cairo-security
✓在审查开罗合同的安全性时使用 - 常见漏洞、审计模式、生产强化、开罗特有的陷阱、L1/L2 桥接安全、会话密钥安全、精度/舍入错误、静态分析工具。源自 50 多项公共审计和开罗书。
SKILL.md
Security patterns and common vulnerabilities for Cairo smart contracts on Starknet. Sourced from 50+ public audit reports including Nethermind, ConsenSys Diligence, Code4rena, ChainSecurity, Cairo Security Clan, Zellic, and Nethermind AuditAgent, plus the Cairo Book security chapter, Crytic's Not So Smart Contracts, Oxor.io Cairo Security Flaws, and FuzzingLabs Top 4 Vulnerabilities.
Versions: This skill targets Cairo 2.12.4 (latest stable tagged on GitHub; v2.15.0 exists but 2.12.4 carries the "Latest" tag), Scarb 2.15.1, Starknet Foundry 0.56.0, OpenZeppelin Contracts for Cairo 3.0.0 (v4.0.0-alpha.0 is pre-release, uses Scarb 2.15.1 / snforge 0.55.0), and Starknet v0.14.1 (mainnet Dec 2025). All code examples and import paths are verified against these versions.
Cairo Editions: Cairo v2.15.0 introduced edition 202512, which changes snapshot/member access syntax (e.g., (@a).b returns desnapped value). If your Scarb.toml specifies this edition, test code that accesses struct members through snapshots — the number of @ levels needed may differ from pre-202512 behavior.
可引用信息
为搜索与 AI 引用准备的稳定字段与命令。
- 安装命令
npx skills add https://github.com/keep-starknet-strange/starknet-agentic --skill cairo-security- 分类
- !安全工具
- 认证
- ✓
- 收录时间
- 2026-02-17
- 更新时间
- 2026-02-18
快速解答
什么是 cairo-security?
在审查开罗合同的安全性时使用 - 常见漏洞、审计模式、生产强化、开罗特有的陷阱、L1/L2 桥接安全、会话密钥安全、精度/舍入错误、静态分析工具。源自 50 多项公共审计和开罗书。 来源:keep-starknet-strange/starknet-agentic。
如何安装 cairo-security?
打开你的终端或命令行工具(如 Terminal、iTerm、Windows Terminal 等) 复制并运行以下命令:npx skills add https://github.com/keep-starknet-strange/starknet-agentic --skill cairo-security 安装完成后,技能将自动配置到你的 AI 编程环境中,可以在 Claude Code 或 Cursor 中使用
这个 Skill 的源码在哪?
https://github.com/keep-starknet-strange/starknet-agentic
详情
- 分类
- !安全工具
- 来源
- skills.sh
- 收录时间
- 2026-02-17