Web3 Smart Contract Audit
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .claude/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .claude/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-eraType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .agents/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .agents/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .agents/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .cursor/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .cursor/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tradecatlabs/vibe-coding-cn.git --path research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .gemini/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .gemini/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-eraInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .github/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .github/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .github/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tradecatlabs/vibe-coding-cn web3-hunt-zksync-era --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era .opencode/skills/web3-hunt-zksync-era && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "web3-hunt-zksync-era" agent skill from https://github.com/tradecatlabs/vibe-coding-cn/tree/develop/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era into .opencode/skills/web3-hunt-zksync-era/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web3-hunt-zksync-era", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
web3-hunt-zksync-eraRecords a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.
This file documents a finished bug bounty hunt on ZKsync Era through Immunefi that produced zero submittable findings across 25 tested attack vectors. It is kept as a defense study: what makes a protocol hard to hunt, which patterns block the ten bug classes, and when to stop. The target profile covers the L2 rollup, a codebase of about 750K lines of Solidity, Rust and Yul, and several prior audits including OpenZeppelin.
A pre-dive scorecard shows the target passing the TVL, payout and complexity checks while getting a warning on audit quality, and the lesson drawn is to weight the audit firm's tier more heavily for very large protocols. The file also sketches the architecture, including the L1 bridge stack, the L2 system and user-space contracts and the diamond proxy pattern with shared storage, and then tabulates the tested vectors with the reason each one failed.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5b76a8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
ZKsync Era Defense Study loads about 2.2k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 872 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tradecatlabs/vibe-coding-cn at commit 5b76a8f, republished under its MIT licence (© tradecatlabs). 872 words, ~2,246 tokens.
.claude/skills/web3-hunt-zksync-era/SKILL.md (or your agent's skills folder).Outcome: 0 submittable findings after 5+ sessions, 22+ agents, 25+ contracts, 25+ attack vectors Lesson: This file exists as a DEFENSE STUDY — what a hardened protocol looks like, and when to stop hunting.
| Field | Value |
|---|---|
| Protocol | ZKsync Era (L2 rollup) |
| Platform | Immunefi |
| TVL | $322M (L2BEAT Total Value Secured) |
| Bounty | $100K minimum Critical, $1.1M max |
| Codebase | 750K LOC (Solidity + Rust + Yul) |
| Audits | OpenZeppelin V29 (June 2025), multiple prior audits |
| Version | Protocol V29.4 |
| Repo | github.com/matter-labs/era-contracts |
| Primacy | Primacy of Impact — even out-of-scope assets qualify |
| Prior payouts | $50K (ChainLight ZK circuit bug) |
| Check | Result | Score |
|---|---|---|
| TVL > $500K | $322M | PASS |
| Max payout > $10K | $100K minimum | PASS |
| Simple protocol? | 750K LOC, L1↔L2 bridge + ZK + governance | PASS (complex) |
| < 500 lines? | 750K LOC | PASS |
| Audit quality | OpenZeppelin (top-tier) on ALL critical paths | WARNING |
REFINEMENT: Pre-dive should weight audit quality MORE for large protocols. A protocol passing TVL/LOC/payout checks can still be unhuntable if OZ/ToB audited the exact code you'd hunt. Add "audit firm tier" as a SOFT kill signal for 500K+ LOC protocols.
Bridgehub (router)
├── L1AssetRouter (token routing)
│ ├── L1Nullifier (deposit/withdrawal state)
│ └── L1NativeTokenVault (token custody)
├── ChainTypeManager (chain registration)
└── ValidatorTimelock (RBAC execution delay)Bootloader (0x8001) → AccountCodeStorage, NonceHolder, KnownCodeStorage,
ImmutableSimulator, ContractDeployer, L1Messenger (0x8008),
MsgValueSimulator, L2BaseToken (0x800a), SystemContext (0x800b),
BootloaderUtilities, Compressor, ComplexUpgraderCreate2Factory, Bridgehub, AssetRouter, NativeTokenVault, MessageRootZKChainStorage struct| # | Vector | Target | Why It Failed |
|---|---|---|---|
| 1 | UnsafeBytes offset miscalculation | L1Nullifier _parseL2WithdrawalMessage | All callers pre-validate message length before UnsafeBytes calls |
| 2 | Legacy/new boundary double-withdrawal | L1Nullifier | _isLegacyTxDataHash try/catch returns false on decode failure; encoding prefix discriminator prevents collision |
| 3 | secondBridgeAddress return value manipulation | Bridgehub requestL2TransactionTwoBridges | >0xFFFF check blocks system contracts; L2-side msg.sender auth makes crafted returns useless |
| 4 | Failed deposit claim wrong amount (legacy encoding) | L1Nullifier claimFailedDeposit | Legacy hash uses try/catch; depositHappened correctly tracks per-encoding-version |
| 5 | V29 interop root forgery | Executor | addChainBatchRoot requires onlyChain + onlyL2; historical roots verified via Merkle |
| 6 | Missing access control on sibling function | All bridge contracts | Every external function has appropriate modifier; checked all 50+ external functions |
| 7 | Fee-on-transfer token accounting desync | NativeTokenVault | L1ERC20Bridge: if (amount != _amount) revert TokensWithFeesNotSupported() |
| 8 | Governance timelock bypass | ValidatorTimelock | 5-role RBAC via AccessControlEnumerable; block.timestamp >= commitTimestamp + delay |
| # | Vector | Why It Failed |
|---|---|---|
| 9 | GatewayTransactionFilterer bypass | Era mainnet: transactionFilterer == address(0), not used |
| 10 | Precommitment sentinel collision | _revertBatches properly resets precommitment; sentinel values don't collide |
| 11 | L2→L1 message forgery via sendToL1 | Anyone can call sendToL1, but L1 verifies sender=0x8008 in log — can't forge system log sender |
| 12 | Compressor state diff manipulation | publishCompressedBytecode called only from bootloader context |
| 13 | Admin privilege escalation | Diamond proxy admin is governance; no facet can self-modify |
| 14 | Fee calculation overflow | All fee math uses SafeMath or checked arithmetic |
| 15 | Free L2 transaction abuse | reservedDynamic field properly handled; bootloader validates gas |
| 16 | DataEncoding L1/L2 mismatch | All 10 encode/decode pairs verified consistent across L1↔L2 |
| 17 | NTV token registration race | _ensureTokenRegistered is idempotent; double registration returns same assetId |
| 18 | Asset ID collision | keccak256(chainId, ntvAddress, tokenAddress) — no collision possible |
| 19 | Beacon proxy CREATE2 collision | Standard CREATE2; address determined by deployer+salt+bytecodeHash |
| 20 | Cross-contract reentrancy | Each contract has independent ReentrancyGuard AND follows CEI |
| 21 | Address aliasing collision | Bijective mapping (add/subtract offset mod 2^160) |
| 22 | Diamond proxy selector clash | Explicit selector mapping in DiamondCut; duplicates would revert |
| 23 | Priority tree manipulation | Merkle range proofs; unprocessedIndex only moves forward |
| 24 | Chain migration state corruption | forwardedBridgeMint validates consistency; atomic revert on mismatch |
| 25 | Cross-chain message replay | isWithdrawalFinalized[chainId][batch][index] prevents replay |
// L1Nullifier._finalizeDeposit (line 411)
isWithdrawalFinalized[chainId][l2BatchNumber][l2MessageIndex] = true; // EFFECT first
// ... then external call to NTVEvery single withdrawal/claim/deposit path follows Check-Effect-Interact.
Each L2 system contract independently enforces access:
L2BaseToken.transferFromTo: checks msg.sender against 3 allowed callersL1Messenger.sendToL1: open to anyone, but L1 verifies sender field in logSystemContext: onlyCallFromBootloader on all state-changing functionsLEGACY_ENCODING_VERSION = 0x00 (first byte)
NEW_ENCODING_VERSION = 0x01 (first byte)Different first byte = impossible to confuse one format for another.
Three bridge generations coexist cleanly:
Each boundary has explicit version checks, try/catch decoding, and fallback paths.
V29 OZ audit found 3 HIGHs. All fixes were thorough — not just patches but architectural improvements. The "least audited code" assumption (that fixes are hastily applied) did NOT hold here.
era-contracts releasesEvmGasManager, EVM opcode compatibility gapsL2InteropRootStorage is minimal now, but interop = massive new surfaceAdd to the scorecard:
SOFT KILL: If protocol has OZ/ToB/Cyfrin audit on current version AND codebase > 500K LOC
→ expect 40+ hours for MAYBE 1 finding
→ only proceed if bounty floor > $50K AND you have protocol-specific expertiseNEXT: 08-ai-tools.md
© tradecatlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era of tradecatlabs/vibe-coding-cn.
Open the folder on GitHubat commit 5b76a8f
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in tradecatlabs/vibe-coding-cn, which our catalogue first saw on October 7, 2026.
ZKsync Era Defense Study next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| ZKsync Era Defense Study this skilltradecatlabs/vibe-coding-cn | 17k | 2 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Flounderadshao/flounder | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | |
| Smart Contract Entry Point Analyzertrailofbits/skills | 7.5k | 1 repos | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Reentrancy Auditoralt-research2/SolidityGuard | 104 | — | ~1.8k | Automated safety check: Pass | Custom licence |
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
adshao/flounder
Operates Flounder, an autonomous white-hat security auditor.
trailofbits/skills
Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.
alt-research2/SolidityGuard
Deep reentrancy vulnerability analysis for Solidity contracts.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
tradecatlabs/vibe-coding-cn
Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.
tradecatlabs/vibe-coding-cn
A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.
tradecatlabs/vibe-coding-cn
Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
tradecatlabs/vibe-coding-cn
Runs reproducible math computations and counterexample searches with SymPy, NumPy and mpmath, logging evidence without presenting results as proofs.
Works with
Categories
Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. This file documents a finished bug bounty hunt on ZKsync Era through Immunefi that produced zero submittable findings across 25 tested attack vectors. It is kept as a defense study: what makes a protocol hard to hunt, which patterns block the ten bug classes, and when to stop.
ZKsync Era Defense Study fits situations like: learning what a well-defended L1 bridge and rollup protocol looks like; deciding when to abandon a bug bounty target after repeated dead ends; refining pre-dive scoring for protocols with very large codebases; reviewing a log of attack vectors that were tried and why each failed.
Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a claude-code`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era in tradecatlabs/vibe-coding-cn) into .claude/skills/web3-hunt-zksync-era in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a codex`. Or copy the skill folder (research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-hunt-zksync-era in tradecatlabs/vibe-coding-cn) into .agents/skills/web3-hunt-zksync-era in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tradecatlabs/vibe-coding-cn --skill web3-hunt-zksync-era -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web3-hunt-zksync-era, .gemini/skills/web3-hunt-zksync-era, .github/skills/web3-hunt-zksync-era and .opencode/skills/web3-hunt-zksync-era in your project.
SKILL.md names no scripts, command-line tools or credentials: ZKsync Era Defense Study is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
ZKsync Era Defense Study is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with ZKsync Era Defense Study: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Fizz (pashov/skills, 1.2k stars), Flounder (adshao/flounder, 518 stars) and Smart Contract Entry Point Analyzer (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tradecatlabs (a GitHub user) maintains it in tradecatlabs/vibe-coding-cn, which has 17,386 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.
Source: tradecatlabs/vibe-coding-cn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.