CtrlK
BlogDocsLog inGet started
Tessl Logo

auditing-foundry-smart-contract-security

Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and arithmetic bugs BEFORE deploying to an EVM chain. Also enforces key hygiene (no plaintext private keys, encrypted cast keystore) and a secure deploy workflow. Use when writing, reviewing, testing, or deploying Solidity/Foundry contracts, building a dApp, or working with forge/cast/anvil, MetaMask, or Web3/DeFi code.

76

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, executable audit playbook: concrete commands in a clear 7-step sequence with an explicit deploy gate, and detailed material appropriately offloaded to one-level-deep reference files that exist in the bundle. Only minor conciseness trimming in the Overview would improve it.

Suggestions

Tighten the Overview by dropping generalities Claude already knows (e.g. 'Deployed smart contracts are immutable and custody real funds, so a bug shipped to mainnet cannot be patched') and lead directly with the four-technique defense-in-depth structure.

In Step 1, add an explicit stop-checkpoint ('if `forge build` fails, fix compilation before running analyzers — they need artifacts') so the build validation is not merely implied.

State the coverage threshold numerically in Step 4 / Expected Output rather than 'below the configured threshold', so the FAIL gate is unambiguous without an external config lookup.

DimensionReasoningScore

Conciseness

Largely lean and command-driven with tool-specific detail that earns its tokens, but the Overview contains framing Claude already knows ('Deployed smart contracts are immutable and custody real funds') and a few explanatory glosses ('explores execution paths and SMT-solves') that could be trimmed.

4 / 5

Actionability

Copy-paste-ready, executable commands throughout — 'forge build', 'slither . --json slither-report.json', 'aderyn . -o aderyn-report.json', 'cast wallet import deployer --interactive', 'forge script ... --broadcast --verify', plus the bundled 'python3 scripts/agent.py' — covering the common audit cases with only appropriate placeholders.

5 / 5

Workflow Clarity

Seven numbered steps are clearly sequenced from build → static → symbolic → testing → manual review → key hygiene → triage, with an explicit PASS/FAIL deploy gate ('FAIL on any high/critical static finding, failing test, leaked secret, or coverage below...') as a validation checkpoint and a triage feedback loop for false-positive removal.

5 / 5

Progressive Disclosure

SKILL.md acts as a concise overview pointing one level deep to real bundled files — references/vulnerability-checklist.md, references/secure-deployment-and-keys.md, references/api-reference.md, and scripts/agent.py (all present on disk) — with each reference clearly signaled at the relevant step.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, complete, and distinct: it names concrete techniques and bug classes, provides an explicit 'Use when' clause covering natural user phrasing, and occupies a well-defined niche with low conflict risk. Third-person voice is maintained throughout, so no voice penalty applies.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across four techniques — 'static analysis (Slither, Aderyn)', 'symbolic execution (Mythril)', 'property-based testing (forge fuzz + invariant tests with handlers)' — plus concrete bug classes ('reentrancy, access-control, oracle/price manipulation, and arithmetic bugs') and key-hygiene enforcement, giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both: the 'what' ('Pre-deployment security audit... Combines static analysis... symbolic execution... property-based testing') and a concrete 'when' ('Use when writing, reviewing, testing, or deploying Solidity/Foundry contracts, building a dApp, or working with forge/cast/anvil, MetaMask, or Web3/DeFi code').

5 / 5

Trigger Term Quality

Comprehensive natural terms users would say: 'Solidity', 'Foundry', 'smart contracts', 'dApp', 'Web3/DeFi', plus tool names 'forge/cast/anvil', 'MetaMask', 'Slither', 'Mythril' — covering synonyms and specific tooling.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche — pre-deployment Foundry/Solidity smart-contract security auditing — with distinct tool- and domain-specific triggers, making overlap with other skills minimal.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.