CtrlK
BlogDocsLog inGet started
Tessl Logo

blockchain-contract-attack

区块链/智能合约:Etherscan,slither/mythril,重入/访问控制/预言机/闪电贷,跨链桥,RPC暴露。Use when auditing smart contracts, DeFi, or blockchain attack surfaces.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/blockchain-contract-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

62%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is maximally token-efficient and dense with domain-specific facts, but it reads as a flat vulnerability checklist rather than an operational skill: no executable commands and no sequenced audit workflow with validation steps. Converting the implicit source→automated→manual flow into explicit steps with runnable tool invocations would substantially raise actionability and workflow clarity.

Suggestions

Add runnable commands for the automated phase, e.g. a concrete slither invocation ('slither . --detect reentrancy-eth reentrancy-no-eth') and the Etherscan getsourcecode API URL template, so the guidance is copy-paste executable.

Restructure the implicit phases into an explicit numbered workflow (1. fetch & verify source matches on-chain bytecode, 2. run slither/mythril, 3. manual checks by category, 4. confirm findings against PoC) with a validation checkpoint before reporting a vulnerability as exploitable.

Replace the single monolithic code block with short labeled sections (Source retrieval / Automated analysis / Manual checks / DeFi & bridges) so the card is scannable and each category can be extended without re-formatting.

DimensionReasoningScore

Conciseness

The body is an extremely lean reference card — no padding, no explanations of concepts Claude already knows; every token carries a specific fact (tool names, C-E-I ordering, port 8545, eth_sendTransaction). Matches anchor 5 ('every token earns its place').

5 / 5

Actionability

Concrete specifics are present ('slither/mythril/manticore', '.call{value}先转账后改状态', '<0.8无SafeMath', 'block.timestamp可控', '暴露8545直接eth_sendTransaction') but there are no executable commands (e.g., an actual slither CLI invocation or Etherscan API call). Anchor 3 ('some concrete guidance but incomplete; missing key details') fits better than 2, since these are far more than high-level hints.

3 / 5

Workflow Clarity

Only a rough implicit three-phase grouping (源码 obtain source → 审计 automated tools → 手工 manual review) with no explicit sequencing and no validation checkpoints for an audit workflow — anchor 2 ('rough sequence present but many gaps; validation absent'), above anchor 1 since a coarse sequence is discernible.

2 / 5

Progressive Disclosure

No bundle files exist and the body is short, so nothing needs splitting; however the entire skill is a single monolithic code block under one heading with internal labels rather than clearly organized sections — anchor 4 ('good structure; minor organization gaps') rather than 5's well-organized sections.

4 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is compact, specific, and carries a clear explicit 'Use when' trigger with low conflict risk. Its main weakness is that the capability statement is a compressed keyword tag list rather than concrete third-person actions, which slightly limits specificity and completeness.

DimensionReasoningScore

Specificity

Names the domain plus concrete tools ('Ethersan,slither/mythril') and specific vulnerability classes ('重入/访问控制/预言机/闪电贷,跨链桥,RPC暴露'), but it is a telegraphic keyword tag list rather than explicit actions, so it sits at anchor 4 with minor gaps rather than comprehensive concrete actions.

4 / 5

Completeness

Both parts are present — 'what' as a keyword enumeration of tools and vulnerability classes, and an explicit 'Use when auditing smart contracts, DeFi, or blockchain attack surfaces' trigger — but the 'what' is implicit (no verbs/actions, just tags), so it matches anchor 4 ('when' present, what could be more explicit) rather than 5's fully explicit both.

4 / 5

Trigger Term Quality

Includes natural phrases users would say ('auditing smart contracts, DeFi, blockchain attack surfaces') but misses common synonyms such as 'Solidity', 'Web3', 'Ethereum', or 'penetration test'. Anchor 4 ('good keyword coverage; a few natural terms missing') fits better than 5's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

Clear niche in smart-contract/blockchain security auditing with distinct trigger phrases ('smart contracts', 'DeFi', 'blockchain attack surfaces') that are unlikely to fire the wrong skill — matches anchor 5.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.