secure-workflow-guide
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas.
Security Assessment
About secure-workflow-guide
The secure-workflow-guide skill is designed to assist developers in implementing a comprehensive, five-step secure development workflow for smart contracts. By integrating automated analysis, visual inspection, and manual review, it aims to mitigate common vulnerabilities and enhance the overall security posture of blockchain-based applications. The skill provides a structured approach to identify and address security risks early in development, ensuring that contracts meet rigorous standards before deployment.
Its main capabilities include automated Slither scans to detect over 70 known vulnerabilities, checks for special features such as upgradeability, ERC conformance, and token integration, and generation of visual security diagrams that map inheritance, function access controls, and state variable authorization. Additionally, the skill guides the documentation of security properties for fuzzing and formal verification using tools like Echidna and Manticore, and it outlines areas for manual security review, including privacy, front-running, cryptography, and DeFi interactions. The workflow adapts dynamically based on the codebase, installed tools, and the project's development stage.
This skill is particularly useful for smart contract developers, security engineers, and auditors who need a systematic approach to security review. It can be applied during every code check-in, before deployment, or whenever a security assessment is required. By combining automated tools with guided manual checks, it helps teams maintain high security standards, reduce vulnerabilities, and provide clear documentation for verification and compliance purposes.
FAQ
How do I start using the secure-workflow-guide skill?
Invoke the skill in your project directory. It will explore your codebase, run the automated Slither scan, perform applicable special feature checks, generate visual security diagrams, guide documentation of security properties, and suggest manual review areas.
Which projects is this skill compatible with?
It is designed for smart contract projects, particularly those written in Solidity, and is compatible with projects that can be analyzed using Slither and related tooling.
Do I need any tools installed to use this skill effectively?
Yes, having Slither installed is required for automated scanning. For full capability, tools like Echidna and Manticore are recommended for property-based fuzzing and formal verification.
Can I skip certain workflow steps if they don’t apply?
The skill adapts checks based on your codebase, but it is recommended to verify applicability carefully rather than skipping steps, as some risks may be implicit.
What types of security issues does the skill help identify?
It identifies common vulnerabilities, upgradeability risks, ERC conformance issues, token integration concerns, privacy leaks, front-running potential, cryptographic weaknesses, and DeFi-specific risks such as oracle manipulation or flash loan vulnerabilities.
Install secure-workflow-guide
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
trailofbits/skills