AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Web3 Start Here

skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-start-here · by shuvonsec

Master index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT.

No reviews yet
0 installs
40 views
0.0% view→install

Install

$ agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-start-here

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-start-here)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Web3 Start Here? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

WEB3 SKILLS — MASTER INDEX

> Built from: 2,749 Immunefi reports + 100+ paid writeups + DeFiHackLabs (681 hacks) + ConsenSys + SlowMist + Trail of Bits + Foundry + Nethermind + Lido + AI agent research + live hunt experience


THE CHAIN (read in this exact order)

00-START-HERE.md              ← YOU ARE HERE
01-foundation.md              ← Mindset, target selection, recon setup
02-bug-classes.md             ← All 10 bug classes with patterns + real examples
03-grep-arsenal.md            ← Master grep patterns for every class
04-poc-and-foundry.md         ← Foundry PoC writing, cheatcodes, 18 exploit templates
05-triage-report-examples.md  ← 7-Question Gate, report format, 20 real paid examples
06-methodology-research.md    ← ToB, SlowMist, ConsenSys, Immunefi, Cyfrin, Lido, Nethermind
07-live-hunt-ern.md           ← Completed hunt: Ern protocol (2 findings)
09-live-hunt-zksync.md        ← Completed hunt: ZKsync Era (0 findings — defense study)
08-ai-tools.md                ← Shannon, LuaN1ao, SmartGuard, CAI Framework, AI code hunting
36-solidity-audit-mcp.md      ← MCP server: Slither+Aderyn+SWC in Claude Code

HOW TO USE THIS

  1. Read one file fully — every section
  2. At the bottom: follow → NEXT
  3. After file 05: you can hunt independently
  4. Files 06-08: advanced tools + active work
  5. File 36: MCP integration for live scanning

QUICK STATS

| Metric | Number | |--------|--------| | Immunefi reports analyzed | 2,749 | | Protocols covered | 51 | | Critical reports | 406 | | High reports | 616 | | Total paid by Immunefi | $100M+ | | Avg critical payout | $50K–$2M | | Nethermind reports analyzed | 166 | | DeFiHackLabs hacks reproduced | 681 |


THE ONE RULE

> "Read ALL sibling functions. If vote() has a modifier, check poke(), reset(), harvest(). The missing modifier on the sibling IS the bug."

This single rule explains 19% of all Critical findings.


→ NEXT: [01-foundation.md](01-foundation.md)

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.