DeFi AMM Security Checklist
Audit Solidity AMMs with Muse: reentrancy and CEI ordering, donation/inflation attacks, TWAP oracles, slippage guards, safe reserve math, and admin controls.
- What
- Audit Solidity AMMs with Muse: reentrancy and CEI ordering, donation/inflation attacks, TWAP oracles, slippage guards, safe reserve math, and admin controls.
- Cost
- Free
- Needs
- Use "DeFi AMM Security Checklist" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a security checklist plus hardened patterns for Solidity AMM contracts, liquidity pools, and swap flows. It walks through the classic failure modes with vulnerable-versus-safe code: reentrancy fixed by checks-effects-interactions ordering plus ReentrancyGuard and SafeERC20 instead of hand-rolled guards; donation or inflation attacks fixed by tracking internal _totalAssets and measuring actual tokens received instead of trusting balanceOf(address(this)); oracle manipulation fixed by reading TWAP instead of flash-loan-manipulable spot prices; missing slippage protection fixed by requiring caller-provided amountOutMin and deadline on every swap; overflow-prone reserve math fixed with FullMath.mulDiv; and admin functions gated behind Ownable2Step with an emergency pause that is actually tested. A closing checklist turns it into a review pass, with slither, echidna, and forge fuzzing as the recommended tooling. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: a checklist is not a professional audit, get one before mainnet; never paste private keys, seed phrases or mainnet signing credentials into a chat while using it; ask before running long fuzzing jobs that consume significant local or paid resources. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "DeFi AMM Security Checklist" with your Muse. Prerequisites: none to install. Pure guidance; a Solidity AMM or liquidity pool contract helps. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/defi-amm-security/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Review this contract against the AMM security checklist: [paste the contract]." 3. Work through the findings entrypoint by entrypoint: reentrancy, share math, oracle reads, slippage, reserve math, admin controls. Tip: ask "which three findings would an attacker exploit first, and what is the hardened pattern for each?" Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste private keys, seed phrases or signing credentials into a chat. Review generated commands before running them.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.