
Solidity Security Audit Assistant
Identify vulnerabilities, gas inefficiencies, and design flaws in Solidity smart contracts
What You Can Do
You can conduct comprehensive security audits of Solidity smart contracts by identifying common vulnerabilities like reentrancy bugs, overflow/underflow issues, and access control gaps. The skill applies OWASP Smart Contract Top 10 patterns and ERC token standards compliance checks to catch critical flaws before deployment, helping you optimize gas usage and strengthen contract architecture.
Features
identifies unsafe call patterns and state management issues that enable reentrancy exploits
catches overflow/underflow bugs and unsafe math operations across contract logic
reviews permission models, function visibility, and role-based restrictions for gaps
pinpoints inefficient loops, redundant storage access, and unnecessary computations
validates token contract implementations against ERC-20, ERC-721, and other standards
evaluates inherited contracts and external libraries for known vulnerability patterns
identifies design flaws in state management, upgrade mechanisms, and contract interactions
Example Output
Vulnerability Report: TokenVault.sol
Critical Issues Found: 2
- Reentrancy in withdraw() (Line 45): External call to
msg.senderbefore updating balance allows recursive withdrawals- Fix: Implement checks-effects-interactions pattern; update balance before transfer
High Priority: 1
- Missing access control on mint() (Line 28): Any address can call minting function
- Fix: Add
onlyOwnermodifier or role-based access control
- Fix: Add
Gas Optimization Opportunities: 3
- Store
balances[msg.sender]in memory before loop (Line 12) to save 3 SLOAD operations (~300 gas) - Replace
forloop with batch processing for mass transfers - Use immutable for token name and symbol declarations
Compliance Status: ERC-20 interface incomplete — missing approve() event emission
What's Included
- SKILL.md: Complete audit methodology and vulnerability classification framework
- Vulnerability Checklist: Structured list of 50+ common Solidity vulnerability patterns
- Code Review Template: Section-by-section contract analysis framework
- Gas Optimization Reference: Documented gas costs for common operations and improvement strategies
- ERC Compliance Validator: Interface requirements for ERC-20, ERC-721, and ERC-1155 standards
Who It's For
- Solidity smart contract developers conducting pre-deployment security reviews
- Blockchain development teams performing peer code review before mainnet launch
- Web3 engineers assessing third-party contracts for integration risks
- Security-focused developers learning secure Solidity patterns and best practices
- Contract auditors preparing code for professional third-party security assessments
Best For
- Pre-deployment security audits of new smart contracts
- Gas optimization analysis before mainnet launch
- Identifying reentrancy vulnerabilities and access control gaps
- Validating ERC token standard compliance
- Reviewing inherited contracts and external dependencies for vulnerabilities







