Solidity

作者 mindrally97184105b5da無授權條款269 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫5 週前更新

Best practices for secure, gas-efficient Solidity smart contract development and Web3 frontend integration. Use when writing or reviewing Solidity contracts, hardening against reentrancy and access-control bugs, optimizing gas usage, setting up Hardhat/Foundry testing and static analysis, or wiring a React frontend to wallets, providers, and on-chain transactions.

AI 產生的概覽

提供安全、省 Gas 的 Solidity 智慧合約開發與 Web3 前端整合最佳實務指引。

功能
為撰寫與審查 Solidity 智慧合約提供最佳實務指引,涵蓋程式碼結構、安全模式、Gas 最佳化、工具與測試。同時針對如何將 React Web3 前端接上錢包、Provider 與鏈上交易提出建議。它只是純說明性參考,不會產生檔案或指令碼。
適用情境
適用於撰寫或審查 Solidity 合約、防範重入與存取控制漏洞、最佳化 Gas 用量的情境。也適合在設定 Hardhat 或 Foundry 測試與靜態分析,或將前端接上錢包與鏈上交易時使用。
執行需求
不需要任何工具、套件或憑證;僅為說明性內容,不附帶指令碼。文中提及 OpenZeppelin、Slither、Mythril、Hardhat、Chainlink VRF、TypeChain 以及 wagmi/viem 等外部工具。

Solidity

This skill covers best practices for Solidity smart contract development, including security patterns, gas optimization, testing/tooling, and integrating contracts with a Web3 React frontend.

Core Principles

  • Cut the fluff. Code or detailed explanations only
  • Maintain brevity while prioritizing accuracy and depth
  • Answer first, explain later when needed

Code Structure & Security

  • Use explicit visibility modifiers and NatSpec documentation
  • Apply function modifiers to reduce redundancy
  • Follow naming conventions:
    • CamelCase for contracts
    • PascalCase for interfaces (prefix with "I")
  • Implement Interface Segregation Principle
  • Use proxy patterns for upgradeable contracts
  • Emit comprehensive events for state changes
  • Follow Checks-Effects-Interactions pattern against reentrancy

Security Best Practices

  • Use OpenZeppelin's AccessControl for permissions
  • Require Solidity 0.8.0+ for overflow/underflow protection
  • Use Pausable pattern for circuit breakers
  • Implement ReentrancyGuard for additional protection
  • Use SafeERC20 for token interactions
  • Employ pull-over-push payment patterns
  • Implement timelocks and multisig controls for sensitive operations

Gas Optimization

  • Optimize gas consumption (deployment and runtime)
  • Use immutable variables for constructor-set values
  • Use custom errors instead of revert strings
  • Pack storage variables efficiently
  • Use appropriate data types

Tools & Analysis

  • Integrate Slither and Mythril for static analysis
  • Leverage Hardhat's testing and development environment
  • Implement robust CI/CD pipelines
  • Use pre-commit linting tools

Advanced Patterns

  • Chainlink VRF for randomness
  • Strategic assembly use with extensive documentation
  • State machine patterns for complex logic
  • ERC20Snapshot, ERC20Permit, and ERC20Votes for specialized tokens

Testing & Quality

  • Comprehensive unit, integration, and end-to-end testing
  • Property-based testing approaches
  • High coverage targets
  • Regular security audits

Web3 Frontend Integration

  • Keep frontend code that talks to contracts type-safe and explicit — generate TypeScript types from ABIs (e.g. via TypeChain or wagmi/viem codegen) rather than hand-writing contract call signatures
  • Treat wallet connection, chain/network state, and transaction status as explicit, typed state (connected/connecting/wrong-network/error), not implicit booleans
  • Surface transaction lifecycle clearly in the UI: submitted, pending confirmation, confirmed, reverted — never assume a submitted transaction succeeded
  • Validate and simulate transactions (e.g. eth_call/gas estimation) before prompting the user to sign, to catch reverts early
  • Never trust client-side reads of contract state for authorization decisions — always re-verify on-chain in the contract itself
  • Handle provider/RPC failures and user rejection of signature requests as expected, recoverable error states

來源與署名

來源:mindrally/skills位於solidity提交9718410

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架