Skip to content
appsgit

Web3 Solidity Audit MCP

Web3 Solidity Audit MCP is an agent skill (a SKILL.md file) from tradecatlabs/vibe-coding-cn. MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 17,171 GitHub stars across a repository of 5 listed skills.

github.com/tradecatlabs/vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-solidity-audit-mcp (opens in a new tab)

  • Multi-skill repo
  • Needs API key
  • Security
  • Actively maintained

Add this skill

Claude

Claude Code loads skills from ~/.claude/skills/ (all projects) or .claude/skills/ (one project):

git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-solidity-audit-mcp ~/.claude/skills/web3-solidity-audit-mcp   # personal, or .claude/skills in a project

In the Claude apps, zip the web3-solidity-audit-mcp folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-solidity-audit-mcp .agents/skills/web3-solidity-audit-mcp   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/tradecatlabs/vibe-coding-cn.git
cp -r vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-solidity-audit-mcp .cursor/skills/web3-solidity-audit-mcp   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow. An MCP server that gives Claude Code direct access to Slither, Aderyn, Slang AST, SWC pattern matching, and a gas optimizer — all in one unified pipeline with auto-deduplication.

When it triggers

  • Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants.

More skills in tradecatlabs/vibe-coding-cn

5 skills are listed from this repository.

FAQ

Web3 Solidity Audit MCP FAQ

Still curious? Email info@appsgit.com.

What is the Web3 Solidity Audit MCP skill?

Web3 Solidity Audit MCP is an agent skill (a SKILL.md file) from tradecatlabs/vibe-coding-cn. MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 17,171 GitHub stars across a repository of 5 listed skills. Its SKILL.md lives at github.com/tradecatlabs/vibe-coding-cn/research/vibe-cybersecurity-cn/skills/web3-bug-bounty-hunting/web3-solidity-audit-mcp.

How do I install the Web3 Solidity Audit MCP skill?

Copy the web3-solidity-audit-mcp folder (the one containing SKILL.md) into ~/.claude/skills/ for Claude Code, .agents/skills/ for Codex or .cursor/skills/ for Cursor. The agent picks it up automatically when a task matches its description.

Is the Web3 Solidity Audit MCP skill free?

Yes. The repository is open source under the MIT license. The skill mentions an API key or token for an external service, which may need its own account.

Is Web3 Solidity Audit MCP maintained?

The repository's most recent commit was on Oct 1, 2026. appsgit only lists skills from repositories with a commit in the last six months.