Skip to content
Back to skills

Skill

ASecurity

Runs a competitive smart-contract audit (HackenProof/Code4rena/Sherlock-style) with a recall-optimized, evidence-driven methodology. Use when the user wants to audit a Solidity/EVM, Solana/Anchor (SVM), or Cosmos-SDK/Go L1 (+ go-ethereum fork) repo/contest for rewardable vulnerabilities (theft / permanent fund lock, or L1-shaped impacts: node crash / DoS / can't-finalize / consensus-halt), triage a scope, build a threat model, or stand up invariant fuzzing / an exploit harness. Detects the ta...

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added October 3, 2026
ai-agentspythongonode

Security analysis

A100/100

Scanned October 3, 2026

npx -y skills add RichJamo/audit-harness --skill skill --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Skill
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richjamo-skill/badge)](https://www.skillsdirectory.com/skills/richjamo-skill)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: audit-contest
description: "Runs a competitive smart-contract audit (HackenProof/Code4rena/Sherlock-style) with a recall-optimized, evidence-driven methodology. Use when the user wants to audit a Solidity/EVM, Solana/Anchor (SVM), or Cosmos-SDK/Go L1 (+ go-ethereum fork) repo/contest for rewardable vulnerabilities (theft / permanent fund lock, or L1-shaped impacts: node crash / DoS / can't-finalize / consensus-halt), triage a scope, build a threat model, or stand up invariant fuzzing / an exploit harness. Detects the target VM and binds the right engine set (Foundry vs LiteSVM vs Go keeper/determinism harness) without forking the methodology. Hunts wide (never kills a hypothesis by argument), proves correctness by PoC, and hands SCOPE calls to the human. Pauses at every human-judgment gate; never auto-decides scope or submits."
hooks:
  PreToolUse:
    - matcher: "Write|Edit"
      hooks:
        - type: command
          command: 'G="${AUDIT_HARNESS_HOME:-$HOME/audit-toolkit}/tooling/guards/ledger_guard.py"; [ -f "$G" ] || { echo "ledger guard MISCONFIGURED: cannot find $G. Failing closed, so every Write/Edit is blocked until the hook path in SKILL.md frontmatter is fixed. See docs/guard-register.md." >&2; exit 2; }; python3 "$G"'
          timeout: 15
  Stop:
    - hooks:
        - type: command
          command: 'G="${AUDIT_HARNESS_HOME:-$HOME/audit-toolkit}/tooling/guards/ledger_state_guard.py"; [ -f "$G" ] || { echo "ledger STATE guard MISCONFIGURED: cannot find $G. Exiting 0 -- a Stop hook that fails closed cannot be routed around and would trap the session. The PreToolUse guard still fails closed. See docs/guard-register.md." >&2; exit 0; }; python3 "$G"'
          timeout: 20
---

# The hunting workflow is not part of this release

This file exists to declare the two hooks above, and nothing else.

In the private toolkit this file holds the audit workflow itself: the phases a hunter works
through, what to generate, where to look and when to stop. That workflow is deliberately left out
of this release, because the value of knowing where to look falls as more people know it.

What is released is the enforcement harness — the ledger command line tool, the two hooks declared
above, the engagement doctor and the scaffold. They hold two rules whatever the model chooses to do:

1. **A hypothesis is killed only by a failed proof-of-concept, or escalated to a human — never by
   an argument in prose.**
2. **Correctness is decided by a proof-of-concept; scope is decided by the human.**

The hooks resolve their scripts under `$HOME/audit-toolkit/`. Clone this repository to that path,
or edit the two `command:` lines in the frontmatter above to wherever you put it. `README.md`
explains the layout and how to install it; `docs/guard-register.md` states each rule, its pass
criterion and the failure that justifies it.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…