Md Shariar Shanaz Shuvon
Community@shuvonsec · Malaysia
NASA-Recognized Ethical Hacker | World’s #1 Hacker on TryHackMe Monthly Leaderboard | Building AI-Powered Security Tools
Agent Skills by Md Shariar Shanaz Shuvon
Showing 22 vetted skills indexed across 2 GitHub repositories.
meme-coin-audit
Detects rug pull patterns and authority risks in EVM and Solana token contracts.
cicd-security
Detects CI/CD pipeline vulnerabilities including workflow injection, secret exfiltration, and runner poisoning.
report-writing
Writes impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.
argus
Scans web targets for CORS, CRLF, NoSQLi, JWT, blind OOB, and LLM vulnerabilities.
client-reverse
Reverse client-side request signing to replay and fuzz protected APIs.
mobile-pentest
Tests Android and iOS apps for bug bounty via proxy interception, decompilation, and runtime instrumentation.
bb-methodology
Orchestrates bug bounty hunting sessions using a five-phase workflow and critical thinking framework.
triage-validation
Validates bug bounty findings through a 7-question gate before report submission.
web2-recon
Automates web reconnaissance from subdomain enumeration through URL crawling to prioritized attack surface mapping.
web3-audit
Audit Solidity and Rust smart contracts for ten DeFi vulnerability classes with grep patterns and Foundry PoC templates.
web3-ai-tools
Automate Web3 bug bounty workflows with AI agents for recon, auditing, and PoC generation.
web3-hunt-foundation
Set up Web3 bug bounty hunts with mindset, recon, and a 10-point scorecard.
web3-bug-classes
Identify DeFi smart contract vulnerability classes for secure code reviews.
web3-triage-report
Triage smart-contract bug reports and format Immunefi-style vulnerability reports.
web3-case-study-role-misconfig
Audit role-based access controls in yield-aggregator contracts to detect missing DISTRIBUTOR_ROLE grants.
web3-poc-foundry
Assemble runnable Foundry PoC projects from templates and cheatcodes.
web3-solidity-audit-mcp
Audit Solidity contracts with Slither, Aderyn, and SWC detectors.
web3-methodology-research
Synthesize external audit methodology research from Web3 security sources.
web3-hunt-zksync-era
Analyze defense patterns in the ZKsync Era L2 bridge protocol.
web3-start-here
Navigate web3 smart contract security guides from 00-START-HERE.md to 36-solidity-audit-mcp.md.
web3-grep-arsenal
Run grep blocks to surface vulnerability patterns in Web3 smart contracts.
bug-bounty
Automate bug bounty workflows from reconnaissance to report writing.