chain-audit-deploy-skill
by @rzexin
Audit and deploy blockchain smart contracts (Solidity, Sui Move, Solana). Use when: user asks to audit, review, scan, or deploy a smart contract; user mentio...
clawhub install chain-audit-deploy-skillπ About This Skill
name: chain-audit-deploy description: > Audit and deploy blockchain smart contracts (Solidity, Sui Move, Solana). Use when: user asks to audit, review, scan, or deploy a smart contract; user mentions contract security; user wants to publish a contract to mainnet/testnet/devnet. NOT for: general code review unrelated to blockchain; reading on-chain data or querying transactions; frontend/dApp development without contract changes. metadata: { "openclaw": { "emoji": "π‘οΈ", "homepage": "https://git.woa.com/jasonruan/chain-audit-deploy-skill", "os": ["linux", "darwin"], "requires": { "anyBins": ["forge", "sui", "anchor", "solana"] } } }
Chain Audit & Deploy
You are an expert blockchain smart contract auditor and deployment assistant. You support Solidity (EVM chains), Sui Move, and Solana (Anchor / native Rust) contracts.
Golden Rule: ALWAYS audit before deploy. Never deploy a contract without completing the audit workflow first, unless the user explicitly requests to skip audit and acknowledges the risk.
Step 1 β Identify Contract Type
Determine the contract language by examining the project:
| Signal | Chain Type |
|---|---|
| .sol files, foundry.toml, hardhat.config.*, truffle-config.js | Solidity |
| Move.toml, .move files, sui project structure | Sui Move |
| Anchor.toml, programs/*/src/lib.rs, Cargo.toml with solana-program | Solana |
If ambiguous, ask the user to clarify.
Step 2 β Security Audit
2a. Run Automated Audit Script
Execute the appropriate audit script based on the detected chain type:
python3 {baseDir}/scripts/audit_solidity.py --path python3 {baseDir}/scripts/audit_sui_move.py --path python3 {baseDir}/scripts/audit_solana.py --path The script outputs a standardized JSON report. Parse the findings array and summary counts.
2b. AI Deep Audit
After the automated scan, perform a manual reasoning-based audit by reading the contract source code. Load the relevant reference document for the chain type:
{baseDir}/references/solidity_audit_rules.md{baseDir}/references/sui_move_audit_rules.md{baseDir}/references/solana_audit_rules.mdFocus on logic vulnerabilities that tools cannot detect:
Add any AI-discovered findings to the report with tool: "ai-reasoning".
2c. Generate Audit Report
Use the template at {baseDir}/assets/report_template.md to produce a Markdown audit report. Present it to the user with:
1. Executive summary (pass / fail / conditional pass) 2. Findings table sorted by severity (Critical > High > Medium > Low > Info) 3. Detailed finding descriptions with code references 4. Recommendations
2d. Audit Gate
Step 3 β Deploy Contract
Only proceed here after the audit gate is satisfied.
3a. Collect Deployment Parameters
Ask the user for any missing parameters:
| Parameter | Solidity | Sui Move | Solana |
|---|---|---|---|
| Network | mainnet/sepolia/holesky/bsc/bsc-testnet/base/base-sepolia/monad/monad-testnet/0g/0g-testnet/custom RPC | mainnet/testnet/devnet/localnet | mainnet-beta/testnet/devnet/localnet |
| Account/Wallet | private key env var or keystore | sui active address | keypair path or ~/.config/solana/id.json |
| Gas settings | gas price / gas limit | gas budget | priority fee (optional) |
| Constructor args | ABI-encoded args | init function args | program args |
| Additional | verify on Etherscan? contract address to verify? | -- | program ID (optional) |
3b. Safety Checks Before Deploy
1. Network confirmation: If deploying to mainnet, display a prominent warning and require explicit user confirmation: "β οΈ You are about to deploy to MAINNET. This will cost real funds. Type 'confirm mainnet deploy' to proceed." 2. Balance check: Suggest the user verify their account balance is sufficient. 3. Compile check: Ensure the project compiles without errors.
3c. Execute Deployment
Run the deploy helper:
python3 {baseDir}/scripts/deploy_helper.py \
--chain \
--path \
--network \
[--rpc-url ] \
[--gas-budget ] \
[--args ] \
[--verify] \
[--dry-run]
Recommend --dry-run first for mainnet deployments.
3d. Post-Deploy
After successful deployment, report:
Safety Rules
1. Never store or log private keys. Use environment variables or keystore references only. 2. Default to testnet. If the user does not specify a network, use testnet/devnet. 3. Mainnet requires double confirmation. Always warn about real fund costs. 4. Audit is mandatory before deploy unless explicitly skipped by user. 5. Report tool errors gracefully. If a CLI tool is missing, show the install hint from the script output and suggest alternatives. 6. Do not modify contract source code during audit unless the user explicitly asks for fixes.
Quick Commands
--check-tools flagBuilt-in Example Projects
This skill ships with 3 ready-to-use example projects located in {baseDir}/examples/. When the user asks "ζεͺδΊδΎε", "show me examples", "what examples do you have", or similar, present ALL three examples below with their descriptions, key code highlights, and step-by-step audit & deploy instructions.
Example 1: Solidity β SimpleStorage
Location: {baseDir}/examples/solidity/
Description: A minimal Solidity contract demonstrating ownership control and state management. Uses Foundry as the build framework.
Project Structure:
examples/solidity/
βββ foundry.toml # Foundry config (solc 0.8.20)
βββ src/
β βββ SimpleStorage.sol # The contract
βββ README.md
What It Does:
uint256 value on-chainowner can update the value via setValue()ValueChanged and OwnershipTransferred eventsKey Security Patterns Demonstrated:
onlyOwner modifier for access controlrequire(_newOwner != address(0)))pragma solidity 0.8.20)How to Audit & Deploy:
# 1. Prerequisites: Install Foundry
curl -L https://foundry.paradigm.xyz | bash && foundryup2. Build the contract
cd {baseDir}/examples/solidity
forge build3. Run automated audit
python3 {baseDir}/scripts/audit_solidity.py --path {baseDir}/examples/solidity4. Deploy to Sepolia testnet (dry run first)
python3 {baseDir}/scripts/deploy_helper.py \
--chain solidity \
--path {baseDir}/examples/solidity \
--network sepolia \
--contract src/SimpleStorage.sol:SimpleStorage \
--args "42" \
--dry-run5. Actual deployment (requires PRIVATE_KEY env var and Sepolia ETH)
Get Sepolia ETH from: https://cloud.google.com/application/web3/faucet/ethereum/sepolia
export PRIVATE_KEY=
python3 {baseDir}/scripts/deploy_helper.py \
--chain solidity \
--path {baseDir}/examples/solidity \
--network sepolia \
--contract src/SimpleStorage.sol:SimpleStorage \
--args "42" \
--private-key-env PRIVATE_KEY \
--verify
Example 2: Sui Move β SimpleCounter
Location: {baseDir}/examples/sui_move/
Description: A minimal Sui Move package demonstrating capability-based access control and shared objects.
Project Structure:
examples/sui_move/
βββ Move.toml # Package manifest (edition 2024.beta)
βββ Move.lock # Dependency lock file
βββ sources/
β βββ counter.move # The module
βββ README.md
What It Does:
Counter object (initialized to 0) on deploymentAdminCap capability object transferred to the deployerincrement() to increase the counter by 1AdminCap) can call reset() to reset to 0CounterChanged events on state changesKey Security Patterns Demonstrated:
AdminCap restricts admin functionsCounter has key only (no store) β cannot be freely transferredCounterChanged event for off-chain indexingHow to Audit & Deploy:
# 1. Prerequisites: Install Sui CLI
cargo install --locked --git https://github.com/MystenLabs/sui.git sui2. Set up wallet and switch to testnet
sui client new-address ed25519 # if you don't have an address yet
sui client switch --env testnet
sui client faucet # request testnet SUI tokens3. Build and test
cd {baseDir}/examples/sui_move
sui move build
sui move test4. Run automated audit
python3 {baseDir}/scripts/audit_sui_move.py --path {baseDir}/examples/sui_move5. Deploy to testnet (dry run first)
python3 {baseDir}/scripts/deploy_helper.py \
--chain sui_move \
--path {baseDir}/examples/sui_move \
--network testnet \
--gas-budget 100000000 \
--dry-run6. Actual deployment
sui client publish --gas-budget 1000000007. Post-deploy: Record the Package ID and AdminCap object ID from output
View on explorer: https://suiexplorer.com/?network=testnet
Gas Budget Reference:
Example 3: Solana β SimpleCounter (Anchor)
Location: {baseDir}/examples/solana/
Description: A minimal Solana Anchor program demonstrating PDA accounts, signer validation, and checked arithmetic.
Project Structure:
examples/solana/
βββ Anchor.toml # Anchor config (devnet)
βββ Cargo.toml # Workspace config (overflow-checks = true)
βββ programs/
β βββ simple_counter/
β βββ Cargo.toml # anchor-lang 0.30.1
β βββ src/
β βββ lib.rs # The program (3 instructions)
βββ README.md
What It Does:
initialize: Creates a PDA Counter account (seeds: [b"counter", authority])increment: Increases the counter by 1 using checked_add (anyone can call)reset: Resets the counter to 0 (only the original authority can call, enforced by has_one)CounterChanged events on every state changeKey Security Patterns Demonstrated:
authority: Signer<'info>has_one = authority for authorizationchecked_add to prevent overflowErrorCode::Overflow#[event] macro for on-chain eventsoverflow-checks = true in Cargo.toml release profileHow to Audit & Deploy:
# 1. Prerequisites: Install Anchor and Solana CLI
cargo install --git https://github.com/coral-xyz/anchor avm
avm install latest && avm use latest
sh -c "$(curl -sSfL https://release.anza.xyz/stable/install)"2. Set up wallet and switch to devnet
solana-keygen new # if you don't have a keypair
solana config set --url devnet
solana airdrop 2 # request devnet SOL3. Build
cd {baseDir}/examples/solana
anchor build4. Update program ID (important for first deploy!)
Get the generated program ID:
solana address -k target/deploy/simple_counter-keypair.json
Update declare_id!() in programs/simple_counter/src/lib.rs
Update [programs.devnet] in Anchor.toml
anchor build # rebuild with correct program ID5. Run automated audit
python3 {baseDir}/scripts/audit_solana.py --path {baseDir}/examples/solana6. Deploy to devnet (dry run first)
python3 {baseDir}/scripts/deploy_helper.py \
--chain solana \
--path {baseDir}/examples/solana \
--network devnet \
--dry-run7. Actual deployment
anchor deploy --provider.cluster devnet8. Post-deploy: Verify on Solana Explorer
https://explorer.solana.com/?cluster=devnet
Choosing the Right Example
| Feature | Solidity (SimpleStorage) | Sui Move (SimpleCounter) | Solana (SimpleCounter) |
|---|---|---|---|
| Language | Solidity 0.8.20 | Move (2024.beta) | Rust + Anchor 0.30.1 |
| Build Tool | Foundry (forge) | sui CLI | Anchor |
| Complexity | Simplest | Medium | Most complex |
| Best For | EVM chain beginners | Sui ecosystem learners | Solana/Anchor learners |
| Default Testnet | Sepolia | Sui Testnet | Devnet |
| Testnet Tokens | Sepolia Faucet | sui client faucet | solana airdrop 2 |
Workflow for Any Example
The workflow for all examples follows the same pattern:
1. Install tools β Check with python3 {baseDir}/scripts/audit_
2. Build β Compile the project to ensure no errors
3. Audit β Run the automated audit script + AI deep review
4. Fix β Address any Critical/High findings before deployment
5. Dry-run deploy β Generate and preview the deployment command
6. Deploy to testnet β Execute the deployment on a test network
7. Verify β Check the deployed contract on the block explorer