All categories
Blockchain & Web3
Crypto, wallets, smart contracts, Web3, DeFi, NFTs, and decentralized apps
- 1,483
- 62
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse blockchain & web3 skills
Showing 73–96 of 1,483 skills
- Dos VectorsDetect denial-of-service vectors — unbounded loops, gas griefing, push-payment chokepoints, block-stuffing exposure, revert-on-receive blocking. Activate on loops over user-controlled arrays, batch withdrawals, push-style payouts, queues, auctions with "highest-bidder" refunds, large airdrops.Votes: 0GitHub stars: 36
- Diamond Eip2535Detect Diamond (EIP-2535) bugs — facet selector collisions, init-vs-upgrade safety, storage-namespace collisions, facet selfdestruct paths, missing facet cuts. Activate on Diamond imports, DiamondCut, IDiamondLoupe, IDiamondCut, LibDiamond, facet patterns.Votes: 0GitHub stars: 36
- Delegatecall RisksDetect delegatecall risks — uninitialized proxies, malicious implementations, storage-slot collisions, delegatecall to user-controlled addresses, library delegatecall pitfalls. Activate on `delegatecall`, UUPS proxy upgrades, multicall implementations, diamond facets, governor-execute patterns.Votes: 0GitHub stars: 36
- Cross Contract StateDetect cross-contract state inconsistency — two or more contracts sharing a token, oracle, or price feed where one mutates and another reads stale, cached state that drifts from source of truth, non-atomic multi-contract updates, accounting that assumes synchronized state, and reads during callbacks. Activate whenever a system spans multiple contracts that must agree on a value but update at different times.Votes: 0GitHub stars: 36
- Confidence ScoringAlways-on meta-skill — for every finding produced, attach a confidence level (HIGH/MEDIUM/LOW) and a reasoning trace. Activate on every /audit, /audit-deep, /audit-changes, /audit-live, /quick-scan invocation.Votes: 0GitHub stars: 36
- Centralization RiskDetect centralization and trust-assumption risks — admin powers, single-key risk, missing timelocks, upgrade authority, treasury keys, pause permanence, blacklisting authority, oracle authority. Activate on `onlyOwner`, `onlyRole`, `AccessControl`, upgrade authorizations, pause/unpause functions, mint/burn caps, treasury/fee setters.Votes: 0GitHub stars: 36
- Caching And IncrementalAlways-on meta-skill — cache audit results per file by content hash so unchanged files aren't re-analyzed on subsequent runs. Activate on every /audit, /quick-scan, /audit-changes invocation.Votes: 0GitHub stars: 36
- Approval IssuesDetect ERC-20 approval pitfalls — approve race (front-run), missing safeApprove, infinite approvals, approval-without-revoke, Permit2 misuse, max-approval to untrusted contracts. Activate on `approve`, `safeApprove`, `permit`, `forceApprove`, `Permit2`, `IERC20.allowance`.Votes: 0GitHub stars: 36
- V4 Hook Reentrancy Via UnlockDetect reentrancy in Uniswap V4 hooks via the PoolManager unlock/lock callback. V4 uses a singleton PoolManager with transient lock state; all pool mutations happen inside an unlockCallback. A hook that makes external calls during beforeSwap/afterSwap/before*Liquidity (to tokens with hooks, arbitrary routers, or user-controlled contracts) can be re-entered, and because the manager is already unlocked the attacker can recursively swap/modify liquidity against stale hook state. Activate on any ...Votes: 0GitHub stars: 36
- V4 Hook Permission Flags MismatchDetect Uniswap V4 hooks whose address-encoded permission flags don't match the callbacks the hook actually implements. In V4 the hook's permissions live in the low bits of its deployed address (mined via CREATE2 salt) and must agree with getHookPermissions(); a callback the hook implements but whose flag bit is unset is never invoked, and a flag set without a real implementation makes pool initialization revert in Hooks.validateHookPermissions. Activate on any BaseHook/IHooks contract, getHoo...Votes: 0GitHub stars: 36
- V4 Hook Delta AccountingDetect Uniswap V4 hooks that fail to settle currency deltas with the PoolManager. Every credit/debit a hook creates (BeforeSwapDelta, afterSwap hookDelta, take/mint, donate, settle/sync) is tracked in the manager's transient nonzeroDeltaCount; if the books aren't flat when unlock returns, the whole transaction reverts (CurrencyNotSettled), and mismatched take/settle/donate either strands hook funds in the manager or lets a swap leave with unpaid debt. Activate on hooks returning deltas, calli...Votes: 0GitHub stars: 36
- Solady Safetransferlib No Contract CheckDetect Solady SafeTransferLib calls that assume the token has code. SafeTransferLib.safeTransfer/safeTransferFrom/safeApprove deliberately skip the EXTCODESIZE check that OpenZeppelin's SafeERC20 performs, so a call to an EOA or a self-destructed/not-yet-deployed token address returns success with no transfer. Activate whenever code imports solady SafeTransferLib, calls safeTransfer/safeTransferFrom on a user-supplied or upgradeable token address, or routes arbitrary tokens.Votes: 0GitHub stars: 36
- Solady Ownable Init FrontrunDetect front-runnable ownership initialization in Solady Ownable / OwnableRoles. Solady's `_initializeOwner` is a guarded one-time setter (it reverts with `AlreadyInitialized` on a second call) but it is NOT access-controlled, so in constructor-less deployment paths (minimal-proxy clones, EIP-1167, factory `create`/`create2` without atomic init) an attacker can call the public initializer first and seize ownership. Activate on solady Ownable/OwnableRoles in clones, factories, or any non-atomi...Votes: 0GitHub stars: 36
- Solady Erc20 Permit2 AssumptionsDetect unsafe assumptions about Solady's gas-optimized ERC20/ERC2612 permit and DN404 metadata. Solady's ERC20 uses custom storage slots, returns bools via assembly, exposes a virtual `_constantNameHash`/`_versionHash` for permit domain separation, and its DN404 mirror splits ERC20/ERC721 logic — integrators that assume OZ-style behavior, revert strings, or that `name()`/`decimals()` are always present can misbehave. Activate on solady/tokens imports, ERC2612 permit flows, DN404, or off-chain...Votes: 0GitHub stars: 36
- Example Fork DetectionTEMPLATE — replace with the description of your rule. Should activate on the specific code patterns your fork has. Activate on `<your trigger keywords or function names>`.Votes: 0GitHub stars: 36
- Trdefi Trdefi LiquidityLive non-custodial stablecoin liquidity for AI agents. Use when an agent needs to find real USDC/USDT maker positions to trade against, quote a stablecoin swap on-chain at the current block, or earn swap fees on idle stablecoins without moving custody. Covers listing positions, quoting a swap, and reading settled volume across 20 networks (Ethereum, Base, Arbitrum, Optimism, Polygon, BNB Chain and 14 more). Read-only tools are free and need no key.Votes: 0GitHub stars: 78
- Solidity AuditorSecurity audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security", "loop mode", "run the auditor in loop mode", "run 3 passes". Modes - default (full repo) or a specific filename. Loop mode runs several passes in one scan, each pass told what the earlier ones found, and ends in one combined report; it remembers findings between scans in a ledger.Votes: 0GitHub stars: 1,225
- Fizz SyncReconcile an existing Fizz harness with a changed source tree. Detects added/removed/changed contract functions, quarantines stale properties, regenerates drifted handler stubs, and refreshes the snapshot. Trigger on "fizz-sync", "resync fuzzing", "sync fuzz harness", "refresh fuzzing properties", "fuzzing drift check".Votes: 0GitHub stars: 1,225
- Fizz ConvertConvert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. Trigger on "fizz-convert", "convert properties", "implement properties from PROPERTIES.md", "convert PROPERTIES.md to Solidity".Votes: 0GitHub stars: 1,225
- WaiaasSelf-hosted crypto wallet daemon for AI agents. Manage wallets, send transactions, interact with DeFi protocols — without exposing private keys. EVM + Solana unified API via MCP. Use when: user asks to send crypto, check wallet balance, swap tokens, interact with DeFi, or manage on-chain assets. NOT for: fiat payments, bank transfers, or centralized exchange trading.Votes: 0GitHub stars: 2
- ClawtrustClawTrust is the trust layer for the agent economy. ERC-8004 identity on Base Sepolia and SKALE on Base (zero gas · BITE encrypted execution · sub-second finality), FusedScore reputation, USDC escrow (on-chain direct + Circle), swarm validation, ERC-8183 Agentic Commerce Adapter (ClawTrustAC — trustless USDC job marketplace with on-chain settlement), ClawTrust Name Service (4 TLDs: .molt/.claw/.shell/.pinch), x402 micropayments, Agent Crews, full ERC-8004 discovery compliance, agent profile e...Votes: 0GitHub stars: 2
- BsocialThis skill should be used when the user asks to "post to BSocial", "like a post", "follow user", "send message", "on-chain social media", "BMAP", "BSocial protocol", "create on-chain post", "read BSocial posts", or needs social operations (posts, likes, follows, messages, reposts, friends) on BSV blockchain.Votes: 0GitHub stars: 2
- Blockchain DeveloperBuild production-ready Web3 applications, smart contracts, and decentralized systems. Implements DeFi protocols, NFT platforms, DAOs, and enterprise blockchain integrations. Use PROACTIVELY for smart contracts, Web3 apps, DeFi protocols, or blockchain infrastructure.Votes: 0GitHub stars: 2
- Bankr Agent TransfersThis skill should be used when the user asks to "send tokens", "transfer ETH", "send to ENS", "transfer to wallet", "send to @username", "transfer to Farcaster", "send to Twitter handle", or any asset transfer operation. Provides guidance on recipient resolution and transfer formats.Votes: 0GitHub stars: 2