
Smart Contract Security Audit & Gas Optimization Review
Audit smart contracts for security vulnerabilities and gas inefficiencies
What You Can Do
You get a comprehensive security and gas optimization review of your Solidity smart contracts. The skill identifies common vulnerabilities like reentrancy attacks, overflow/underflow bugs, and unchecked external calls, while also pinpointing expensive operations and suggesting specific gas optimizations. Use this as a pre-audit screening to catch issues early and prepare your code for professional security review.
Features
identifies reentrancy, integer overflow/underflow, unchecked calls, and other common exploits
analyzes execution paths, storage patterns, and loop operations to find optimization opportunities
examines permission models, role assignments, and authorization checks for gaps
compares code against Solidity style guidelines, naming conventions, and industry standards
prioritizes findings from critical to info-level so you fix the highest-impact items first
provides specific code changes with explanations for each optimization
identifies inefficient storage patterns and suggests packing strategies
flags risky interactions with other contracts and suggests SafeERC20/checked call patterns
Example Output
Security Finding — Critical: Reentrancy Vulnerability
// VULNERABLE
function withdraw(uint amount) external {
require(balanceOf[msg.sender] >= amount);
(bool success,) = msg.sender.call{value: amount}("");
require(success);
balanceOf[msg.sender] -= amount; // State change AFTER external call
}
Fix: Move state update before external call (checks-effects-interactions pattern).
Gas Optimization — Medium: Redundant Storage Reads
Your batchTransfer() function reads contractState.maxSupply inside the loop 10+ times. Estimated savings: ~2,000 gas per transaction. Cache it as a local variable before the loop.
Access Control Issue — High: The burn() function requires msg.sender == owner, but owner is never initialized in the constructor. This will always revert.
What's Included
- SKILL.md: Complete audit workflow and security analysis methodology
- Security Checklist: 40+ vulnerability patterns and exploit vectors to analyze
- Gas Optimization Matrix: Common inefficiencies mapped to gas savings
- Risk Scoring Template: Framework for ranking findings by severity and exploitability
- Remediation Tracker: Checklist to track fixes before professional audit
Who It's For
- Smart contract developers preparing code for deployment or professional audit
- DeFi protocol teams reducing gas costs and improving contract security
- Blockchain security engineers performing initial risk assessment and code review
- Web3 audit firms using this as a pre-screening tool before formal engagement
- Protocol founders who need fast security visibility before stakeholder review
Best For
- Pre-audit security screening — catch vulnerabilities before paying for professional audits
- Gas cost optimization — reduce transaction costs and improve user experience
- Code review preparation — self-audit before team or community review
- Smart contract refactoring — identify architectural weaknesses and improvement opportunities
- Post-incident analysis — quickly audit similar contracts after ecosystem security events







