Agent skill

Web3 Hunt Foundation

by tradecatlabs in tradecatlabs/vibe-coding-cn

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.

MITAuto-check passedSecurity

Install Web3 Hunt Foundation

skills CLI
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-foundation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-foundation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-foundation .claude/skills/web3-hunt-foundation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web3-hunt-foundation
GitHub stars
17k
Used in
2 other repos
Token cost
~2.5k tokens
SKILL.md length
835 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.

  • Works in 6 steps: Read Immunefi Page (5 min) → Clone + Setup (5 min) → Read ALL Prior Audit Reports (15 min) → …
  • Beginning a bug bounty hunt on a new Web3 protocol
  • SKILL.md covers PART 1: THE HUNTER MINDSET, PART 2: TARGET SCORING — GO /…, PART 3: RECON METHODOLOGY… and PART 4: RECON CHECKLIST, plus 2 more sections
  • Calls git and vault

What it does

Meant to be read before touching a new protocol's code, this skill combines mindset, recon setup and target scoring for Web3 bug bounty work. Its core rule is to look for concrete actions that cost the protocol something rather than abstract vulnerabilities, and a validation template asks the hunter to spell out the setup and the exact calls. If those steps cannot be filled in with specific function calls, the finding is dropped.

For each external function the skill lists ten questions, such as what happens with a zero amount, a repeated call in one block, a call before initialize, a fee-on-transfer token or a sibling function missing the modifier its neighbor has. Six triager counter-questions then try to disprove the finding, for instance whether an upstream check exists or a prior audit already accepted the risk, and a five-minute rule says to move on when no attack path appears.

When your agent uses it

  • Beginning a bug bounty hunt on a new Web3 protocol
  • Deciding whether a suspected issue is real before writing a proof of concept
  • Scoring a bounty target and setting up the recon environment

Example prompts

  • “I am starting a bounty hunt on a new lending protocol, so give me the checklist to run first.”
  • “Run the ten attacker questions against the withdraw function in Vault.sol.”
  • “Here is my suspected bug in the reward claim. Try to disprove it with the triager questions.”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Read Immunefi Page (5 min)
  2. Clone + Setup (5 min)
  3. Read ALL Prior Audit Reports (15 min)
  4. Crown Jewels (2 min)
  5. Architecture + Fund Flow (3 min)
  6. Static Analysis (5 min)

What it can do on your machine

Read from SKILL.md and the folder at commit 5b76a8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • vault

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web3 Hunt Foundation loads about 2.5k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 835 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tradecatlabs/vibe-coding-cn at commit 5b76a8f, republished under its MIT licence (© tradecatlabs). 835 words, ~2,459 tokens.

Download SKILL.mdSave it as .claude/skills/web3-hunt-foundation/SKILL.md (or your agent's skills folder).
name
web3-hunt-foundation
description
Hunter mindset, recon setup, and target scoring for Web3 bug bounty. Use at the START of any new protocol hunt - scoring targets, setting up environment, understanding architecture.
Contains
attack/triage mental models, 10-point scorecard (score ≥6 to proceed), crown jewels approach, static analysis setup, recon checklist.

WEB3 HUNT FOUNDATION

Mindset + Recon + Setup. Read this before touching any new target's code. Replaces: 01-mindset, 02-recon-setup, 20-chain-complete


PART 1: THE HUNTER MINDSET

The Core Mental Shift

You are NOT looking for "vulnerabilities" in the abstract. You are looking for specific actions an attacker can take TODAY that result in profit.

Everything flows from one question: "What can I STEAL, FREEZE, or DESTROY — and what do I END UP WITH?"

The Bug Validation Template

Apply to every finding before writing a single line:

I am an attacker. I will:
1. SETUP:   What do I need? (wallet, capital, any whitelisted permissions?)
2. CALL:    Exact transactions, exact order, exact function names
3. RESULT:  What do I end up with that I didn't start with?
4. COST:    Gas + capital + flash loan fee + any other expense
5. DETECT:  Can anyone stop or reverse this?
6. NET ROI: I gained X at cost of Y. Is Y << X?

If you can't fill in steps 2 and 3 with specific function calls → it's not a real bug. Stop. Move on.

10 Attacker Questions (Ask For Every External Function)
  1. What if amount = 0? Does anything revert or silently pass?
  2. What if I call this function twice in the same block?
  3. What if I call this before initialize() is called?
  4. What if I front-run this transaction?
  5. What if the external call fails? Does state get half-updated?
  6. What if the token has fee-on-transfer? Does amount received ≠ amount sent?
  7. What if I pass address(0) or a malicious contract as an address param?
  8. What if I pass type(uint256).max as a numeric param?
  9. Can I combine this with a flash loan? (zero-cost capital changes the math)
  10. Does a sibling function lack the same modifier this function has?

Question #10 explains 19% of all Critical findings. If vote() has onlyRole(VOTER), check poke(), reset(), harvest() — the missing modifier on the sibling IS the bug.

6 Triager Counter-Questions (Disprove Your Own Finding)

Before spending time on a PoC, try to KILL the finding:

  1. Is there an upstream check I missed that actually prevents this?
  2. Is this documented intended behavior (whitepaper, NatSpec, design decision)?
  3. Does exploitation require admin/privileged access? (Usually invalid if yes)
  4. Is the economic cost to exploit greater than the gain? (Not viable if yes)
  5. Was this flagged in a prior audit as "acknowledged" or "risk accepted"?
  6. Is the "sensitive" data already publicly visible to anyone in the web UI?

One YES = KILL. Move on.

5-Minute Rule

If you've been on the same function for 5 minutes with no clear attack path → STOP. Add it to a low-priority list. Move to the next function. Top hunters: 95% fast-reject + 5% deep dives on confirmed leads.

Depth Over Breadth

Don't review 10 protocols in one week. Pick ONE. Spend 3-5 days becoming the expert. Protocol-specific knowledge compounds. The Curve expert found 5 bugs. The 10-protocol tourist found 0.

Inconsistency Is Proof

If functionA() has a security check, and functionB() doesn't — that IS the report. You don't need to fully understand why. The inconsistency proves the developer intended the check.


PART 2: TARGET SCORING — GO / NO-GO

Before touching any code: score the target. Score < 6 → skip.

Show full SKILL.md (370 more words)Show less
Target Scorecard
CriterionPointsHow to Check
Max bounty ≥ $50K+2Immunefi program page
TVL > $1M+2DeFiLlama
Program launched < 30 days ago+2Immunefi "new" filter
Custom math (AMM/vault/lending)+1Read scope contracts
Recent code changes+1git log --oneline -20
Prior audits available+1Program page / GitHub
In-scope includes smart contracts+1Scope section
Protocol type you know well+1Your specialization
Source code public/readable+1GitHub / Etherscan verified

< 4: Skip — too small, too audited, wrong fit 4-5: Only if nothing better available 6-8: Good — spend 1-3 days ≥ 9: Excellent — spend up to 1 week


PART 3: RECON METHODOLOGY (30-Minute Protocol)

Step 1 — Read Immunefi Page (5 min)
Note:
- All in-scope contract addresses + GitHub links
- Out-of-scope list (DO NOT report these)
- Primacy of Impact: YES/NO (YES = more forgiving on novel impacts)
- Max bounty amounts by severity
- Time on Immunefi (newer = fewer duplicates)
Step 2 — Clone + Setup (5 min)
bash
git clone <target-repo>
cd <target-repo>
git log --oneline -20       # Recent changes = freshest bugs here
forge build                 # Must compile clean (fix if not)
forge test                  # Note failures — may indicate known issues
forge coverage              # Untested code = priority review target
Step 3 — Read ALL Prior Audit Reports (15 min)

For each finding, note its status:

  • Fixed: Skip
  • Acknowledged / Risk Accepted: ⚡ START HERE ⚡
    • Developer knows about it but chose not to fix it
    • Variants, escalations, related attack paths = in-scope and uncovered
  • Partially Fixed: Verify fix actually closes ALL attack paths

Find audits: GitHub repo, protocol docs, Immunefi page, Google "[protocol] audit report"

Step 4 — Crown Jewels (2 min)

Ask: "Worst thing an attacker could do to users of this protocol?"

Work backward from impact to code:

  • "Steal deposits" → find: withdrawal functions, access control on transfer
  • "Mint infinite tokens" → find: mint functions, who calls them, what checks
  • "Freeze all funds" → find: emergency functions, time locks, role assignments
  • "Steal all rewards" → find: reward distribution, distributor role, harvest functions
Step 5 — Architecture + Fund Flow (3 min)

Draw the money flow (even mentally):

User USDC
   ↓ deposit()
[Protocol Vault] ──→ External Protocol (Aave/Compound/Uniswap)
   ↓ yield accumulates
[Reward Distributor] ──→ Users via claim/harvest

Find WHERE VALUE ACCUMULATES. That contract = highest priority.

Key state variables to map:

  • Total deposited / total assets / total shares
  • Per-user balance tracking (how is it updated?)
  • Reward accumulator (index, per-share, per-second?)
  • Role assignments (owner, admin, governance, distributor)
  • Time locks (timestamps, epochs, cooldowns)
Step 6 — Static Analysis (5 min)
bash
# Slither — 93 detectors, fast
slither . --exclude-low --filter-paths "test|lib|node_modules"
slither . --detect reentrancy-eth,unprotected-upgrade,arbitrary-send-eth

# Aderyn — Rust-based, Foundry-native
aderyn . --output report.md

# Read output → note HIGH/CRITICAL only
# Tools catch ~30-40% of bugs. Human review finds the rest.

PART 4: RECON CHECKLIST

Run through this before any deep review:

PROGRAM:
[ ] Max bounty noted per severity
[ ] ALL in-scope contracts listed (name + address)
[ ] Out-of-scope list read — nothing to falsely report
[ ] Primacy of Impact: YES/NO noted
[ ] Program launch date noted (new = good)

PRIOR AUDITS:
[ ] All audit PDFs downloaded and scanned
[ ] Each finding: status noted (Fixed/Ack/Risk Accepted)
[ ] Acknowledged items in notes as starting points

CODEBASE:
[ ] git clone + forge build passes
[ ] git log checked — recent commits noted
[ ] forge coverage run — untested functions noted
[ ] Slither + Aderyn run — high/critical noted

ARCHITECTURE:
[ ] Fund flow drawn
[ ] Crown jewels identified (where value lives)
[ ] External dependencies mapped (Chainlink, Uniswap, Aave, etc.)
[ ] ALL privileged roles found (onlyOwner, onlyRole, etc.)
[ ] Proxy/upgradeable pattern identified (if any)

ATTACK SURFACE:
[ ] All external/public non-view functions listed
[ ] Mint/burn functions located
[ ] Withdraw/emergencyWithdraw functions located
[ ] Upgrade/migration functions located
[ ] Oracle dependencies found
[ ] Signature/permit usage found
[ ] Cross-contract interactions mapped

ATTACK SURFACE BY PROTOCOL TYPE

DEX / AMM:
- Oracle manipulation (getReserves, slot0 = flash-loan manipulable)
- Rounding in pool math (1-wei attacks × flash swap)
- Missing slippage protection (sandwich vector)
- Fee-on-transfer token handling

LENDING / BORROWING:
- Collateral valuation (oracle → overborrow)
- Liquidation logic (bad debt creation, self-liquidation)
- Interest accrual rounding (favors borrower or protocol?)
- Flash loan → inflate collateral → borrow → repay

VAULT / YIELD:
- First depositor share inflation (ERC4626)
- Donation attack via direct balanceOf transfer
- Strategy rug (malicious strategy contract)
- Reward accounting timing (enter/exit attacks)

BRIDGE / CROSS-CHAIN:
- Message replay (missing nonce/nullifier)
- Signature replay (no chainId)
- Validator set manipulation
- Destination execution reentrancy

STAKING / RESTAKING:
- Reward distribution timing attacks
- Slashing logic errors
- Role never granted → permanent lock
- Withdrawal queue multi-field desync

WHEN TO RE-READ THIS CHAIN

SituationFile to Read
Starting new huntThis file
Need specific grep commands03-grep-arsenal
Found a bug, building PoC04-poc-and-foundry
Ready to validate + submit05-triage-report
Need all bug class patterns02-bug-classes
Want external research depth06-methodology
Hunting Ern protocol07-live-hunt-ern
Want AI tool automation08-ai-tools

→ NEXT: 02-bug-classes.md

© tradecatlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-foundation of tradecatlabs/vibe-coding-cn.

Open the folder on GitHubat commit 5b76a8f

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in tradecatlabs/vibe-coding-cn, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Web3 Hunt Foundation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web3 Hunt Foundation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web3 Hunt Foundation this skilltradecatlabs/vibe-coding-cn17k2 repos~2.5kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed

More from tradecatlabs/vibe-coding-cn

All 17 skills in this repo
  • Auto Skill Builder

    tradecatlabs/vibe-coding-cn

    Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.

    17k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Web3 Smart Contract Grep Arsenal

    tradecatlabs/vibe-coding-cn

    A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

    17k GitHub starsUsed in 2 repos~3.3k tokens
    Auto-check passed
  • Auto tmux Operator

    tradecatlabs/vibe-coding-cn

    Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.

    17k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: warnings
  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    Auto-check passed
  • Math Computation

    tradecatlabs/vibe-coding-cn

    Runs reproducible math computations and counterexample searches with SymPy, NumPy and mpmath, logging evidence without presenting results as proofs.

    17k GitHub stars~881 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Web3 Hunt Foundation

What does Web3 Hunt Foundation do?

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring. Meant to be read before touching a new protocol's code, this skill combines mindset, recon setup and target scoring for Web3 bug bounty work. Its core rule is to look for concrete actions that cost the protocol something rather than abstract vulnerabilities, and a validation template asks the hunter to spell out the setup and the exact calls.

When should I use Web3 Hunt Foundation?

Web3 Hunt Foundation fits situations like: beginning a bug bounty hunt on a new Web3 protocol; deciding whether a suspected issue is real before writing a proof of concept; scoring a bounty target and setting up the recon environment.

How do I install Web3 Hunt Foundation in Claude Code?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-foundation -a claude-code`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-foundation in tradecatlabs/vibe-coding-cn) into .claude/skills/web3-hunt-foundation in your project. Claude Code loads it when a task matches its description.

How do I install Web3 Hunt Foundation in Codex?

Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-foundation -a codex`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-foundation in tradecatlabs/vibe-coding-cn) into .agents/skills/web3-hunt-foundation in your project. Codex loads it when a task matches its description.

Can I use Web3 Hunt Foundation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-foundation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web3-hunt-foundation, .gemini/skills/web3-hunt-foundation, .github/skills/web3-hunt-foundation and .opencode/skills/web3-hunt-foundation in your project.

What does Web3 Hunt Foundation need to run?

Going by SKILL.md and its folder, Web3 Hunt Foundation needs the command-line tools its instructions call (git and vault).

Does Web3 Hunt Foundation access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Web3 Hunt Foundation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web3 Hunt Foundation use?

Web3 Hunt Foundation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web3 Hunt Foundation use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web3 Hunt Foundation?

Skills that share tags, products or a category with Web3 Hunt Foundation: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web3 Hunt Foundation?

tradecatlabs (a GitHub user) maintains it in tradecatlabs/vibe-coding-cn, which has 17,386 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: tradecatlabs/vibe-coding-cn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.