Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Secure checkout via Stripe
Works with the AI tools you already use
See it in action
You say
Analyze /contracts/Vault.sol using the pattern library. Identify potential accounting issues in the deposit/withdraw flow and provide a hypothesis and PoC direction.
Your agent does
Pattern: Improper Accounting in Rebase Logic (High)
CWE: 682
Target: /contracts/Vault.sol:L142
Hypothesis: External transfer tax causes share mismatch.
Evidence Needed: Check if totalAssets is updated before or after safeTransfer.
PoC: Deposit 100 tokens, trigger tax, attempt full withdraw.
What you get
About this skill
Supercharge Your Security Audits
The Bounty Security Pattern Master Library is an exhaustive repository of 399 structured vulnerability patterns designed for developers and security researchers performing bug bounties or smart contract audits. It bridges the gap between seeing code and identifying deep logic flaws by providing an agentic framework for vulnerability discovery.
What it does
This skill provides your AI agent with a high-fidelity dataset of exploitation patterns, covering everything from classic web vulnerabilities (CWE-mapped) to emerging DeFi accounting and cross-chain trust issues. It enables agents to move beyond generic advice toward specific attack scenarios, root cause analysis, and PoC heuristics.
- 399 Vulnerability Patterns: A machine-readable library in JSON format.
- DeFi Specialization: Includes "Monetrix" emerging patterns for Hyperliquid-style and cross-chain protocols.
- Structured Reasoning: Maps code paths to exploitability hypotheses and false-positive checklists.
- Audit Readiness: Generates formatted summaries ready for triage or bounty submission.
Why use this skill?
Standard LLMs often hallucinate security flaws or miss complex logic bugs. This skill provides the specific domain knowledge—such as oracle paths, withdrawal accounting, and bridge redemption flows—that normally takes years of research to compile. It turns your agent into an expert reviewer that knows exactly where to look and how to validate a finding before you submit it.
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
12 people have installed this skill.
Trust & safety
Security scanned
Verified clean 2 months ago
- 30-day refund guarantee
- One-time purchase, yours forever
- Secure checkout via Stripe
Creator
Frequently Asked Questions
Popular in Security & Compliance

🔒 PII & Data-Leak Scanner
Scan your schemas, seed data, config, and logs for personal data before it leaks. Detects PII-indicating column and key names (email, ssn, phone, address) across SQL, CSV, and JSON, plus PII in the data itself: email addresses, SSN-like numbers, credit-card-like numbers, phone numbers, and PII written into log files. Each finding is flagged with its location and a GDPR-style review note. Heuristic by design: it surfaces what to review, not a compliance guarantee.
dependency-auditor
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
skill-security-vendor-pack
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.

skill-install-safety-gate
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.