·cairo-security

在審查開羅合約的安全性時使用 - 常見漏洞、審計模式、生產強化、開羅特有的陷阱、L1/L2 橋接安全性、會話密鑰安全、精度/舍入錯誤、靜態分析工具。源自 50 多項公共審計和開羅書。

5安裝·1熱度·@keep-starknet-strange

安裝

$npx skills add https://github.com/keep-starknet-strange/starknet-agentic --skill cairo-security

SKILL.md

Security patterns and common vulnerabilities for Cairo smart contracts on Starknet. Sourced from 50+ public audit reports including Nethermind, ConsenSys Diligence, Code4rena, ChainSecurity, Cairo Security Clan, Zellic, and Nethermind AuditAgent, plus the Cairo Book security chapter, Crytic's Not So Smart Contracts, Oxor.io Cairo Security Flaws, and FuzzingLabs Top 4 Vulnerabilities.

Versions: This skill targets Cairo 2.12.4 (latest stable tagged on GitHub; v2.15.0 exists but 2.12.4 carries the "Latest" tag), Scarb 2.15.1, Starknet Foundry 0.56.0, OpenZeppelin Contracts for Cairo 3.0.0 (v4.0.0-alpha.0 is pre-release, uses Scarb 2.15.1 / snforge 0.55.0), and Starknet v0.14.1 (mainnet Dec 2025). All code examples and import paths are verified against these versions.

Cairo Editions: Cairo v2.15.0 introduced edition 202512, which changes snapshot/member access syntax (e.g., (@a).b returns desnapped value). If your Scarb.toml specifies this edition, test code that accesses struct members through snapshots — the number of @ levels needed may differ from pre-202512 behavior.

查看原文

可引用資訊

為搜尋與 AI 引用準備的穩定欄位與指令。

安裝指令
npx skills add https://github.com/keep-starknet-strange/starknet-agentic --skill cairo-security
分類
!安全工具
認證
收錄時間
2026-02-17
更新時間
2026-02-18

快速解答

什麼是 cairo-security?

在審查開羅合約的安全性時使用 - 常見漏洞、審計模式、生產強化、開羅特有的陷阱、L1/L2 橋接安全性、會話密鑰安全、精度/舍入錯誤、靜態分析工具。源自 50 多項公共審計和開羅書。 來源:keep-starknet-strange/starknet-agentic。

如何安裝 cairo-security?

開啟你的終端機或命令列工具(如 Terminal、iTerm、Windows Terminal 等) 複製並執行以下指令:npx skills add https://github.com/keep-starknet-strange/starknet-agentic --skill cairo-security 安裝完成後,技能將自動設定到你的 AI 程式設計環境中,可以在 Claude Code 或 Cursor 中使用

這個 Skill 的原始碼在哪?

https://github.com/keep-starknet-strange/starknet-agentic