# Solidity Smart Contract Audit Checklist

Use only for contracts you own, are engaged to review, or are examining in a
public-interest defensive context. Do not exploit live contracts.

## Access Control
- Are privileged functions protected by explicit roles or ownership checks?
- Are role transfers, emergency actions, and upgrade paths logged?
- Can initialization be called more than once?

## Asset Handling
- Are token transfers checked for return values and reverts?
- Are external calls ordered after state changes where appropriate?
- Are fee-on-transfer and rebasing tokens considered?
- Are stuck funds recoverable through an approved governance path?

## Reentrancy and External Calls
- Are external calls minimized and isolated?
- Is a reentrancy guard used where balances or ownership change?
- Are callbacks from ERC777/ERC721/ERC1155 considered?

## Arithmetic and Accounting
- Are decimals, rounding, and precision loss documented?
- Are share-price calculations resistant to donation or inflation attacks?
- Are invariant tests defined for total assets, supply, and balances?

## Oracle and Price Risk
- Are stale, manipulated, or missing oracle prices handled safely?
- Is there a circuit breaker for abnormal price movement?
- Are TWAP windows and liquidity assumptions documented?

## Upgradeability
- Are storage gaps and layout changes reviewed?
- Are implementation contracts initialized or disabled?
- Is upgrade authority timelocked or multisig-controlled?

## Testing Evidence
- Unit tests:
- Fuzz/property tests:
- Static analysis:
- Manual review notes:
- Residual risk:
