Install
$ agentstack add skill-omermaksutii-rugproof-pragma-and-addresses ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Pragma & address-hygiene detection
When this applies
- Top of every Solidity file
- Constants and immutables typed
address - Constructor / initializer parameters typed
address mapping(address => …)updates- Any cross-chain deployment where addresses differ per chain
Detection patterns
Floating pragma (LOW-MEDIUM)
pragma solidity ^0.8.0; // ← floats to any 0.8.x
Production deployments should pin: pragma solidity 0.8.24;. Floating pragma means audited bytecode ≠ deployed bytecode.
Outdated Solidity version (MEDIUM)
<0.8.0 lacks built-in overflow checks. <0.8.20 lacks PUSH0 opcode handling for some L2s. Audit pin date vs known compiler bugs.
Hardcoded address tied to a single chain (HIGH)
address constant WETH = 0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2; // ← mainnet WETH, breaks on Base/Arbitrum
WETH/USDC/USDT all have different addresses per chain. Use a chain-configurable resolver.
Missing zero-address check (HIGH on key fields)
function setOwner(address newOwner) external onlyOwner {
owner = newOwner; // ← if 0x0, contract is bricked
}
Affects ownership, oracles, treasury, fee receiver, token addresses.
Address(0) as default sentinel (MEDIUM)
Using address(0) to mean "unset" works but is brittle — collides with default mapping values.
payable(0) as burn (LOW-MEDIUM)
Burning by sending to address(0)'s payable is legal but locks ether forever. Document intent.
address(this) in cross-chain context (HIGH for CREATE2 deployments)
address(this) differs unless deterministically deployed at same address across chains.
address public foo; instead of address public immutable foo; (LOW)
Mutable when it shouldn't be — gas cost + risk of accidental setter.
Chain-ID-dependent address resolution missing (HIGH)
if (block.chainid == 1) router = MAINNET_ROUTER;
else if (block.chainid == 42161) router = ARB_ROUTER;
else revert("unsupported chain"); // ← without this, unsupported chain silently uses mainnet address
Severity rubric
| Pattern | Severity | |---|---| | Hardcoded mainnet address in multi-chain deployment | High | | Missing zero-address check on owner/admin set | High | | Chain-ID-based resolver missing for cross-chain | High | | Outdated Solidity version with known CVE | High | | Floating pragma (^0.8.0) in production | Medium | | Mutable address that should be immutable | Low | | Outdated but CVE-free Solidity version | Low | | Comment-only address documentation outdated | Info |
Remediation patterns
- Pin exact Solidity version:
pragma solidity 0.8.24;(or whatever you tested with). - Zero-address checks on every setter:
require(newAddr != address(0), "zero address");. - Chain-aware address resolver:
``solidity function _weth() internal view returns (address) { if (block.chainid == 1) return MAINNET_WETH; if (block.chainid == 8453) return BASE_WETH; if (block.chainid == 42161) return ARB_WETH; revert UnsupportedChain(); } ``
- Use OZ
Ownable2Stepso even a bad zero-address would require accept(). - For immutable-when-possible, mark with
immutablekeyword.
False-positive notes
- Test/mock files with hardcoded addresses are fine.
address(0)checks may be redundant if subsequent OZ library calls already validate.- Floating pragma in libraries (vs deployed contracts) is sometimes intentional.
Related
- [[access-control]]
- [[storage-layout]]
- [[upgrade-safety]]
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: omermaksutii
- Source: omermaksutii/RugProof
- License: MIT
- Homepage: https://omermaksutii.github.io/RugProof
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.