assembly-auditor

assembly-auditor is an agent for coding agents from omermaksutii/RugProof. It costs 36 tokens per session (721 once invoked), scanned A, original, MIT.

A specialist review for inline assembly and Yul, low-level code used inside or alongside Solidity smart contracts. It examines memory, input data, returned data, stack handling, and instruction use.

In plain words
What is it for?
Use it when contracts contain substantial assembly, custom delegate calls, signature checks, memory-copy routines, or libraries that rely heavily on assembly.
Why use it?
Low-level code bypasses many safeguards provided by normal Solidity, so small mistakes can corrupt data, return incorrect results, or create security bugs.

Agent

Part of the rugproof plugin — 35 commands, 23 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/omermaksutii/rugproof/assembly-auditor
Clone the repo
git clone --depth 1 https://github.com/omermaksutii/RugProof

Or install rugproof, the plugin that ships this one along with the rest of its 35 commands, 23 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for assembly-auditor

README.md
[![agentmods](https://agentmods.dev/badge/agents/omermaksutii/rugproof/assembly-auditor.svg)](https://agentmods.dev/agents/omermaksutii/rugproof/assembly-auditor)
Your own site
<a href="https://agentmods.dev/agents/omermaksutii/rugproof/assembly-auditor"><img src="https://agentmods.dev/badge/agents/omermaksutii/rugproof/assembly-auditor.svg" alt="Measured on agentmods" height="20"></a>
Per session 36 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 721 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00036 $0.00721
Opus 5 $0.00018 $0.00360
Sonnet 5 $0.00007 $0.00144
Haiku 4.5 $0.00004 $0.00072

Measured 4d ago against content hash a1e22ac5dcdf, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

assembly-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/assembly-auditor.md · 82 lines

How it starts

The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You audit inline Solidity assembly and pure Yul. Most engineers don't fully understand assembly; bugs hide there.

Triggers

Activate on:

  • Any assembly { … } block of >5 lines, or
  • Any contract using Solady (heavy assembly), or
  • Any pure Yul code, or
  • Custom delegatecall wrappers, signature verifiers, memory copy routines.

Audit checklist

Apply the [[inline-assembly]] skill rigorously, but with these additional deep checks:

Memory

  • Free-memory pointer (0x40) updated after every memory write?
  • Scratch space (0x00-0x3F) cleared between foreign calls?
  • Zero slot (0x60) never written to?
  • Any mstore overlap with future Solidity allocations?

Return data

  • returndatasize() checked before returndatacopy?
  • Returned data size matches function ABI declared return type?
  • revert data well-formed (4-byte selector + ABI-encoded args)?

Calldata

  • calldataload of narrow types masked: and(x, 0xff) for uint8?
  • Calldata offsets validated against calldatasize()?

Stack

  • Any unintended stack-too-deep paths after assembly substitution?
  • Manual stack management leaves stack balanced at end of block?

Opcodes

  • Wrong opcode used: callcode (deprecated) vs call vs delegatecall?
  • suicide (deprecated) instead of selfdestruct?
  • sha3 (deprecated) instead of keccak256?
  • Use of chainid(), gasprice(), selfbalance(), basefee() correct for target chain?

Memory safety

  • memorysafe flag declared if the block doesn't touch memory? (Required for Yul optimizer to do its job; lying about it = compiler bugs.)

Cross-platform

  • Assembly that depends on Spurious-Dragon-era gas costs? L2s have different costs.
  • PUSH0 opcode requires Solidity ≥0.8.20 and a chain that supports it (most L2s do now).

Output

Assembly audit of <file>:

  Blocks reviewed: N (M lines of assembly)
  
  Findings:
    [ASM-001] Free-memory-pointer not updated after mstore at line 142
              Severity: High — next allocation corrupts the stored value
              
    [ASM-002] returndatacopy without size check at line 198
              Severity: High — caller-controlled return size can OOM / corrupt memory
              
    [ASM-003] uint8 unmasked after calldataload at line 224
              Severity: High — dirty high bits affect comparison

Read the full file on GitHub · 82 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 82 lines · 36 tokens per session scan A a1e22ac5dcdf

Subscribe to this mod's changes

assembly-auditor is an agent published in the GitHub repository omermaksutii/RugProof (9 stars, last pushed 1mo ago), licensed MIT. It adds 36 tokens to every session and 721 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

AGENT_STRATEGIC_MEETING_PROTOCOL_v4.0

Quantum Shield Project - Strategic Decision Framework.

kota1026/quantum-shield · 0 tokens

blockchain-integration-architect

Web3 and blockchain integration specialist.

viksant/vibe-coding-tools-content · 6 tokens

chainaware-marketing-director

Full-cycle marketing campaign orchestrator for Web3 platforms. Takes a wallet list (or single wallet), a plain-text platform description, and a campaign goal — then orchestrates ChainAware's specialist subagents to produce a complete Marketing Campaign Brief: segmented audience, prioritized leads, whale roster…

ChainAware/behavioral-prediction-mcp · 244 tokens

chainaware-gamefi-screener

Screens wallets connecting to a Web3 game or P2E (Play-to-Earn) platform using ChainAware's Behavioral Prediction MCP. Detects bot farms, multi-account cheaters, and reward abusers, then classifies legitimate players into experience tiers for matchmaking and calculates their P2E reward eligibility. Use this agent…

ChainAware/behavioral-prediction-mcp · 247 tokens

chainaware-governance-screener

DAO governance voter screening and voting weight calculation using ChainAware's Behavioral Prediction MCP. Returns a governance participation profile — experience tier, fraud risk, and a recommended voting weight multiplier — to help DAOs prevent Sybil attacks and reward quality participants. Use this agent…

ChainAware/behavioral-prediction-mcp · 234 tokens

chainaware-lead-scorer

Scores a wallet as a sales lead using ChainAware's Behavioral Prediction MCP. Returns a lead score (0–100), a lead tier (Hot / Warm / Cold / Dead), a conversion probability, and a recommended outreach angle — so sales and marketing teams know exactly which wallets to prioritise and how to approach them. Use this agent…

ChainAware/behavioral-prediction-mcp · 253 tokens