Sabitlenmiş Tweet
Auditware
705 posts

Auditware
@audit_wizard
Industry leading OpSec audits, security tools, and code reviews performed by true security wizards
Katılım Ağustos 2022
507 Takip Edilen2.6K Takipçiler
Auditware retweetledi

🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT
> end-to-end without an IDE
> from skills and prompts to a google doc report
> result report and repo below
▶️ youtube.com/watch?v=5jcZ85…
I didn't risk my auditing career posting this just to have fun with prompts.
This is a social demonstration of the power that's at hand of the new version of our adversaries.
I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always
Skills I've used can all be found at the Auditor Skill Registry:
✨ forefy.com/skills
Skills used (other than the ones under github.com/forefy/.context):
- solidity-auditor by @pashov github.com/pashov/skills
- security-auditor by @archethect github.com/Archethect/sc-…
- hackenproof-triage-marketplace by @HackenProof
github.com/hackenproof-pu…
- web3-poc-foundry by @shuvonsec
github.com/shuvonsec/web3…
- code-sleuth by @ZeroCool_AI github.com/zerocoolailabs…
Repo and Report:
github.com/forefy/vulnvau…
Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment
▶️ youtube.com/watch?v=5jcZ85…
Please repost, comment, share and raise awareness for what's coming!

YouTube
English

Oracle manipulation exploits like this often succeed when liquidity checks are absent and price feeds lack deviation monitoring.
Common safeguards include liquidity thresholds, median aggregation across sources, and circuit breakers for anomalies.
quillaudits.com/blog/hack-anal…
English

A Meta security researcher ran an OpenClaw AI agent on her inbox with one rule: confirm before deleting anything.
The agent lost the instruction and started deleting emails until the process was stopped.
x.com/summeryue0/sta…
Summer Yue@summeryue0
Nothing humbles you like telling your OpenClaw “confirm before acting” and watching it speedrun deleting your inbox. I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.
English

Great discussion today featuring our CTO @forefy on the future of auditing.
QuillAudits@QuillAudits_AI
AI vs Hackers - The Future of Smart Contract Auditing x.com/i/broadcasts/1…
English

@audit_wizard auditing the contract is the easy part. auditing the key management, the deploymet pipeline, and the dependency tree is where most teams have zero coverage
English
Auditware retweetledi

🪐 Livestream tomorrow 📻🎙️
to share thoughts about the recent AI auditing changes
Hype is only usefull if the right people step up to channel it to practical secure and professional flows that will shape our future
Set an alarm ⏰ ⏰ and don't miss it!
QuillAudits@QuillAudits_AI
Hot take: AI might be the biggest thing to happen to smart contract security or it might be the most overhyped tool since static analyzers. We are finding it out tomorrow, joining us are @forefy, @d0rsky, @iampeersky and Siddharth! What - AI vs Hackers: The Future of Smart Contract Auditing Wen - 10th March | 3:30 PM UTC | LIVE on X
English
Auditware retweetledi

Being the 1st public auditing skills author I can share this:
• AI can't write skills as well as actual auditors
• Over-verbose skills (e.g more than 5000 tokens a page) are creating context rot
• Installing other people's skills is much scarier than npm install
I solved this by utilizing my profile site to host the Auditor Skills Registry
• Skills I personally use (including skills from @pashov , @trailofbits , @QuillAudits_AI , @auditmos myself etc.)
• Security reviewed, guardrails, AI reliance rating
• Easy and secure 1-click installation to claude code / copilot cli / gemini cli / codex
IMPORTANT: Like or repost if you plan on using it, to let me know if I should keep it live:
forefy.com/skills

English

Sentry and Multisigmonitor are built for this.
Free and open source:
auditware.io
English

Protect yourself:
* Lock your package dependencies to known-good versions
* Scan packages with Socket before installing
* Keep sensitive keys off dev machines entirely
Full technical breakdown: socket.dev/blog/sandworm-…
English

Radar is free and open source. Hunt for vulnerabilities at scale with shared detectors across Solidity and Rust contracts.
github.com/Auditware/radar
English

Test your organization's operational security with Sentry 👁️🗨️
Free and open to everyone: sentry.auditware.io
English

At an @EthereumDenver side event, an employee of a security firm left their laptop unlocked at a table for 10 minutes.
That's enough time to grab SSH keys, install malware, exfiltrate documents, etc
Anyone can fail at OpSec. Use things like screen locks so you stay secure.
English

