CtrlK
BlogDocsLog inGet started
Tessl Logo

defi-amm-security

Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. Covers reentrancy, CEI ordering, donation or inflation attacks, oracle manipulation, slippage, admin controls, and integer math. Use when auditing or writing Solidity AMM, liquidity pool, or swap code.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, terse pattern-library skill: every category pairs vulnerable and hardened code, ends with a concrete checklist and runnable tool commands, and wastes almost no tokens. The gaps are that key safe snippets assume undeclared context and the audit workflow is a checklist rather than an explicit sequenced process.

Suggestions

Complete the safe deposit and swap examples with the minimal state declarations and helper signatures (totalShares, _totalAssets, _calculateOut, _executeSwap) so the code is copy-paste executable rather than fragmentary.

Promote the workflow from a checklist to a short numbered audit sequence (enumerate entrypoints -> match against categories -> apply hardened patterns -> verify with the checklist -> run slither/echidna), making the validation checkpoint and fix-retry loop explicit.

Move the per-vulnerability example library into a one-level-deep references/ file (e.g., PATTERNS.md) and keep SKILL.md as an overview with clearly signaled links, reducing the inline body length.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence ("Spot prices are flash-loan manipulable. Prefer TWAP."), with no explanation of concepts Claude already knows; the only trims are the somewhat boilerplate four-sentence Execution Safety paragraph and a few one-liners that repeat the checklist.

4 / 5

Actionability

Concrete vulnerable/safe code pairs and real tool commands (slither, echidna, forge) are provided, but the safe deposit and swap snippets depend on undeclared state and helpers (totalShares, _totalAssets, _calculateOut, _executeSwap), so they are not fully copy-paste ready.

4 / 5

Workflow Clarity

"Review every user entrypoint against the categories below and prefer the hardened examples" gives a clear method, and the Security Checklist plus static-analysis/fuzzing items serve as validation checkpoints; however the sequence is implied rather than stepwise and there is no explicit fix-and-recheck loop.

4 / 5

Progressive Disclosure

Sections are well-organized and easy to navigate, but at ~165 lines everything is inlined in SKILL.md with no bundle files; the per-vulnerability example library is a natural candidate for one-level-deep reference files.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states a clear niche, enumerates comprehensive concrete coverage areas, and pairs an explicit what with an explicit use-when clause in natural third-person trigger language. No changes needed.

DimensionReasoningScore

Specificity

The description enumerates seven concrete coverage areas ("reentrancy, CEI ordering, donation or inflation attacks, oracle manipulation, slippage, admin controls, and integer math") within a clearly named domain, matching the comprehensiveness of the anchor-5 example.

5 / 5

Completeness

It explicitly answers both parts: a clear what ("Security checklist for Solidity AMM contracts... Covers reentrancy...") and a concrete when ("Use when auditing or writing Solidity AMM, liquidity pool, or swap code"), in third person.

5 / 5

Trigger Term Quality

Natural trigger phrases users would actually say are comprehensively covered: "auditing", "writing", "Solidity AMM", "liquidity pool", "swap", plus natural vulnerability terms like reentrancy and slippage; no common variations are missing.

5 / 5

Distinctiveness Conflict Risk

The Solidity AMM/liquidity-pool/swap niche is distinct with domain-specific triggers (reentrancy, oracle manipulation, slippage) that would not cause a generic or sibling security skill to trigger instead.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.