All skills

Review DeFi automated market maker (AMM) smart contracts for flash loan attacks, bad slippage checks, sandwich attacks, price changes, reentry, unsafe token calls, access flaws, and math errors. Use for swaps, liquidity adds, liquidity removes, minting, burning, fees, and pool price logic.

  • 1 file
  • 5.4 KB
  • Updated 3 weeks ago
  • GitHub

Use this Skill: https://skilld.dev/gh/agenticluke/amm-security-audit-plus/skill

This session only. Nothing lands on disk.

SKILL.md

≈74 tokens always: the name and description. ≈1.3k when used: this file.

DeFi AMM Security

Credit

This skill comes from ECC. Credit ECC clearly when you share or reuse it.

Use This Skill

Use this skill to:

  • Review AMMs such as Uniswap, Curve, and Balancer.
  • Check swap, mint, burn, fee, and liquidity code.
  • Find flash loan and price change risks.
  • Test the safety of DeFi pool rules.

Review Steps

  1. List all public and external functions.
  2. Mark each function that moves tokens or changes pool funds.
  3. Trace all price, reserve, fee, and share math.
  4. Check every call to another contract.
  5. Test each risk in the checklist below.
  6. Report the code path, attack steps, impact, and fix.
  7. Do not call code safe when key files or facts are missing.

Main Risks

Flash Loans and Price Changes

Assume an attacker can borrow a large amount for one transaction.

Check if the contract:

  • Uses the current pool price as a trusted price.
  • Reads reserves after an attacker can change them.
  • Lets one transaction change a price, then use that price for a loan, mint, burn, or reward.
  • Uses a weak or stale price feed.

Use a trusted price feed when an outside price is needed. Check that it is fresh. Do not assume every price must come from a price feed. AMMs need pool math for swaps.

Slippage and Sandwich Attacks

Each user trade should set:

  • A minimum amount out, or a maximum amount in.
  • A deadline.
  • The right receiver.

Reject zero or unsafe limits unless the action is meant to allow them. Check whether a bot can trade before and after the user to cause a bad price.

Reentry

Use checks, state changes, then outside calls.

Check calls to:

  • Tokens.
  • Hooks.
  • Routers.
  • Flash loan users.
  • Fee receivers.
  • Native coin receivers.

A lock can help, but it does not fix bad state order. Also check reentry between two different functions.

Math and Rounding

Check:

  • Multiply before divide when safe.
  • Rounding direction helps the pool, not the caller.
  • Zero values and empty pools.
  • Very small and very large values.
  • Token decimals.
  • Fee math.
  • Share mint and burn math.
  • Overflow and underflow in unchecked blocks.
  • Loss of funds from repeated rounding.

For the first liquidity add, check share rules and locked shares. Test for share price gifts and low-cost pool takeover.

Token Edge Cases

Do not assume every token acts like a basic ERC-20 token.

Test tokens that:

  • Take a transfer fee.
  • Change balances over time.
  • Return no value.
  • Run hooks during transfer.
  • Block some users.
  • Have 6, 8, 18, or unusual decimals.

Use real balance changes when the contract must know how many tokens arrived.

Pool Rules and Access

Check that:

  • Swaps keep the pool rule after fees.
  • Mint and burn use the right reserves.
  • Fees cannot be set above safe limits.
  • Admin roles are small and clear.
  • Setup functions can run only once.
  • Pause and rescue functions cannot steal user funds.
  • Upgrades cannot skip access checks or break storage.
  • Users cannot send funds to the zero address by mistake.

Security Checklist

  • User slippage limits are required and checked.
  • Deadlines are required and checked.
  • Sandwich attack impact is limited.
  • Flash loan price changes do not create profit.
  • Trusted price feeds are fresh and use the right units.
  • Pool spot prices are not trusted for loans or account value.
  • State changes happen before outside calls.
  • Reentry between functions is blocked.
  • Swap, mint, burn, fee, and share math is tested.
  • Rounding does not leak value.
  • Empty pool and first deposit cases are safe.
  • Token decimal and transfer edge cases are handled.
  • Pool balances match saved reserves.
  • Admin and upgrade rights are limited.
  • Emergency actions cannot take user funds.
  • Tests cover zero, small, large, and repeated actions.

Concrete Example

For this function:

function swap(uint256 amountIn) external {
    tokenIn.transferFrom(msg.sender, address(this), amountIn);
    uint256 amountOut = quote(amountIn);
    tokenOut.transfer(msg.sender, amountOut);
    updateReserves();
}

Flag these issues:

  1. The user cannot set minAmountOut.
  2. There is no deadline.
  3. quote may use a price changed in the same transaction.
  4. Token calls happen before reserves are saved.
  5. A transfer-fee token may send less than amountIn.
  6. A token hook may reenter the contract.

A safer form should check the real amount received, apply fees, check the pool rule, require amountOut >= minAmountOut, update state before the last outside call, and use a reentry guard where needed.

Finding Format

For each issue, give:

  • Title: A short risk name.
  • Severity: Critical, high, medium, low, or note.
  • Code: The file, function, and line.
  • Cause: The exact unsafe rule.
  • Attack: Clear steps an attacker can take.
  • Impact: What funds or rights can be lost.
  • Fix: A small and direct code change.
  • Test: One test that fails before the fix and passes after it.

State any missing facts. Do not claim an attack works unless the code path and profit or harm are clear.

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 277a9f2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 weeks ago.

Activeupdated 3 weeks ago
origin
ECC

README badge

README badge for agenticluke/amm-security-audit-plus