
Smart Contract Security Analysis & Code Review
Detect smart contract vulnerabilities and optimize security instantly
What You Can Do
Analyze Solidity and other smart contract code for security vulnerabilities, gas inefficiencies, and best practice violations. Get detailed reports with risk scoring, remediation suggestions, and optimization recommendations. Whether you're auditing before deployment or reviewing third-party contracts, this skill identifies critical issues faster than manual review.
Features
Identifies reentrancy, integer overflow/underflow, unchecked call returns, timestamp dependency, and 50+ known attack vectors
Finds inefficient patterns and suggests storage layout improvements, loop optimization, and calldata vs memory tradeoffs
Checks for proper access control, input validation, state management, and ERC-20/721/1155 standard compliance
Detects suspicious patterns like delegatecall usage, proxy vulnerabilities, and initialization issues
Rates each finding as critical, high, medium, or low with detailed justification and impact assessment
Provides code examples and step-by-step fixes for every vulnerability found
Visualizes external calls, dependencies, and potential attack surfaces across contract interactions
Produces professional security audit reports suitable for stakeholders and deployment teams
Example Output
Vulnerability Report for TokenMint.sol:
- 🔴 CRITICAL — Reentrancy Vulnerability (Line 42)
// Vulnerable
(bool success, ) = recipient.call{value: amount}("");
require(success, "Transfer failed");
balances[recipient] -= amount; // State change after call
Risk: Attacker can drain contract during callback Fix: Update state before external call using checks-effects-interactions pattern
- ⚠️ HIGH — Unchecked Integer Overflow (Line 18)
uint8 price = 100;
price += user_input; // No validation
Recommendation: Use Solidity 0.8.0+ (automatic checks) or OpenZeppelin SafeMath
- 💡 MEDIUM — Gas Inefficiency (Line 35)
for (uint i = 0; i < array.length; i++) { // Reads length each iteration
// ...
}
Optimization: Cache array.length in local variable (saves ~3 gas per iteration)
Summary: 8 issues found (1 critical, 2 high, 3 medium, 2 low). Estimated severity: High. Recommend: Deploy blocklist contract, audit reentrancy fixes, optimize loops before mainnet.
What's Included
- SKILL.md: Complete smart contract security analysis workflow with decision trees and verification checklists
- Vulnerability checklist template: 50+ known vulnerabilities organized by category (reentrancy, overflow, access control, etc.)
- Security audit report template: Professional format suitable for stakeholder review and deployment teams
- Gas optimization guide: Common patterns and their gas costs with before/after comparisons
- Remediation code examples: Copy-paste fixes for common vulnerabilities (SafeMath, ReentrancyGuard, etc.)
- Contract interaction mapper: Workflow for analyzing call chains and dependency graphs
- ERC standard compliance checklist: Verification for ERC-20, ERC-721, ERC-1155, and ERC-4626
Who It's For
- Smart contract developers — Review your own code before deployment or during development iterations
- Blockchain security auditors — Streamline manual audits with automated vulnerability detection and reporting
- DeFi protocol teams — Pre-launch security review for staking, yield farming, and lending contracts
- Smart contract reviewers — Code review specialists evaluating third-party contracts or community contributions
- Web3 startup teams — Quick security assessments when you need results faster than hiring external auditors
Best For
- Pre-deployment security audits — Run before testnet/mainnet launch
- Vulnerability detection — Identify reentrancy, overflow, and access control issues automatically
- Gas optimization — Reduce transaction costs by identifying inefficient patterns
- Code review preparation — Audit third-party contracts or contributions quickly
- Compliance checking — Verify ERC token standards and security best practices
- Post-incident analysis — Investigate exploited contracts and understand attack vectors







