pashov/skills: The Multi-Agent Mind Split for Smart Contract Security

How a collection of Markdown files forces LLMs to adopt eight distinct attacker personas and an adversarial judge to find deep Solidity vulnerabilities.

8 min read • View on GitHub • More from pashov

A massive crystalline monolith surrounded by eight shadow figures in vintage gear, each examining a different facet of the crystal. This represents the eight distinct attacker personas analyzing a single smart contract.
Instead of a single massive prompt, pashov/skills splits the AI's attention into eight specialized attacker personas.
Key Takeaways

The Hallucination Problem in Web3 Security

General-purpose AI agents are notoriously bad at auditing smart contracts. Ask an LLM to "audit this codebase" and it will inevitably return 2021-era reentrancy warnings and obsess over superficial gas optimizations. It will miss the deeply buried logic flaws that actually drain protocols.

Vibe coding fails in high-stakes environments. A generic agent lacks structured, domain-specific intent. To find zero-days, an auditor needs to simulate economic attacks, verify math precision, and question first-principle assumptions. A single prompt cannot maintain that level of cognitive load without hallucinating false positives.

Orchestrating the Eight-Headed Attacker

The core of pashov/skills is not a Python framework. It is a prompt orchestrator that hacks the agent's context window using standard shell commands. The repository defines a strict 4-turn protocol in its primary SKILL.md file.

The magic happens in Turn 3. The orchestrator instructs the LLM to spawn eight parallel foreground agents. These include an Economic Security agent that assumes unlimited capital, a Math Precision agent hunting for rounding errors, and a First Principles agent instructed to ignore known patterns entirely. This forces the LLM out of its generic helpful persona and into highly specialized adversarial roles.

The 4-Turn Orchestration Protocol defined in SKILL.md.

The Adversarial Judge

Generating eight streams of parallel attacks produces noise. The system solves this in Turn 4 with a ruthless deduplication and refutation phase defined in judging.md.

This phase acts as a quality filter. It forces the AI into an internal monologue to refute its own findings. If the AI cannot prove that a vulnerable state is reachable in a live deployment, the finding is silently killed. The system essentially weaponizes the LLM's reasoning capabilities against its own prior outputs.

Context Injection over Static Rules

Traditional static analysis tools like Slither rely on hardcoded Abstract Syntax Tree rules. They take months to update when a new protocol standard emerges. pashov/skills replaces static rules with dynamic, living reference files.

Files like attack-vectors.md inject cutting-edge zero-day knowledge, such as EIP-7702 delegation vulnerabilities or LayerZero spoofing, directly into the context window just in time. This makes the AI an adaptable, protocol-aware reasoning engine rather than a rigid sorting machine.

FeatureTraditional Static Analysis (Slither)AI Agent Skills (pashov/skills)
Detection MethodHardcoded AST rulesPrompt-driven economic reasoning
AdaptabilityRequires core engine updatesUpdating a Markdown file
False PositivesHigh, requires manual triageLow, filtered by AI Judge
Logic FlawsBlind to protocol-specific economicsCapable of economic/math simulation

The Zero-Dependency Distribution Model

The developer experience is intentionally frictionless. There is no Docker container or Python package to install. It leverages the open SKILL.md standard, allowing agents to fetch and execute the logic using native curl and bash commands directly inside the user's terminal.

By distributing specialized team knowledge as modular Markdown files, pashov/skills turns any standard AI coding assistant into an expert-level security auditor in under five minutes.

Hedcut portrait of pashov, founder of Pashov Audit Group.