本文へ移動
cccskills
無料GitHub で公開

web3-start-here

Master index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

WEB3 SKILLS — MASTER INDEX

Built from: 2,749 Immunefi reports + 100+ paid writeups + DeFiHackLabs (681 hacks) + ConsenSys + SlowMist + Trail of Bits + Foundry + Nethermind + Lido + AI agent research + live hunt experience


THE CHAIN (read in this exact order)

00-START-HERE.md              ← YOU ARE HERE
01-foundation.md              ← Mindset, target selection, recon setup
02-bug-classes.md             ← All 10 bug classes with patterns + real examples
03-grep-arsenal.md            ← Master grep patterns for every class
04-poc-and-foundry.md         ← Foundry PoC writing, cheatcodes, 18 exploit templates
05-triage-report-examples.md  ← 7-Question Gate, report format, 20 real paid examples
06-methodology-research.md    ← ToB, SlowMist, ConsenSys, Immunefi, Cyfrin, Lido, Nethermind
07-live-hunt-ern.md           ← Completed hunt: Ern protocol (2 findings)
09-live-hunt-zksync.md        ← Completed hunt: ZKsync Era (0 findings — defense study)
08-ai-tools.md                ← Shannon, LuaN1ao, SmartGuard, CAI Framework, AI code hunting
36-solidity-audit-mcp.md      ← MCP server: Slither+Aderyn+SWC in Claude Code

HOW TO USE THIS

  1. Read one file fully — every section
  2. At the bottom: follow → NEXT
  3. After file 05: you can hunt independently
  4. Files 06-08: advanced tools + active work
  5. File 36: MCP integration for live scanning

QUICK STATS

MetricNumber
Immunefi reports analyzed2,749
Protocols covered51
Critical reports406
High reports616
Total paid by Immunefi$100M+
Avg critical payout$50K–$2M
Nethermind reports analyzed166
DeFiHackLabs hacks reproduced681

THE ONE RULE

"Read ALL sibling functions. If vote() has a modifier, check poke(), reset(), harvest(). The missing modifier on the sibling IS the bug."

This single rule explains 19% of all Critical findings.


→ NEXT: 01-foundation.md

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and arithmetic bugs BEFORE deploying to an EVM chain. Also enforces key hygiene (no plaintext private keys, encrypted cast keystore) and a secure deploy workflow. Use when writing, reviewing, testing, or deploying Solidity/Foundry contracts, building a dApp, or working with forge/cast/anvil, MetaMask, or Web3/DeFi code.

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

Claude Skills meta-skill: extract domain material (docs/APIs/code/specs) into a reusable Skill (SKILL.md + references/scripts/assets), and refactor existing Skills for clarity, activation reliability, and quality gates.

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

auto-tmux

無料

tmux 自动化操控:用 scripts/auto-tmux.sh 安全读取、发送、巡检、救援、录制 session|window|pane,用 swarm-state.sh 管理蜂群任务/锁/状态,并基于 oh-my-tmux 组织多 AI 终端协作。触发:capture-pane、send-keys、批量巡检、蜂群 AI 协作、卡死救援、tmux 工作台初始化。

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

可重跑的数学计算与反例实验。用于 SymPy 精确代数/微积分/方程/矩阵、NumPy/SciPy 数值方法、mpmath 高精度交叉检查、OEIS 序列识别、有限范围反例搜索和计算证据记录。

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

数学公式与理论线推导。用于整理散乱公式、固定不变量和记号、推导恒等式/近似/局部命题、检查隐藏假设,或把理论笔记变成可审计推导包。

日本語の概要は準備中です。原文の説明を表示しています。

tradecatlabs/vibe-coding-cn1.7万2026年10月10日 更新

tradecatlabs のスキルをすべて見る

このスキルの問題を報告する