Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
$75
Works with the AI tools you already use
Bounty Security Pattern Master Library — 399 Vulnerability Patterns
Example session with this skill installed
Analyze /contracts/Vault.sol using the pattern library. Identify potential accounting issues in the deposit/withdraw flow and provide a hypothesis and PoC direction.
- Read your context and instructions
- Compiled the bounty security pattern
Pattern: Improper Accounting in Rebase Logic (High)
CWE: 682
Target: /contracts/Vault.sol:L142
Hypothesis: External transfer tax causes share mismatch.
Evidence Needed: Check if totalAssets is updated before or after safeTransfer.
PoC: Deposit 100 tokens, trigger tax, attempt full withdraw.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Supercharge Your Security Audits
The Bounty Security Pattern Master Library is an exhaustive repository of 399 structured vulnerability patterns designed for developers and security researchers performing bug bounties or smart contract audits. It bridges the gap between seeing code and identifying deep logic flaws by providing an agentic framework for vulnerability discovery.
What it does
This skill provides your AI agent with a high-fidelity dataset of exploitation patterns, covering everything from classic web vulnerabilities (CWE-mapped) to emerging DeFi accounting and cross-chain trust issues. It enables agents to move beyond generic advice toward specific attack scenarios, root cause analysis, and PoC heuristics.
- 399 Vulnerability Patterns: A machine-readable library in JSON format.
- DeFi Specialization: Includes "Monetrix" emerging patterns for Hyperliquid-style and cross-chain protocols.
- Structured Reasoning: Maps code paths to exploitability hypotheses and false-positive checklists.
- Audit Readiness: Generates formatted summaries ready for triage or bounty submission.
Why use this skill?
Standard LLMs often hallucinate security flaws or miss complex logic bugs. This skill provides the specific domain knowledge—such as oracle paths, withdrawal accounting, and bridge redemption flows—that normally takes years of research to compile. It turns your agent into an expert reviewer that knows exactly where to look and how to validate a finding before you submit it.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
13 people have installed this skill.
Trust & safety
Security scanned
Verified clean 3 months ago
- Passed all security checks, Safe to install