~ / rigs / mnedelchev-vn / solidity-claude-setup

mnedelchev-vn/solidity-claude-setup

Claude Code skills purpose-built for Solidity security auditing and protocol research.

↗ GitHub ★ 2 MIT updated 10d ago personal setup Claude Code
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~3.1k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit mnedelchev-vn/solidity-claude-setup/.claude ./rig-solidity-claude-setup  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit mnedelchev-vn/solidity-claude-setup/.claude/skills/smart-contract-analyzer .claude/skills/smart-contract-analyzer
$ npx degit mnedelchev-vn/solidity-claude-setup/.claude/skills/solidity-protocol-context .claude/skills/solidity-protocol-context
$ curl -fsSL --create-dirs -o .claude/agents/access-control-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/access-control-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/amm-dex-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/amm-dex-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/auction-mechanism-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/auction-mechanism-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/centralization-privilege-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/centralization-privilege-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/cross-chain-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/cross-chain-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/data-validation-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/data-validation-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/donation-attack-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/donation-attack-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/dos-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/dos-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/eth-native-handler-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/eth-native-handler-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/fee-accounting-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/fee-accounting-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/flashloan-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/flashloan-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/frontrunning-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/frontrunning-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/governance-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/governance-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/lending-protocol-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/lending-protocol-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/liquid-staking-restaking-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/liquid-staking-restaking-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/liquidation-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/liquidation-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/lock-funds-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/lock-funds-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/math-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/math-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/merkle-airdrop-claims-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/merkle-airdrop-claims-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/nft-marketplace-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/nft-marketplace-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/oracle-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/oracle-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/perpetual-derivatives-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/perpetual-derivatives-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/reentrancy-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/reentrancy-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/reward-accounting-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/reward-accounting-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/signature-verification-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/signature-verification-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/state-management-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/state-management-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/timestamp-time-dependence-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/timestamp-time-dependence-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/token-compatibility-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/token-compatibility-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/upgrade-proxy-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/upgrade-proxy-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/vault-share-accounting-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/vault-share-accounting-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/vesting-streaming-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/vesting-streaming-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/withdrawal-queue-redemption-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/withdrawal-queue-redemption-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/yul-assembly-analyzer.md https://raw.githubusercontent.com/mnedelchev-vn/solidity-claude-setup/master/.claude/agents/yul-assembly-analyzer.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (2)

Subagents (33)

access-control-analyzerExpert Solidity access control and authorization analyzer. Use this agent when auditing Solidity smart contracts for missing or broken access control, unauthorized function calls, privilege escalation
amm-dex-analyzerExpert Solidity AMM and DEX security analyzer. Use this agent when auditing Solidity smart contracts that implement or interact with automated market makers (AMMs), decentralized exchanges (DEXs), liq
auction-mechanism-analyzerExpert Solidity auction mechanism security analyzer. Use this agent when auditing Solidity smart contracts that implement auction mechanics including Dutch auctions, English auctions, sealed-bid aucti
centralization-privilege-analyzerExpert Solidity centralization and privileged-role risk analyzer. Use this agent when auditing Solidity smart contracts where a trusted role (owner, admin, governance, operator, keeper) holds powers t
cross-chain-analyzerExpert Solidity cross-chain and bridge security analyzer. Use this agent when auditing Solidity smart contracts that involve cross-chain messaging, token bridges, L2 interactions, relayers, or any mul
data-validation-analyzerExpert Solidity input validation and data integrity analyzer. Use this agent when auditing Solidity smart contracts for missing input validation, zero-address checks, unchecked return values, incorrec
donation-attack-analyzerExpert Solidity donation and share inflation attack analyzer. Use this agent when auditing Solidity smart contracts that implement vault/share-based accounting (ERC4626, custom vaults, staking pools)
dos-analyzerExpert Solidity denial-of-service (DoS) vulnerability analyzer. Use this agent when auditing Solidity smart contracts for DoS vectors including unbounded loops, gas griefing, block gas limit issues, e
eth-native-handler-analyzerExpert Solidity ETH/native token handling analyzer. Use this agent when auditing Solidity smart contracts that handle native ETH (or chain-native tokens), including payable functions, msg.value usage,
fee-accounting-analyzerExpert Solidity fee logic and economic accounting analyzer. Use this agent when auditing Solidity smart contracts for fee calculation errors, fee bypass vectors, double-fee charges, missing fee collec
flashloan-analyzerExpert Solidity flash loan vulnerability analyzer. Use this agent when auditing Solidity smart contracts for flash loan attack vectors, including price manipulation via flash loans, flash-loan-enabled
frontrunning-analyzerExpert Solidity front-running and MEV vulnerability analyzer. Use this agent when auditing Solidity smart contracts for front-running attacks, sandwich attacks, MEV extraction, slippage protection iss
governance-analyzerExpert Solidity governance and voting security analyzer. Use this agent when auditing Solidity smart contracts that implement on-chain governance, voting mechanisms, proposal systems, DAOs, timelocks,
lending-protocol-analyzerExpert Solidity lending protocol security analyzer. Use this agent when auditing Solidity smart contracts that implement lending/borrowing mechanics, interest accrual, debt tracking, collateral manage
liquid-staking-restaking-analyzerExpert Solidity liquid staking and restaking protocol security analyzer. Use this agent when auditing Solidity smart contracts that implement liquid staking (stETH, rETH, cbETH), restaking (EigenLayer
liquidation-analyzerExpert Solidity liquidation logic security analyzer. Use this agent when auditing Solidity smart contracts that implement liquidation mechanisms in lending protocols, perpetual exchanges, CDPs, or any
lock-funds-analyzerExpert Solidity locked/stuck funds analyzer. Use this agent when auditing Solidity smart contracts for scenarios where user or protocol funds can become permanently locked, stuck, unclaimable, or unre
math-analyzerExpert Solidity rounding issues analyzer. Use this agent when the main agent needs to audit Solidity smart contract code for mathematical vulnerabilities, precision loss, rounding errors, and division
merkle-airdrop-claims-analyzerExpert Solidity Merkle airdrop and claim analyzer. Use this agent when auditing Solidity smart contracts that distribute tokens/allocations via Merkle proofs or claim lists: proof verification, double
nft-marketplace-analyzerExpert Solidity NFT and ERC721/ERC1155 security analyzer. Use this agent when auditing Solidity smart contracts that implement or interact with NFTs (ERC721, ERC1155), including minting, burning, mark
oracle-analyzerUse this agent when reviewing Solidity smart contracts that integrate with on-chain price oracles such as Chainlink or Pyth. This agent should be invoked whenever oracle-related code is written or mod
perpetual-derivatives-analyzerExpert Solidity perpetual exchange and derivatives security analyzer. Use this agent when auditing Solidity smart contracts that implement perpetual futures, options, funding rate mechanisms, margin t
reentrancy-analyzerExpert Solidity reentrancy vulnerability analyzer. Use this agent when auditing Solidity smart contracts for all forms of reentrancy including single-function, cross-function, cross-contract, read-onl
reward-accounting-analyzerExpert Solidity reward distribution and accounting security analyzer. Use this agent when auditing Solidity smart contracts that implement staking rewards, yield distribution, fee collection, internal
signature-verification-analyzerExpert Solidity on-chain signature verification analyzer. Use this agent when you need to audit Solidity smart contracts for signature-related vulnerabilities. This agent should be invoked after writi
state-management-analyzerExpert Solidity state management and consistency analyzer. Use this agent when auditing Solidity smart contracts for stale state bugs, missing state updates, inconsistent state across functions, stora
timestamp-time-dependence-analyzerExpert Solidity timestamp and time-dependence analyzer. Use this agent when auditing Solidity smart contracts whose logic depends on block.timestamp or block.number: time-based interest/reward accrual
token-compatibility-analyzerExpert Solidity <redacted> and ERC20 edge-case analyzer. Use this agent when auditing Solidity smart contracts that interact with arbitrary or user-supplied ERC20 tokens, including fee-on-transfer tok
upgrade-proxy-analyzerExpert Solidity upgradeable contract and proxy security analyzer. Use this agent when auditing Solidity smart contracts that use proxy patterns (UUPS, Transparent, Beacon, Diamond/EIP-2535), initializ
vault-share-accounting-analyzerExpert Solidity vault share-accounting analyzer. Use this agent when auditing Solidity smart contracts that mint/burn shares against an underlying asset balance (ERC4626 and custom vaults, tokenized s
vesting-streaming-analyzerExpert Solidity vesting and token streaming security analyzer. Use this agent when auditing Solidity smart contracts that implement token vesting schedules, cliff unlocks, linear/stepped releases, tok
withdrawal-queue-redemption-analyzerExpert Solidity withdrawal-queue and redemption analyzer. Use this agent when auditing Solidity smart contracts that implement asynchronous withdrawals/redemptions: request-then-claim flows, withdrawa
yul-assembly-analyzerExpert Solidity Yul / inline-assembly security analyzer. Use this agent when auditing Solidity smart contracts that contain `assembly { ... }` blocks, Yul code, Huff, or any low-level EVM manipulation

Similar rigs

copied ✓