offensive-tools/vuln-scanners/slither/SKILL.md
Auth/lab ref: smart contract static analyzer for Solidity and Vyper with detectors, printers, and custom analysis APIs.
npx skillsauth add aeondave/malskill slitherInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Fast static analysis for Solidity and Vyper codebases.
Use Slither when you need to:
# Recommended
uv tool install slither-analyzer
# Or pip
python3 -m pip install slither-analyzer
Upstream recommends solc-select or a supported build framework when multiple compiler versions are in play.
# Preferred for real projects with imports
slither .
# Single self-contained file
slither contracts/Token.sol
# Markdown checklist report
slither . --checklist
If the project uses Hardhat, Foundry, Brownie, or another framework, ensure its normal compile command succeeds before blaming Slither.
Run Slither from the project root, not from an isolated contract file, when imports and dependencies exist.
slither .
This gives broad coverage for issues like:
tx.origin misuseslither . --checklist
slither . --print human-summary
slither . --print call-graph,cfg,function-summary
Use printers for comprehension, not just bug hunting.
slither . --checklist
slither . --print human-summary,inheritance-graph,entry-points
Use Slither's Python API when a one-off audit question is too specific for stock detectors.
mythril for symbolic execution depth on suspicious paths.No bundled scripts/, references/, or assets/.
Use the upstream detector and printer documentation for the full detector list and tuning options.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.