Raze — Security skill for Claude Code
MCP-first security orchestrator for Solidity smart contracts.
How to install Raze
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open xhulz/raze and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Raze does
MCP-first security orchestrator for Solidity smart contracts. Validates AI attack hypotheses, generates Foundry proof scaffolds, catches bugs before auditors do.
Alternatives in Security
- Octoboss Clean Contexts — You are the Octoboss — a cross-tentacle orchestrator 1.4k ★
- /web3 Audit — Smart contract security audit using the 10-bug-class methodology 927 ★
- Query Token Audit — Audit token security to detect scams, honeypots, and malicious contracts across BSC, Base, Solana, and Ethereu 483 ★
README
raze
Raze is an open-source, AI-orchestrated smart contract security tool for Foundry projects.
It is built for developers who want to explore, validate, and prove smart contract security issues with their existing AI, without giving up deterministic execution.
Raze does not ship its own LLM. Instead, it works with your existing AI through MCP and gives that AI a deterministic execution layer for:
- project inspection
- attack validation
- deterministic proof scaffolding
- Foundry execution
- developer fuzz generation
- structured reporting
The external AI can then:
- analyze a contract
- propose attack hypotheses
- choose proof goals
- call Raze tools to validate and execute those ideas
Raze helps turn smart contract security reasoning into validated, executable proof, and it is being built in the open from day one.
No API key is required. No Docker is used.

Prerequisites
Install
**Use in your Foundry project:**
npm install raze-security
npx raze init
**Contributing to Raze itself:**
git clone https://github.com/xhulz/raze.git
cd raze
npm install
npm run build
Internal Development System
This repository also contains an internal `.ia/` directory used to help Codex, Cursor, and Claude build Raze consistently.
- it is local and file-based
- it is not part of the product runtime
- it defines routing, retrieval, memory, and specialized agent instructions for development work
- it is separate from the runtime context that
raze initgenerates for user projects
How it works
┌─────────────────────────────────────────────────────────┐
│ YOUR AI ASSISTANT │
│ (Cursor, C
Related Skills
POC Or It Didnt Happen Web3
A Web3-only security thinking framework that supercharges any coding agent (Claude Code / Codex / opencode / D
Solidity Security
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity
Smart Contract Security Review
Run security review on Scalus smart contracts at specified path
Exploit Chain
Chain multiple findings into a single multi-step exploit. Produces a Foundry test that proves the chain works.
Ctxinit
Claude Code skill that scaffolds a single-source context/ knowledge hub — engineering rules, security law, com
POC
Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain,
Related Agents
Blockchain Specialist
Smart contract and Web3 expert. Use PROACTIVELY for Solidity development, Hardhat/Foundry testing, Wagmi integ
Evaluator Evm Agent
EVM smart-contract vulnerability evaluator — spawned per smart_contract surface, scaffolds and runs Foundry te
Delforge Solidity Engineer
Use for Solidity smart contract development tasks — designing, implementing, testing, analyzing, documenting,