# evm-contract-audit

Audits EVM/Solidity smart contracts for security vulnerabilities. Covers reentrancy, access control, flash loan exploits, upgrade issues, oracle manipulation, signature attacks, and more. Learned from EVMbench (120 real Code4rena vulnerabilities across 40 production codebases).

- **Type:** Agent Skill
- **Trust:** 10/100 (F), scored on the remote rubric — Limited: the scan came back clean but coverage was partial, so the score sits below what full coverage would allow. Nothing was found.
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.0.0
- **Author:** gabrielkoerich
- **License:** Unknown
- **Source:** https://github.com/gabrielkoerich/skills/tree/main/evm-contract-audit

## Trust

10/100 (F), scored on the remote rubric — Limited: the scan came back clean but coverage was partial, so the score sits below what full coverage would allow. Nothing was found.
- Publisher verified: no
- Install scripts: not scanned
- Prompt-injection scan: not run
- Obfuscation scan: not run

## Security scan

Not scanned. This is a coverage gap, not a clean result — Forge asserts nothing about this entry's security posture.

## Install

This is an Agent Skill — a prompt, not an MCP server, so there is no client config to generate. Fetch it with forge_get_skill and install it with forge_add_skill.

## Blast radius

Contained blast radius — runs as a prompt.
- Floor 4, ceiling 4 (tier: contained)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/evm-contract-audit
- Install plan: https://forgeregistry.com/api/v1/packages/evm-contract-audit/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/evm-contract-audit
- HTML page: https://forgeregistry.com/registry/evm-contract-audit
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
