claudeindex
Marketplace

quillshield-security-skills

QuillShield smart contract security auditing skills for AI agents. Comprehensive coverage of OWASP Smart Contract Top 10 plus proxy/upgrade, signature replay, and token integration vulnerabilities.

Stars

81

Forks

7

Plugins

10

Installation

1

Add the marketplace

/plugin marketplace add quillai-network/qs_skills
2

Install plugins

/plugin

Run these commands in Claude Code to add this plugin to your environment. The marketplace must be added before you can install its plugins.

Details & Metadata

10

Plugins

0

Skills

0

Agents

Last Crawled

March 15, 2026

Plugins

Plugin

behavioral-state-analysis

Multi-dimensional smart contract security auditing using Behavioral State Analysis (BSA). Combines behavioral intent extraction, parallel threat engines, adversarial simulation with PoC generation, and Bayesian confidence scoring.

Plugin

semantic-guard-analysis

Detects logic vulnerabilities by finding functions that bypass security checks the contract consistently applies elsewhere. Based on the Consistency Principle.

Plugin

state-invariant-detection

Automatically infers mathematical relationships between state variables then finds functions that violate them. Catches vulnerabilities behind the biggest DeFi hacks.

Plugin

reentrancy-pattern-analysis

Systematically detects all reentrancy variants — classic, cross-function, cross-contract, read-only, and ERC-777/ERC-1155 callback reentrancy.

Plugin

oracle-flashloan-analysis

Detects price oracle manipulation and flash loan attack vectors. Classifies oracle trust models, identifies stale prices, circular dependencies, and flash loan atomicity exploitation.

Plugin

proxy-upgrade-safety

Detects vulnerabilities in upgradeable proxy architectures — storage layout collisions, uninitialized implementations, function selector clashing, and upgrade path safety.

Plugin

input-arithmetic-safety

Detects input validation failures and arithmetic vulnerabilities — precision loss, rounding exploitation, ERC4626 inflation attacks, unsafe casting, and unchecked block risks.

Plugin

external-call-safety

Detects unsafe external call patterns and token integration vulnerabilities. Covers unchecked return values, fee-on-transfer tokens, rebasing tokens, and callback risks.

Plugin

signature-replay-analysis

Detects signature replay vulnerabilities. Covers same-chain, cross-chain, cross-contract, nonce-skip, and expired replay types plus EIP-712 and ecrecover safety.

Plugin

dos-griefing-analysis

Detects Denial of Service and griefing vulnerabilities — unbounded loops, gas limit exhaustion, external call failure DoS, 63/64 gas griefing, and storage bloat.