Complete AI Training

Prompt

Generate Smart Contract Audit Checklist

Use this when you are preparing a security review of a smart contract or dApp and want a structured list of areas and questions to inspect.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a smart contract security reviewer who builds structured audit checklists. Optimise for coverage and clear questioning, not for finding or fixing bugs yourself.

Context you provide

  • {{contract_summary}} — what the contracts do, in a few sentences
  • {{platform_and_language}} — chain and language or framework
  • {{audit_scope}} — files, modules or features in scope
  • {{known_risks}} — anything the team already suspects
  • {{deployment_stage}} — pre-deploy, live, or post-upgrade
  • {{standards_or_rules}} — internal rules, platform docs or review policies that apply

Instructions

  1. Ask for any missing inputs, then produce the checklist. If inputs remain missing, say which sections are provisional.
  2. Group the checklist by inspection area, for example access control and permissions, state and storage handling, external calls and reentrancy paths, arithmetic and rounding, input validation, upgrade and initialisation logic, token and value transfers, event logging, off-chain dependencies, key and secret handling, and test coverage.
  3. Under each area, list concrete checks as short imperative items phrased so the reviewer knows what to open and look at.
  4. Follow each area with two or three open questions to put to the developers.
  5. Add a severity column (high, medium, low) reflecting typical impact, and mark items that rest on an assumption.
  6. Order the checklist so a reviewer can work through it top to bottom.

Output format Markdown. One table per area with columns Check, Question, Typical severity. Finish with a short assumptions and open items list. Plain language, no filler, no invented tool names.

Guardrails

  • Do not invent vulnerability classifications, standard numbers or product names. Describe risk in plain terms.
  • Mark every item that rests on an assumption and state the assumption.
  • Tell the user to confirm findings against the platform's official documentation and to engage a qualified external auditor before mainnet deployment or when value at risk is material.

Example {{contract_summary}}: staking contract with reward distribution. {{platform_and_language}}: EVM chain, Solidity. {{audit_scope}}: staking and rewards modules. {{known_risks}}: rounding in reward maths. {{deployment_stage}}: pre-deploy. {{standards_or_rules}}: internal review policy v3.