Skip to main content

ChatGPT/Claude Prompt for a Smart Contract Security Audit

Run a systematic Solidity security review covering reentrancy, access control, arithmetic, oracle manipulation, DoS, and front-running.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
Perform a security audit of a DeFi lending pool with liquidation mechanism Solidity smart contract. The contract handles $10M+ in value, has been deployed on testnet, preparing for mainnet launch, and uses OpenZeppelin 4.9, Chainlink Oracles, Uniswap V3 interfaces. Audit: 1) Reentrancy analysis: check all external calls in withdraw(), liquidate(), claimRewards(), flashLoan() — verify checks-effects-interactions pattern, identify cross-function reentrancy risks where state is shared between deposit and borrow share user balance mapping, and confirm ReentrancyGuard on vulnerable functions. 2) Access control review: map all privileged functions to their access modifiers, identify owner can pause, change interest rates, upgrade contract, and set oracle address centralization risks (can owner drain funds?), check for missing access controls on setOracle, setLiquidationThreshold, emergencyWithdraw, and verify role hierarchy cannot be escalated. 3) Integer and arithmetic: verify no unsafe casting between uint256 to uint128 for balance packing, int256 to uint256 for oracle prices, check for division-before-multiplication precision loss in interest accrual calculation, collateral ratio computation, liquidation bonus, and confirm unchecked blocks are truly safe. 4) Oracle and price manipulation: analyze Chainlink price feed for collateral valuation, spot price for liquidation trigger for flash loan vulnerability — can an attacker manipulate the price within a single transaction? Check TWAP window length and multi-source validation. 5) DoS vectors: identify iterating over all depositors in liquidation, unbounded reward distribution loop — unbounded loops, block gas limit risks in batch operations, griefing attacks via revert in callbacks. 6) Front-running: identify liquidation calls, large swaps within the protocol, oracle price updates susceptible to sandwich attacks or MEV extraction, and recommend commit-reveal for liquidations, slippage protection, MEV-resistant design. 7) Produce a findings report with severity (Critical/High/Medium/Low/Informational), description, proof of concept, and recommended fix for each issue.

What this prompt does

This prompt runs a structured Solidity security audit so nothing gets hand-waved before a contract holds real value. You describe the [contract_type], the [value_at_risk], its [deployment_status], and its [dependencies], and it works through seven categories: reentrancy in [external_call_functions], access control and [centralization_risks], arithmetic and casting between [cast_types], oracle manipulation in [oracle_usage], DoS vectors, front-running, and a severity-tagged findings report.

The structure works because the failures that actually drain funds are predictable. Reentrancy, missing access control, and oracle manipulation recur in nearly every major exploit, so the prompt forces each onto the table with specific targets — checks-effects-interactions in [shared_state_functions], missing guards on [sensitive_functions], flash-loan vulnerability in [oracle_usage], unbounded loops in [dos_risks], and sandwich exposure in [frontrun_targets] — and demands a proof of concept and recommended fix for each issue. Naming the [value_at_risk], [deployment_status], and [dependencies] up front also calibrates how paranoid the review should be, since a testnet contract preparing for a large mainnet launch deserves the harshest scrutiny.

When to use it

  • You are reviewing a contract before it goes near mainnet
  • You want a structured audit instead of ad-hoc "looks fine" reading
  • You need reentrancy checked against specific [external_call_functions]
  • You want [centralization_risks] surfaced — can the owner drain funds?
  • You need oracle manipulation in [oracle_usage] analyzed for flash-loan exposure
  • You want arithmetic and casting between [cast_types] checked for silent truncation
  • You want a severity-tagged findings report you can act on and track

Example output

Expect a findings report organized by the seven audit categories: a reentrancy section examining [external_call_functions] and [shared_state_functions], an access-control map of privileged functions with [centralization_risks] flagged, an arithmetic section checking [cast_types] and precision in [math_functions], an oracle section analyzing [oracle_usage] for manipulation, a DoS section covering [dos_risks], a front-running section on [frontrun_targets] with [frontrun_mitigations], and a consolidated table where each issue has a severity (Critical/High/Medium/Low/Informational), description, proof of concept, and fix. The report is structured so you can triage by severity and track each finding to resolution rather than wading through prose.

Pro tips

  • Treat this as one layer, not a replacement for a professional human audit when [value_at_risk] is high
  • Make [external_call_functions] and [shared_state_functions] precise so reentrancy analysis targets real call sites, not generic warnings
  • Be honest about [centralization_risks] — an owner who can change the oracle or drain funds is often the biggest real risk
  • Specify [oracle_usage] exactly, including whether you use spot price anywhere, since spot price in liquidation logic is a classic flash-loan vector
  • Call out unsafe [cast_types] like uint256-to-uint128 for packing, since silent truncation there can corrupt balances
  • List concrete [dos_risks] like unbounded loops over depositors so the audit checks gas-limit failure modes
  • Demand the proof-of-concept for each finding; a severity label without a PoC is hard to prioritize or verify

Frequently Asked Questions

Can this replace a professional audit firm?
No. It is a structured first-pass review that catches common, well-understood vulnerability classes. For a contract with significant `[value_at_risk]`, you should still commission a professional human audit; treat this as preparation that surfaces issues early and makes the paid audit more efficient.
What vulnerability classes does it cover?
Reentrancy, access control and centralization, integer and casting issues, oracle and price manipulation, DoS vectors, and front-running. Each is checked against the specific functions you name, such as `[external_call_functions]` and `[sensitive_functions]`, then compiled into a severity-tagged report.
Does it produce proof-of-concept exploits?
It includes a proof-of-concept description for each finding alongside severity and a recommended fix. These are conceptual demonstrations to validate the issue; you should reproduce them in a test harness before treating any finding as confirmed.
How does it assess oracle manipulation risk?
It analyzes `[oracle_usage]` for flash-loan vulnerability, asking whether an attacker can move the price within a single transaction. It checks TWAP window length and whether multiple sources are validated, since reliance on spot price is the usual root cause of oracle exploits.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Blockchain & Web3 Development Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support