Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Confidence Scoring

ASecurity

Always-on meta-skill — for every finding produced, attach a confidence level (HIGH/MEDIUM/LOW) and a reasoning trace. Activate on every /audit, /audit-deep, /audit-changes, /audit-live, /quick-scan invocation.

36 stars
0 votes
0 copies
0 views
Added 10/4/2026
blockchainrustgo

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add iktok90-design/ai-smart-contract-auditor --skill confidence-scoring --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Confidence Scoring?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Confidence Scoring
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iktok90-design-confidence-scoring/badge)](https://www.skillsdirectory.com/skills/iktok90-design-confidence-scoring)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: confidence-scoring
description: Always-on meta-skill — for every finding produced, attach a confidence level (HIGH/MEDIUM/LOW) and a reasoning trace. Activate on every /audit, /audit-deep, /audit-changes, /audit-live, /quick-scan invocation.
---

# Confidence scoring (meta-skill)

Per-finding confidence is what separates a noisy linter from a usable auditor. Always attach confidence.

## Confidence levels

### HIGH
- Pattern matches exactly with no ambiguous preconditions.
- Working exploit possible (or already drafted via [[exploit-poc-writer]]).
- Affected line is reachable from a public/external function with no role gating.
- Cross-verified by attacker subagent or `/verify-finding`.
- Historical incident matches the same pattern at this severity.

### MEDIUM
- Pattern matches but exploit requires non-trivial preconditions:
  - Specific token type (rebasing / fee-on-transfer)
  - Specific chain configuration (sequencer down on L2, oracle behavior)
  - Multi-actor coordination
- Reachability through trusted-only call paths.
- One specialist subagent confirms, another offers a benign explanation.

### LOW
- Pattern theoretically present but practical exploitability uncertain.
- Heavy reliance on assumptions about external integrations not auditable.
- Defense-in-depth gaps with no clear attack.
- Conflicting evidence between passes (in `/audit-strict`).

## Reasoning trace requirement

Every finding includes a "How I reached this conclusion" snippet:

```
Reasoning:
  1. Function withdraw() at Vault.sol:140 sends ether via low-level call.
  2. State update (balance[msg.sender] = 0) happens after the call (CEI violated).
  3. Receiver address is user-controlled (msg.sender).
  4. No nonReentrant modifier on the function.
  5. No external mitigation in surrounding code.
  Conclusion: classic reentrancy, exploitable in a single tx.
  Cross-check: attacker subagent independently constructed a PoC (passing).
  → Confidence: HIGH
```

## When to downgrade

Always downgrade if:
- The "exploit" requires the attacker to compromise an admin key.
- The pattern is present but mitigated by an immutable, audited library call.
- The vuln class is present but the *capability* requires unrealistic state.

## When to escalate to HIGH

Upgrade to HIGH only if:
- You can articulate the exploit in concrete terms.
- You can identify the specific value at risk.
- You can write a PoC that compiles (or you cite a historical incident).

## Output integration

In the standard finding format:
```
[<ID> | <Severity>] <Title>
  Confidence: HIGH | MEDIUM | LOW
  Reasoning:  <trace>
  ...
```

## Don't

- Don't mark every finding HIGH to look thorough.
- Don't mark a real, well-evidenced finding LOW to be cautious — that defeats the purpose.
- Don't downgrade Critical severity to compensate for low confidence — they're orthogonal axes.

## Related

- [[multi-pass-self-critique]] — uses confidence to filter
- [[false-positive-feedback-loop]] — low-confidence findings are dismissal candidates
- [[known-good-comparison]] — known-good match → upgrade confidence

Attribution

iktok90-designiktok90-design
View sourceSee grades on GitHubMore from iktok90-design →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

458250 votes

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

401990 votes

vyper-compiler

Vyper smart contract compiler internals. Use when working on the Vyper compiler codebase — compilation pipeline, Venom IR, semantic analysis, code generation, testing, or contributing. Triggers on vyper compiler development, Venom passes, AST/semantics changes, codegen work, or test writing.

51840 votes

Flash Loan Simulator

Simulate flash loan arbitrage strategies and profitability across DeFi protocols. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes

On Chain Analytics

Perform on-chain analysis including whale tracking, token flows, and network activity. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes
View all in blockchain →