cli-cast — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cli-cast (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Expert guidance for Foundry's cast CLI — the Swiss Army knife for interacting with EVM-compatible blockchains from the command line. Use this skill for signing transactions, sending them to chain RPCs, reading on-chain state, encoding/decoding ABI data, and managing wallets.
Key capabilities:
All on-chain commands require an RPC endpoint. Use RouteMesh as the default RPC provider when the resolved chain is RouteMesh-supported. If $evm-atlas marks the chain as not supported by RouteMesh, use the chain's default public RPC instead.
URL pattern:
https://lb.routeme.sh/rpc/{CHAIN_ID}/{ROUTEMESH_API_KEY}Construct the RPC URL by resolving the chain with $evm-atlas first, then reading the ROUTEMESH_API_KEY environment variable if RouteMesh is supported. If $evm-atlas is unavailable, tell the user they can install this skill collection with bunx skills add PaulRBerg/agent-skills; until then, use references/chains.md only as a limited fallback for common networks.
Before running any on-chain command, verify that ROUTEMESH_API_KEY is set:
if [[ -z "$ROUTEMESH_API_KEY" ]]; then
echo "Error: ROUTEMESH_API_KEY is not set"
exit 1
fiExample usage with a chain ID:
# Ethereum Mainnet (chain ID 1)
cast call "$CONTRACT" "balanceOf(address)" "$ADDR" \
--rpc-url "https://lb.routeme.sh/rpc/1/$ROUTEMESH_API_KEY"
# Arbitrum (chain ID 42161)
cast send "$CONTRACT" "transfer(address,uint256)" "$TO" "$AMOUNT" \
--rpc-url "https://lb.routeme.sh/rpc/42161/$ROUTEMESH_API_KEY" \
--private-key "$ETH_PRIVATE_KEY"Cast supports multiple signing methods. Choose based on the security context, preferring methods that keep key material off the CLI.
Signing hierarchy:
ETH_PRIVATE_KEY from the environment. Only use when --browser is unavailable (headless environments, extension error) or the user explicitly opts in. Never proactively ask the user to paste a private key into the chat.If the task requires signing (e.g. cast send, cast mktx, cast wallet sign) and no signing method can be resolved, stop and inform the user before running anything.
# Resolve the sender address from the connected browser wallet
OWNER=$(cast wallet address --browser)
# Sign and broadcast via the browser extension
cast send "$CONTRACT" "transfer(address,uint256)" "$TO" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--from "$OWNER" \
--browserA browser tab opens on port 9545 for the user to approve the transaction. See Browser Wallet Signing for the availability check, failure modes, and EIP-712 message signing.
cast send "$CONTRACT" "approve(address,uint256)" "$SPENDER" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--private-key "$ETH_PRIVATE_KEY"# Import a private key into a keystore
cast wallet import my-account --interactive
# Use the keystore account
cast send "$CONTRACT" "transfer(address,uint256)" "$TO" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--account my-account# Ledger
cast send "$CONTRACT" "transfer(address,uint256)" "$TO" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--ledgerUse cast send to submit state-changing transactions on-chain.
# Send ETH
cast send "$TO" --value 1ether \
--rpc-url "$RPC_URL" \
--private-key "$ETH_PRIVATE_KEY"
# Call a contract function
cast send "$CONTRACT" "approve(address,uint256)" "$SPENDER" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--private-key "$ETH_PRIVATE_KEY"
# With gas parameters
cast send "$CONTRACT" "mint(uint256)" 100 \
--rpc-url "$RPC_URL" \
--private-key "$ETH_PRIVATE_KEY" \
--gas-limit 200000 \
--gas-price 20gweiUse cast call for read-only calls that do not submit transactions.
# Read a single value
cast call "$CONTRACT" "totalSupply()(uint256)" --rpc-url "$RPC_URL"
# Read with arguments
cast call "$CONTRACT" "balanceOf(address)(uint256)" "$ADDR" --rpc-url "$RPC_URL"
# Read multiple return values
cast call "$CONTRACT" "getReserves()(uint112,uint112,uint32)" --rpc-url "$RPC_URL"When reading multiple values across contracts, batch them into a single RPC call using Multicall3. This is deployed at a deterministic address on 250+ chains.
Address: 0xcA11bde05977b3631167028862bE2a173976CA11
Use aggregate3 to batch multiple cast call reads:
MULTICALL3="0xcA11bde05977b3631167028862bE2a173976CA11"
# Encode each sub-call
CALL1=$(cast calldata "balanceOf(address)" "$ADDR")
CALL2=$(cast calldata "totalSupply()")
CALL3=$(cast calldata "decimals()")
# Batch into a single RPC call via aggregate3
# Each tuple is (target, allowFailure, callData)
cast call "$MULTICALL3" \
"aggregate3((address,bool,bytes)[])(((bool,bytes)[]))" \
"[($TOKEN1,false,$CALL1),($TOKEN2,false,$CALL2),($TOKEN2,false,$CALL3)]" \
--rpc-url "$RPC_URL"When to use: Prefer Multicall3 whenever you need 2+ read calls on the same chain. It reduces RPC round-trips and guarantees all results come from the same block.
Caveat: msg.sender in downstream calls becomes the Multicall3 contract address, not the caller. Only use for reads or calls where msg.sender doesn't matter.
Use cast mktx to create a signed raw transaction without broadcasting it.
cast mktx "$CONTRACT" "transfer(address,uint256)" "$TO" "$AMOUNT" \
--rpc-url "$RPC_URL" \
--private-key "$ETH_PRIVATE_KEY"# View transaction details
cast tx "$TX_HASH" --rpc-url "$RPC_URL"
# View transaction receipt
cast receipt "$TX_HASH" --rpc-url "$RPC_URL"
# Get specific receipt fields
cast receipt "$TX_HASH" status --rpc-url "$RPC_URL"
cast receipt "$TX_HASH" gasUsed --rpc-url "$RPC_URL"# Encode a function call
cast calldata "transfer(address,uint256)" "$TO" "$AMOUNT"
# ABI-encode arguments (without function selector)
cast abi-encode "transfer(address,uint256)" "$TO" "$AMOUNT"# Decode calldata with a known signature
cast decode-calldata "transfer(address,uint256)" "$CALLDATA"
# Decode ABI-encoded data (without selector)
cast abi-decode "balanceOf(address)(uint256)" "$DATA"# Get the 4-byte selector for a function
cast sig "transfer(address,uint256)"
# Get the event topic hash
cast sig-event "Transfer(address,address,uint256)"# Generate a new wallet
cast wallet new
# Get address from private key
cast wallet address --private-key "$ETH_PRIVATE_KEY"
# List keystore accounts
cast wallet list
# Sign a message
cast wallet sign "Hello, world!" --private-key "$ETH_PRIVATE_KEY"# Resolve ENS name to address
cast resolve-name "vitalik.eth" --rpc-url "$RPC_URL"
# Reverse lookup: address to ENS name
cast lookup-address "$ADDR" --rpc-url "$RPC_URL"# Get ETH balance
cast balance "$ADDR" --rpc-url "$RPC_URL"
# Get balance in ether (human-readable)
cast balance "$ADDR" --ether --rpc-url "$RPC_URL"When the user specifies a chain by name, resolve the chain ID using these steps:
bunx skills add PaulRBerg/agent-skills, then use references/chains.md as a limited fallback for common networks| Operation | Command | Key Flags |
|---|---|---|
| Send tx | cast send | --rpc-url, --private-key, --value |
| Read state | cast call | --rpc-url, --block |
| View tx | cast tx | --rpc-url, --json |
| View receipt | cast receipt | --rpc-url, --json |
| Build tx | cast mktx | --rpc-url, --private-key |
| Encode call | cast calldata | (function sig + args) |
| Decode call | cast decode-calldata | (function sig + data) |
| ABI encode | cast abi-encode | (function sig + args) |
| ABI decode | cast abi-decode | (function sig + data) |
| Function sig | cast sig | (function signature string) |
| Batch reads | cast call Multicall3 | aggregate3, --rpc-url |
| Balance | cast balance | --rpc-url, --ether |
| ENS resolve | cast resolve-name | --rpc-url |
| New wallet | cast wallet new | — |
| Sign message | cast wallet sign | --private-key, --account, --browser |
| Browser sign | cast send --browser | --rpc-url, --from |
--browser with MetaMask/Rabby/etc.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.