solidity-security
Installation
SKILL.md
Solidity Security Standards
Language Rule
- Always respond in the same language the user is using. If the user asks in Chinese, respond in Chinese. If in English, respond in English.
Private Key Protection
- Before an on-chain write, let the developer choose a signing method:
- Foundry Keystore (recommended): import with
cast wallet import <NAME> --interactiveand use--account <NAME>. - Environment file: store
PRIVATE_KEYin.env, load it withsource .env, and reference"$PRIVATE_KEY"; never paste the literal value into a command.
- Foundry Keystore (recommended): import with
- Never expose private keys in logs, screenshots, conversations, or commits
- Provide
.env.examplewith placeholder values for team reference - Add
.envto.gitignore— verify withgit statusbefore every commit - Never read or print a developer's
.env; only provide commands for the developer to run
Security Decision Rules
When writing or reviewing Solidity code, apply these rules: