Solidity Security

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

AI 生成的概览

指导安全的 Solidity 智能合约开发,涵盖常见漏洞、安全模式与审计准备。

功能
该技能提供智能合约安全最佳实践、漏洞防范和安全 Solidity 开发模式的指导。内容涵盖重入、整数溢出和访问控制等主题,并包含 Hardhat 安全测试示例和可供审计的合约示例。它还指向一个包含详细模式与完整示例的参考文件。
适用场景
适用于编写安全的智能合约、审计现有合约中的漏洞,或为区块链应用实施安全措施。在准备专业审计或研究常见攻击向量时也很有用。
运行要求
不附带脚本,仅为说明性内容。示例涉及 Hardhat、Chai 和 ethers 用于测试,但未指定安装步骤或凭据。

Solidity Security

Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.

When to Use This Skill

  • Writing secure smart contracts
  • Auditing existing contracts for vulnerabilities
  • Implementing secure DeFi protocols
  • Preventing reentrancy, overflow, and access control issues
  • Optimizing gas usage while maintaining security
  • Preparing contracts for professional audits
  • Understanding common attack vectors

Detailed patterns and worked examples

Detailed pattern documentation lives in references/details.md. Read that file when the navigation tier above is insufficient.

Testing for Security

javascript
// Hardhat test exampleconst { expect } = require("chai");const { ethers } = require("hardhat");
describe("Security Tests", function () {  it("Should prevent reentrancy attack", async function () {    const [attacker] = await ethers.getSigners();
    const VictimBank = await ethers.getContractFactory("SecureBank");    const bank = await VictimBank.deploy();
    const Attacker = await ethers.getContractFactory("ReentrancyAttacker");    const attackerContract = await Attacker.deploy(bank.address);
    // Deposit funds    await bank.deposit({ value: ethers.utils.parseEther("10") });
    // Attempt reentrancy attack    await expect(      attackerContract.attack({ value: ethers.utils.parseEther("1") }),    ).to.be.revertedWith("ReentrancyGuard: reentrant call");  });
  it("Should prevent integer overflow", async function () {    const Token = await ethers.getContractFactory("SecureToken");    const token = await Token.deploy();
    // Attempt overflow    await expect(token.transfer(attacker.address, ethers.constants.MaxUint256))      .to.be.reverted;  });
  it("Should enforce access control", async function () {    const [owner, attacker] = await ethers.getSigners();
    const Contract = await ethers.getContractFactory("SecureContract");    const contract = await Contract.deploy();
    // Attempt unauthorized withdrawal    await expect(contract.connect(attacker).withdraw(100)).to.be.revertedWith(      "Ownable: caller is not the owner",    );  });});

Audit Preparation

solidity
contract WellDocumentedContract {    /**     * @title Well Documented Contract     * @dev Example of proper documentation for audits     * @notice This contract handles user deposits and withdrawals     */
    /// @notice Mapping of user balances    mapping(address => uint256) public balances;
    /**     * @dev Deposits ETH into the contract     * @notice Anyone can deposit funds     */    function deposit() public payable {        require(msg.value > 0, "Must send ETH");        balances[msg.sender] += msg.value;    }
    /**     * @dev Withdraws user's balance     * @notice Follows CEI pattern to prevent reentrancy     * @param amount Amount to withdraw in wei     */    function withdraw(uint256 amount) public {        // CHECKS        require(amount <= balances[msg.sender], "Insufficient balance");
        // EFFECTS        balances[msg.sender] -= amount;
        // INTERACTIONS        (bool success, ) = msg.sender.call{value: amount}("");        require(success, "Transfer failed");    }}

来源与署名

来源:wshobson/agents位于plugins/blockchain-web3/skills/solidity-security提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架