Agent skill

Web3 Smart Contract Grep Arsenal

by tradecatlabs in tradecatlabs/vibe-coding-cn

A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

MITAuto-check passedSecurity

Install Web3 Smart Contract Grep Arsenal

skills CLI
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-grep-arsenal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tradecatlabs/vibe-coding-cn web3-grep-arsenal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-grep-arsenal .claude/skills/web3-grep-arsenal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web3-grep-arsenal
GitHub stars
17k
Used in
2 other repos
Token cost
~3.3k tokens
SKILL.md length
569 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

  • Works in 5 steps: Run ALL 10 blocks below (takes ~5 min) → Collect all results in a notes file → Tier-rank the hits (see Tier System below) → …
  • Starting a vulnerability scan on a new smart contract protocol
  • SKILL.md covers HOW TO USE THE SURFACE MAP, THE 10 GREP BLOCKS (Copy-Paste…, PROTOCOL-SPECIFIC PATTERNS and 2025 NEW PATTERN SCANS, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This skill consolidates grep commands that would otherwise be spread across several individual audit checklists into one master reference, meant to run in full near the start of any new target. The process is fixed: run all ten blocks, collect every result into a notes file, tier-rank the hits, read everything in a first pass without investigating yet, then deep-dive on the top two tiers in a second pass.

Each of the ten blocks targets one vulnerability class - among them access control, reentrancy, and oracle or price manipulation - with a ready-to-paste shell command and a list of red flags to watch for in the output, such as tx.origin used for authorization, an external call or token transfer happening before a state update, or a price read from a spot AMM function that a flash loan can manipulate.

Results are sorted into three tiers: Tier 1 for code near privileged paths, external calls, or state changes with no visible guard, which gets investigated first; Tier 2 for interesting patterns that need more context before judging; and Tier 3 for purely informational hits such as documentation, test files or comments, which are skipped unless the first two tiers are already exhausted.

When your agent uses it

  • Starting a vulnerability scan on a new smart contract protocol
  • Doing a quick reentrancy or oracle-manipulation sweep before a deep review
  • Triaging grep hits by severity before a smart contract audit

Example prompts

  • “Run the full grep surface map on this new Solidity protocol.”
  • “Check this contract for reentrancy and oracle manipulation patterns.”
  • “Tier-rank these grep hits before I start the deep review.”

Requirements

  • grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run ALL 10 blocks below (takes ~5 min)
  2. Collect all results in a notes file
  3. Tier-rank the hits (see Tier System below)
  4. In pass 1: READ everything, DON'T investigate yet
  5. In pass 2: Deep-dive on Tier 1 + 2 items

What it can do on your machine

Read from SKILL.md and the folder at commit 5b76a8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web3 Smart Contract Grep Arsenal loads about 3.3k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 569 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tradecatlabs/vibe-coding-cn at commit 5b76a8f, republished under its MIT licence (© tradecatlabs). 569 words, ~3,275 tokens.

Download SKILL.mdSave it as .claude/skills/web3-grep-arsenal/SKILL.md (or your agent's skills folder).
name
web3-grep-arsenal
description
Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.
Contains
10 grep blocks for all major vuln classes, tier ranking, protocol-specific patterns, 2025 new patterns, copy-paste ready blocks.

GREP ARSENAL — MASTER REFERENCE

All grep commands in one place. Run in the first 30 minutes of any new target. Replaces: 03-grep-surface-map, 14-grep-master-patterns + grep sections from 04-13


HOW TO USE THE SURFACE MAP

Process:

  1. Run ALL 10 blocks below (takes ~5 min)
  2. Collect all results in a notes file
  3. Tier-rank the hits (see Tier System below)
  4. In pass 1: READ everything, DON'T investigate yet
  5. In pass 2: Deep-dive on Tier 1 + 2 items

Tier System:

  • Tier 1 — Near privileged code, external calls, or state changes with no guards → Investigate first
  • Tier 2 — Interesting patterns that need context before judging → Investigate after Tier 1
  • Tier 3 — Informational only (documentation, test files, comments) → Skip unless Tier 1+2 exhausted

THE 10 GREP BLOCKS (Copy-Paste Each)

Block 1 — Access Control
bash
echo "=== ACCESS CONTROL ===" && \
grep -rn "tx\.origin" src/ --include="*.sol" && \
grep -rn "msg\.sender == owner\b" src/ --include="*.sol" && \
grep -rn "modifier only" src/ --include="*.sol" -A5 && \
grep -rn "onlyOwner\|onlyAdmin\|onlyRole" src/ --include="*.sol" | wc -l && \
grep -rn "def admin_\|router\..*admin\|function.*[Aa]dmin" src/ --include="*.sol"

Red flags:

  • tx.origin used for auth → Tier 1 (phishing vector)
  • Modifier uses if (condition) { _; } without else → Tier 1 (silent bypass — function still executes for unauthorized callers)
  • onlyOwner count << total external function count → likely missing guards on siblings
Block 2 — Reentrancy
bash
echo "=== REENTRANCY ===" && \
grep -rn "\.call{value\|\.call(" src/ --include="*.sol" && \
grep -rn "\.transfer(\|\.send(" src/ --include="*.sol" && \
grep -rn "safeTransfer\|safeTransferFrom" src/ --include="*.sol" && \
grep -rn "onERC721Received\|onERC1155Received\|tokensReceived" src/ --include="*.sol" && \
grep -rn "nonReentrant\|ReentrancyGuard" src/ --include="*.sol"

Red flags:

  • .call{value:} or safeTransfer BEFORE state updates in same function → Tier 1 (CEI violation)
  • onERC721Received/onERC1155Received hooks present → check for reentrancy path
  • External calls present but nonReentrant missing → verify CEI is followed
Block 3 — Oracle / Price
bash
echo "=== ORACLE / PRICE ===" && \
grep -rn "slot0\b" src/ --include="*.sol" && \
grep -rn "getReserves()" src/ --include="*.sol" && \
grep -rn "latestRoundData\|latestAnswer" src/ --include="*.sol" && \
grep -rn "updatedAt" src/ --include="*.sol" && \
grep -rn "block\.timestamp" src/ --include="*.sol" | grep -v "//\|test\|Test" | head -20

Red flags:

  • slot0() used for price → Tier 1 (Uniswap V3 spot, flash-loan manipulable)
  • getReserves() used for price → Tier 1 (Uniswap V2 spot, flash-loan manipulable)
  • latestRoundData without updatedAt check → Tier 1 (stale Chainlink price)
  • latestAnswer → Tier 1 (deprecated, no round validation)
Block 4 — Arithmetic / Math
bash
echo "=== ARITHMETIC ===" && \
grep -rn "unchecked {" src/ --include="*.sol" && \
grep -rn "/ \|/=" src/ --include="*.sol" | grep -v "//\|test\|Test" | head -30 && \
grep -rn "mulDiv\|FullMath\|PRBMath" src/ --include="*.sol" && \
grep -rn "\* 10\*\*\|* 1e18\|* WAD\|* RAY" src/ --include="*.sol"

Red flags:

  • unchecked {} blocks → manually verify each (Solidity 0.8+ unwraps here)
  • Division before multiplication (a / b * c) → precision loss
  • / 1e18 in contract that handles 6-decimal tokens → decimal mismatch
Block 5 — Input Validation
bash
echo "=== INPUT VALIDATION ===" && \
grep -rn "address(0)\b" src/ --include="*.sol" && \
grep -rn "require.*length\|\.length ==" src/ --include="*.sol" && \
grep -rn "delegatecall" src/ --include="*.sol" && \
grep -rn "abi\.decode\|abi\.encodePacked" src/ --include="*.sol" | head -20

Red flags:

  • delegatecall with user-controlled target → Tier 1 (arbitrary code execution)
  • abi.decode on user-supplied calldata without length validation → Tier 1
  • Array params in batch functions without dedup check → Tier 1 (double-count attack)
Block 6 — Token Handling
bash
echo "=== TOKEN HANDLING ===" && \
grep -rn "IERC20\.\|ERC20\." src/ --include="*.sol" | grep "transfer\b\|transferFrom\b" && \
grep -rn "SafeERC20\|safeTransfer\b" src/ --include="*.sol" | head -10 && \
grep -rn "balanceOf(address(this))" src/ --include="*.sol" && \
grep -rn "permit(" src/ --include="*.sol" | grep -v "//\|IERC20Permit" && \
grep -rn "try.*permit\|catch.*permit" src/ --include="*.sol"

Red flags:

  • token.transfer() without SafeERC20.safeTransfer() → Tier 1 (return value unchecked, fails silently on old USDT)
  • balanceOf(address(this)) for pricing/shares → Tier 1 (donation attack vector)
  • permit() without try/catch wrapper → Tier 2 (frontrun DoS possible)
Show full SKILL.md (218 more words)Show less
Block 7 — ERC4626 / Vault
bash
echo "=== ERC4626 / VAULT ===" && \
grep -rn "totalAssets\|convertToShares\|previewDeposit\|previewMint" src/ --include="*.sol" && \
grep -rn "_decimalsOffset\|decimalsOffset\|virtual_shares\|dead.*shares" src/ --include="*.sol" && \
grep -rn "shares.*supply\|totalSupply\|mint.*shares" src/ --include="*.sol" | head -20

Red flags:

  • ERC4626 present but _decimalsOffset() NOT present → Tier 1 (first depositor inflation)
  • totalAssets() uses balanceOf(address(this)) → Tier 1 (donation attack)
  • mint() or deposit() called without same validation path → Tier 1 (MetaPool bug: mint skipped receipt check)
Block 8 — Proxy / Upgradeable
bash
echo "=== PROXY / UPGRADE ===" && \
grep -rn "_authorizeUpgrade\|upgradeTo\|upgradeToAndCall" src/ --include="*.sol" && \
grep -rn "initialize(" src/ --include="*.sol" | grep -v "//\|test\|Test" && \
grep -rn "_disableInitializers\|initializer\b\|Initializable" src/ --include="*.sol" && \
grep -rn "StorageSlot\|ERC1967\|TransparentProxy\|UUPSUpgradeable" src/ --include="*.sol"

Red flags:

  • _authorizeUpgrade() without onlyOwner or role check → Tier 1 (anyone can upgrade)
  • initialize() without initializer modifier → Tier 1 (re-initialization possible)
  • Proxy present but _disableInitializers() NOT in impl constructor → Tier 1 (impl attackable)
Block 9 — Signature / Replay
bash
echo "=== SIGNATURES ===" && \
grep -rn "ecrecover\|ECDSA\.recover" src/ --include="*.sol" && \
grep -rn "chainId\|block\.chainid\|DOMAIN_SEPARATOR" src/ --include="*.sol" && \
grep -rn "nonces\[" src/ --include="*.sol" && \
grep -rn "keccak256.*abi\.encode" src/ --include="*.sol" | head -20

Red flags:

  • ecrecover present but chainId/DOMAIN_SEPARATOR NOT present → Tier 1 (cross-chain replay)
  • ecrecover without nonce → Tier 1 (same-chain replay)
  • ecrecover return not checked against address(0) → Tier 1 (invalid sigs succeed)
Block 10 — State Completeness / Access
bash
echo "=== STATE COMPLETENESS ===" && \
grep -rn "grantRole\|revokeRole\|hasRole" src/ --include="*.sol" && \
grep -rn "bytes32.*ROLE\s*=" src/ --include="*.sol" && \
grep -rn "function.*migrate\|function.*batch.*stake\|function.*multiStake" src/ --include="*.sol" -A10 && \
grep -rn "} catch" src/ --include="*.sol" -A5 | grep -A5 "revert\|Error" && \
grep -rn "cached\|_cache\|lastKnown\|storedBalance" src/ --include="*.sol"

Red flags:

  • Role defined but grantRole() call for that role NOT found anywhere → Tier 1 (role permanently empty)
  • Array-based function: flag = true OUTSIDE/AFTER loop → Tier 1 (empty array bypass)
  • } catch { revert } on critical path → Tier 2 (liveness DoS if external changes)
  • Cache variable initialized to 0 with no first-access guard → Tier 1 (uninitialized cache)

PROTOCOL-SPECIFIC PATTERNS

Yield Aggregator (like Ern, Yearn, Beefy)
bash
grep -rn "cumulativeReward\|rewardPerShare\|accRewardPerShare" src/ --include="*.sol"
grep -rn "harvestCooldown\|canHarvest\|performHarvest\|_harvest" src/ --include="*.sol"
grep -rn "totalDeposited\|totalPrincipal" src/ --include="*.sol"
# Check: does cumulativeReward always update before user checkpoint?
Lending Protocol (like Aave, Compound)
bash
grep -rn "collateral\|borrow\|liquidat" src/ --include="*.sol"
grep -rn "healthFactor\|isSolvent\|isLiquidatable" src/ --include="*.sol"
grep -rn "interest.*accrual\|accrueInterest\|indexIncrease" src/ --include="*.sol"
grep -rn "amplification\|A_PARAMETER\|getA()" src/ --include="*.sol"
# Check: is price oracle manipulation possible? Is interest accrual order correct?
AMM / DEX
bash
grep -rn "getReserves\|reserve0\|reserve1" src/ --include="*.sol"
grep -rn "slot0\|sqrtPriceX96\|tick\b" src/ --include="*.sol"
grep -rn "K\s*=\|invariant\|_invariant" src/ --include="*.sol"
grep -rn "amountOutMin\|minAmountOut\|deadline" src/ --include="*.sol"
# Check: is spot price used for any security decision? Missing slippage?
Staking / Restaking
bash
grep -rn "epoch\|currentEpoch\|lastEpoch\|epochId" src/ --include="*.sol"
grep -rn "unstake\|migrate\|slash\|jailValidator" src/ --include="*.sol"
grep -rn "validatorIds\|stakeIds\|delegateIds" src/ --include="*.sol"
# Check: can same ID be passed twice? Empty array skips state reset?
ZK / Proof Contracts
bash
grep -rn "verifyProof\|IVerifier\|publicInputs\b" src/ --include="*.sol"
grep -rn "return true" src/ --include="*.sol" | grep -i "verify\|proof"
grep -rn "require.*inputs\[0\]\|rangeCheck\|MAX_BALANCE" src/ --include="*.sol"
# Check: are public inputs range-checked after proof verification?

2025 NEW PATTERN SCANS

bash
# ERC4626 near-empty vault (inflation variant, now widespread)
grep -rn "totalAssets\b" src/ --include="*.sol" -A10 | grep "balanceOf\|balance()"
# If totalAssets() uses raw balanceOf → donation attack risk

# EIP-2612 permit frontrun DoS
grep -rn "permitAndDeposit\|permitAndStake\|permitAndBorrow" src/ --include="*.sol"
grep -rn "try.*permit\|catch.*permit" src/ --include="*.sol"
# Missing try/catch around permit = DoS possible

# Decimal precision mismatch (6 vs 18 decimals)
grep -rn "/ 1e18\|/ WAD" src/ --include="*.sol"
grep -rn "decimals()\|IERC20Metadata" src/ --include="*.sol"
# / 1e18 WITHOUT decimals() call in same function = decimal mismatch candidate

# Uninitialized cache
grep -rn "uint256.*cached\|uint128.*cached\|int256.*cached" src/ --include="*.sol"
# Cache initialized to 0 with no first-access sync = uninitialized cache bug

# Empty array bypass
grep -rn "= true;" src/ --include="*.sol" -B15 | grep -B15 "for.*calldata"
# flag = true AFTER a loop that can be empty = bypass critical

# Streaming/continuous precision (per-second rewards)
grep -rn "rewardPerSecond\|ratePerSecond\|flowRate\|perSecond" src/ --include="*.sol"
grep -rn "uint128.*reward\|uint96.*rate" src/ --include="*.sol"
# uint128 accumulator × per-second rate = overflow risk on long time periods

# Withdrawal queue multi-field invariant
grep -rn "\.queued\b\|\.claimable\b\|\.claimed\b" src/ --include="*.sol"
# claimed <= claimable <= queued must hold — check all update paths

# Cross-chain signature reuse
grep -rn "keccak256.*abi\.encodePacked\|ECDSA\.recover" src/ --include="*.sol"
grep -rn "chainId\|block\.chainid" src/ --include="*.sol"
# ecrecover WITHOUT chainId = same sig valid on all chains

# try/catch DoS liveness
grep -rn "} catch" src/ --include="*.sol" -A5 | grep -B1 "revert\|IncompatibleAdapter"

# Nullifier timing (Worldcoin-style)
grep -rn "nullifiers\[.*\] = true\|nullifierUsed\[" src/ --include="*.sol" -B5
# Marked before action = frontrun can permanently DoS identity

SPECIFIC BUG PATTERN SEARCHES

Silent Modifier (if vs require)
bash
# Find modifiers that use if() without revert — silently does nothing for unauthorized callers
grep -rn "modifier only" src/ --include="*.sol" -A10 | grep -A10 "if ("
# Correct: require(condition, "msg"); _;
# BUG: if (condition) { _; }  ← no else = still executes for unauthorized
Tautology Check (variable compared to itself)
bash
grep -rn "require(" src/ --include="*.sol" | grep "\b\(\w\+\) == \1\b"
# e.g. require(a == a, ...) = always true → always passes
Same-Role Count Mismatch
bash
grep -rn "onlyRole\b" src/ --include="*.sol" | wc -l
grep -rn "grantRole(" src/ --include="*.sol" | wc -l
# More onlyRole uses than grantRole calls = some roles may never be granted
Accounting: Balance vs Tracked
bash
grep -rn "balanceOf(address(this))" src/ --include="*.sol"
grep -rn "totalDeposited\|totalPrincipal\|_balance\b" src/ --include="*.sol"
# If protocol uses raw balanceOf for pricing AND has separate totalDeposited
# → donation attack: send tokens directly to contract → inflates balance

→ NEXT: 04-poc-and-foundry.md

© tradecatlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-grep-arsenal of tradecatlabs/vibe-coding-cn.

Open the folder on GitHubat commit 5b76a8f

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in tradecatlabs/vibe-coding-cn, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Web3 Smart Contract Grep Arsenal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web3 Smart Contract Grep Arsenal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web3 Smart Contract Grep Arsenal this skilltradecatlabs/vibe-coding-cn17k2 repos~3.3kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed

More from tradecatlabs/vibe-coding-cn

All 17 skills in this repo
  • Auto Skill Builder

    tradecatlabs/vibe-coding-cn

    Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.

    17k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Auto tmux Operator

    tradecatlabs/vibe-coding-cn

    Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.

    17k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: warnings
  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    Auto-check passed
  • Math Computation

    tradecatlabs/vibe-coding-cn

    Runs reproducible math computations and counterexample searches with SymPy, NumPy and mpmath, logging evidence without presenting results as proofs.

    17k GitHub stars~881 tokensUpdated yesterday
    Auto-check passed
  • DeFi Smart Contract Bug Classes

    tradecatlabs/vibe-coding-cn

    Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews.

    17k GitHub starsUsed in 2 repos~10k tokens
    Auto-check passed

Categories

Questions about Web3 Smart Contract Grep Arsenal

What does Web3 Smart Contract Grep Arsenal do?

A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol. This skill consolidates grep commands that would otherwise be spread across several individual audit checklists into one master reference, meant to run in full near the start of any new target. The process is fixed: run all ten blocks, collect every result into a notes file, tier-rank the hits, read everything in a first pass without investigating yet, then deep-dive on the top two tiers in a second pass.

When should I use Web3 Smart Contract Grep Arsenal?

Web3 Smart Contract Grep Arsenal fits situations like: starting a vulnerability scan on a new smart contract protocol; doing a quick reentrancy or oracle-manipulation sweep before a deep review; triaging grep hits by severity before a smart contract audit.

How do I install Web3 Smart Contract Grep Arsenal in Claude Code?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-grep-arsenal -a claude-code`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-grep-arsenal in tradecatlabs/vibe-coding-cn) into .claude/skills/web3-grep-arsenal in your project. Claude Code loads it when a task matches its description.

How do I install Web3 Smart Contract Grep Arsenal in Codex?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-grep-arsenal -a codex`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-grep-arsenal in tradecatlabs/vibe-coding-cn) into .agents/skills/web3-grep-arsenal in your project. Codex loads it when a task matches its description.

Can I use Web3 Smart Contract Grep Arsenal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-grep-arsenal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web3-grep-arsenal, .gemini/skills/web3-grep-arsenal, .github/skills/web3-grep-arsenal and .opencode/skills/web3-grep-arsenal in your project.

What does Web3 Smart Contract Grep Arsenal need to run?

SKILL.md names no scripts, command-line tools or credentials: Web3 Smart Contract Grep Arsenal is instructions for the agent only. Our summary lists: grep.

Does Web3 Smart Contract Grep Arsenal access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Web3 Smart Contract Grep Arsenal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web3 Smart Contract Grep Arsenal use?

Web3 Smart Contract Grep Arsenal is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web3 Smart Contract Grep Arsenal use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web3 Smart Contract Grep Arsenal?

Skills that share tags, products or a category with Web3 Smart Contract Grep Arsenal: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web3 Smart Contract Grep Arsenal?

tradecatlabs (a GitHub user) maintains it in tradecatlabs/vibe-coding-cn, which has 17,386 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: tradecatlabs/vibe-coding-cn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.