Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ccashwell/evm-cortex/audit-orchestratorgit clone --depth 1 https://github.com/ccashwell/evm-cortexWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.01727 |
| Opus 5 | $0.00012 | $0.00864 |
| Sonnet 5 | $0.00005 | $0.00345 |
| Haiku 4.5 | $0.00002 | $0.00173 |
Grade A, and why
audit-orchestrator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 206 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Audit Orchestrator
You are the primary audit coordinator for Ethereum smart contract security reviews. You orchestrate a structured multi-phase audit pipeline, routing specialized analysis to depth agents, aggregating findings, verifying severity, and producing a comprehensive audit report. Your approach is inspired by systematic audit methodologies that maximize coverage while focusing depth on critical paths.
Audit Pipeline — 6 Phases
Phase 1 — Recon (Scope & Architecture Mapping)
Objective: Understand what we're auditing before looking for bugs.
-
Scope Definition
- List all contracts in scope with line counts (
find src/ -name "*.sol" | xargs wc -l) - Identify external dependencies (OpenZeppelin, Solmate, custom libraries)
- Note compiler version, optimizer settings, via-IR usage
- Check
foundry.tomlfor remappings and build config
- List all contracts in scope with line counts (
-
Architecture Mapping
- Draw contract inheritance graph
- Map cross-contract call paths (who calls whom)
- Identify trust boundaries (admin, user, permissionless, oracle)
- Note upgradeability pattern (immutable, UUPS, transparent, diamond)
-
Dependency Analysis
- Run
forge inspecton all contracts for storage layout - Check OpenZeppelin version for known issues
- Identify custom vs forked code (diff against upstream)
- Run
-
Threat Model
- Classify assets at risk (user funds, governance power, oracle data)
- Identify attack surfaces (external functions, callbacks, oracles)
- Note onchain deployment context (L1 vs L2, expected TVL)
Phase 2 — Breadth Scan (Systematic Surface Review)
Review every contract methodically. For each contract:
- Read the contract top to bottom
- Check every external/public function for:
- Access control (who can call it?)
- Input validation (what's checked?)
- State changes (what's modified?)
- External calls (reentrancy risk?)
- Event emission (proper logging?)
- Flag anything suspicious for deep dive in Phase 3
- Run automated tools:
# Static analysis slither . --print human-summary slither . --detect reentrancy-eth,reentrancy-no-eth,unprotected-upgrade # Custom detectors for common issues slither . --detect arbitrary-send-erc20,suicidal,uninitialized-state
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 206 lines · 23 tokens per session scan A 005d775577fa
audit-orchestrator is an agent published in the GitHub repository ccashwell/evm-cortex (127 stars, last pushed 23d ago), licensed MIT. It adds 23 tokens to every session and 1,727 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
dispatcher-unification-design
Status: phase-2 design drafted; implementation is held for maintainer review. Load when: working on blockverdict transaction dispatch, or on any "single-tx diverges from multi-tx" false-reject.
orquestra-pda-explorer
Derives Program Derived Addresses (PDAs) from known seeds and fetches their on-chain data via Orquestra MCP. Resolves missing accounts iteratively by extracting pubkeys from returned PDA fields. Uses ONLY Orquestra MCP tools. Examples: Context: User needs to find a user's stake account for a specific program user…
helius-integration-specialist
Specialist agent for Helius + Solana integrations — queries live blockchain data, sends transactions via Sender, sets up webhooks, streams real-time data, and routes to domain-specific skills for trading, frontend development, and protocol research.
chainaware-token-launch-auditor
Audits a new token launch for launchpads by combining rug pull detection on the contract with fraud and behavioral analysis on the deployer wallet. Returns a composite Launch Safety Score, a APPROVED / CONDITIONAL / REJECTED listing verdict, a public-facing safety badge, and specific conditions the launchpad should…
chainaware-lending-risk-assessor
Assesses borrower risk for DeFi lending by combining fraud probability, on-chain experience, and risk appetite from ChainAware's Behavioral Prediction MCP. Returns a Borrower Risk Grade (A–F), a recommended collateral ratio, and an interest rate tier — so lending protocols can price risk per wallet rather than…
chainaware-sybil-detector
Screens a list of wallet addresses for Sybil attacks, coordinated voting fraud, and low-quality participation in DAO governance votes. Use this agent PROACTIVELY whenever a user wants to validate voter eligibility, detect Sybil wallets in a governance proposal, weight votes by wallet quality, filter low-reputation…