What problem does it solve?
This Skill eliminates the risk of missing critical smart contract vulnerabilities in DeFi protocols that can lead to catastrophic financial losses, and helps security researchers identify high-impact bugs to earn legitimate bug bounties.
Core Features & Use Cases
- 10 Core DeFi Bug Classes: Covers accounting desync, access control, reentrancy, flash loan attacks, oracle manipulation, and other high-severity vulnerability types with real Immunefi paid examples.
- Pre-Dive Target Filtering: Kill signals and scoring rubric to skip low-value engagements (e.g., low TVL, already well-audited protocols) and focus on high-ROI targets.
- Audit Tooling Templates: Includes Foundry proof-of-concept templates, grep patterns for automated bug detection, and 2026-specific operator notes for current DeFi attack surfaces.
- Use Case: Ideal for authorized smart contract audits, DeFi bug bounty hunting on platforms like Immunefi, and triaging new protocol targets before committing to a full code review.
Quick Start
Use the web3-audit skill to review the target DeFi protocol's Solidity smart contracts for critical vulnerabilities and generate a compliant Foundry proof-of-concept for any confirmed findings.