
Solidity Security Audit Assistant
Audit Solidity contracts for vulnerabilities, gas issues, and best practice violations
What You Can Do
You can conduct comprehensive security audits of Solidity smart contracts by providing your contract code and receiving structured analysis across multiple vulnerability categories. Claude identifies reentrancy risks, integer overflow/underflow issues, access control flaws, state management problems, gas inefficiencies, and best practice violations—catching subtle issues that automated analyzers miss. You'll receive detailed audit reports with severity ratings, specific remediation code, and business impact assessments to guide your fixes before mainnet deployment.
Features
identifies checks-effects-interactions violations and guard patterns
detects unchecked arithmetic and suggests SafeMath patterns
examines permission checks, modifier usage, and authorization flows
analyzes storage layout, initialization, and state consistency issues
finds inefficient patterns and suggests optimization techniques
flags deviations from Solidity standards and security guidelines
rates findings as critical, high, medium, or low with business impact
provides patched code snippets for each identified issue
Example Output
Audit Report: TokenSwap.sol
CRITICAL: Reentrancy vulnerability in withdraw() function
- Issue: External call to user address precedes balance update
- Impact: Attacker can drain contract via fallback function loop
- Fix: Move
balances[msg.sender] = 0beforemsg.sender.call{value: amount}()
HIGH: Integer overflow in mint() function
- Issue:
totalSupply += amountlacks bounds checking - Impact: Attacker can mint unlimited tokens if supply approaches uint256 max
- Fix: Add
require(totalSupply + amount > totalSupply)or use SafeMath
MEDIUM: Missing event emission in transfer()
- Issue: No event logged for token movements
- Impact: Off-chain indexing and monitoring fail
- Fix: Add
emit Transfer(from, to, amount)after balance updates
What's Included
- SKILL.md instruction file with systematic audit methodology and vulnerability taxonomy:
- Solidity Vulnerability Checklist: comprehensive reference for 25+ common attack patterns
- Audit Report Template: standardized format with severity levels and remediation sections
- Code Review Prompts: copy-paste templates for analyzing specific contract functions
- Security Patterns Reference: examples of correct vs. vulnerable code implementations
Who It's For
- Smart contract developers preparing for mainnet deployment
- Protocol engineers conducting internal security reviews before upgrades
- Technical leads auditing third-party contract integrations
- Blockchain security engineers establishing baseline reports before external audits
- DeFi developers reviewing code for inherited or forked protocols
Best For
- Pre-deployment security analysis of new smart contracts
- Internal code reviews for protocol upgrades and feature changes
- Baseline audit generation before engaging professional auditors
- Learning security patterns by analyzing vulnerabilities in existing code
- Risk assessment of contract forks and inherited codebases







