Solidity

mindrally/skills/solidity

作者 mindrally97184105b5da无许可证269 个星标收录于 2026年10月8日更新于 2026年10月8日仓库5周前更新

Best practices for secure, gas-efficient Solidity smart contract development and Web3 frontend integration. Use when writing or reviewing Solidity contracts, hardening against reentrancy and access-control bugs, optimizing gas usage, setting up Hardhat/Foundry testing and static analysis, or wiring a React frontend to wallets, providers, and on-chain transactions.

AI 生成的概览

提供安全、省 Gas 的 Solidity 智能合约开发与 Web3 前端集成的最佳实践指导。

功能
为编写和审查 Solidity 智能合约提供最佳实践指导,涵盖代码结构、安全模式、Gas 优化、工具与测试。同时就如何将 React Web3 前端接入钱包、Provider 和链上交易给出建议。它只是纯说明性参考,不生成文件或脚本。
适用场景
适用于编写或审查 Solidity 合约、防范重入与访问控制漏洞、优化 Gas 消耗的场景。也适用于搭建 Hardhat 或 Foundry 测试与静态分析,或将前端接入钱包和链上交易。
运行要求
无需任何工具、软件包或凭据;仅为说明性内容,不附带脚本。文中提及 OpenZeppelin、Slither、Mythril、Hardhat、Chainlink VRF、TypeChain 以及 wagmi/viem 等外部工具。

Solidity

This skill covers best practices for Solidity smart contract development, including security patterns, gas optimization, testing/tooling, and integrating contracts with a Web3 React frontend.

Core Principles

  • Cut the fluff. Code or detailed explanations only
  • Maintain brevity while prioritizing accuracy and depth
  • Answer first, explain later when needed

Code Structure & Security

  • Use explicit visibility modifiers and NatSpec documentation
  • Apply function modifiers to reduce redundancy
  • Follow naming conventions:
    • CamelCase for contracts
    • PascalCase for interfaces (prefix with "I")
  • Implement Interface Segregation Principle
  • Use proxy patterns for upgradeable contracts
  • Emit comprehensive events for state changes
  • Follow Checks-Effects-Interactions pattern against reentrancy

Security Best Practices

  • Use OpenZeppelin's AccessControl for permissions
  • Require Solidity 0.8.0+ for overflow/underflow protection
  • Use Pausable pattern for circuit breakers
  • Implement ReentrancyGuard for additional protection
  • Use SafeERC20 for token interactions
  • Employ pull-over-push payment patterns
  • Implement timelocks and multisig controls for sensitive operations

Gas Optimization

  • Optimize gas consumption (deployment and runtime)
  • Use immutable variables for constructor-set values
  • Use custom errors instead of revert strings
  • Pack storage variables efficiently
  • Use appropriate data types

Tools & Analysis

  • Integrate Slither and Mythril for static analysis
  • Leverage Hardhat's testing and development environment
  • Implement robust CI/CD pipelines
  • Use pre-commit linting tools

Advanced Patterns

  • Chainlink VRF for randomness
  • Strategic assembly use with extensive documentation
  • State machine patterns for complex logic
  • ERC20Snapshot, ERC20Permit, and ERC20Votes for specialized tokens

Testing & Quality

  • Comprehensive unit, integration, and end-to-end testing
  • Property-based testing approaches
  • High coverage targets
  • Regular security audits

Web3 Frontend Integration

  • Keep frontend code that talks to contracts type-safe and explicit — generate TypeScript types from ABIs (e.g. via TypeChain or wagmi/viem codegen) rather than hand-writing contract call signatures
  • Treat wallet connection, chain/network state, and transaction status as explicit, typed state (connected/connecting/wrong-network/error), not implicit booleans
  • Surface transaction lifecycle clearly in the UI: submitted, pending confirmation, confirmed, reverted — never assume a submitted transaction succeeded
  • Validate and simulate transactions (e.g. eth_call/gas estimation) before prompting the user to sign, to catch reverts early
  • Never trust client-side reads of contract state for authorization decisions — always re-verify on-chain in the contract itself
  • Handle provider/RPC failures and user rejection of signature requests as expected, recoverable error states

来源与署名

来源:mindrally/skills位于solidity提交9718410

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架