solidity-security

Installation
SKILL.md

Solidity Security Standards

Language Rule

  • Always respond in the same language the user is using. If the user asks in Chinese, respond in Chinese. If in English, respond in English.

Private Key Protection

  • Before an on-chain write, let the developer choose a signing method:
    • Foundry Keystore (recommended): import with cast wallet import <NAME> --interactive and use --account <NAME>.
    • Environment file: store PRIVATE_KEY in .env, load it with source .env, and reference "$PRIVATE_KEY"; never paste the literal value into a command.
  • Never expose private keys in logs, screenshots, conversations, or commits
  • Provide .env.example with placeholder values for team reference
  • Add .env to .gitignore — verify with git status before every commit
  • Never read or print a developer's .env; only provide commands for the developer to run

Security Decision Rules

When writing or reviewing Solidity code, apply these rules:

Installs
125
GitHub Stars
4
First Seen
Feb 9, 2026
solidity-security — 0xlayerghost/solidity-agent-kit