analyzing-ethereum-smart-contract-vulnerabilities

analyzing-ethereum-smart-contract-vulnerabilities is a skill for Claude Code from killvxk/cybersecurity-skills-zh. It costs 60 tokens per session (587 once invoked), scanned A, original, Apache-2.0.

A security-analysis guide for Solidity smart contracts, which are programs that run on the Ethereum blockchain. It uses Slither and Mythril to inspect contract code and execution paths for vulnerabilities.

In plain words
What is it for?
Use it to look for reentrancy, arithmetic errors, unchecked external calls, and access-control flaws, then organize the findings into an audit report.
Why use it?
It can reveal security problems before a contract is deployed, when fixes are still possible.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the cybersecurity-skills-zh plugin — 58 skills shipped together

Good fit Use it to look for reentrancy, arithmetic errors, unchecked external calls, and access-control flaws, then organize the findings into an audit report.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add killvxk/cybersecurity-skills-zh --skill analyzing-ethereum-smart-contract-vulnerabilities
Clone the repo
git clone --depth 1 https://github.com/killvxk/cybersecurity-skills-zh

Made for: Claude Code.

Or install cybersecurity-skills-zh, the plugin that ships this one along with the rest of its 58 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for analyzing-ethereum-smart-contract-vulnerabilities

README.md
[![agentmods](https://agentmods.dev/badge/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities/github.svg)](https://agentmods.dev/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities)
Your own site
<a href="https://agentmods.dev/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities"><img src="https://agentmods.dev/badge/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for analyzing-ethereum-smart-contract-vulnerabilities

Your own site · 80×15
<a href="https://agentmods.dev/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities"><img src="https://agentmods.dev/badge/skills/killvxk/cybersecurity-skills-zh/analyzing-ethereum-smart-contract-vulnerabilities.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 60 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 587 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00060 $0.00587
Opus 5 $0.00030 $0.00293
Sonnet 5 $0.00012 $0.00117
Haiku 4.5 $0.00006 $0.00059

Measured 11d ago against content hash 7d5c23bf6024, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

analyzing-ethereum-smart-contract-vulnerabilities scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/agent.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/analyzing-ethereum-smart-contract-vulnerabilities/SKILL.md · 47 lines

What it actually says

分析以太坊智能合约漏洞

概述

智能合约漏洞已在各 DeFi 协议中造成数十亿美元的损失。与传统软件不同,已部署的智能合约是不可变的,且直接处理真实金融资产,这使得部署前的安全分析至关重要。Slither 使用中间表示进行快速静态分析,能在几秒内检测 90 多种漏洞模式;而 Mythril 则使用符号执行和 SMT 求解来发现复杂执行路径漏洞,如重入攻击(Reentrancy)和整数溢出。本技能涵盖对 Solidity 合约运行两款工具、解读分析结果、按严重程度分类发现项,以及生成审计报告。

前置条件

  • Python 3.10+ 与 pip
  • Slither(pip install slither-analyzer)和 solc 编译器
  • Mythril(pip install mythril)与 solc-select(用于管理编译器版本)
  • Solidity 源代码或编译后的合约字节码
  • Foundry 或 Hardhat 开发框架(可选,用于项目级分析)

步骤

步骤 1:运行 Slither 静态分析

对合约代码库执行 Slither,使用其 90+ 内置检测器识别漏洞模式、优化机会和代码质量问题。

步骤 2:运行 Mythril 符号执行

运行 Mythril 深度分析,探索执行路径,发现需要路径敏感分析的重入攻击、未检查的外部调用和算术漏洞。

步骤 3:分类和关联发现

合并两款工具的结果,去重发现项,根据可利用性和财务影响评估严重程度,并过滤误报。

步骤 4:生成审计报告

生成包含漏洞描述、受影响代码位置、利用场景和修复建议的结构化审计报告。

预期输出

JSON 报告,列出漏洞及其 SWC(智能合约弱点分类)标识符、严重程度评级、受影响函数和建议修复方案。

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 47 lines · 60 tokens per session scan A 7d5c23bf6024

Subscribe to this mod's changes

analyzing-ethereum-smart-contract-vulnerabilities is a skill published in the GitHub repository killvxk/cybersecurity-skills-zh (44 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 60 tokens to every session and 587 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

mukul975/Anthropic-Cybersecurity-Skills · 49 tokens

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

xalgorix/xalgorix · 49 tokens

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

26zl/cybersec-toolkit · 49 tokens

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

plurigrid/asi · 49 tokens

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

autohandai/community-skills · 49 tokens

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

pinkpixel-dev/skills-collection-1 · 49 tokens