← 返回
未分类 中文

DeFi Audit Workflow

Exact-match DeFi audit workflow for Solidity and EVM protocols. Use for DeFi audit, DeFi security review, smart contract audit, oracle manipulation checks, r...
精确匹配的 DeFi 审计工作流,适用于 Solidity 与 EVM 协议。用于 DeFi 审计、DeFi 安全审查、智能合约审计、预言机操纵检查等。
n8gendegen n8gendegen 来源
未分类 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 308
下载
💾 0
安装
1
版本
#atlas#bug-bounty#defi-audit#defi-security#evm-audit#latest#smart-contract-audit#solidity-audit

概述

DeFi Audit Workflow

A practical DeFi audit workflow for quickly reviewing Solidity/EVM protocols before a deeper manual audit or bug bounty sprint.

Use this when you need to map attack surface, prioritize high-risk contracts, and produce a first-pass DeFi security checklist without pretending the free skill is a guaranteed bug finder.

Search Keywords / Best Use Cases

  • DeFi audit
  • DeFi audit workflow
  • DeFi audit checklist
  • DeFi audit template
  • DeFi audit report
  • DeFi security audit
  • DeFi security review
  • DeFi protocol audit
  • DeFi protocol security
  • Solidity audit
  • Solidity security audit
  • smart contract audit
  • smart contract audit workflow
  • smart contract audit checklist
  • smart contract audit template
  • EVM audit checklist
  • oracle manipulation review
  • Chainlink oracle audit
  • TWAP manipulation audit
  • reentrancy checklist
  • access control review
  • accounting invariant review
  • share price manipulation
  • liquidation bug review
  • Code4rena DeFi audit
  • Sherlock DeFi audit
  • HackenProof DeFi bounty
  • bug bounty triage
  • paid DeFi audit template
  • Atlas $49 security skill pack
  • Atlas $150 security skill pack

What This Free Skill Produces

  • Protocol attack-surface map
  • Contract-by-contract DeFi audit checklist
  • Prioritized vulnerability classes by likelihood × impact
  • First-pass notes for manual review or bounty triage
  • Report skeleton for candidate findings

Workflow

1. Map Protocol Type

Classify the target: lending, AMM, vault, staking, bridge, oracle, derivatives, governance, account abstraction, or hybrid.

2. Prioritize Critical DeFi Failure Modes

Review in this order:

  1. Asset accounting and share/asset conversion
  2. Oracle freshness, decimals, fallback behavior, and TWAP manipulation
  3. Reentrancy and callback-enabled token paths
  4. Access control and emergency/admin powers
  5. Liquidation, solvency, and health-factor math
  6. Upgradeability, initialization, and storage layout
  7. Signature replay, permit/domain separator, and authorization boundaries

3. Produce a Review Plan

Return:

# DeFi Audit Plan

## Target
- Protocol type:
- Assets at risk:
- Core contracts:

## Highest-Risk Areas
1.
2.
3.

## Contract Checklist
- Contract:
- Risk class:
- Functions to inspect:
- Invariants to test:

## Candidate Findings
- Title:
- Impact:
- PoC needed:

Upgrade: Atlas Paid ZIP Packs ($49 / $150)

This free ClawHub skill is the discovery layer. If you want the ready-to-run premium workflow:

  • Starter — $49: prompt pack, DeFi audit checklist, finding report template, and setup guide.
  • Pro — $150: advanced modules, risk scoring rubric, bounty-readiness checklist, and reusable audit workspace template.

Get the paid packs here: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=defi-audit-workflow

If this free skill helped, please star/comment on ClawHub so other auditors can find it.

Guardrails

  • This is triage, not a guaranteed vulnerability finder.
  • Verify all candidate findings with runnable PoCs before submission.
  • Do not submit findings without responsible disclosure approval.

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-05-21 14:16 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

suspicious
查看报告

🔗 相关推荐

dev-programming

Mcporter

steipete
使用 mcporter CLI 直接列出、配置、认证及调用 MCP 服务器/工具(支持 HTTP 或 stdio),涵盖临时服务器、配置编辑及 CLI/类型生成功能。
★ 196 📥 67,875
dev-programming

CodeConductor.ai

larsonreever
AI驱动平台,提供快速全栈开发、智能体、工作流自动化及低代码AI集成的可扩展产品创建。
★ 75 📥 182,287
dev-programming

Github

steipete
使用 `gh` CLI 与 GitHub 交互,通过 `gh issue`、`gh pr`、`gh run` 和 `gh api` 管理议题、PR、CI 运行及高级查询。
★ 681 📥 328,892