Solidity Security

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

AI 產生的概覽

指導安全的 Solidity 智慧合約開發,涵蓋常見漏洞、安全模式與稽核準備。

功能
此技能提供智慧合約安全最佳實務、漏洞防範與安全 Solidity 開發模式的指引。內容涵蓋重入、整數溢位與存取控制等主題,並包含 Hardhat 安全測試範例與可供稽核的合約範例。它也指向一個包含詳細模式與完整範例的參考檔案。
適用情境
適用於撰寫安全的智慧合約、稽核現有合約中的漏洞,或為區塊鏈應用實作安全措施。在準備專業稽核或研究常見攻擊向量時也很有用。
執行需求
不隨附指令碼,僅為說明性內容。範例涉及 Hardhat、Chai 與 ethers 用於測試,但未指定安裝步驟或認證資訊。

Solidity Security

Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.

When to Use This Skill

  • Writing secure smart contracts
  • Auditing existing contracts for vulnerabilities
  • Implementing secure DeFi protocols
  • Preventing reentrancy, overflow, and access control issues
  • Optimizing gas usage while maintaining security
  • Preparing contracts for professional audits
  • Understanding common attack vectors

Detailed patterns and worked examples

Detailed pattern documentation lives in references/details.md. Read that file when the navigation tier above is insufficient.

Testing for Security

javascript
// Hardhat test exampleconst { expect } = require("chai");const { ethers } = require("hardhat");
describe("Security Tests", function () {  it("Should prevent reentrancy attack", async function () {    const [attacker] = await ethers.getSigners();
    const VictimBank = await ethers.getContractFactory("SecureBank");    const bank = await VictimBank.deploy();
    const Attacker = await ethers.getContractFactory("ReentrancyAttacker");    const attackerContract = await Attacker.deploy(bank.address);
    // Deposit funds    await bank.deposit({ value: ethers.utils.parseEther("10") });
    // Attempt reentrancy attack    await expect(      attackerContract.attack({ value: ethers.utils.parseEther("1") }),    ).to.be.revertedWith("ReentrancyGuard: reentrant call");  });
  it("Should prevent integer overflow", async function () {    const Token = await ethers.getContractFactory("SecureToken");    const token = await Token.deploy();
    // Attempt overflow    await expect(token.transfer(attacker.address, ethers.constants.MaxUint256))      .to.be.reverted;  });
  it("Should enforce access control", async function () {    const [owner, attacker] = await ethers.getSigners();
    const Contract = await ethers.getContractFactory("SecureContract");    const contract = await Contract.deploy();
    // Attempt unauthorized withdrawal    await expect(contract.connect(attacker).withdraw(100)).to.be.revertedWith(      "Ownable: caller is not the owner",    );  });});

Audit Preparation

solidity
contract WellDocumentedContract {    /**     * @title Well Documented Contract     * @dev Example of proper documentation for audits     * @notice This contract handles user deposits and withdrawals     */
    /// @notice Mapping of user balances    mapping(address => uint256) public balances;
    /**     * @dev Deposits ETH into the contract     * @notice Anyone can deposit funds     */    function deposit() public payable {        require(msg.value > 0, "Must send ETH");        balances[msg.sender] += msg.value;    }
    /**     * @dev Withdraws user's balance     * @notice Follows CEI pattern to prevent reentrancy     * @param amount Amount to withdraw in wei     */    function withdraw(uint256 amount) public {        // CHECKS        require(amount <= balances[msg.sender], "Insufficient balance");
        // EFFECTS        balances[msg.sender] -= amount;
        // INTERACTIONS        (bool success, ) = msg.sender.call{value: amount}("");        require(success, "Transfer failed");    }}

來源與署名

來源:wshobson/agents位於plugins/blockchain-web3/skills/solidity-security提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架