security-smart-contracts
Audit Solidity and EVM smart contracts, web3 protocols, and on-chain code. Use for smart contract review, Solidity or DeFi audit, proxy and upgradeability checks, invariant and property fuzzing design, oracle and price manipulation review, ERC-4337 or EIP-7702 account abstraction, Permit2 and signature replay, L2 and cross-chain risk, and for running Slither, Aderyn, Echidna, Medusa, Halmos, or Foundry invariants. Skip it for off-chain application, cloud, container, or dependency security, for gas golfing, and for tokenomics or economic-design review with no security question attached.
Pinned to revision 6335fa80c2f6, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-smart-contracts/SKILL.md
- skills/security-smart-contracts/references/invariants-and-fuzzing.md
- skills/security-smart-contracts/references/operations.md
- skills/security-smart-contracts/references/tooling.md
- skills/security-smart-contracts/references/vulnerability-classes.md
Every link opens the file at its source, pinned to the revision this page describes.