analyzing-ethereum-sma…
Perform static and symbolic analysis of Solidity smart contracts using
Bug triage validation system, Immunefi report format, and 20 real paid bounty examples dissected. Use this when validating a finding before submitting, writing an Immunefi report, checking if a bug is actually valid, or studying real examples of paid vulnerabilities.
$ npx -y skills add tradecatlabs/vibe-coding-cn --skill web3-triage-report --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/web3-triage-reportContext preview
The summary Claude sees to decide when to auto-load this skill.
Bug triage validation system, Immunefi report format, and 20 real paid bounty examples dissected. Use this when validating a finding before submitting, writing an Immunefi report, checking if a bug is actually valid, or studying real examples of paid vulnerabilities.
name: web3-triage-report description: Bug triage validation system, Immunefi report format, and 20 real paid bounty examples dissected. Use this when validating a finding before submitting, writing an Immunefi report, checking if a bug is actually valid, or studying real examples of paid vulnerabilities.
---
Ask these IN ORDER before writing a single word of your report. ONE wrong answer = STOP and move on.
---
Complete this template:
1. Setup: [what I need] 2. Call: [exact function, exact params] 3. Result: [what I have that I didn't have before] 4. Cost: [gas + capital] 5. ROI: [profit / cost ratio]
If you cannot complete steps 2 and 3 with specific function calls: **KILL IT.**
---
Go to the Immunefi program page. Find "Impacts in Scope." Match your bug to one of these EXACTLY.
Example impact tiers:
If your bug does not match any impact in scope: **KILL IT.**
---
Confirm the exact deployed address is in scope on the program page.
If the bug is in Aave, Uniswap, OpenZeppelin, or any external dependency: **KILL IT.**
---
"Admin can drain funds" = centralization risk = **KILL IT.** "Admin can set parameter X which under condition Y creates DoS" = borderline.
Salvage path: can the bug trigger WITHOUT the admin doing anything unusual?
---
Find the audit reports for the protocol. Search for "Risk Accepted," "Acknowledged," "Won't Fix."
If your bug matches a known finding: **KILL IT.**
Edge case: if acknowledged finding + NEW code around it creates a new attack path → that is a new bug, not the acknowledged one. Must prove the new path.
---
Attacker spends: gas + capital Attacker gains: tokens stolen or protocol damaged If profit < cost: KILL IT.
Example:
---
If yes: **KILL IT.**
---
Score = Impact × Likelihood × Exploitability (each 1–3)
| | Impact=1 (info leak) | Impact=2 (partial) | Impact=3 (theft/freeze) | |--|--|--|--| | L=1 E=1 | 1 (Info) | 2 (Low) | 3 (Low) | | L=2 E=2 | 4 (Medium) | 8 (High) | 12 (High) | | L=3 E=3 | 9 (High) | 18 (Critical) | 27 (Critical) |
**Rule: When borderline, round DOWN. Over-classification destroys credibility.**
---
Before writing your report, fill in this attack scenario:
Protocol: [name] Target contract: [address + function] Preconditions: [what state must exist?] Attack sequence: 1. Attacker calls [exact function] with [exact params] 2. [What happens in the contract] 3. [What state changes] 4. Attacker ends up with: [X more tokens / broken state / DoS] Total cost: [gas estimate + capital requirement] Total gain: [$X stolen / $Y TVL frozen] Viable? [yes/no + reason]
If you can't fill in steps 1–4 with specific values, the bug is not ready to submit.
---
A triager reviewing your report will immediately check:
If your report can't pass this checklist: revise before submitting.
---
| Condition | Severity drops | |-----------|---------------| | Requires specific admin configuration | -1 level | | Impact limited to a small subset of users | -1 level | | Requires long time window (>24h) to exploit | -1 level | | Protocol can detect and pause before loss | -1 level | | Impact is yield loss, not principal loss | -1 level | | Bug is theoretical with no practical attack | Down to Info | | Attack costs more than attacker gains | Invalid |
---
| Bug | Valid? | Reason | |-----|--------|--------| | DISTRIBUTOR_ROLE never granted → claimFor() permanently uncallable | **Valid (Medium)** | Deployment bug, not admin action, real impact on users | | `- 1` strands 1 wei per harvest | **Valid (Low/Info)** | Real, quantified, honest about minor impact | | Front-run harvest (acknowledged in prior audit) | **Invalid** | Known issue = instant rejection | | Admin can change fee to 100% | **Invalid** | Centralization risk = almost always OOS | | Harvest DoS via dust (requires admin misconfiguration) | **Borderline** | Must prove it triggers without unusual admin action | | ecrecover returns address(0) = anyone can pass | **Valid (Critical)** | No precon
从想法到产品的 AI 结对编程工作流标准:Prompt + Skill + Context + Quality Gate + 工程闭环 <!-- 徽章区域 (BADGES) --> 本仓库的 AI 解读链接:zread.ai/tukuaiai/vibe-coding-cn 🧠 六条核心命题
Repo: tradecatlabs/vibe-coding-cn
Perform static and symbolic analysis of Solidity smart contracts using
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines…
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run…
Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for…
Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a…
Master grep command arsenal for Web3 smart contract auditing. Use when starting a new…