
Smart Contract Vulnerability Analyzer
Identify and classify smart contract security vulnerabilities with structured analysis
What You Can Do
You can conduct comprehensive security assessments of smart contracts by feeding Claude modular contract code with explicit vulnerability analysis frameworks. Claude traces execution paths, identifies state management issues, evaluates cryptographic implementations, and spots economic model exploits. This structured approach catches interdependencies and subtle design flaws that surface-level reviews miss, making it ideal for pre-deployment audits and incident investigations.
Features
guide Claude through contract logic, state management, and external calls using structured prompts
categorize vulnerabilities by severity (critical, high, medium, low) with exploit feasibility assessment
identify known patterns (reentrancy, overflow, access control bypass, economic exploits) against contract logic
reason about how contract functions interact and where state assumptions break down
evaluate signature schemes, randomness sources, and key management for weaknesses
spot incentive misalignments, flash loan vulnerabilities, and protocol-level design flaws
generate fixes with code examples and explain why each fix closes the vulnerability
validate implementations against best practices for the contract type (ERC-20, DEX, staking, etc.)
Example Output
Reentrancy Vulnerability Found:
- Location:
withdraw()function, line 47 - Severity: Critical
- Issue: Contract transfers funds before updating balance, allowing recursive calls
- Exploit: Attacker calls
withdraw(), receives ETH via fallback function, callswithdraw()again beforebalances[msg.sender]is zeroed - Fix: Update balance before transfer (CEI pattern) or add reentrancy guard
Access Control Gap:
- Location:
updateAdmin()function, line 82 - Severity: High
- Issue: Function lacks
onlyOwnermodifier, allows any address to change admin - Impact: Attacker gains protocol control
- Fix: Add
require(msg.sender == owner)check
Economic Model Risk:
- Location: Staking reward distribution
- Severity: Medium
- Issue: Rewards calculated without rounding protection; dust amounts accumulate and cause precision loss over time
What's Included
- SKILL.md: core instructions for structuring vulnerability analysis prompts
- Vulnerability Checklist: 40+ vulnerability types organized by category (reentrancy, access control, state management, cryptography, economics)
- Analysis Framework Template: step-by-step prompts for guiding Claude through contract code sections
- Risk Severity Matrix: criteria for classifying vulnerabilities by impact and likelihood
- Exploit Pattern Reference: known attack vectors with code examples and mitigation strategies
- Audit Report Template: markdown structure for documenting findings with remediation priorities
Who It's For
- Smart contract security auditors — conduct comprehensive pre-deployment security assessments
- DeFi protocol developers — review contracts before mainnet launch to identify design flaws
- Security researchers — investigate vulnerabilities in complex mechanisms (AMMs, staking, lending)
- Bug bounty hunters — systematically analyze contracts for exploitable flaws
- Blockchain engineers — validate third-party integrations and external contract interactions
Best For
- Pre-mainnet contract audits with modular code review
- Incident investigation and post-exploit root cause analysis
- Reviewing novel mechanisms and unfamiliar Solidity patterns
- Validating security fixes against previously identified vulnerabilities
- Economic model assessment in DeFi protocols
- Assessing cryptographic implementations and randomness sources







