# Web3 Bug Classes (agent skill)

> Web3 Bug Classes is an agent skill (a SKILL.md file) from tradecatlabs/vibe-coding-cn. Complete reference for all 10 DeFi smart contract bug classes. It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 17,171 GitHub stars across a repository of 5 listed skills.

Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs. 10 bug classes. Each one with root cause, vulnerable code, fix, grep patterns, and real paid examples.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/tradecatlabs/vibe-coding-cn |
| Skill path | research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-bug-classes/SKILL.md |
| Skill name | web3-bug-classes |
| GitHub stars | 17,171 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 5 |
| Plugin marketplace | no |
| Official | no |
| Works with | Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode |
| Category | Testing & QA |
| Last commit | Oct 1, 2026 |

## When it triggers

- Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrad

## Add this skill

### Claude Code

```sh
git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-bug-classes ~/.claude/skills/web3-bug-classes   # personal, or .claude/skills in a project
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-bug-classes .agents/skills/web3-bug-classes   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-bug-classes .cursor/skills/web3-bug-classes   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/tradecatlabs-web3-bug-classes
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
