Web3 Auditor — Security agent for Claude Code
Smart contract security auditor.
How to install Web3 Auditor
Installs to ~/.claude/agents/mikacr1138-claude-bug-bounty-web3-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Mikacr1138/claude-bug-bounty/HEAD/agents/web3-auditor.md -o ~/.claude/agents/mikacr1138-claude-bug-bounty-web3-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Web3 Auditor does
name: web3-auditor description: Smart contract security auditor. Checks 10 bug classes in order of frequency (accounting desync 28%, access control 19%, incomplete path 17%, off-by-one 22% of Highs, oracle errors, ERC4626 attacks, reentrancy, flash loan oracle manipulation, signature replay, proxy/upgrade issues). Applies pre-dive kill signals first. Use for any Solidity/Rust contract audit or to check if a DeFi target is worth hunting. tools: Read, Bash, Glob, Grep model: claude-sonnet-4-6
Alternatives in Security
- JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
- GraphQL Audit — GraphQL API security specialist 812 ★
- Review Security — Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu 432 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Blockchain Web3 Specialist
Smart contract development, security auditing, and dApp integration. Use for Solidity, contract audits, wallet
Crypto Attacker
Cryptography and TLS security specialist. Handles TLS configuration auditing, JWT algorithm confusion, padding
Audit Orchestrator
End-to-end smart contract audit orchestrator with configurable modes. Takes a codebase path, optional protocol
Correctness Reviewer
Reviews code changes for logic errors, race conditions, security vulnerabilities, and edge cases. Use when per
Lens Security
Security lens of the production readiness audit. Attacks the codebase on paper - injection, SSRF, path travers
Sstack Security Attacker
Security lens attacker. Attacks every mapped surface for SQL injection, OS command injection, path traversal,
Related Skills
Web3 Audit
Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomp
/web3 Audit
Smart contract security audit using the 10-bug-class methodology.
Web3 Bug Bounty Hunting AI Skills
18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack repro