← Back to Skills Marketplace
n8gendegen

Atlas Smart Contract Audit & DeFi Bounty Triage

by n8gendegen · GitHub ↗ · v1.0.1 · MIT-0
cross-platform ✓ Security Clean
76
Downloads
0
Stars
0
Active Installs
2
Versions
Install in OpenClaw
/install atlas-bounty-triage
Description
Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surfa...
README (SKILL.md)

Atlas Smart Contract Audit & DeFi Bounty Triage

A lightweight smart contract audit and DeFi security triage skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.

Use this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.

Search Keywords / Best Use Cases

  • smart contract audit
  • DeFi audit
  • DeFi security audit
  • Solidity audit
  • EVM audit
  • vulnerability scanner
  • smart contract vulnerability triage
  • bug bounty triage
  • Code4rena audit workflow
  • Sherlock audit workflow
  • HackenProof bounty workflow
  • access control review
  • oracle manipulation review
  • reentrancy checklist
  • upgradeable proxy review

When to Use

  • New smart contract audit target assigned
  • DeFi contest just opened and you need to prioritize files
  • Bug bounty scope includes Solidity/EVM contracts
  • You need a structured first-pass vulnerability checklist
  • You want to map attack surface before deep manual review

What It Produces

A structured markdown audit triage report with:

  • Target overview
  • Protocol type and contract categories
  • Attack surface map
  • High-priority vulnerability classes
  • Contract-by-contract checklist
  • Recommended deep-dive order
  • Quick-win review items

Workflow

Phase 1: Smart Contract Scope Mapping

For each contract in scope:

  1. Identify protocol type: lending, AMM, vault, staking, bridge, oracle, governance, NFT, account abstraction
  2. Identify external integrations: Chainlink, Uniswap, Curve, ERC20 tokens, bridges, routers, keepers
  3. Flag proxy/upgrade patterns: EIP1967, UUPS, transparent proxy, beacon proxy, clones
  4. Identify privileged roles: owner, admin, guardian, pauser, timelock, operator
  5. Note novel or high-risk mechanisms: custom accounting, share pricing, liquidation math, rewards, TWAPs

Phase 2: DeFi Vulnerability Prioritization

Score each vulnerability class by likelihood × impact:

HIGH PRIORITY
- Reentrancy: external calls + state changes + callbacks
- Access control: missing modifiers, wrong role assumptions, admin bypass
- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs
- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch
- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths
- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover

MEDIUM PRIORITY
- Fee-on-transfer / rebasing token edge cases
- ERC777 / callback-enabled token surprises
- Sandwich / MEV-sensitive pricing
- DOS via unbounded loops or griefable state
- Signature replay / permit domain separator issues

LOW PRIORITY BUT CHECK
- Input validation gaps
- Event/reporting mismatch
- Gas griefing
- Minor precision loss without exploitable value extraction

Phase 3: Contract-by-Contract Checklist

## Contract: \x3CName>

### External Calls / Reentrancy
- [ ] External calls happen after state updates?
- [ ] Reentrancy guard exists where callbacks are possible?
- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?

### Access Control
- [ ] Privileged functions use correct modifier?
- [ ] Timelock/owner/admin boundaries are clear?
- [ ] Emergency functions cannot steal user funds?

### Oracle / Pricing
- [ ] Oracle freshness checked?
- [ ] Decimal normalization correct?
- [ ] Fallback oracle cannot be manipulated?
- [ ] TWAP window long enough for protocol value at risk?

### Accounting
- [ ] Shares/assets conversion handles rounding direction correctly?
- [ ] Fee calculations cannot drain or brick accounting?
- [ ] Deposits/withdrawals preserve invariants?

### Upgradeability
- [ ] Initializers protected?
- [ ] Storage layout compatible?
- [ ] Implementation cannot be selfdestructed or hijacked?

Phase 4: Audit Triage Report

# Smart Contract Audit Triage: \x3CTarget>

## Target Overview
- Protocol type:
- Chain(s):
- Contracts in scope:
- Highest-value assets:

## Attack Surface Summary
- External integrations:
- Oracle dependencies:
- Upgrade pattern:
- Privileged roles:

## Top Vulnerability Classes to Review
1. [HIGH] \x3Cclass> — \x3Cwhy this target is exposed>
2. [HIGH] \x3Cclass> — \x3Cwhy this target is exposed>
3. [MEDIUM] \x3Cclass> — \x3Cwhy this target is exposed>

## Recommended Deep-Dive Order
1. \x3Ccontract> — focus on \x3Cvulnerability class>
2. \x3Ccontract> — focus on \x3Cvulnerability class>
3. \x3Ccontract> — focus on \x3Cvulnerability class>

## Quick Wins Checklist
- [ ] Reentrancy review
- [ ] Access control review
- [ ] Oracle manipulation review
- [ ] Upgradeability review
- [ ] Accounting invariant review

---
Generated by Atlas Smart Contract Audit & DeFi Bounty Triage.
Full Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage

Guardrails

This is a triage and audit workflow, not a guaranteed vulnerability finder. It helps prioritize manual review and produce better audit notes. Always verify candidate findings with a proof of concept before submission.

Get the Full Atlas Agent Suite

The full Atlas Bounty Ops workflow includes:

  • Contest monitoring for Code4rena, Sherlock, HackenProof
  • Target scoring and prioritization
  • Daily vulnerability pattern promotion
  • Finding writeup templates
  • Scheduled research briefings
  • Revenue ops and marketing agents

👉 https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage

Usage Guidance
This appears safe to install based on the provided artifacts. It is a guidance/checklist skill rather than an automated scanner, so users should still manually verify any audit conclusions before relying on them.
Capability Analysis
Type: OpenClaw Skill Name: atlas-bounty-triage Version: 1.0.1 The skill bundle provides a structured workflow and markdown templates for an AI agent to perform smart contract audits and DeFi security triage. It contains no executable code, shell commands, or instructions to access sensitive system data. The content is limited to guidance for information processing and report generation, including marketing links to the author's website (atlasagentsuite.com).
Capability Tags
crypto
Capability Assessment
Purpose & Capability
The stated purpose—Solidity/EVM audit triage and DeFi bounty checklist generation—matches the SKILL.md and README content.
Instruction Scope
The provided instructions focus on producing structured audit triage reports and checklists; they do not direct the agent to override users, run tools, submit findings, or mutate accounts.
Install Mechanism
No install spec, binaries, packages, scripts, or runtime code are present.
Credentials
No environment variables, credentials, local file indexing, network access, or privileged system access are requested.
Persistence & Privilege
No persistence, background execution, memory storage, account authority, or elevated privilege is described.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install atlas-bounty-triage
  3. After installation, invoke the skill by name or use /atlas-bounty-triage
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.1
SEO update for smart contract audit and DeFi audit search discovery
v1.0.0
Initial free lead-magnet release
Metadata
Slug atlas-bounty-triage
Version 1.0.1
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 2
Frequently Asked Questions

What is Atlas Smart Contract Audit & DeFi Bounty Triage?

Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surfa... It is an AI Agent Skill for Claude Code / OpenClaw, with 76 downloads so far.

How do I install Atlas Smart Contract Audit & DeFi Bounty Triage?

Run "/install atlas-bounty-triage" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Atlas Smart Contract Audit & DeFi Bounty Triage free?

Yes, Atlas Smart Contract Audit & DeFi Bounty Triage is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does Atlas Smart Contract Audit & DeFi Bounty Triage support?

Atlas Smart Contract Audit & DeFi Bounty Triage is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Atlas Smart Contract Audit & DeFi Bounty Triage?

It is built and maintained by n8gendegen (@n8gendegen); the current version is v1.0.1.

💬 Comments