
Smart Contract Security Audit & Optimizer
Audit and optimize Solidity contracts for vulnerabilities and gas efficiency
What You Can Do
You can submit your Solidity smart contracts for comprehensive security analysis, vulnerability detection, and gas optimization recommendations. Claude reviews your code against known attack vectors, design patterns, and best practices—identifying reentrancy risks, overflow/underflow issues, access control flaws, and inefficient operations. You receive actionable fix recommendations with explanations of the security implications and gas savings potential.
Features
Identifies reentrancy, integer overflow/underflow, unchecked calls, and access control flaws
Finds inefficient storage patterns, expensive loops, and unnecessary operations with cost estimates
Checks compliance with ERC-20, ERC-721, and other standard interfaces plus common anti-patterns
Proposes specific code changes with explanations of security and performance impact
Rates vulnerabilities as critical, high, medium, or low based on exploitability and impact
Verifies adherence to OpenZeppelin standards, SafeMath patterns, and reentrancy guards
Estimates transaction cost changes and provides before/after gas comparisons
Example Output
Sample Vulnerability Report
Critical Issue: Reentrancy in withdraw() function
- Location: Line 45,
(success, ) = recipient.call{value: amount}("") - Risk: Attacker contract can recursively call
withdraw()before balance updates - Fix: Move balance update before external call:
balances[msg.sender] = 0; (success, ) = recipient.call{value: amount}("") - Gas Savings: 200 gas per call
Gas Optimization Example
Current code:
for (uint i = 0; i < users.length; i++) {
if (balances[users[i]] > 0) { /* ... */ }
}
Optimized code:
for (uint i = 0; i < users.length; ++i) { // ++i saves 6 gas
uint bal = balances[users[i]]; // cache storage read
if (bal > 0) { /* ... */ }
}
Estimated savings: ~2,400 gas for 100 iterations
What's Included
- SKILL.md: Complete security audit framework with vulnerability taxonomy and remediation workflows
- Security Checklist: 50+ vulnerability patterns across contracts, functions, and math operations
- Gas Optimization Guide: Reference for storage, loops, function calls, and opcode efficiency
- Audit Report Template: Structure for organizing findings, severity levels, and fix recommendations
- ERC Standards Compliance Matrix: Requirements for ERC-20, ERC-721, ERC-1155, and proxy patterns
- Common Anti-Patterns Reference: Guide to pull-over-push, delegation, and upgradability risks
Who It's For
- Solidity Developers building production dApps and protocols
- Security Auditors & Code Reviewers performing pre-deployment validation
- DeFi Protocol Teams shipping complex financial contracts
- Web3 Startups launching EVM-based smart contracts
- Smart Contract QA Engineers verifying code quality and safety before mainnet
Best For
- Pre-deployment security review of new or modified contracts
- Gas optimization for reducing transaction costs before release
- Best practices validation against ERC standards and design patterns
- Vulnerability discovery in existing contracts or audits
- Code pattern compliance verification against organization standards







