Web3 Smart Contract Audit
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
Audit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action.
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .claude/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .claude/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulnsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .agents/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .agents/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .cursor/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .cursor/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bitwarden/ai-plugins.git --path plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .gemini/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .gemini/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulnsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .github/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .github/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bitwarden/ai-plugins auditing-hackerone-vulns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns .opencode/skills/auditing-hackerone-vulns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auditing-hackerone-vulns" agent skill from https://github.com/bitwarden/ai-plugins/tree/main/plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns into .opencode/skills/auditing-hackerone-vulns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-hackerone-vulns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditing-hackerone-vulnsAudit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action.
Auditing Hackerone Vulns is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Audit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action. Use this skill whenever the user wants to: check VULN ticket status, see which HackerOne findings need status updates, identify vulnerabilities ready to verify or close, run a remediation audit, check "what do I need to do on my VULN tickets today", or get a prioritized view of open vulnerabilities. Outputs a sorted action table with emoji tokens. Always use this skill for HackerOne/VULN…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Bug bounty. It works with Jira. The repository describes itself as: AI plugin marketplace.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3e6bea3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
mcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__search_issuesmcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__get_issuemcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__get_issue_remote_linksBash(gh api --methodGET *)Bash(gh pr view *)Bash(gh release list *)Bash(gh api repos/bitwarden/*/compare/*)Bash(gh search prs *)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghjqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
bitwarden.atlassian.nethackerone.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auditing Hackerone Vulns loads about 3.4k tokens when it runs. Until then it costs about 156 tokens; SKILL.md has 865 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 865 words (~3,427 tokens).
Just SKILL.md in plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns of bitwarden/ai-plugins.
Open the folder on GitHubat commit 3e6bea3
Auditing Hackerone Vulns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auditing Hackerone Vulns this skillbitwarden/ai-plugins | 154 | — | ~3.4k | Automated safety check: Pass | Custom licence | |
| Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | |
| Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT |
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
bitwarden/ai-plugins
Retrieves a link from Mailcatcher. An agent skill from bitwarden/ai-plugins.
bitwarden/ai-plugins
Query read-only Stripe test-mode data and advance an already-attached test clock.
bitwarden/ai-plugins
Reviews Claude configuration files for security, structure, and prompt engineering quality.
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
bitwarden/ai-plugins
This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess…
bitwarden/ai-plugins
Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.
Works with
Categories
Audit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action. Auditing Hackerone Vulns is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Audit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action.
Auditing Hackerone Vulns fits situations like: the user wants to: check VULN ticket status; see which HackerOne findings need status updates; identify vulnerabilities ready to verify; run a remediation audit.
Run `npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a claude-code`. Or copy the skill folder (plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns in bitwarden/ai-plugins) into .claude/skills/auditing-hackerone-vulns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a codex`. Or copy the skill folder (plugins/bitwarden-security-engineer/skills/auditing-hackerone-vulns in bitwarden/ai-plugins) into .agents/skills/auditing-hackerone-vulns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bitwarden/ai-plugins --skill auditing-hackerone-vulns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-hackerone-vulns, .gemini/skills/auditing-hackerone-vulns, .github/skills/auditing-hackerone-vulns and .opencode/skills/auditing-hackerone-vulns in your project.
Going by SKILL.md and its folder, Auditing Hackerone Vulns needs the command-line tools its instructions call (gh and jq). Our summary lists: Python 3. Its frontmatter pre-approves these tools: mcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__search_issues, mcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__get_issue, mcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__get_issue_remote_links, Bash(gh api --method GET *), Bash(gh pr view *), Bash(gh release list *), Bash(gh api repos/bitwarden/*/compare/*), Bash(gh search prs *).
SKILL.md names 2 domains. In commands or code: bitwarden.atlassian.net and hackerone.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auditing Hackerone Vulns has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Auditing Hackerone Vulns: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bitwarden (a GitHub organization, an official publisher) maintains it in bitwarden/ai-plugins, which has 154 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 9, 2026.
Source: bitwarden/ai-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.