Skip to content
Security
Skill

/web3-ai-tools

AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.

BOOST
From plugin
tradecatlabs-vibe-coding-cn
17k18 skills
Install
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill web3-ai-tools --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/web3-ai-tools

Context preview

The summary Claude sees to decide when to auto-load this skill.

AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.

SKILL.md

web3-ai-tools.SKILL.md
name: web3-ai-tools
description: AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.
Contains: CAI Framework, Shannon AI pentester, LuaN1ao dual-graph agent, SmartGuard multi-agent auditor, AI-generated code hunting patterns, Claude security skills.

AI TOOLS ARSENAL

> AI-powered automation for every phase of Web3 bug hunting. > Replaces: 28-cai-framework, 29-claude-skills-security, 30-shannon-ai-pentester, > 31-luan1ao-agent, 32-ai-generated-code-hunting, 33-smartguard-agent

---

TOOL SELECTION GUIDE

| Tool | Target Type | Best For | Cost | |------|------------|----------|------| | **Shannon** | Web apps + API (white-box) | IDOR, SQLi, SSRF, auth bypass | ~$50/run | | **LuaN1ao** | Any web target | Autonomous OWASP Top 10 | $0.09/exploit | | **CAI** | Web/network/IoT | Bug bounty recon + validation | API cost only | | **SmartGuard** | Solidity files | Auto PoC generation for SC bugs | API cost | | **AI Code Hunt** | AI-written contracts | Bugs Slither/Forge miss | Manual (patterns) |

**For DeFi smart contracts:** SmartGuard + AI Code Hunt patterns **For DeFi web frontends:** Shannon (web layer) + skills 01-07 (contract layer) **For CTF/web targets:** LuaN1ao or CAI

---

TOOL 1: SHANNON — AUTONOMOUS WEB PENTESTER

**Source:** github.com/KeygraphHQ/shannon **Score:** 96.15% on XBOW source-aware benchmark (100/104 exploits) **Model:** Claude Agent SDK (Anthropic) **Cost:** ~$50/run | ~1-1.5 hours

What Shannon Finds

✅ IDOR — changes IDs across accounts, tests all API routes
✅ SQLi — error-based and time-based blind
✅ Command injection — OS separators in all inputs
✅ XSS — reflected + stored (confirmed in real browser)
✅ SSRF — webhook/fetch URL inputs, OOB callbacks
✅ JWT attacks — alg:none, RS256→HS256 confusion, weak keys
✅ Auth bypass — session fixation, forgot-password flaws
✅ Privilege escalation — viewer→admin, cross-tenant
✅ OAuth misconfigs — state parameter, redirect_uri

❌ Race conditions (sequential, not concurrent)
❌ Business logic (needs domain expertise)
❌ Smart contract bugs — use files 01-07 for these
❌ Novel techniques not in prompt templates

Setup

git clone https://github.com/KeygraphHQ/shannon
cd shannon && npm install
cp .env.example .env  # Add: ANTHROPIC_API_KEY=sk-ant-...
npm run build

# Direct mode (simple):
node dist/index.js --config configs/my-target.yaml

# Docker (includes nmap, subfinder, whatweb):
docker run --env-file .env \
  -v ./configs:/app/configs \
  keygraph/shannon:latest \
  --config configs/my-target.yaml

Config Template

# configs/target.yaml
target:
  name: "DeFi App Frontend"
  url: "https://app.DEFI.com"
  source_path: "/path/to/frontend/clone"  # white-box = much better
  additional_context: |
    DeFi app. Users connect MetaMask wallets.
    Focus on: IDOR in /api/portfolio?address=0x...,
    GraphQL introspection, JWT handling, SSRF via webhooks.
    DO NOT interact with smart contracts.

authentication:
  login_type: form  # form | sso | api | basic
  login_url: "https://app.DEFI.com/login"
  credentials:
    username: "attacker@test.com"
    password: "testpassword"
  login_flow:
    - "Fill in username field with $username"
    - "Fill in password field with $password"
    - "Click the login button"
  success_condition:
    type: url
    value: "/dashboard"

test_accounts:
  - username: "attacker@test.com"
    password: "testpassword"
    role: "viewer"
  - username: "victim@test.com"
    password: "victimpassword"
    role: "admin"

scope:
  include: ["https://app.DEFI.com/*"]
  exclude: ["https://app.DEFI.com/admin/destroy-all"]

The Shannon Workflow

YOUR PLAN:
1. Setup config + 2 test accounts (15 min)
2. Run Shannon (90 min) → do MANUAL business logic testing while it runs
3. Review Shannon findings (30 min) → verify each PoC manually
4. Manual hunting for what Shannon misses: race conditions, business logic, contract layer (60 min)
5. Write reports adapting Shannon's PoC to Immunefi/H1 format (30 min)

Shannon + manual = 4 hours → coverage that takes 2 days manually.

**WARNINGS:**

  • NEVER run on production without explicit written authorization
  • Check program rules: many prohibit automated scanning → instant rejection + ban
  • Only worth it for targets with max bounty ≥ $5K (costs ~$50)
  • Always verify findings manually before submitting — LLMs can hallucinate

---

TOOL 2: LUAN1AO — DUAL-GRAPH AUTONOMOUS PENTESTER

**Source:** github.com/SanMuzZzZz/LuaN1aoAgent **Score:** 90.4% on XBOW Benchmark (beats commercial XBOW at 85%) **Architecture:** Causal Graph + Plan-on-Graph (PoG) | P-E-R (Planner-Executor-Reflector) **Cost:** $0.09 median per exploit

What Makes LuaN1ao Different

  • **Causal Graph:** Every action requires evidence → no hallucinated attacks
  • **Plan-on-Graph:** DAG that rewrites itself mid-test → parallel independent paths
  • **Reflector:** L1-L4 failure attribution → learns from failures mid-run

Evidence Chain Example

Port scan → 3306/tcp open
  → Hypothesis: MySQL running (confidence 0.8)
  → Validated: banner confirms MySQL 5.7
  → Vulnerability: empty root password
  → Exploit: mysql -h target -u root -p

Setup

git clone https://github.com/SanMuzZzZz/LuaN1aoAgent && cd LuaN1aoAgent
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
# Edit .env: set LLM_API_KEY + LLM_API_BASE_URL

# Build RAG knowledge base (one-time, ~5 min):
mkdir -p knowledge_base
git clone https://github.com/swisskyrepo/PayloadsAllTheThings knowledge_base/PayloadsAllTheThings
cd rag && python -m rag_kdprepare && cd ..

# Run:
python agent.py \
  --goal "Comprehensive web security testing on http://target.com" \
  --task-name "hunt_01" \
  --web  # enables Web UI at localhost:8088

Key Config

LLM_PLANNER_MODEL=claude-sonnet-4-6
LLM_EXECUTOR_MODEL=claude-sonnet-4-6
Read more
Ships withtradecatlabs-vibe-coding-cn

从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题

Get the whole plugin