Back to Discover

zeus

skill

Wizbisy

Zeus: The premier AI Skill security auditor for the GenLayer ecosystem.

View on GitHub
0 starsApache-2.0Synced Aug 2, 2026

Install to Claude Code

/plugin marketplace add Wizbisy/zeus

README

Zeus Auditor

Agent Skills Claude Code Codex

Zeus is an AI-first security auditor specifically designed for GenLayer Intelligent Contracts. It runs a structured 4-phase audit pipeline to detect vulnerabilities unique to LLM integration, web connectivity, the Equivalence Principle, and the GenVM execution environment.

Executable discipline for AI coding agents - skills the agent loads on demand and applies while it works, not prose guides it ignores.

Install

npx skills - recommended for any Agent Skills host

Works with any compatible agent (Claude Code, Cursor, Copilot, Gemini CLI, OpenCode, Codex, and more). Each command is independent - run the one(s) you want:

npx skills add https://github.com/Wizbisy/zeus

Claude Code

/plugin marketplace add Wizbisy/zeus
/plugin install zeus@Wizbisy

Codex

codex plugin marketplace add Wizbisy/zeus

Then run codex, open /plugins, select zeus, and install it.

For other hosts, expand below.

Cursor
git clone https://github.com/Wizbisy/zeus.git
ln -s "$(pwd)/zeus/skills/zeus" ~/.cursor/skills/zeus

Cursor auto-discovers skills from .agents/skills/ and .cursor/skills/.

Copilot
git clone https://github.com/Wizbisy/zeus.git ~/.copilot/skills/zeus

Copilot auto-discovers skills from .copilot/skills/.

OpenCode
git clone https://github.com/Wizbisy/zeus.git ~/.agents/skills/zeus

OpenCode auto-discovers skills from .agents/skills/, .opencode/skills/, and .claude/skills/.

Antigravity / Antigravity IDE
git clone https://github.com/Wizbisy/zeus.git
ln -s "$(pwd)/zeus/skills/zeus" ~/.gemini/config/skills/zeus
Kiro (Powers)

Zeus is also available as a Kiro Power. In Kiro: Powers panel → "Add power from GitHub", then paste:

https://github.com/Wizbisy/zeus

What changes with the plugin

Routes GenLayer audits to a rigorous 4-phase methodology instead of blind text-based guessing. Ensures GenVM and Equivalence Principle specifics are respected.

tldr - what changes with the plugin:

PromptWithout the pluginWith the plugin
/zeusAgent blindly guesses security issues with standard Python toolsAgent runs a rigorous 4-phase GenLayer audit pipeline with 12 GenVM-specific heuristics and mandatory reviewer
/zeus-fuzzAgent struggles to write GenLayer-compatible testsAgent generates property-based fuzz tests mocking gl.nondet.*
/zeus-reviewAgent accepts false positivesAgent critically evaluates killed findings through 6 kill gates

Try:

  • /zeus
  • /zeus-quick
  • /zeus-fuzz
  • /zeus-review
  • /zeus-init

Features & Detection Lenses

  • GenLayer Native: Specifically built for Python contracts using the genlayer SDK (gl.Contract, gl.nondet.*, gl.eq_principle.*).
  • 4-Lens Detection: Analyzes contracts for:
    • Lens A (AI-01→03): Prompt Injection & LLM Output Safety
    • Lens B (WEB-01→02): Web Data & SSRF
    • Lens C (EQ-01→03): Equivalence Principle & Consensus Logic
    • Lens D (ST-01→03, MSG-01): State, Storage & Access Control
  • State Auditor: Tracks state mutations driven by non-deterministic outputs and verifies appropriate GenVM storage types (TreeMap, DynArray, u256).
  • Strict Verification (Critic): 6 kill gates automatically destroy false positives. Gate 2 requires demonstrable sanitization — response_format="json" alone does not kill injection findings. Gate 6 exempts AI-* and WEB-* categories from low-impact filtering.
  • Mandatory Reviewer: Every audit runs a devil's advocate phase on killed findings to catch over-filtering before the final report.
  • Property-Based Fuzzing: Auto-generates Python test scripts that mock non-deterministic LLM/web APIs with adversarial payloads to fuzz contract invariants.
  • Test Fixtures: Runnable .py contracts with .expected.md golden reports for reproducible audit verification (see tests/fixtures/).

Why this plugin

  • Honest by construction. Any findings killed by the 6 kill gates are reviewed by a mandatory devil's advocate phase. You can also re-run the review via /zeus-review.
  • Reproducible. Runnable test fixtures with golden expected reports let you verify the pipeline produces correct results.
  • Token-lean. A short SKILL.md routes to reference files that load only when the task needs them. The agent does not carry the whole guide in context.
  • Portable. One discipline across Claude Code, Cursor, Copilot, Antigravity, OpenCode, Codex, and Kiro.

Authors & Attribution

Zeus is built by Wizbisy.

The pipeline architecture and verification methodology were adapted from Krait (by Zealynx Security). For full details, see ATTRIBUTION.md.

License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.

Rendered live from Wizbisy/zeus's GitHub README — not stored, always reflects the source repo.

0 Plugins

No plugins listed in this repo's manifest.

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.