide when to auto-load this skill.
Perform static and symbolic analysis of Solidity smart contracts using
name: analyzing-ethereum-smart-contract-vulnerabilities description: Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet. domain: cybersecurity subdomain: blockchain-security tags: - ethereum - solidity - smart-contract - slither - mythril - blockchain - defi - audit version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.DS-01 - PR.DS-02 - ID.RA-01 mitre_attack: - T1190 - T1059
Smart contract vulnerabilities have led to billions of dollars in losses across DeFi protocols. Unlike traditional software, deployed smart contracts are immutable and handle real financial assets, making pre-deployment security analysis critical. Slither performs fast static analysis using an intermediate representation to detect over 90 vulnerability patterns in seconds, while Mythril uses symbolic execution and SMT solving to discover complex execution path vulnerabilities like reentrancy and integer overflows. This skill covers running both tools against Solidity contracts, interpreting results, triaging findings by severity, and generating audit reports.
Execute Slither against the contract codebase to identify vulnerability patterns, optimization opportunities, and code quality issues using its 90+ built-in detectors.
Run Mythril deep analysis to explore execution paths and discover reentrancy, unchecked external calls, and arithmetic vulnerabilities that require path-sensitive analysis.
Combine results from both tools, deduplicate findings, assess severity based on exploitability and financial impact, and filter false positives.
Produce a structured audit report with vulnerability descriptions, affected code locations, exploit scenarios, and remediation recommendations.
JSON report listing vulnerabilities with SWC (Smart Contract Weakness Classification) identifiers, severity ratings, affected functions, and suggested fixes.
从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题
Repo: tradecatlabs/vibe-coding-cn
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines…
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run…
Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for…
Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a…
Master grep command arsenal for Web3 smart contract auditing. Use when starting a new…
Hunter mindset, recon setup, and target scoring for Web3 bug bounty. Use at the START of any…