w3hunt

Automate web3 bug bounty hunts across Immunefi hybrid programs.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill w3hunt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: w3hunt
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/w3hunt
Command: npx skills add https://github.com/n4igme/randscript --skill w3hunt

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires hermes_tools, pyyaml, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Automates and orchestrates end-to-end Web3 bug-bounty engagements on Immunefi, guiding researchers from triage to exploit submission.

Core Features & Use Cases

  • Phase-driven workflow spanning Triaged, Recon, Web Assessment, SC Audit, and Exploit/Submit.
  • Integrated references, scripts, and tooling for reproducible investigations.
  • Gate-driven progression with state tracking and postmortem ROI metrics to inform future hunting decisions.

Quick Start

Run the w3hunt skill to initialize a session and guide you through Phase 1 triage.

Frequently Asked Questions about w3hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate Web3 bug bounty hunts on Immunefi?

Automate Web3 bug bounty hunts on Immunefi by orchestrating end-to-end engagements from triage to exploit submission, applying phase-driven workflows to recon, web assessment, and smart contract audits for reproducible findings.

What is the best way to structure a smart contract audit for a DeFi frontend?

Structure a smart contract audit for DeFi frontends using a gate-driven phase progression spanning recon, web assessment, and SC audit, linking to phased references and executing script-powered tasks for reproducible investigations.

Does this bug bounty workflow support hybrid Immunefi programs?

This bug bounty workflow supports Immunefi's hybrid programs, targeting DeFi frontends with on-chain components to enable recon, web assessment, SC audit, and exploit submission workflows with state tracking.

How do I track ROI metrics after a Web3 bug hunt?

Track ROI metrics after a Web3 bug hunt by utilizing built-in postmortem analysis and state tracking that evaluates engagement outcomes to inform future hunting decisions across hybrid programs.

Do I need hermes_tools to execute phase-driven bug bounty scripts?

You need hermes_tools and pyyaml dependencies to execute phase-driven bug bounty scripts, enabling gate-driven progression and reproducible findings across triaged recon and exploit submission phases.