Skip to main content

contracts-overview

Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.

跳到安装

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年8月17日 22:24
检测到的 SKILL.md 语言
英语
星标
5,522
分支
1,048

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
10 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
contracts-overview
description
Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.
metadata
{"subdomain":"smart-contracts","when_to_use":"smart contract solidity evm slither foundry defi audit lane overview routing","mitre_attack":["T1190","T1565","T1565.001"],"capability_contract":{"lane":"web3","scope":"isolated-lab","environment":["anvil","forked-chain"],"required_tools":["forge","slither"],"evidence":["foundry-poc","evm-trace","patched-build-result"],"verification":"run the exploit test against the exact deployment or pinned fork","negative_control":"run the baseline test without the exploit precondition","scorecard":["validated-rate","patched-build-non-repro-rate","unique-root-causes"],"benchmark":"held-out-web3"}}
# Smart Contract Audit Catalog ## Playbooks | Skill | Use for | |---|---| | `/skills/standard/contracts/reentrancy/SKILL.md` | Classic + read-only reentrancy | | `/skills/standard/contracts/oracle-manipulation/SKILL.md`| Single-block TWAP / spot price abuse | | `/skills/standard/contracts/flash-loan/SKILL.md` | Flash-loan callback + unauth gadgets | | `/skills/standard/contracts/access-control/SKILL.md` | Missing modifiers, wrong msg.sender | | `/skills/standard/contracts/upgradeable-proxy/SKILL.md` | Uninitialized impl, storage clash | | `/skills/standard/contracts/signature-replay/SKILL.md` | Cross-chain, ecrecover zero address | ## Workflow 1. Map the target: `bash("find /workspace/src -name '*.sol' | head -50")` 2. `solidity_scan_file` on each file 3. Run slither: `bash("cd /workspace && slither . --json slither.json")` 4. `slither_ingest("/workspace/slither.json")` 5. `kg_query(kind="vulnerability", min_severity="high")` to see the highs 6. For each high, generate a Foundry PoC via `foundry_reentrancy_test` etc. 7. `bash("forge test -vvv --match-contract Test_")` to run 8. Promote passing PoCs as validated findings ## Default severity floor | Impact | CVSS / Reward tier | |--------------------------------|--------------------| | Loss of user funds | Critical (9.8+) | | Locked funds / permanent DoS | High (7.5-9.0) | | Temporary DoS / griefing | Medium (5-7) | | View-only data leak | Low (3-5) |
在 GitHub 查看