CtrlK
BlogDocsLog inGet started
Tessl Logo

solidity-security

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

70

1.00x
Quality

58%

Does it follow best practices?

Impact

94%

1.00x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/blockchain-web3/skills/solidity-security/SKILL.md

The canonical home for this skill is solidity-security in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers concrete, pattern-based Solidity examples, but it is a monolithic knowledge dump: it re-teaches security concepts Claude already knows, inlines ~500 lines that its own Resources section says should live in separate files, and every one of those referenced bundle files is missing from the bundle. There is also no sequenced audit workflow despite auditing being a headline use case.

Suggestions

Create the actual bundle files (references/reentrancy.md, references/access-control.md, etc.) or remove the Resources section — currently all 8 cited paths are dangling, so progressive disclosure is broken.

Cut the body to a lean overview: keep one compact example per vulnerability class and move the extended vulnerable/secure code pairs, gas optimization details, and testing snippets into the referenced files.

Add a sequenced audit workflow with validation checkpoints, e.g., run Slither/Mythril with the actual commands, triage findings, apply the security checklist, and re-run analysis before declaring a contract clean.

DimensionReasoningScore

Conciseness

At ~500 lines the body restates material Claude already knows well — full explanations of reentrancy, CEI ordering, integer overflow, SafeMath, and basic gas tips like 'uint256 instead of smaller types' and 'calldata instead of memory' are standard Solidity knowledge. Several padded sections ('Attacker calls back into your contract before state is updated', complete vulnerable-vs-secure contract pairs for overflow) could be cut to a one-line reminder, matching 'Noticeably verbose; several unnecessary explanations or padded sections' rather than the 'mostly efficient' anchor at 3.

2 / 5

Actionability

Mostly concrete, copy-adaptable Solidity snippets: named OpenZeppelin imports (ReentrancyGuard, Ownable, Pausable, SafeMath), a working commit-reveal scheme, and a runnable Hardhat/Chai test block. Not a 5 because several examples are non-compiling fragments — the Input Validation and Front-Running contracts reference undeclared mappings/functions (e.g., `balances` never declared, `calculateOutput` undefined) — so they are illustrative rather than fully executable.

4 / 5

Workflow Clarity

Auditing is a multi-step process, but the body provides no sequenced workflow — the tools (Slither, Mythril, Echidna) are name-dropped with no commands, and the 'Security Checklist Contract' embeds a checklist inside a code comment rather than an actionable procedure. There are no validation checkpoints (run analyzer → triage findings → re-check), matching 'sequence present but checkpoints missing or implicit' at 3; a 4 would require an ordered audit flow with verification steps.

3 / 5

Progressive Disclosure

The Resources section cites 8 bundle files (references/reentrancy.md, references/access-control.md, references/overflow-underflow.md, references/gas-optimization.md, references/vulnerability-patterns.md, assets/solidity-contracts-templates.sol, assets/security-checklist.md, scripts/analyze-contract.sh), but none of these files or directories exist — every reference is dangling. Meanwhile ~500 lines of content that the skill itself claims belongs in those files is inlined, matching 'content that clearly belongs in separate files is inlined' at 2; it avoids a 1 only because section headers give the document reasonable navigability.

2 / 5

Total

11

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit 'Use when...' clause covering three trigger scenarios and good natural keywords. Its main weakness is that the 'what' half relies on generic phrasing ('master best practices', 'common vulnerabilities') rather than naming the concrete security capabilities the skill actually covers.

DimensionReasoningScore

Specificity

The description names the domain and two actions — "prevent common vulnerabilities and implement secure Solidity patterns" — but the actions are generic; no concrete capability (e.g., reentrancy prevention, access control, audit prep) is named. It matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive'; a 4 would require several specifically enumerated actions, and 'Master... best practices' is borderline fluff rather than a concrete action.

3 / 5

Completeness

Both parts are explicit: what ("Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns") and when ("Use when writing smart contracts, auditing existing contracts, or implementing security measures"). Not a 5 because the 'what' leans on the vague 'master best practices' rather than concrete capabilities with concrete trigger phrases; clearly above 3 since the 'when' clause is explicit and multi-condition, not weakly implied.

4 / 5

Trigger Term Quality

Good natural keyword coverage: "writing smart contracts", "auditing existing contracts", "Solidity", "blockchain applications", "security measures" — phrases users would plausibly say. A 5 would add common synonyms/variants (e.g., 'DeFi', 'EVM', 'Web3', 'audit'), which are missing.

4 / 5

Distinctiveness Conflict Risk

Smart contract security auditing is a clear niche with distinct triggers, so it is mostly distinguishable from unrelated skills. Minor overlap risk remains with a hypothetical general Solidity-development or code-audit skill, since 'Use when writing smart contracts' would also fire there — keeping it below the 'minimal conflict risk' anchor at 5.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (526 lines); consider splitting into references/ and linking

Warning

referenced_paths_exist

Referenced path issues: 8 missing

Warning

Total

14

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.