Skip to content
Back to skills

Contract Audit

ASecurity

Audit a smart contract for security vulnerabilities and report findings by severity

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
ai-agentsrustgosecurity

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill contract-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Contract Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Contract Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-contract-audit/badge)](https://www.skillsdirectory.com/skills/black141312-contract-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: contract-audit
description: Audit a smart contract for security vulnerabilities and report findings by severity
category: web3
---

# Contract Audit

Use when reviewing a Solidity contract for exploitable bugs before deployment or when triaging a reported issue. Be adversarial: assume every external call is hostile.

1. Map the surface: list all external/public functions, who can call them, and which ones move value or change privileged state.
2. Trace value flows and trust boundaries; flag every external call, `delegatecall`, and low-level `call`/`transfer`.
3. Hunt the classic classes: reentrancy, integer/rounding errors, unchecked return values, access-control gaps, front-running/MEV, oracle/price manipulation, and unbounded loops (DoS).
4. Check upgradeability and init: uninitialized proxies, storage-layout collisions, missing `initializer` guards, and dangerous `selfdestruct`.
5. Run tooling: `slither`, `aderyn`, fuzz/invariant tests (`forge test`), and diff against known-good library versions.
6. Rate each finding (Critical/High/Medium/Low/Informational) with impact, a concrete exploit scenario, and a fix.
7. Re-verify after fixes — confirm the patch closes the issue without opening a new one.

## Rules
- Confirm exploitability with a PoC test or a precise call sequence; do not report theoretical noise as High.
- Reentrancy: verify checks-effects-interactions, not just the presence of a guard.
- Treat any external/oracle data as attacker-controlled until proven otherwise.
- Check for missing access modifiers on initializers, setters, and withdrawal functions.
- Flag floating pragmas and outdated/vulnerable dependency versions.
- Never modify contract logic silently during an audit — report, then fix in a separate, reviewed change.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…