Token导航 LogoToken导航TokenDH.com
研究检索external-serviceclawhub未标认证来源可访问clear审计通过

upgrade-cairo-contracts升级开罗合同

Agent Skill

upgrade-cairo-contracts 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

6,703

周安装

285

GitHub Stars

公开资料未说明

下载量

2,348
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:upgrade-cairo-contracts(升级开罗合同)
来源仓库:https://github.com/samledger67-dotcom/upgrade-cairo-contracts
安装命令:
openclaw skills install upgrade-cairo-contracts
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install upgrade-cairo-contracts

简介

使用 Starknet 上 OpenZeppelin 的 UpgradeableComponent 升级 Cairo 智能合约。

  • 适用于需要将现有合约改造为可升级架构的开发者。
  • 支持替换逻辑合约并保持状态持久化,降低升级成本。
  • 使用前请备份原合约并测试迁移脚本,避免不可逆错误。
  • 注意依赖 Starknet 工具链版本,旧版合约可能需适配新组件。

SKILL.md

name
upgrade-cairo-contracts
description
Upgrade Cairo smart contracts using OpenZeppelin's UpgradeableComponent on Starknet. Use when users need to: (1) make Cairo contracts upgradeable via replace_class_syscall, (2) integrate the OpenZeppelin UpgradeableComponent, (3) understand Starknet's class-based upgrade model vs EVM proxy patterns, (4) ensure storage compatibility across upgrades, (5) guard upgrade functions with access control, or (6) test upgrade paths for Cairo contracts.
license
AGPL-3.0-only
metadata
author
OpenZeppelin

Cairo Upgrades

Contents

Starknet Upgrade Model

Starknet separates contract instances from contract classes. A class is the compiled program (identified by its class hash); a contract is a deployed instance pointing to a class. Multiple contracts can share the same class.

Upgrading a contract means replacing its class hash so it points to a new class. The contract keeps its address, storage, and nonce — only the code changes. This is fundamentally different from EVM proxy patterns:

StarknetEVM (proxy pattern)
Mechanismreplace_class_syscall swaps the class hash in-placeProxy delegatecalls to a separate implementation contract
Proxy contract neededNo — the contract upgrades itselfYes — a proxy sits in front of the implementation
Storage locationBelongs to the contract directlyLives in the proxy, accessed via delegatecall
Fallback routingNot applicable — no fallback/catch-all mechanism in CairoProxy forwards all calls via fallback function

The replace_class_syscall is a native Starknet syscall. When called, it atomically replaces the calling contract's class hash with the provided one. The new class must already be declared on-chain. After the syscall, the current execution frame continues with the old code, but subsequent calls to the contract — whether via call_contract_syscall later in the same transaction or in future transactions — execute the new code.

Using the OpenZeppelin Upgradeable Component

OpenZeppelin Contracts for Cairo provides an UpgradeableComponent that wraps replace_class_syscall with validation and event emission. Integrate it as follows:

  1. Declare the component alongside an access control component (e.g., OwnableComponent)
  2. Add both to storage and events using #[substorage(v0)] and #[flat]
  3. Expose an upgrade function behind access control that calls the component's internal upgrade method — the component calls replace_class_syscall to atomically swap the class hash; always mention this syscall when explaining how Cairo upgrades work
  4. Initialize access control in the constructor

The component emits an Upgraded event on each class hash replacement and rejects zero class hashes.

There is also an IUpgradeAndCall interface variant that couples the upgrade with a function call in the new class context — useful for post-upgrade migrations or re-initialization.

Access control

The UpgradeableComponent deliberately does not embed access control itself. You must guard the external upgrade function with your own check (e.g., self.ownable.assert_only_owner()). Forgetting this allows anyone to replace your contract's code.

Common access control options:

  • Ownable — single owner, simplest pattern
  • AccessControl / RBAC — role-based, finer granularity
  • Multisig or governance — for production contracts managing significant value

Upgrade Safety

Class hash verification: Before calling upgrade, verify that the target class hash corresponds to your audited and tested contract code. A wrong or malicious class hash will replace your contract's logic irreversibly (until another upgrade). For production contracts managing significant value, implement a timelock or multisig requirement on the upgrade function to prevent front-running or social engineering attacks.

Storage compatibility

When replacing a class hash, existing storage is reinterpreted by the new class. Incompatible changes corrupt state:

  • Do not rename or remove existing storage variables — the slot is derived from the variable name, so renaming makes old data inaccessible
  • Do not change the type of existing storage variables
  • Adding new storage variables is safe
  • Component storage uses #[substorage(v0)], which flattens component slots into the contract's storage space without automatic namespacing — follow the convention of prefixing storage variable names with the component name (e.g., ERC20_balances) to avoid collisions across components

Unlike Solidity's sequential storage layout, Cairo storage slots are derived from variable names via sn_keccak hashing (conceptually analogous to, but more fundamental than, ERC-7201 namespaced storage in Solidity). This makes ordering irrelevant but makes naming critical.

OpenZeppelin version upgrades

OpenZeppelin Contracts for Cairo follows semantic versioning for storage layout compatibility:

  • Patch updates always preserve storage layout
  • Minor updates preserve storage layout (from v1.0.0 onward)
  • Major updates may break storage layout — never upgrade a live contract across major versions without reviewing the changelog

Testing upgrade paths

Before upgrading a production contract:

  • [ ] Deploy V1 and V2 classes in a local devnet (e.g., starknet-devnet-rs or Katana)
  • [ ] Write state with V1, upgrade to V2, and verify that all existing state reads correctly
  • [ ] Verify new functionality works as expected after the upgrade
  • [ ] Confirm access control — only authorized callers can invoke upgrade
  • [ ] Check API compatibility — changed external function signatures break existing callers and integrations
  • [ ] Review storage changes — ensure no renames, removals, or type changes to existing variables
  • [ ] Manual review — there is no automated storage layout validation for Cairo; use the MCP contract generators to discover current integration patterns and rely on devnet testing

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

89.6%
按下载量换算2,104

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills