- Home
- Skills
- Web3 & Crypto
- proofforge
Works with the AI tools you already use
proofforge
A test-driven Solidity auditing skill that identifies and proves smart contract vulnerabilities using Foundry.
$7
proofforge
Example session with this skill installed
Audit this vault deposit function for rounding errors. The vault uses a shares-for-assets model with a 5,000,000:1 reserve ratio. Verify if a user can lose precision on small deposits.
- Read your context and instructions
- Compiled the proofforge
I have analyzed the Vault.deposit function and identified a rounding-to-zero vulnerability when the reserve ratio is extreme. I have verified this via a forked mainnet test.
Vulnerability: Precision Loss in Share Calculation
The contract uses shares = (assets * totalSupply) / totalAssets. At high reserve ratios (e.g., 5,000,000 assets per 1 share), small deposits result in 0 shares being minted while the assets are still transferred to the vault.
// target/RoundingExploit.t.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
import "forge-std/Test.sol";
import "../src/Vault.sol";
contract RoundingExploit is Test {
Vault public vault;
address public attacker = address(0xBAD);
function setUp() public {
vault = new Vault();
// Simulate extreme reserve ratio: 1 share for 5M tokens
deal(address(vault), 5_000_000 * 1e18);
// vault.setInitialShares(1);
}
function test_rounding_to_zero_loss() public {
uint256 smallDeposit = 4_999_999 * 1e18;
deal(attacker, smallDeposit);
vm.startPrank(attacker);
vault.asset().approve(address(vault), smallDeposit);
uint256 sharesBefore = vault.balanceOf(attacker);
vault.deposit(smallDeposit, attacker);
uint256 sharesAfter = vault.balanceOf(attacker);
// Assert economic loss: assets gone, 0 shares received
assertEq(sharesAfter - sharesBefore, 0);
assertEq(vault.asset().balanceOf(attacker), 0);
vm.stopPrank();
}
}
| ID | Entry Point | Class | Claim | Status |
|---|---|---|---|---|
| H-01 | Vault.deposit | Rounding | Precision loss at high asset:share ratio | CONFIRMED |
Next steps
- Implement
Virtual Shares(ERC4626) to mitigate inflation and rounding attacks. - Add a
require(shares > 0)check to prevent silent asset loss for users. - Run the provided test after applying the fix to ensure the transaction reverts as expected.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Stop relying on manual code reviews that miss edge cases. This skill implements a disciplined, test-driven security methodology for Solidity smart contracts. It moves beyond "looks right" audits by forcing every hypothesis to be proven or killed through executed Foundry tests. ## What it does - **Attack surface mapping** catalogs external functions, trust boundaries, and value flows to identify reachable vectors. - **Symmetry analysis** detects divergences in round-trip operations, accounting-vs-balance checks, and conservation laws. - **Hypothesis logging** tracks every potential vulnerability from identification through formal confirmation or refutation. - **Invariant fuzzing** generates stateful Foundry handlers to stress-test protocol invariants at extreme regimes. - **Economic validation** calculates real-world profitability, accounting for gas, slippage, and mainnet fork state. ## How it works 1. **Target filtering** assesses TVL and monetization paths to prioritize high-value entry points. 2. **Symmetry stress-testing** applies 0/1/max and extreme reserve ratio values to find rounding and precision errors. 3. **Exploit construction** builds reachable trajectories using only actions available to a real attacker. 4. **Red-to-green verification** applies a fix and reruns tests to ensure the exploit is neutralized, preventing false positives. ## Frameworks & tools Specifically designed for Solidity smart contract auditing using Foundry (Forge/Cast), Slither, and Aderyn. Optimized for mainnet-forked environments. ## Why this beats prompting it yourself Generic LLMs often hallucinate vulnerabilities or miss subtle accounting bugs because they don't execute code. This skill enforces a "test-first" protocol that requires mechanical proof, ensuring every reported finding is economically viable and technically reachable. ## Use cases - **Protocol audits** for new DeFi primitives or complex vault accounting. - **Bounty hunting** to verify suspected vulnerabilities with concrete proof-of-concept code. - **Regression testing** by establishing stateful invariants that catch breaking changes during upgrades. - **Security reviews** of external integrations like oracles, callbacks, and non-standard ERC20 tokens. ## Known limitations Requires a functional Foundry environment. Does not support non-EVM chains or Vyper. Cannot guarantee 100% coverage of off-chain components or social engineering vectors.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 days ago
- Passed all security checks, Safe to install
Needs access to