web3-ai-tools

Solid

AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.

AI & Automation 4 stars 5 forks Updated yesterday MIT

Install

View on GitHub

Quality Score: 80/100

Stars 20%
23
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# AI TOOLS ARSENAL > AI-powered automation for every phase of Web3 bug hunting. > Replaces: 28-cai-framework, 29-claude-skills-security, 30-shannon-ai-pentester, > 31-luan1ao-agent, 32-ai-generated-code-hunting, 33-smartguard-agent --- ## TOOL SELECTION GUIDE | Tool | Target Type | Best For | Cost | |------|------------|----------|------| | **Shannon** | Web apps + API (white-box) | IDOR, SQLi, SSRF, auth bypass | ~$50/run | | **LuaN1ao** | Any web target | Autonomous OWASP Top 10 | $0.09/exploit | | **CAI** | Web/network/IoT | Bug bounty recon + validation | API cost only | | **SmartGuard** | Solidity files | Auto PoC generation for SC bugs | API cost | | **AI Code Hunt** | AI-written contracts | Bugs Slither/Forge miss | Manual (patterns) | **For DeFi smart contracts:** SmartGuard + AI Code Hunt patterns **For DeFi web frontends:** Shannon (web layer) + skills 01-07 (contract layer) **For CTF/web targets:** LuaN1ao or CAI --- ## TOOL 1: SHANNON — AUTONOMOUS WEB PENTESTER **Source:** github.com/KeygraphHQ/shannon **Score:** 96.15% on XBOW source-aware benchmark (100/104 exploits) **Model:** Claude Agent SDK (Anthropic) **Cost:** ~$50/run | ~1-1.5 hours ### What Shannon Finds ``` ✅ IDOR — changes IDs across accounts, tests all API routes ✅ SQLi — error-based and time-based blind ✅ Command injection — OS separators in all inputs ✅ XSS — reflected + stored (confirmed in real browser) ✅ SSRF — webhook/fetch URL inputs, OOB callbacks ✅ JWT attacks — alg:none, RS...

Details

Author
Olaradiallysymmetrical491
Repository
Olaradiallysymmetrical491/web3-bug-bounty-hunting-ai-skills
Created
4 months ago
Last Updated
yesterday
Language
N/A
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

security-audit

Audit codebases, infrastructure, AND agentic AI systems for security issues. Covers traditional security (dependencies, secrets, OWASP web top 10, SSL/TLS, file permissions) PLUS agentic security (prompt injection scanning, identity spoofing detection, memory poisoning checks, multi-agent communication audit, OWASP Agentic Top 10). Use when scanning for vulnerabilities, detecting hardcoded secrets, reviewing agent workspace configuration, checking prompt injection vectors, or auditing agent permissions and boundaries.

81 Updated today
aAAaqwq
AI & Automation Solid

bb-local-toolkit

Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing use the bug-bounty skill. Workflow it covers — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SS

3,220 Updated today
elementalsouls
AI & Automation Featured

ai-security

Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.

23,342 Updated 1 weeks ago
alirezarezvani