Skip to content
Security
Skill

/web3-grep-arsenal

Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.

BOOST
From plugin
tradecatlabs-vibe-coding-cn
17k18 skills
Install
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill web3-grep-arsenal --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/web3-grep-arsenal

Context preview

The summary Claude sees to decide when to auto-load this skill.

Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.

SKILL.md

web3-grep-arsenal.SKILL.md
name: web3-grep-arsenal
description: Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.
Contains: 10 grep blocks for all major vuln classes, tier ranking, protocol-specific patterns, 2025 new patterns, copy-paste ready blocks.

GREP ARSENAL — MASTER REFERENCE

> All grep commands in one place. Run in the first 30 minutes of any new target. > Replaces: 03-grep-surface-map, 14-grep-master-patterns + grep sections from 04-13

---

HOW TO USE THE SURFACE MAP

**Process:** 1. Run ALL 10 blocks below (takes ~5 min) 2. Collect all results in a notes file 3. Tier-rank the hits (see Tier System below) 4. In pass 1: READ everything, DON'T investigate yet 5. In pass 2: Deep-dive on Tier 1 + 2 items

**Tier System:**

  • **Tier 1** — Near privileged code, external calls, or state changes with no guards → Investigate first
  • **Tier 2** — Interesting patterns that need context before judging → Investigate after Tier 1
  • **Tier 3** — Informational only (documentation, test files, comments) → Skip unless Tier 1+2 exhausted

---

THE 10 GREP BLOCKS (Copy-Paste Each)

Block 1 — Access Control

echo "=== ACCESS CONTROL ===" && \
grep -rn "tx\.origin" src/ --include="*.sol" && \
grep -rn "msg\.sender == owner\b" src/ --include="*.sol" && \
grep -rn "modifier only" src/ --include="*.sol" -A5 && \
grep -rn "onlyOwner\|onlyAdmin\|onlyRole" src/ --include="*.sol" | wc -l && \
grep -rn "def admin_\|router\..*admin\|function.*[Aa]dmin" src/ --include="*.sol"

**Red flags:**

  • `tx.origin` used for auth → Tier 1 (phishing vector)
  • Modifier uses `if (condition) { _; }` without else → Tier 1 (silent bypass — function still executes for unauthorized callers)
  • `onlyOwner` count << total external function count → likely missing guards on siblings

Block 2 — Reentrancy

echo "=== REENTRANCY ===" && \
grep -rn "\.call{value\|\.call(" src/ --include="*.sol" && \
grep -rn "\.transfer(\|\.send(" src/ --include="*.sol" && \
grep -rn "safeTransfer\|safeTransferFrom" src/ --include="*.sol" && \
grep -rn "onERC721Received\|onERC1155Received\|tokensReceived" src/ --include="*.sol" && \
grep -rn "nonReentrant\|ReentrancyGuard" src/ --include="*.sol"

**Red flags:**

  • `.call{value:}` or `safeTransfer` BEFORE state updates in same function → Tier 1 (CEI violation)
  • `onERC721Received`/`onERC1155Received` hooks present → check for reentrancy path
  • External calls present but `nonReentrant` missing → verify CEI is followed

Block 3 — Oracle / Price

echo "=== ORACLE / PRICE ===" && \
grep -rn "slot0\b" src/ --include="*.sol" && \
grep -rn "getReserves()" src/ --include="*.sol" && \
grep -rn "latestRoundData\|latestAnswer" src/ --include="*.sol" && \
grep -rn "updatedAt" src/ --include="*.sol" && \
grep -rn "block\.timestamp" src/ --include="*.sol" | grep -v "//\|test\|Test" | head -20

**Red flags:**

  • `slot0()` used for price → Tier 1 (Uniswap V3 spot, flash-loan manipulable)
  • `getReserves()` used for price → Tier 1 (Uniswap V2 spot, flash-loan manipulable)
  • `latestRoundData` without `updatedAt` check → Tier 1 (stale Chainlink price)
  • `latestAnswer` → Tier 1 (deprecated, no round validation)

Block 4 — Arithmetic / Math

echo "=== ARITHMETIC ===" && \
grep -rn "unchecked {" src/ --include="*.sol" && \
grep -rn "/ \|/=" src/ --include="*.sol" | grep -v "//\|test\|Test" | head -30 && \
grep -rn "mulDiv\|FullMath\|PRBMath" src/ --include="*.sol" && \
grep -rn "\* 10\*\*\|* 1e18\|* WAD\|* RAY" src/ --include="*.sol"

**Red flags:**

  • `unchecked {}` blocks → manually verify each (Solidity 0.8+ unwraps here)
  • Division before multiplication (`a / b * c`) → precision loss
  • `/ 1e18` in contract that handles 6-decimal tokens → decimal mismatch

Block 5 — Input Validation

echo "=== INPUT VALIDATION ===" && \
grep -rn "address(0)\b" src/ --include="*.sol" && \
grep -rn "require.*length\|\.length ==" src/ --include="*.sol" && \
grep -rn "delegatecall" src/ --include="*.sol" && \
grep -rn "abi\.decode\|abi\.encodePacked" src/ --include="*.sol" | head -20

**Red flags:**

  • `delegatecall` with user-controlled target → Tier 1 (arbitrary code execution)
  • `abi.decode` on user-supplied calldata without length validation → Tier 1
  • Array params in batch functions without dedup check → Tier 1 (double-count attack)

Block 6 — Token Handling

echo "=== TOKEN HANDLING ===" && \
grep -rn "IERC20\.\|ERC20\." src/ --include="*.sol" | grep "transfer\b\|transferFrom\b" && \
grep -rn "SafeERC20\|safeTransfer\b" src/ --include="*.sol" | head -10 && \
grep -rn "balanceOf(address(this))" src/ --include="*.sol" && \
grep -rn "permit(" src/ --include="*.sol" | grep -v "//\|IERC20Permit" && \
grep -rn "try.*permit\|catch.*permit" src/ --include="*.sol"

**Red flags:**

  • `token.transfer()` without `SafeERC20.safeTransfer()` → Tier 1 (return value unchecked, fails silently on old USDT)
  • `balanceOf(address(this))` for pricing/shares → Tier 1 (donation attack vector)
  • `permit()` without try/catch wrapper → Tier 2 (frontrun DoS possible)

Block 7 — ERC4626 / Vault

echo "=== ERC4626 / VAULT ===" && \
grep -rn "totalAssets\|convertToShares\|previewDeposit\|previewMint" src/ --include="*.sol" && \
grep -rn "_decimalsOffset\|decimalsOffset\|virtual_shares\|dead.*shares" src/ --include="*.sol" && \
grep -rn "shares.*supply\|totalSupply\|mint.*shares" src/ --include="*.sol" | head -20

**Red flags:**

  • ERC4626 present but `_decimalsOffset()` NOT present → Tier 1 (first depositor inflation)
  • `totalAssets()` uses `balanceOf(address(this))` → Tier 1 (donation attack)
  • `mint()` or `deposit()` called without same validation path → Tier 1 (MetaPool bug: mint skipped receipt check)

Block 8 — Proxy / Upgradeable

echo "=== PROXY / UPGRADE ===" && \
grep -rn "_authorizeUpgrade\|upgradeTo\|upgradeToAndCall" src/ --includ
Read more
Ships withtradecatlabs-vibe-coding-cn

从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题

Get the whole plugin