← Back to list

smart-contract-security
by gmh5225
A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.
⭐ 2🍴 0📅 Jan 22, 2026
SKILL.md
name: smart-contract-security description: "Guide for EVM/solidity smart contract security work: vulnerability taxonomy, review workflow, and where to place resources in README.md."
Smart Contract Security (EVM / Solidity)
Scope
Use this skill when working on:
- Solidity/EVM auditing resources
- EVM vulnerability categories and examples
- Tooling for contract analysis (static, dynamic, fuzzing)
Common Vulnerabilities (Cheat Sheet)
- Reentrancy
- Access control bugs
- Price oracle manipulation
- MEV / sandwich / frontrunning
- Flash loan enabled logic flaws
- Precision / rounding / decimal mismatch
- Signature and permit mistakes (EIP-2612 / Permit2)
- Upgradeability mistakes (UUPS / Transparent)
Recommended Review Workflow
- Threat model: assets, trust boundaries, privileged roles
- State machine: invariants, transitions, edge cases
- Access control: ownership, roles, upgrade admin
- External calls: reentrancy, callback surfaces, token hooks
- Economic analysis: pricing, liquidity, oracle, incentives
- Testing: unit tests + fuzzing + invariant tests
- Reporting: severity, exploitability, PoC, remediation
Where to Add Links in README
- New analyzers/fuzzers:
Development → ToolsorSecurity(choose primary) - Audit methodologies/standards:
Security - Practice labs/CTFs:
Security Starter Pack → CTFs / Practice - Audit report portfolios:
Security Starter Pack → Audit Reports
Notes
Keep additions:
- English descriptions
- Non-duplicated URLs
- Minimal structural changes
Score
Total Score
60/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
✓最近の活動
1ヶ月以内に更新
+10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
○言語
プログラミング言語が設定されている
0/5
✓タグ
1つ以上のタグが設定されている
+5
Reviews
💬
Reviews coming soon
