home/categories/smart-contracts/shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-bug-classes-skill-md
smart-contractsblockchain

web3-bug-classes

Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs.

shuvonsec
maintainer
shuvonsec
Updated 3/14/2026
Stars
45
Forks
16
quick start

Installation and usage

Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs.

Installation
$ install --globalskills.sh
Usage

Once installed, you can use this skill by running the following command in your terminal:

skills use web3-bug-classes