.context
forefy • Open
Generate and administer interactive knowledge quizzes for security auditors based on repository documentation and code. Use when an auditor needs to be tested on their understanding of a codebase, protocol mechanics,...
AI Skills
Repo-level index of the local audits skills library: AI skill packs, smart-contract audit workflows, chain-specific guides, primers, and security tooling.
Visible now
120 / 120
forefy • Open
Generate and administer interactive knowledge quizzes for security auditors based on repository documentation and code. Use when an auditor needs to be tested on their understanding of a codebase, protocol mechanics,...
l33tdawg • Open
Aether v6.0 — Smart Contract Security Analysis Framework
PaulRBerg • Open
This skill should be used when the user asks to resolve an EVM chain name or chain ID; find chain metadata such as a default public RPC, native currency symbol, or block explorer URL; determine whether a chain is supp...
wshobson • MIT
Python design patterns including KISS, Separation of Concerns, Single Responsibility, and composition over inheritance. Use this skill when designing a new service or component from scratch and choosing how to layer r...
devdacian • Open
This repository contains open-source Primer documents to be ingested by AI prior to conducting smart contract audits.
rakeshkumawat12 • Open
Move Contract Auditor
0din-ai • Open
An open-source web application for AI model security assessments, built with Ruby on Rails and NVIDIA garak. Scanner helps organizations test their AI systems for vulnerabilities before deployment — similar to penetra...
robert-zaremba • MIT
Sui Move smart contract development - patterns, best practices, standard library, and idiomatic code for the Sui blockchain
inirafaila • Open
🤖 Auditor AI: AI-Powered Smart Contract Security Assistant
hummusonrails • Open
Opinionated guide for building dApps on Arbitrum using Stylus (Rust) and/or Solidity. Covers local devnode setup, contract development, testing, deployment, and React frontend integration with viem. Use when starting...
auditmos • MIT
Audits Solidity liquidation mechanisms for denial of service vulnerabilities including unbounded loops over positions causing out-of-gas reverts, data structure corruption preventing liquidation, front-running to bloc...
Artifex1 • Open
Conducting interactive security audits of codebases. RECON builds a structural map with the aud CLI and establishes trust assumptions. SCAN spawns fresh isolated agents to reason about clusters and hypotheses — the au...
ashucoder9 • Open
Avalanche Developer Skill
marchev • Open
Awesome AI × Web3 Security [](https://awesome.re)
base • Complete terms in LICENSE.txt
Integrate Base Builder Codes (ERC-8021) into web3 applications for onchain transaction attribution and referral fee earning. Use when a project needs to append a builder code or dataSuffix to transactions on Base L2,...
agentlisa • Open
LISA-Bench: Smart Contract Vulnerability Detection Benchmark
agentlisa • Open
LISA-Bench: Smart Contract Vulnerability Detection Benchmark
ImmuneBytes-Security-Audit • Open
Blockchain-Attack-Vectors
33Audits • Open
Double-pass CCA vulnerability scanner for Uniswap Continuous Clearing Auction contracts. Detects 9 core vectors (VC1-VC9) and 6 integration vectors (VI1-VI6) with parallel agent analysis. Scope is auto-detected; findi...
CDSecurity • Open
Cdsecurity Skills repository mirror from the local audits skills library.
shuvonsec • Open
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling)...
McGo • Open
Comprehensive security audit with findings classification, epic generation, and PDF report
Jeremy Longshore <jeremy@intentsolutions.io> • MIT
Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .csv, or .tsv file (e.g., adding columns, comp...
Cyfrin • Open
Instructions for building and maintaining Cyfrin documentation sites. Use this skill when working on a Next.js docs site with MDX, Tailwind CSS, and the Cyfrin docs template.
wrsmith108 • Open
Security Auditor Skill
cameronkarthik • Open
Use when building multi-wallet transaction pipelines with ephemeral keypairs -- token launches, bundled buys/sells, or any flow that generates temporary wallets, funds them, executes operations, and consolidates funds...
max-taylor • Open
Generate a comprehensive Foundry/Forge test suite for a Solidity contract. Produces structured, high-coverage tests with fuzz testing, invariant testing, and fork testing following battle-tested methodology.
carlvellotti • Open
Analyze a Solana token for safety risks. Use when the user provides a Solana token contract address (CA) and wants to know if it's safe, asks "is this token safe", "check this token", "rug check", "tokenscreen", or "/...
marchev • Open
Search Solodit for similar smart contract security findings. Use when reviewing vulnerabilities, comparing to known issues, or researching prior art from real audits.
OpenZeppelin • Open
OpenZeppelin Contracts for Sui
defillama • MIT
Use this skill when the user mentions wallet login, sign in, verify OTP, add wallet, switch account, wallet status, logout, wallet balance, assets, holdings, send tokens, transfer ETH, transfer USDC, pay someone, send...
raunit-dev • Apache-2.0
Solana vault management via GLAM Protocol. Triggers: glam, glam-cli, glam-sdk, vault create/manage, tokenized vault, share class, DeFi vault, treasury, asset management, access control, delegate permissions, Jupiter s...
SunWeb3Sec • Open
DeFi Hacks Reproduce - Foundry
thenameisdevair • Open
Foundry test verification layer for pashov solidity-auditor findings. Invoke after running pashov/skills solidity-auditor on a codebase. Reads the pashov report, classifies each finding by testability, writes Foundry...
solana-foundation • Open
Content Moved to solana-com Repo
Sir-Shaedy • Open
AI-powered Solidity security intelligence in VS Code, backed by real audit findings.
DXD-LABS • Open
DXDLABS – Smart Contract Security Audits
austintgriffith • Open
Use when a request involves Ethereum, the EVM, or blockchain systems. Applies to building, auditing, deploying, or interacting with smart contracts, dApps, wallets, or DeFi protocols. Covers Solidity development, cont...
austintgriffith • Open
Use when a request involves Ethereum, the EVM, or blockchain systems. Applies to building, auditing, deploying, or interacting with smart contracts, dApps, wallets, or DeFi protocols. Covers Solidity development, cont...
0xGval • Open
Ethereum Tools for Claude MCP
exvulsec • Open
Prompt-only Solana security audit skill. Run one autonomous full audit, adversarially remove false positives, and output exvulsolanaauditor.md.
BradMoonUESTC • Open
Finite Monkey Engine v3.0
DeFiFoFum • Open
Fofum Solidity Skills repository mirror from the local audits skills library.
PraneshASP • Open
A simple, lightweight and fast MCP (Model Context Protocol) server that provides Solidity development capabilities using the Foundry toolchain (Forge, Cast, and Anvil).
cholakovvv • Open
Use this skill when the user wants to write a Foundry Proof of Concept (PoC) test that reproduces a smart contract vulnerability against a real deployed protocol on a mainnet fork. Triggers include phrases like "write...
gabrielkoerich • Open
End-to-end Solana development playbook (Jan 2026). Prefer Solana Foundation framework-kit (@solana/client + @solana/react-hooks) for React/Next.js UI. Prefer @solana/kit for all new client/RPC/transaction code. When l...
JoranHonig • Open
-
hackenproof-public • Open
Export ALL reports of a HackenProof program into a structured file. User chooses report detail level (Full, No Comments, or Public) and output format (Markdown, JSON, or CSV). Trigger on "export all reports to markdow...
ZealynxSecurity • Open
AI-first security auditor for Solidity smart contracts. 4-phase pipeline (recon → detection → state analysis → verification) with 101 heuristics, 15 detection modules, 8 kill gates, and a 6-field methodology audit tra...
SunWeb3Sec • Open
Llm Sast Scanner repository mirror from the local audits skills library.
EasonC13 • Open
OPENAIAPIKEY="sk-proj-xxx"
Monethic • Open
Monethic AI Auditor (MAIA) - Smart contract security audit engine for EVM, Move-Aptos, and Move-Sui projects. Use for automated multi-phase security audits with over 192 detectors across all platforms.
0xriazaka • Open
Move Audit Resources
pantheraudits • Open
Audits Move contracts (Sui & Aptos) for security bugs.
sanbir • Open
Security audit of Sui Move contracts while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ Sui protocol analysis), or a specific filename.
1NickPappas • Open
Analyzes Move language packages against the official Move Book Code Quality Checklist. Use this skill when reviewing Move code, checking Move 2024 Edition compliance, or analyzing Move packages for best practices. Act...
0xCryptoZen • Open
Generate professional SKILL.md files for any Sui Move contract
0xiehnnkta • Open
Deep business logic bug finder using the Feynman technique. Language-agnostic — works on Solidity, Move, Rust, Go, C++, or any codebase. Questions every line, every ordering choice, every guard presence/absence, and e...
NewmanXBT • Open
Audit and optimize tweets, X articles, and threads for X's recommendation algorithm. Use when user wants to review content before posting, improve engagement potential, or get algorithm-friendly suggestions. Triggers...
OpenZeppelin • AGPL-3.0-only
Develop secure smart contracts using OpenZeppelin Contracts libraries. Use when users need to integrate OpenZeppelin library components — including token standards (ERC20, ERC721, ERC1155), access control (Ownable, Ac...
pashov • Open
Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping), invariants, integratio...
PlamenTSV • Open
Performs comprehensive token flow analysis by tracing all token entry and exit paths, verifying accounting consistency, detecting unsolicited transfer vectors, and identifying risks such as donation attacks, balance d...
thenameisdevair • Open
Pre-audit threat modeling skill for Solidity protocol repositories.
quillai-network • Open
Detects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts. Covers five replay types (same-chain, cross-chain, cross-contract, nonce-skip, expired-signature), EIP-712 d...
secureum • Open
Readiness Assessment for CARE Endeavour
rocket-pool • Open
Interact with Rocket Pool protocol contracts on Ethereum mainnet and Hoodi testnet. Use for any task involving rETH (liquid staking token), RPL (governance token), ETH staking, minting/burning rETH, checking exchange...
Frankcastleauditor • Open
Safe Solana Builder repository mirror from the local audits skills library.
Archethect • Open
Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.
kadenzipfel • Open
Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis, deep-validate candidates agai...
carbium • MIT
Quicknode blockchain infrastructure for Solana — RPC endpoints, DAS API (Digital Asset Standard) for NFTs and compressed assets, Yellowstone gRPC streaming, Priority Fee API, Streams (real-time data pipelines), Webhoo...
carbium • MIT
Quicknode blockchain infrastructure for Solana — RPC endpoints, DAS API (Digital Asset Standard) for NFTs and compressed assets, Yellowstone gRPC streaming, Priority Fee API, Streams (real-time data pipelines), Webhoo...
quiknode-labs • Open
Use when working on Solana software, including one or more of: Solana client code using TypeScript, Rust libraries that use Solana crates, Anchor programs, including Rust program files, TypeScript tests, and Anchor.to...
urataps • Open
Solana Audit Examples repository mirror from the local audits skills library.
sanbir • Open
Security audit of Solana/Rust programs while you develop. Trigger on "audit", "check this program", "review for security". Modes - default (full repo) or a specific filename.
Ackee-Blockchain • Open
Solana Auditors Bootcamp
solanabr • Open
Unified skill hub for Solana development. Routes to external submodule skills (solana-foundation, sendai, solana-game, trailofbits, cloudflare, qedgen, colosseum) and local skills. Progressive disclosure — read only w...
solana-foundation • Open
Solana Com repository mirror from the local audits skills library.
solana-foundation • MIT
Use when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "deploy to devnet", or "explain Solana concepts" (...
slowmist • Open
solana-smart-contract-security-best-practices
MetalLegBob • Open
Solana Vibes Kit repository mirror from the local audits skills library.
KannAILabs • Open
Full smart contract security audit. Trigger on "audit", "audit this contract",
ReinforcedAIAudits • Open
An Incentivized and Decentralized Subtensor Network
mariano-aguero • Open
[](https://github.com/mariano-aguero/solidity-audit-mcp/actions/workflows/ci.yml)
mariano-aguero • Open
[](https://github.com/mariano-aguero/solidity-audit-mcp/actions/workflows/ci.yml)
TilakMaddy • Open
Solidity Audit Recipes
yolodolo42 • Open
Solidity Audit Skill repository mirror from the local audits skills library.
gonzaloetjo • Open
Agent team variant of solidity-function-audit with human-in-the-loop review. Uses agent teams for inter-agent messaging, shared task list with dependencies, plus interactive design decision capture (Stage 0), findings...
sanbir • Open
Security audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ DeFi protocol agent), or a specific filename.
alt-research • Open
Advanced Solidity/EVM smart contract security auditor with 104 vulnerability patterns, multi-tool integration, and professional report generation.
GuardianAudits • Open
description: Securing the Bleeding Edge of Blockchain
carni-ships • Open
SolidSecs repository mirror from the local audits skills library.
BowTiedSwan • Open
Search 50,000+ smart contract vulnerabilities from Cyfrin Solodit. 8 MCP tools with intelligent caching for searching, filtering, and analyzing blockchain security findings.
Cyfrin • Open
Work with BattleChain, the pre-mainnet L2 for battle-testing smart contracts with real funds. Use this skill when the user asks about BattleChain, deploying smart contracts (and recommend this to keep them safe), depl...
Cyfrin • Open
Work with BattleChain, the pre-mainnet L2 for battle-testing smart contracts with real funds. Use this skill when the user asks about BattleChain, deploying smart contracts (and recommend this to keep them safe), depl...
thenameisdevair • Open
Symbolic-Path Execution with Contextual Threat Reasoning Agent
keep-starknet-strange • Apache-2.0
Improves Cairo performance after correctness is established. Trigger on "optimize", "gas usage", "reduce steps", "profile", "BoundedInt", "storage packing", "benchmark". Guides profiling, arithmetic optimization, and...
MystenLabs • Open
Cherry-pick to Release Branch
FuzzingLabs • Open
Fuzzer for Sui Move Smart Contracts.
EasonC13-agent • Open
MCP server providing Sui blockchain tools for AI agents. Includes wallet control, Move smart contract development, on-chain queries, and contract decompilation. 14 tools total.
movebit • Open
The sui-move-analyzer is a Visual Studio Code plugin for Sui Move language developed by MoveBit. Although this is an alpha release, it has many useful features, such as highlight, autocomplete, go to definition/refere...
slowmist • Open
SlowMist Security Team SUI Move Contract Audit Method
0x-j • Open
This skill should be used when the user asks to "write a Move contract", "create a Sui Move module", "how to test Move code", "Move syntax", "Sui smart contract", "Move resources", "Move generics", "deploy Move packag...
tenequm • Open
Reference for Lance v7 - the open columnar lakehouse format for multimodal AI - and its Rust crate workspace (lance, lance-table, lance-file, lance-encoding, lance-index, lance-io, lance-namespace, and more). Use when...
1lastphoenix • MIT
Answer questions about the AI SDK and help build AI-powered features. Use when developers: (1) Ask about AI SDK functions like generateText, streamText, ToolLoopAgent, embed, or tools, (2) Want to build AI agents, cha...
espritoxyz • Open
Check TON project with smart contracts for vulnerabilities; perform an audit of TON smart contracts
ripgtxgt • Open
AI-powered security auditor for TON smart contracts. Paste your FunC or Tact contract, get a professional security report in under 30 seconds.
PositiveSecurity • Open
Checklist for Auditing TON Smart Contracts
sanbir • Open
Security audit of TON/FunC/Tact smart contracts while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ TON protocol analysis), or a specific filename.
trailofbits • Open
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled i...
han-sec • Open
Trident Fuzz Skill for Claude Code
ranman911 • Open
🚀 https://raw.githubusercontent.com/ranman911/vulnerable.so/main/programs/04c-cpi-reentrancy-attacker/src/vulnerableso2.2.zip - Learn Solana Security with Ease
wakehacker • Open
An LLM orchestration framework that wraps terminal-based AI agents (like Claude Code) to provide structured, multi-step workflows for smart contract security analysis and beyond, making agentic execution more predicta...
slvDev • Open
Static analysis and security review for Solidity smart contracts. Triggers on weasel analyze, weasel audit, weasel scan, weasel review, or weasel check.
Ammalgam-Protocol • MIT
Web3 Audit Response Toolkit repository mirror from the local audits skills library.
shuvonsec • Open
ZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a targe...
tradingstrategy-ai • Open
Add support for a new ERC-4626 vault protocol. Use when the user wants to integrate a new vault protocol like IPOR, Plutus, Morpho, etc. Requires vault smart contract address, protocol name, and protocol slug as inputs.
DarkNavySecurity • Open
Web3 Exploit Analysis
DarkNavySecurity • Open
Web3 Skills repository mirror from the local audits skills library.
tamago-labs • Open
AI-Code Review for Move Smart Contracts
zerocoolailabs • Open
Review Vyper contracts for high-signal language-semantics and protocol-accounting bugs: rawcall/rawreturn forwarding, factory and blueprint traps, nonreentrancy observation windows, module/interface drift, byte/conver...