analyzing-ethereum-sma…
Perform static and symbolic analysis of Solidity smart contracts using
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill web3-ai-tools --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/web3-ai-toolsContext preview
The summary Claude sees to decide when to auto-load this skill.
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.
name: web3-ai-tools description: AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery. Contains: CAI Framework, Shannon AI pentester, LuaN1ao dual-graph agent, SmartGuard multi-agent auditor, AI-generated code hunting patterns, Claude security skills.
> AI-powered automation for every phase of Web3 bug hunting. > Replaces: 28-cai-framework, 29-claude-skills-security, 30-shannon-ai-pentester, > 31-luan1ao-agent, 32-ai-generated-code-hunting, 33-smartguard-agent
---
| Tool | Target Type | Best For | Cost | |------|------------|----------|------| | **Shannon** | Web apps + API (white-box) | IDOR, SQLi, SSRF, auth bypass | ~$50/run | | **LuaN1ao** | Any web target | Autonomous OWASP Top 10 | $0.09/exploit | | **CAI** | Web/network/IoT | Bug bounty recon + validation | API cost only | | **SmartGuard** | Solidity files | Auto PoC generation for SC bugs | API cost | | **AI Code Hunt** | AI-written contracts | Bugs Slither/Forge miss | Manual (patterns) |
**For DeFi smart contracts:** SmartGuard + AI Code Hunt patterns **For DeFi web frontends:** Shannon (web layer) + skills 01-07 (contract layer) **For CTF/web targets:** LuaN1ao or CAI
---
**Source:** github.com/KeygraphHQ/shannon **Score:** 96.15% on XBOW source-aware benchmark (100/104 exploits) **Model:** Claude Agent SDK (Anthropic) **Cost:** ~$50/run | ~1-1.5 hours
✅ IDOR — changes IDs across accounts, tests all API routes ✅ SQLi — error-based and time-based blind ✅ Command injection — OS separators in all inputs ✅ XSS — reflected + stored (confirmed in real browser) ✅ SSRF — webhook/fetch URL inputs, OOB callbacks ✅ JWT attacks — alg:none, RS256→HS256 confusion, weak keys ✅ Auth bypass — session fixation, forgot-password flaws ✅ Privilege escalation — viewer→admin, cross-tenant ✅ OAuth misconfigs — state parameter, redirect_uri ❌ Race conditions (sequential, not concurrent) ❌ Business logic (needs domain expertise) ❌ Smart contract bugs — use files 01-07 for these ❌ Novel techniques not in prompt templates
git clone https://github.com/KeygraphHQ/shannon cd shannon && npm install cp .env.example .env # Add: ANTHROPIC_API_KEY=sk-ant-... npm run build # Direct mode (simple): node dist/index.js --config configs/my-target.yaml # Docker (includes nmap, subfinder, whatweb): docker run --env-file .env \ -v ./configs:/app/configs \ keygraph/shannon:latest \ --config configs/my-target.yaml
# configs/target.yaml
target:
name: "DeFi App Frontend"
url: "https://app.DEFI.com"
source_path: "/path/to/frontend/clone" # white-box = much better
additional_context: |
DeFi app. Users connect MetaMask wallets.
Focus on: IDOR in /api/portfolio?address=0x...,
GraphQL introspection, JWT handling, SSRF via webhooks.
DO NOT interact with smart contracts.
authentication:
login_type: form # form | sso | api | basic
login_url: "https://app.DEFI.com/login"
credentials:
username: "attacker@test.com"
password: "testpassword"
login_flow:
- "Fill in username field with $username"
- "Fill in password field with $password"
- "Click the login button"
success_condition:
type: url
value: "/dashboard"
test_accounts:
- username: "attacker@test.com"
password: "testpassword"
role: "viewer"
- username: "victim@test.com"
password: "victimpassword"
role: "admin"
scope:
include: ["https://app.DEFI.com/*"]
exclude: ["https://app.DEFI.com/admin/destroy-all"]YOUR PLAN: 1. Setup config + 2 test accounts (15 min) 2. Run Shannon (90 min) → do MANUAL business logic testing while it runs 3. Review Shannon findings (30 min) → verify each PoC manually 4. Manual hunting for what Shannon misses: race conditions, business logic, contract layer (60 min) 5. Write reports adapting Shannon's PoC to Immunefi/H1 format (30 min) Shannon + manual = 4 hours → coverage that takes 2 days manually.
**WARNINGS:**
---
**Source:** github.com/SanMuzZzZz/LuaN1aoAgent **Score:** 90.4% on XBOW Benchmark (beats commercial XBOW at 85%) **Architecture:** Causal Graph + Plan-on-Graph (PoG) | P-E-R (Planner-Executor-Reflector) **Cost:** $0.09 median per exploit
Port scan → 3306/tcp open → Hypothesis: MySQL running (confidence 0.8) → Validated: banner confirms MySQL 5.7 → Vulnerability: empty root password → Exploit: mysql -h target -u root -p
git clone https://github.com/SanMuzZzZz/LuaN1aoAgent && cd LuaN1aoAgent python3 -m venv venv && source venv/bin/activate pip install -r requirements.txt cp .env.example .env # Edit .env: set LLM_API_KEY + LLM_API_BASE_URL # Build RAG knowledge base (one-time, ~5 min): mkdir -p knowledge_base git clone https://github.com/swisskyrepo/PayloadsAllTheThings knowledge_base/PayloadsAllTheThings cd rag && python -m rag_kdprepare && cd .. # Run: python agent.py \ --goal "Comprehensive web security testing on http://target.com" \ --task-name "hunt_01" \ --web # enables Web UI at localhost:8088
LLM_PLANNER_MODEL=claude-sonnet-4-6 LLM_EXECUTOR_MODEL=claude-sonnet-4-6
从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题
Repo: tradecatlabs/vibe-coding-cn
Perform static and symbolic analysis of Solidity smart contracts using
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines…
Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for…
Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a…
Master grep command arsenal for Web3 smart contract auditing. Use when starting a new…
Hunter mindset, recon setup, and target scoring for Web3 bug bounty. Use at the START of any…