secure-workflow-guide

Automate a 5-step security review workflow for Solidity smart contracts.

6.5k|561|Updated Jan 14, 2026
One-click install
npx skills add https://github.com/trailofbits/skills --skill secure-workflow-guide-trailofbits
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secure-workflow-guide
Source: https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/secure-workflow-guide
Command: npx skills add https://github.com/trailofbits/skills --skill secure-workflow-guide-trailofbits

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Guides teams through Trail of Bits' 5-step secure development workflow for smart contracts, providing a repeatable security review process that reduces oversight and accelerates audits.

Core Features & Use Cases

  • 5-step workflow execution: Slither scans, upgradeability/ERC conformance/token integration checks, visual security diagrams, security properties documentation, and manual review areas.
  • Artifact generation & guidance: produces diagrams, property definitions, and a prioritized action plan for fixes.
  • Use cases: pre-deployment audits, post-check-in reviews, and periodic security reviews of Solidity projects.

Quick Start

Run this skill on your Solidity project to begin a 5-step secure development workflow.

Frequently Asked Questions about secure-workflow-guide

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a smart contract security audit workflow for Solidity projects?

Automate a smart contract security audit by running a 5-step workflow that executes Slither scans, checks upgradeability and ERC conformance, generates visual security diagrams, documents security properties, and guides manual risk reviews.

What is included in a structured pre-deployment security review for smart contracts?

A structured pre-deployment security review includes Slither scanning, upgradeability and ERC conformance checks, visual security diagrams, security property documentation, and a prioritized action plan for manual risk areas.

How do I document security properties and generate visual diagrams for smart contract audits?

Document security properties and generate visual diagrams by executing the workflow steps that produce visual security diagrams, define property documentation plans, and output a prioritized action plan for fixes.

Can I use this workflow for post-check-in reviews and periodic security audits of Solidity projects?

Yes, the secure workflow applies to post-check-in reviews, pre-deployment audits, and periodic security reviews of Solidity projects, providing a repeatable process to reduce oversight and accelerate audits.

Does the secure workflow guide integrate with Slither for token integration and conformance checks?

Yes, the secure workflow integrates with Slither to execute scanning, upgradeability checks, ERC conformance verification, and token integration checks as part of its structured 5-step review process.

What's the best way to streamline secure smart-contract reviews before deployment?

Streamline secure smart-contract reviews by following Trail of Bits' 5-step secure development workflow, which automates Slither scans, conformance checks, diagram generation, and manual review area guidance to accelerate audits.