/web3-audit banner
shuvonsec shuvonsec

/web3-audit

Security community intermediate

Description

Smart contract security audit using the 10-bug-class methodology.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

Repository README

This is the README for shuvonsec/claude-bug-bounty, shared by 16 entries in this directory. It describes the repository, not this entry specifically.


description: Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626, reentrancy, flash loan, signature replay, proxy/upgrade). Applies pre-dive kill signals first. Generates Foundry PoC template for confirmed findings. Usage: /web3-audit

/web3-audit

Smart contract security audit using the 10-bug-class methodology.

Usage

/web3-audit VulnerableContract.sol
/web3-audit https://github.com/protocol/contracts
/web3-audit [paste contract code]

Step 0: Pre-Dive Kill Signals

ALWAYS check these BEFORE reading any code:

1. TVL < $500K → max payout too low for effort → SKIP
2. 2+ top-tier audits (Halborn, ToB, Cyfrin, OZ) on simple protocol → SKIP
3. Protocol < 500 lines, single A→B→C flow → minimal attack surface → SKIP
4. max_payout = min(10% × TVL, program_cap) → if < $10K → SKIP

Formula: Is [TVL * 10%] > [hours I'll spend * hourly rate]? If not, skip.

Only proceed if score >= 6/10:

  • TVL > $10M: +2
  • Immunefi Critical >= $50K: +2
  • No top-tier audit on current version: +2
  • < 30 days since deploy: +1
  • Protocol you've hunted before: +1
  • Upgradeable proxies present: +1

Step 1: Accounting State Desynchronization (28% of Criticals)

# Find accounting variables
grep -rn "totalSupply\|totalShares\|totalAssets\|totalDebt\|cumulativeReward" contracts/

# Find ALL early returns in critical functions
grep -rn "\breturn\b" contracts/ -B3 | grep -B3 "if\b"

Check: For each early return in claim/redeem/withdraw functions:

  • Which state variables are updated in the normal path?
  • Are ALL of them also updated in the early return path?
  • If A updated but B isn't → potential desync bug

Step 2: Access Control (19% of Criticals)

# Sibling function families — do ALL have same modifier set?
grep -rn "function vote\|function poke\|function reset\|function update\|function claim\|function harvest" contracts/ -A2

# Ownership check: existence vs ownership
grep -rn "_requireOwned\|ownerOf\|_isApprovedOrOwner" contracts/ -B5

# Silent modifiers (if without revert)
grep -rn "modifier\b" contracts/ -A8 | grep -B3 "if (" | grep -v "require\|revert"

# Uninitialized proxy
grep -rn "function initialize\b" contracts/ -A3
grep -rn "_disableInitializers()" contracts/

Check: Does EVERY sibling function in a family have the SAME modifiers?

Step 3: Incomplete Code Path (17% of Criticals)

The function family comparison test:

1. List all state changes in function A (deposit/place/create)
2. List all state changes in function B (withdraw/update/cancel)
3. For each state change in A: does B have the corresponding reverse?
4. For each token transfer in A: does B have the corresponding refund?
grep -rn "safeApprove\b" contracts/    # safeApprove without zero-reset?
grep -rn "delete\b" contracts/ -B5     # delete before operation completes?
grep -rn "function deposit\|function mint\|fun