All categories
Blockchain & Web3
Crypto, wallets, smart contracts, Web3, DeFi, NFTs, and decentralized apps
- 1,483
- 62
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse blockchain & web3 skills
Showing 25–48 of 1,483 skills
- 2565 Errors 69b67e5d``` Error: No API key configured, using mock data ``` **Cause**: WHALE_ALERT_API_KEY environment variable not set **Solution**: 1. Get API key from https://whale-alert.io 2. Set environment variable: `export WHALE_ALERT_API_KEY=your_key` 3. Or add to config fileVotes: 0GitHub stars: 9
- 2603 Weak Sources Randomness 34b619d7- Contract generates "random" values using on-chain data: `block.timestamp`, `blockhash`, `block.difficulty` / `block.prevrandao`, `block.number`, or combinations thereof - The random value determines outcomes with economic value (lotteries, games, minting, distributions)Votes: 0GitHub stars: 9
- 2593 Reentrancy 44db9f25- Contract makes an external call (ETH transfer, token transfer, `.call()`, `.send()`, `.transfer()`, callback hook) - State is modified after the external call, not before - No reentrancy guard (`nonReentrant` modifier) on the function - For cross-function: two or more functions share state, and at least one makes an external call before updating that shared state - For cross-contract: Contract B reads Contract A's state, and A makes an external call before updating it - For read-only: ContractVotes: 0GitHub stars: 9
- 2591 Incorrect Constructor 63cf3819- Solidity version <0.4.22 where constructors are named functions matching the contract name - The function name does not exactly match the contract name (typo, case mismatch, or contract renamed without updating the constructor)Votes: 0GitHub stars: 9
- 2587 Asserting Contract From Code Size 53dd37d1- Contract uses `extcodesize` or `address.code.length` to check whether an address is an EOA vs. a contract - This check gates access control, anti-bot logic, or security-sensitive operations - The check assumes that code size == 0 means EOAVotes: 0GitHub stars: 9
- 027 Prd A7c2a982**One-liner**: Query and analyze blockchain data including blocks, transactions, addresses, and smart contracts across multiple chains. **Domain**: Cryptocurrency / Blockchain Analytics **Users**: Developers, Analysts, Traders, ResearchersVotes: 0GitHub stars: 9
- 027 Prd 261ed085**One-liner**: Simulate and analyze flash loan strategies with profitability calculations and risk assessment **Domain**: Cryptocurrency / DeFi / Flash Loans **Users**: DeFi Developers, Arbitrage Researchers, Smart Contract AuditorsVotes: 0GitHub stars: 9
- 027 Prd 19e1813c**One-liner**: Predict optimal gas prices and timing to minimize blockchain transaction costs **Domain**: Cryptocurrency / Blockchain / Transaction Optimization **Users**: Traders, DeFi Users, NFT Collectors, Protocol DevelopersVotes: 0GitHub stars: 9
- 003 Name Skill Bc914e27Build production-ready Web3 applications, smart contracts, and decentralized systems. Implements DeFi protocols, NFT platforms, DAOs, and enterprise blockchain integrations. Use PROACTIVELY for smart contracts, Web3 apps, DeFi protocols, or blockchain infrastructure.Votes: 0GitHub stars: 9
- 003 Name Skill 1d9db141- Working on blockchain developer tasks or workflows - Needing guidance, best practices, or checklists for blockchain developerVotes: 0GitHub stars: 9
- 003 Name Skill 2cfa63f4Provides Next.js App Router data fetching patterns including SWR and React Query integration, parallel data fetching, Incremental Static Regeneration (ISR), revalidation strategies, and error boundaries. Use when implementing data fetching in Next.js applications, choosing between server and client fetching, setting up caching strategies, or handling loading and error states.Votes: 0GitHub stars: 9
- 559 Optimize Gas Eacd2ff4Optimize gas fees with timing and routing strategiesVotes: 0GitHub stars: 9
- 559 Optimize Gas 0237bc2dOptimize gas fees with timing and routing strategiesVotes: 0GitHub stars: 9
- Blockchain Cryptocurrency DevelopmentUse when designing or implementing a blockchain, cryptocurrency ledger, wallet prototype, transaction format, or consensus experiment to separate educational simulation from production financial systems, define state-transition invariants, and use vetted cryptographic libraries rather than inventing primitives. Trigger for ledger, token, block, transaction, wallet, or chain-reorganization work.Votes: 0GitHub stars: 2
- Onchain PayBinance Onchain Pay enables users to buy cryptocurrency with fiat (e.g., EUR, USD) or send existing crypto from their Binance account directly to any external on-chain wallet address in a single flow—no manual withdrawal needed. Enables partners to integrate crypto buying services: - payment-method-list: Get available payment methods (Card, P2P, Google Pay, Apple Pay, etc.) with limits for a fiat/crypto pair - trading-pairs: List all supported fiat currencies and cryptocurrencies - estimated...Votes: 0GitHub stars: 158
- Smart Contract AuditorAI智能合约安全审计,检测重入攻击、整数溢出、权限问题、未检查返回值等常见漏洞。每次调用收费0.001 USDT。触发词:合约审计、contract audit、智能合约安全、代码审计、solidity审计。Votes: 0GitHub stars: 2
- Crypto HuntScan all crypto markets for sweet-spot opportunities and entry timing signalsVotes: 0GitHub stars: 2
- Zk Verifier BugsDetect ZK proof-verifier contract bugs — missing public-input binding (unconstrained input → forgery), proof malleability, BN254 field-element range checks (input >= field modulus), unchecked pairing/ecAdd/ecMul precompile returns, nullifier reuse / double-spend, verification-key upgradeability, and trusted-setup assumptions. Activate whenever a contract verifies a SNARK/STARK proof, calls the bn256/altbn128 precompiles, or consumes nullifiers.Votes: 0GitHub stars: 36
- Vyper SpecificDetect Vyper-specific bug classes — compiler-version reentrancy bugs, raw_call return-value handling, send/raw_call gas defaults, immutables vs constants, default-bytes scope, msg.sender-based auth corner cases. Activate on any `.vy` file or `pragma version` directive.Votes: 0GitHub stars: 36
- Ve Lock GovernanceDetect vote-escrow (ve) governance manipulation — Curve veCRV, Velodrome/Aerodrome veNFT, Balancer veBAL, and gauge/bribe markets. Activate whenever code reads voting power from a lock balance, computes gauge weights, distributes bribes/incentives, snapshots votes, or lets locks be created/extended/merged/split/transferred — especially when vote weight is read live rather than at proposal-creation block.Votes: 0GitHub stars: 36
- Unchecked CallsDetect ignored external-call return values — silent failures from low-level call/delegatecall/staticcall, ignored ERC20 transfer return values, return-data length issues. Activate on `.call`, `.delegatecall`, `.staticcall`, `.send`, `transfer`/`transferFrom` (without SafeERC20), and any function returning `bool` whose return is discarded.Votes: 0GitHub stars: 36
- Tx Context MisuseDetect misuse of tx.origin, block.timestamp, block.number — phishing via tx.origin, timestamp dependence, L2-block-number assumptions. Activate on `tx.origin`, `block.timestamp`, `block.number`, `blockhash`, `block.prevrandao`, `block.coinbase`.Votes: 0GitHub stars: 36
- Token CompatibilityDetect ERC-20 token compatibility issues — fee-on-transfer, rebasing, non-standard return values, missing decimals(), low-decimal tokens, blacklistable tokens (USDC), pausable tokens. Activate on any ERC-20 integration, `transfer`/`transferFrom` use, balance-based accounting, decimal scaling.Votes: 0GitHub stars: 36
- Stylus RustDetect bug classes specific to Arbitrum Stylus (Rust→WASM) contracts — storage aliasing & EVM state-cache coherence, msg::value / #[payable] handling, external-call reentrancy, panic-on-attacker-input DoS, release-mode integer wrapping, host-IO (evm::) misuse, #[entrypoint]/#[public] access control, and lossy U256 conversions. Activate on any `.rs` file with `use stylus_sdk`, `#[entrypoint]`, `#[storage]`, `sol_storage!`, `#[public]`, or `#[payable]`.Votes: 0GitHub stars: 36