fhevm-solidity

A set of Solidity development and review rules for Zama FHEVM smart contracts. FHEVM is a system for computing on encrypted data; encrypted values are represented by references rather than ordinary numbers or booleans.

In plain words
What is it for?
Use it to write, review or audit Solidity contracts using encrypted types, FHE operations, access controls, Zama configuration, or confidential token interfaces.
Why use it?
It prevents common mistakes such as treating an encrypted condition like a normal Solidity boolean, and highlights code that follows older FHEVM versions. This is useful when developing or auditing contracts that keep data confidential.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/zunmax/fhevm-skill/fhevm-solidity
Clone the repo
git clone --depth 1 https://github.com/zunmax/fhevm-skill

Made for: Cursor.

Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 8,874 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.08874
Opus 5 $0.00000 $0.04437
Sonnet 5 $0.00000 $0.01775
Haiku 4.5 $0.00000 $0.00887

Measured 2d ago against content hash c40c4dc54180, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

fhevm-solidity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/fhevm-solidity.mdc · 442 lines

How it starts

The opening of the file, as written. The whole thing — 442 lines — stays where its author put it; the contents beside it link to each section on GitHub.

FHEVM Solidity Rules (v0.11)

This rule set targets @fhevm/[email protected] (Solidity Guides v0.11 on docs.zama.org). Generated code assumes v0.11. Pre-v0.11 patterns (TFHE.*, requestDecryption, SepoliaConfig as Solidity base, neq/lte/gte) are flagged for migration. v0.11-specific identifiers to know: IERC7984ERC20Wrapper interface ID 0x1f1c62b2, inferredTotalSupply() (replaces v0.10 totalSupply()), UnwrapRequested / UnwrapFinalized events carry bytes32 indexed unwrapRequestId.

Contracts operate on opaque bytes32 handles - a coprocessor does FHE computation off-chain. You CANNOT branch on encrypted values: ebool is a bytes32 UDVT, so require(ebool) and if (ebool) are Solidity compile errors. The bug to flag is when a dev unwraps the handle to a primitive (ebool.unwrap(r) != bytes32(0)) - the non-zero handle always passes.

Setup

pragma solidity ^0.8.28;
import { FHE, euint64, externalEuint64, ebool } from "@fhevm/solidity/lib/FHE.sol";
import { ZamaEthereumConfig } from "@fhevm/solidity/config/ZamaConfig.sol";
contract MyContract is ZamaEthereumConfig { }

Pragma Policy

Case Pragma
Default for new contracts ^0.8.28 (matches reference template, hardhat.config.ts uses version: "0.8.28")
Importing @openzeppelin/confidential-contracts (ERC-7984) ^0.8.27 minimum (ERC7984.sol declares ^0.8.27)
Absolute minimum for FHEVM ^0.8.24 (only if a dependency pins lower)

EVM target: "cancun". Do not target a lower EVM version.

ALWAYS / ASK FIRST / NEVER

ALWAYS:

  • Read .cursor/references/anti-patterns.md before writing FHEVM code
  • Call FHE.allowThis() after every stored encrypted computation
  • Call FHE.allow(result, user) for values users need to decrypt
  • Use ZamaEthereumConfig, FHE.fromExternal(), FHE.select()
  • Run 2-layer verification (references + installed source) on every technical value. Trust hierarchy: source > .cursor/references/ > Zama docs > training knowledge. If layers conflict, source wins.
  • Grep output for deprecated patterns before delivering

Read the full file on GitHub · 442 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 442 lines · 0 tokens per session scan A c40c4dc54180

Subscribe to this mod's changes

fhevm-solidity is a cursor rule published in the GitHub repository zunmax/fhevm-skill (2 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 8,874 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.