Skill 08 security audit
Skill vaquarkhan/web3-agent-skills/skills/skill-08-security-audit
Production-grade Agent Skills for Web3 AI agents: 15 workflows, 6 MCP servers, DeFi/NFT/compliance guardrails, and VS Code/JetBrains installers.
npx -y skills add vaquarkhan/web3-agent-skills --skill skill-08-security-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Performs Web3 security analysis including vulnerability detection, rug pull checks, and exploit monitoring. Use before interacting with unknown contracts or when auditing smart contract code.
SKILL.md
2.5 KB, as published. Nobody here has run it
Security Audit
When to Use
- Evaluating unknown smart contracts before interaction
- Detecting rug pull and honeypot patterns
- Monitoring for active exploits and protocol incidents
- Reviewing contract code for common vulnerabilities
- Pre-deployment security checklist
Prerequisites
- MCP:
blockchain-rpc-server,defi-protocol-server - Knowledge base:
knowledge-base/security/
Workflow
1. Automated Rug Pull Checks
Run before any token swap or liquidity add:
| Check | Red Flag |
|---|---|
| Ownership | owner() can mint unlimited tokens |
| Liquidity | LP not locked or unlock imminent |
| Honeypot | Sell simulation reverts |
| Hidden fees | Transfer tax > 10% or modifiable |
| Proxy | Unverified implementation, no timelock |
| Blacklist | isBlacklisted or pause on transfers |
Use eth_call simulation: attempt buy → approve → sell in single trace.
2. Vulnerability Patterns
Scan for OWASP Smart Contract Top 10:
- Reentrancy — external calls before state updates
- Access control — missing
onlyOwneron critical functions - Oracle manipulation — spot price without TWAP
- Flash loan attacks — single-block price dependency
- Integer issues — unchecked math (pre-0.8.0)
- Delegatecall — untrusted implementation in proxy
- Front-running — no slippage/deadline protection
See knowledge-base/security/common-vulnerabilities/ for patterns.
3. Exploit Monitoring
- Monitor Rekt News, DeFiLlama hacks dashboard
- Check contract against known exploit DB
- Verify protocol TVL hasn't dropped > 20% in 24h
4. Code Review Checklist
- Uses Solidity ≥ 0.8.0 with overflow checks
- External calls use checks-effects-interactions
- No
selfdestructordelegatecallto user input - Timelock on admin functions (> 24h for DeFi)
- Events emitted for state changes
- Formal verification or audit report available
Verdict Format
RISK: LOW | MEDIUM | HIGH | CRITICAL
FINDINGS: [list with severity]
RECOMMENDATION: PROCEED | CAUTION | BLOCK
Block interaction when RISK = CRITICAL or honeypot detected.
References
knowledge-base/security/audit-patterns/knowledge-base/security/exploit-db/