forefy

652 posts

forefy banner
forefy

forefy

@forefy

Over a decade of security research and engineering channeled into securing web3 ㅤ CTO @audit_wizard 🧙‍♂️🪄🪄 ㅤㅤㅤㅤㅤㅤㅤ Co-Founder @hackstackapp

Katılım Aralık 2021
191 Takip Edilen398 Takipçiler
Sabitlenmiş Tweet
forefy
forefy@forefy·
Being the 1st public auditing skills author I can share this: •⁠ ⁠AI can't write skills as well as actual auditors •⁠ ⁠Over-verbose skills (e.g more than 5000 tokens a page) are creating context rot •⁠ ⁠Installing other people's skills is much scarier than npm install I solved this by utilizing my profile site to host the Auditor Skills Registry •⁠ ⁠Skills I personally use (including skills from @pashov , @trailofbits , @QuillAudits_AI , @auditmos myself etc.) •⁠ ⁠Security reviewed, guardrails, AI reliance rating •⁠ ⁠Easy and secure 1-click installation to claude code / copilot cli / gemini cli / codex IMPORTANT: Like or repost if you plan on using it, to let me know if I should keep it live: forefy.com/skills
forefy tweet media
English
5
9
74
6.3K
forefy
forefy@forefy·
@MartinMarchev Thanks the mention 🤍 You may also add Auditor Skills Registry! x.com/forefy/status/…
forefy@forefy

Being the 1st public auditing skills author I can share this: •⁠ ⁠AI can't write skills as well as actual auditors •⁠ ⁠Over-verbose skills (e.g more than 5000 tokens a page) are creating context rot •⁠ ⁠Installing other people's skills is much scarier than npm install I solved this by utilizing my profile site to host the Auditor Skills Registry •⁠ ⁠Skills I personally use (including skills from @pashov , @trailofbits , @QuillAudits_AI , @auditmos myself etc.) •⁠ ⁠Security reviewed, guardrails, AI reliance rating •⁠ ⁠Easy and secure 1-click installation to claude code / copilot cli / gemini cli / codex IMPORTANT: Like or repost if you plan on using it, to let me know if I should keep it live: forefy.com/skills

English
1
0
3
141
Martin Marchev
Martin Marchev@MartinMarchev·
There is no single place that lists all AI tools for web3 security. So I made one. 50 tools. AI auditors, agent toolkits, AI-powered on-chain monitoring, benchmarks, datasets. Every link verified by hand. It's all yours now. 👇
Martin Marchev tweet media
English
4
4
71
1.6K
forefy
forefy@forefy·
@theSouilos All are right there 😎x.com/forefy/status/…
forefy@forefy

🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT > end-to-end without an IDE > from skills and prompts to a google doc report > result report and repo below ▶️ youtube.com/watch?v=5jcZ85… I didn't risk my auditing career posting this just to have fun with prompts. This is a social demonstration of the power that's at hand of the new version of our adversaries. I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always Skills I've used can all be found at the Auditor Skill Registry: ✨ forefy.com/skills Skills used (other than the ones under github.com/forefy/.context): - solidity-auditor by @pashov github.com/pashov/skills - security-auditor by @archethect github.com/Archethect/sc-… - hackenproof-triage-marketplace by @HackenProof github.com/hackenproof-pu… - web3-poc-foundry by @shuvonsec github.com/shuvonsec/web3… - code-sleuth by @ZeroCool_AI github.com/zerocoolailabs… Repo and Report: github.com/forefy/vulnvau… Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment ▶️ youtube.com/watch?v=5jcZ85… Please repost, comment, share and raise awareness for what's coming!

English
0
0
2
25
souilos
souilos@theSouilos·
What are your favorite AI agents for auditing, in Web2 or Web3?
English
1
0
1
104
forefy
forefy@forefy·
I updated the video description to match skill usage to author with github/x links, hoping I didn't make mistakes or forgot anyone!
forefy tweet media
English
0
0
1
65
forefy
forefy@forefy·
🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT > end-to-end without an IDE > from skills and prompts to a google doc report > result report and repo below ▶️ youtube.com/watch?v=5jcZ85… I didn't risk my auditing career posting this just to have fun with prompts. This is a social demonstration of the power that's at hand of the new version of our adversaries. I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always Skills I've used can all be found at the Auditor Skill Registry: ✨ forefy.com/skills Skills used (other than the ones under github.com/forefy/.context): - solidity-auditor by @pashov github.com/pashov/skills - security-auditor by @archethect github.com/Archethect/sc-… - hackenproof-triage-marketplace by @HackenProof github.com/hackenproof-pu… - web3-poc-foundry by @shuvonsec github.com/shuvonsec/web3… - code-sleuth by @ZeroCool_AI github.com/zerocoolailabs… Repo and Report: github.com/forefy/vulnvau… Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment ▶️ youtube.com/watch?v=5jcZ85… Please repost, comment, share and raise awareness for what's coming!
YouTube video
YouTube
English
6
5
51
5K
forefy
forefy@forefy·
@AntithesisHQ @GergelyOrosz As a security auditor my work remains exactly the same time, but the work done is MUCH better x.com/forefy/status/…
forefy@forefy

🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT > end-to-end without an IDE > from skills and prompts to a google doc report > result report and repo below ▶️ youtube.com/watch?v=5jcZ85… I didn't risk my auditing career posting this just to have fun with prompts. This is a social demonstration of the power that's at hand of the new version of our adversaries. I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always Skills I've used can all be found at the Auditor Skill Registry: ✨ forefy.com/skills Skills used (other than the ones under github.com/forefy/.context): - solidity-auditor by @pashov github.com/pashov/skills - security-auditor by @archethect github.com/Archethect/sc-… - hackenproof-triage-marketplace by @HackenProof github.com/hackenproof-pu… - web3-poc-foundry by @shuvonsec github.com/shuvonsec/web3… - code-sleuth by @ZeroCool_AI github.com/zerocoolailabs… Repo and Report: github.com/forefy/vulnvau… Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment ▶️ youtube.com/watch?v=5jcZ85… Please repost, comment, share and raise awareness for what's coming!

English
0
0
0
7
Antithesis
Antithesis@AntithesisHQ·
We have some thoughts... how about continuous runtime validation against an external definition of correctness? @GergelyOrosz
Antithesis tweet media
English
4
1
10
492
Plamen Tsanev
Plamen Tsanev@p_tsanev·
Every AI auditor now does the same boring thing. So I went and fused the 4 security pillars into a singular pipeline: - Static analysis - RAG vulnerability search - Recursive depth analysis - Fuzzing and testing Fully autonomous 🤖 Fully open-source 🔓 Going live tomorrow 🚨
Plamen Tsanev tweet media
English
27
50
511
25.5K
Plamen Tsanev
Plamen Tsanev@p_tsanev·
🚀Dear builders and auditors, your Claude Code sub just became a 100x audit team. Up to 95 specialized AI security agents running in one orchestrated autonomous pipeline. Fully open-source. "Plamen" is live 🔥🐉
Plamen Tsanev tweet media
English
41
32
321
52.9K
Kann Audits
Kann Audits@KannAudits·
🚨 Solidity Developers & Security Researchers: Our open-source AI Solidity Security Auditor is live. You can now install and use it completely for free to catch critical vulnerabilities in smart contracts fully autonomous. Link below 👇
English
5
7
80
4.1K
forefy
forefy@forefy·
Currently I use: ⚙️ 3 native macos terminal tabs, each one with its own tmux session 🖥️ where each tmux session nicely holds 4 split windows but can also do 6 and even 8 with mouse mode 📲 notifications come from the macos terminal app But I've looked in your profile and you seem to do it better? I was looking for something like that! how does one get started with 49 agents?
English
0
0
1
7
49 Agents - Agentic Coding IDE
@forefy thats 9-12 concurrent agent sessions. how are you tracking which one is stuck vs which one is actually working? i ran into this exact setup and found myself tab-hopping constantly to check status. the layout gets unmanageable past a certain point
49 Agents - Agentic Coding IDE tweet media
English
1
0
1
10
forefy
forefy@forefy·
@0xZulkifilu Some devs are under the assumption that claude code giving you crits is enough to match the truth Meanwhile me advancing in day 1/10 of the audit before the first coffee: x.com/forefy/status/…
forefy@forefy

🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT > end-to-end without an IDE > from skills and prompts to a google doc report > result report and repo below ▶️ youtube.com/watch?v=5jcZ85… I didn't risk my auditing career posting this just to have fun with prompts. This is a social demonstration of the power that's at hand of the new version of our adversaries. I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always Skills I've used can all be found at the Auditor Skill Registry: ✨ forefy.com/skills Skills used (other than the ones under github.com/forefy/.context): - solidity-auditor by @pashov github.com/pashov/skills - security-auditor by @archethect github.com/Archethect/sc-… - hackenproof-triage-marketplace by @HackenProof github.com/hackenproof-pu… - web3-poc-foundry by @shuvonsec github.com/shuvonsec/web3… - code-sleuth by @ZeroCool_AI github.com/zerocoolailabs… Repo and Report: github.com/forefy/vulnvau… Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment ▶️ youtube.com/watch?v=5jcZ85… Please repost, comment, share and raise awareness for what's coming!

English
0
0
0
53
0xZulkifilu 💎🥷
0xZulkifilu 💎🥷@0xZulkifilu·
Developers that fully rely on AI audit is enough:
English
4
7
20
1.5K
forefy
forefy@forefy·
@BlockSecTeam @OpenAI I agree with the controversy and I'm not sure these benchmarks even make sense but still x.com/forefy/status/…
forefy@forefy

🚨🚨 WATCH ME VIBE-AUDIT A SMART CONTRACT > end-to-end without an IDE > from skills and prompts to a google doc report > result report and repo below ▶️ youtube.com/watch?v=5jcZ85… I didn't risk my auditing career posting this just to have fun with prompts. This is a social demonstration of the power that's at hand of the new version of our adversaries. I literally just sat down and showed you a summarized way of my first 15 minutes starting an audit (before the first coffee ends) - it's obviously not enough for a professional audit, not even close, it's a really good starting point though (still have an entire week after that in industry timelines). I want you all to start interacting with code like this, exploring it through the agents, asking questions, creating creative skills and gain more and more ways of asking the right questions and improve and learn always Skills I've used can all be found at the Auditor Skill Registry: ✨ forefy.com/skills Skills used (other than the ones under github.com/forefy/.context): - solidity-auditor by @pashov github.com/pashov/skills - security-auditor by @archethect github.com/Archethect/sc-… - hackenproof-triage-marketplace by @HackenProof github.com/hackenproof-pu… - web3-poc-foundry by @shuvonsec github.com/shuvonsec/web3… - code-sleuth by @ZeroCool_AI github.com/zerocoolailabs… Repo and Report: github.com/forefy/vulnvau… Would've used much more, but wanted to make this fit under a 15 minutes video and improvised what came to mind at the moment ▶️ youtube.com/watch?v=5jcZ85… Please repost, comment, share and raise awareness for what's coming!

English
0
0
1
39
Trident
Trident@TridentSolana·
A Claude Code skill for Trident fuzzing built by @4lifemen. Five phases that walk you from account mapping to coverage analysis, using Trident's invariant-driven stateful approach. The skill gets the hard part right. Building a valid protocol state is where most fuzz campaigns succeed or fail. Phase 1 alone covers 60% of the work. Trident is the first and only fuzzer for Solana programs. Manually-guided fuzzing with flow-based sequences and property-based testing, processing thousands of transactions per second. This skill makes it easier to get started with Claude Code. Community contributions like this are what grow the ecosystem. Solid work. GitHub repo link below ↓
Trident tweet media
English
5
3
17
814
Wils
Wils@zkWils·
@forefy This is fire 🔥 AI will be a pro tool for those who know how to put it to use or the bane of those who can't really
English
1
0
1
72
forefy
forefy@forefy·
@pashov Top benchmarked skill 🔥 lfg
English
1
0
4
95
pashov
pashov@pashov·
@forefy "of course `solidity-auditor` by pashov, obviously" hahaha Good good video, people are starting to use these tools like... A LOT
English
1
0
9
379
forefy
forefy@forefy·
@0xandreitoma Interesting take! I wouldn't want an orchestrator skill because being the orchestrator is the 1 most important job Also, would not want to get numbed out, I still want to understand and interact with every single functionality in the codebase myself
English
0
0
2
77
Andrei Toma
Andrei Toma@0xandreitoma·
@forefy "it's a really good starting point though" usually I like to have my AI scans at the end to avoid being biased by the AI, or at least after I've got a solid grasp of the protocol I'm auditing. What do you think about an orchestrator skill that runs all these skills?
English
1
0
1
89