
Solidity Security Audit Assistant
Audit Solidity contracts for vulnerabilities, gas inefficiencies & best practices
What You Can Do
You can conduct comprehensive security audits of Solidity smart contracts by submitting code for systematic analysis across vulnerability categories, gas optimization, and best practice compliance. Claude identifies critical issues like reentrancy attacks, integer overflow/underflow, improper access controls, and unoptimized patterns—providing actionable findings with severity levels and remediation guidance. This skill works best as a pre-audit screening tool to catch issues before engaging professional auditors.
Features
identifies reentrancy, integer overflow/underflow, access control flaws, delegatecall risks, and other OWASP top vulnerabilities
flags inefficient storage patterns, unnecessary computations, and opportunities to reduce transaction costs
validates compliance with Solidity conventions, OpenZeppelin standards, and architectural patterns
categorizes findings as critical, high, medium, or low with clear impact explanations
evaluates contract design patterns, separation of concerns, and principle of least privilege implementation
supports iterative refinement by analyzing contract modifications and explanations of fix attempts
produces audit findings summaries suitable for internal records or compliance documentation
detects common vulnerability classes like improper initialization, unchecked external calls, and state management issues
Example Output
Contract Analysis Request:
function withdraw(uint amount) public {
require(balances[msg.sender] >= amount);
(bool success, ) = msg.sender.call{value: amount}("");
require(success);
balances[msg.sender] -= amount;
}
Audit Output:
- CRITICAL: Reentrancy Vulnerability — Balance is decremented after external call. Attacker can recursively call
withdraw()to drain contract. Fix: Use CEI pattern (Checks-Effects-Interactions) or ReentrancyGuard. - HIGH: Unchecked Return Value — External call success checked but no fallback mechanism. Add try-catch or explicit revert with reason.
- MEDIUM: Gas Inefficiency — Use
transfer()ortransferFrom()instead of low-levelcall{}for standard ERC20 transfers.
Recommended Remediations:
- Move balance update before external call
- Implement OpenZeppelin ReentrancyGuard
- Add detailed revert reasons for failed withdrawals
What's Included
- SKILL.md: Core instruction file with audit framework and vulnerability taxonomy
- Vulnerability Checklist: Structured list of 40+ vulnerability patterns organized by category (access control, state management, external interactions)
- Audit Report Template: Markdown template for documenting findings with severity levels, code snippets, and remediation steps
- Gas Optimization Guide: Reference list of common gas inefficiencies with before/after code examples
- Best Practices Framework: Solidity conventions checklist covering naming, documentation, error handling, and design patterns
Who It's For
- Smart Contract Developers — conducting internal security reviews before mainnet deployment
- Blockchain Security Engineers — analyzing contract code for vulnerability patterns and compliance
- Code Reviewers — evaluating pull requests containing Solidity modifications
- Junior Developers — learning vulnerability patterns and security-first coding practices
- DeFi Protocol Teams — assessing third-party contract integrations and inherited codebases
Best For
- Pre-audit screening of smart contracts before engaging professional auditors
- Pull request security reviews for ongoing contract development
- Gas optimization analysis for production contract cost reduction
- Training and knowledge transfer on Solidity vulnerability patterns
- Risk assessment of contract integrations and external dependencies







