Bounty Security Pattern Master Library — 399 Vulnerability Patterns

    6

    A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.

    $75

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    13 installs5.0 (1 review)

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Bounty Security Pattern Master Library — 399 Vulnerability Patterns

    Example session with this skill installed

    Analyze /contracts/Vault.sol using the pattern library. Identify potential accounting issues in the deposit/withdraw flow and provide a hypothesis and PoC direction.

    • Read your context and instructions
    • Compiled the bounty security pattern

    Pattern: Improper Accounting in Rebase Logic (High)
    CWE: 682
    Target: /contracts/Vault.sol:L142
    Hypothesis: External transfer tax causes share mismatch.
    Evidence Needed: Check if totalAssets is updated before or after safeTransfer.
    PoC: Deposit 100 tokens, trigger tax, attempt full withdraw.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify 399+ vulnerability types in complex codebases automatically.Generate exploit hypotheses and PoC directions for DeFi smart contracts.Map codebase architecture to specific CWE and high-severity attack patterns.Perform fast triage on bug bounty scopes using structured security checklists.Create submission-ready finding reports with root cause and impact analysis.

    About this skill

    Supercharge Your Security Audits

    The Bounty Security Pattern Master Library is an exhaustive repository of 399 structured vulnerability patterns designed for developers and security researchers performing bug bounties or smart contract audits. It bridges the gap between seeing code and identifying deep logic flaws by providing an agentic framework for vulnerability discovery.

    What it does

    This skill provides your AI agent with a high-fidelity dataset of exploitation patterns, covering everything from classic web vulnerabilities (CWE-mapped) to emerging DeFi accounting and cross-chain trust issues. It enables agents to move beyond generic advice toward specific attack scenarios, root cause analysis, and PoC heuristics.

    • 399 Vulnerability Patterns: A machine-readable library in JSON format.
    • DeFi Specialization: Includes "Monetrix" emerging patterns for Hyperliquid-style and cross-chain protocols.
    • Structured Reasoning: Maps code paths to exploitability hypotheses and false-positive checklists.
    • Audit Readiness: Generates formatted summaries ready for triage or bounty submission.

    Why use this skill?

    Standard LLMs often hallucinate security flaws or miss complex logic bugs. This skill provides the specific domain knowledge—such as oracle paths, withdrawal accounting, and bridge redemption flows—that normally takes years of research to compile. It turns your agent into an expert reviewer that knows exactly where to look and how to validate a finding before you submit it.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    5.0
    1 review
    5
    1
    4
    0
    3
    0
    2
    0
    1
    0

    13 people have installed this skill.

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Passed all security checks, Safe to install

    Listed3 months ago

    Frequently Asked Questions