Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Bug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis.
.claude/skills/a5c-ai-bug-bounty/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 68% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 72% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 63% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 112% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 39% | 0% |
Expert management of bug bounty programs and responsible security disclosure for blockchain protocols.
| Tool | Purpose | Reference | |------|---------|-----------| | Trail of Bits Skills | Security analysis, property testing | building-secure-contracts | | Slither MCP | Static analysis for validation | slither-mcp | | Phalcon MCP | Transaction analysis | phalcon-mcp |
yamlprogram: name: "Protocol Name" website: "https://protocol.xyz" assets: smart_contracts: - type: "Smart Contract" target: "0x..." severity: "Critical" websites: - type: "Web Application" target: "https://app.protocol.xyz" severity: "High" severity_levels: critical: range: "$100,000 - $1,000,000" description: "Direct theft of funds, permanent freezing" high: range: "$10,000 - $100,000" description: "Theft requiring user action, temporary freezing" medium: range: "$1,000 - $10,000" description: "Griefing, DoS with medium impact" low: range: "$100 - $1,000" description: "Minor issues, informational" exclusions: - "Issues in test files" - "Third-party dependencies" - "Issues requiring admin key compromise" - "Front-running issues without significant impact"
| Severity | Impact | Examples | |----------|--------|----------| | Critical | Direct fund loss, protocol takeover | Reentrancy draining funds, access control bypass | | High | Significant fund loss, protocol disruption | Oracle manipulation, flash loan attacks | | Medium | Limited fund loss, degraded functionality | Griefing attacks, minor calculation errors | | Low | No fund loss, minor issues | Gas inefficiency, informational findings |
markdown## Triage Checklist - [ ] Report is within program scope - [ ] Vulnerability is reproducible - [ ] Impact assessment is accurate - [ ] No duplicate of existing report - [ ] Not a known issue or design decision ## Initial Classification | Field | Value | |-------|-------| | Report ID | BB-2024-XXX | | Submission Date | YYYY-MM-DD | | Reporter | @handle | | Asset Affected | Contract/URL | | Initial Severity | Critical/High/Medium/Low | | Status | Triaging |
bash# Clone and setup test environment git clone <protocol-repo> cd protocol # Create PoC test forge test --match-test test_VulnerabilityPoC -vvvv # Run against mainnet fork forge test --fork-url $MAINNET_RPC --match-test test_VulnerabilityPoC
Consider:
Final Severity = Base Impact - Mitigating Factors + Aggravating FactorsDay 0: Report received
Day 1-3: Initial triage and acknowledgment
Day 3-7: Validation and severity confirmation
Day 7-14: Fix development
Day 14-21: Fix review and testing
Day 21-30: Coordinated disclosure preparation
Day 30+: Public disclosure (if agreed)Acknowledgment:
Subject: [BB-XXXX] Report Acknowledged
Dear Security Researcher,
Thank you for your submission to our bug bounty program. We have received
your report and assigned it reference number BB-XXXX.
Our security team is currently reviewing your submission. We will provide
an initial assessment within 3 business days.
Timeline:
- Initial response: 24-72 hours
- Severity assessment: 3-7 days
- Fix timeline: TBD based on severity
Best regards,
Security TeamSeverity Confirmation:
Subject: [BB-XXXX] Severity Assessment Complete
Dear Security Researcher,
After thorough review, we have assessed your vulnerability report:
Severity: [CRITICAL/HIGH/MEDIUM/LOW]
Bounty Range: $X - $Y
Fix Timeline: X days
[Details of assessment]
Next Steps:
1. Fix development (ETA: X days)
2. Fix verification with your input
3. Coordinated disclosure discussion
Best regards,
Security Teamjavascriptconst bountyCalculation = { baseBounty: getSeverityBase(severity), // Based on tier adjustments: { qualityOfReport: 1.0 - 1.5, // Well-documented PoC impactAccuracy: 0.8 - 1.2, // Accurate impact assessment firstReporter: 1.0, // First to report duplicatePartial: 0.0 - 0.5, // Partial duplicate responsibleBehavior: 1.0 - 1.2 // No public disclosure }, calculate() { return this.baseBounty * this.adjustments.qualityOfReport * this.adjustments.impactAccuracy * this.adjustments.responsibleBehavior; } };
markdown# Security Incident Post-Mortem: [Title] ## Summary - **Date Discovered**: YYYY-MM-DD - **Date Fixed**: YYYY-MM-DD - **Severity**: Critical/High/Medium/Low - **Bounty Paid**: $X ## Root Cause [Detailed explanation of the vulnerability] ## Timeline | Time | Event | |------|-------| | T+0h | Report received | | T+2h | Triage complete | | T+24h | Fix developed | | T+48h | Fix deployed | | T+168h | Public disclosure | ## Technical Details [Code snippets, attack vectors, affected functions] ## Fix Implementation [How the issue was resolved] ## Lessons Learned 1. [Lesson 1] 2. [Lesson 2] 3. [Lesson 3] ## Process Improvements - [ ] Improvement 1 - [ ] Improvement 2
This skill integrates with:
bug-bounty-program.js - Full program management processincident-response-exploits.js - Exploit response coordinationsmart-contract-security-audit.js - Pre-launch security review| Issue | Solution | |-------|----------| | Slow response | Set up triage rotation, clear escalation | | Scope disputes | Pre-define edge cases in program terms | | Severity disagreements | Use CVSS scoring, document rationale | | Payment delays | Pre-fund bounty pool, streamline KYC |
markdown## Summary [Brief description] ## Severity [CVSS Score] - [Critical/High/Medium/Low] ## Affected Versions - >= 1.0.0, < 1.2.3 ## Patches Fixed in version 1.2.3 ## Workarounds [If applicable] ## References - [Link to fix PR] - [Related documentation] ## Credits Thanks to @researcher for responsible disclosure
agents/incident-response/AGENT.md - Incident response expertsmart-contract-security-audit.js - Security audit processreferences.md - Security disclosure resources| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 22,047 | 18,665 | -15% | 1 | 1 | 0% | 3,614 | 5,346 | +48% | 0 | 0 | — |
case-02 | fail→pass | 11,075 | 5,685 | -49% | 1 | 1 | 0% | 1,869 | 3,146 | +68% | 0 | 0 | — |
case-03 | fail→fail | 36,462 | 17,843 | -51% | 1 | 1 | 0% | 1,038 | 5,354 | +416% | 0 | 0 | — |
case-04 | fail→fail | 11,517 | 11,905 | +3% | 1 | 1 | 0% | 2,015 | 3,954 | +96% | 0 | 0 | — |
case-05 | fail→pass | 9,771 | 7,815 | -20% | 1 | 1 | 0% | 1,914 | 3,288 | +72% | 0 | 0 | — |
case-06 | fail→pass | 12,758 | 11,028 | -14% | 1 | 1 | 0% | 2,371 | 3,867 | +63% | 0 | 0 | — |
case-07 | fail→pass | 8,274 | 5,793 | -30% | 1 | 1 | 0% | 1,429 | 3,033 | +112% | 0 | 0 | — |
case-08 | fail→fail | 16,837 | 8,012 | -52% | 1 | 1 | 0% | 2,878 | 3,471 | +21% | 0 | 0 | — |
case-09 | fail→pass | 12,833 | 4,908 | -62% | 1 | 1 | 0% | 2,083 | 2,885 | +39% | 0 | 0 | — |
case-10 | fail→pass | 14,555 | 8,462 | -42% | 1 | 1 | 0% | 2,435 | 3,549 | +46% | 0 | 0 | — |
case-11 | fail→fail | 16,601 | 13,638 | -18% | 1 | 1 | 0% | 2,659 | 4,223 | +59% | 0 | 0 | — |
case-12 | fail→fail | 13,555 | 9,583 | -29% | 1 | 1 | 0% | 2,068 | 3,601 | +74% | 0 | 0 | — |
case-13 | fail→fail | 15,369 | 9,930 | -35% | 1 | 1 | 0% | 2,663 | 3,800 | +43% | 0 | 0 | — |
case-14 | fail→fail | 8,747 | 5,048 | -42% | 1 | 1 | 0% | 1,563 | 2,937 | +88% | 0 | 0 | — |
case-15 | pass→pass | 6,256 | 2,697 | -57% | 1 | 1 | 0% | 1,049 | 2,602 | +148% | 0 | 0 | — |
case-16 | fail→pass | 11,051 | 10,817 | -2% | 1 | 1 | 0% | 1,805 | 3,949 | +119% | 0 | 0 | — |
case-17 | fail→pass | 11,848 | 7,507 | -37% | 1 | 1 | 0% | 1,872 | 3,272 | +75% | 0 | 0 | — |
case-18 | fail→fail | 11,971 | 7,064 | -41% | 1 | 1 | 0% | 1,994 | 3,258 | +63% | 0 | 0 | — |
case-19 | fail→fail | 13,325 | 13,928 | +5% | 1 | 1 | 0% | 2,436 | 4,444 | +82% | 0 | 0 | — |
case-20 | fail→fail | 10,544 | 10,062 | -5% | 1 | 1 | 0% | 2,305 | 4,228 | +83% | 0 | 0 | — |
case-21 | fail→fail | 19,986 | 17,177 | -14% | 1 | 1 | 0% | 4,192 | 5,848 | +40% | 0 | 0 | — |
case-22 | fail→fail | 11,504 | 11,649 | +1% | 1 | 1 | 0% | 2,427 | 4,740 | +95% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 21 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +36 percentage points is the difference between those two pass rates over the 21 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.