analyzing-ethereum-sma…
Perform static and symbolic analysis of Solidity smart contracts using
MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow.
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill web3-solidity-audit-mcp --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/web3-solidity-audit-mcpContext preview
The summary Claude sees to decide when to auto-load this skill.
MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow.
name: web3-solidity-audit-mcp description: MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow.
> From: github.com/mariano-aguero/solidity-audit-mcp — MCP server plugging Slither + Aderyn + SWC patterns into Claude Code > 10 tools. 19 built-in finding explainers. 86 SWC detectors. DeFi + Web3 preset detector packs. CI/CD ready.
---
An MCP server that gives Claude Code direct access to Slither, Aderyn, Slang AST, SWC pattern matching, and a gas optimizer — all in one unified pipeline with auto-deduplication. Instead of context-switching between tools, you ask Claude to audit a contract and get a merged, severity-sorted report.
**Stack:**
External (install separately): Slither → Trail of Bits, 90+ detectors, deep data flow Aderyn → Cyfrin Rust-based, fast AST analysis Echidna → Property fuzzer (optional) Halmos → Symbolic execution (optional) Built-in (no install): Slang → Nomic Foundation AST parser, precise pattern matching SWC → 86 detectors against Smart Contract Weakness Classification registry Gas → Storage packing, loop, calldata optimizations
---
# Prerequisites pip install slither-analyzer solc-select solc-select install 0.8.20 && solc-select use 0.8.20 curl -L https://foundry.paradigm.xyz | bash && foundryup # Aderyn (Rust) cargo install aderyn # or: curl -L https://raw.githubusercontent.com/Cyfrin/aderyn/dev/cyfrinup/install | bash # MCP server npm install -g solidity-audit-mcp # or: npx solidity-audit-mcp # Optional fuzzers brew install echidna # macOS pip install halmos # symbolic execution
**Wire into Claude Code** — add to `~/.claude/mcp.json`:
{
"mcpServers": {
"audit": {
"command": "npx",
"args": ["solidity-audit-mcp"]
}
}
}**Or project-level** `.mcp.json` in repo root:
{
"mcpServers": {
"audit": {
"command": "node",
"args": ["/path/to/solidity-audit-mcp/dist/index.js"]
}
}
}**Docker** (all tools pre-installed):
docker run -v $(pwd):/contracts solidity-audit-mcp audit /contracts/Token.sol
---
analyze_contract( contractPath: "contracts/Vault.sol", analyzers: ["slither", "aderyn", "slang"], # or omit for all runTests: true # run forge tests too )
**Pipeline:** 1. Parse metadata (functions, state vars, inheritance) 2. Run Slither + Aderyn in parallel 3. Detect risky patterns via Slang AST 4. Deduplicate findings across all tools 5. Sort by severity 6. Return unified report + JSON
get_contract_info("contracts/Protocol.sol")Returns instantly:
**Use before full audit to understand the attack surface.**
check_vulnerabilities( contractPath: "contracts/Token.sol", detectors: ["SWC-107", "SWC-115", "CUSTOM-017"] # or omit for all 86 )
**19 built-in finding explainers (full Foundry PoC + remediation):**
| ID | Finding | Severity | |----|---------|---------| | SWC-107 | Reentrancy | Critical | | SWC-112 | Delegatecall to untrusted callee | Critical | | CUSTOM-017 | Missing access control on critical function | Critical | | CUSTOM-018 | ERC-7702 unprotected initializer | Critical | | CUSTOM-004 | Price oracle manipulation / flash loan | Critical | | CUSTOM-032 | ERC-4337 paymaster drain | Critical | | SWC-101 | Integer overflow/underflow (unchecked) | High | | SWC-104 | Unchecked call return value | High | | SWC-115 | Authorization through tx.origin | High | | CUSTOM-001 | Array length mismatch | High | | CUSTOM-011 | Signature without replay protection | High | | CUSTOM-029 | Merkle double-claim | High | | SWC-116 | Block timestamp dependence | Medium | | CUSTOM-005 | Missing zero address validation | Medium | | CUSTOM-013 | Hash collision via abi.encodePacked | Medium | | CUSTOM-015 | Division before multiplication | Medium | | CUSTOM-016 | Permit without deadline | Medium | | SWC-100 | Function default visibility | Medium | | SWC-103 | Floating pragma | Low |
explain_finding( findingId: "CUSTOM-011", # or "SWC-107", or keyword "reentrancy" contractContext: "ERC4626 vault with harvest callback" )
Returns: root cause → impact → step-by-step exploit → vulnerable code → secure code → Foundry PoC template → remediation → references.
**Use this mid-hunt** when you find a suspicious pattern and want the full exploit scenario before writing a PoC.
**Supported keywords:** `reentrancy`, `overflow`, `flash loan`, `oracle`, `replay`, `nonce`, `encodepacked`, `precision loss`, `permit`, `access control`, `merkle`, `airdrop`, `erc-7702`, `paymaster`, `erc-4337`, `delegatecall`, `tx.origin`, `zero address`, `timestamp`
generate_invariants( contractPath: "contracts/Vault.sol", protocolType: "vault" # auto, erc20, erc721, vault, lending, amm, governance, staking )
Returns ready-to-paste `invariant_*()` functions + handler contract + `forge test --invariant` run commands.
**Protocol-specific invariants generated:**
ERC-4626 vault: totalAssets >= total share value
share price non-decreasing
deposit/withdraw round-trip solvency
Lending: protocol solvency, l从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题
Repo: tradecatlabs/vibe-coding-cn
Perform static and symbolic analysis of Solidity smart contracts using
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines…
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run…
Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for…
Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a…
Master grep command arsenal for Web3 smart contract auditing. Use when starting a new…