tradecatlabs/vibe-coding-cn: 24 Agent Skills
Vibe Coding 从入门到精通教程|AI 结对编程工作流|Prompt、Skill、Workflow、上下文管理、codex实战指南
| Repository | tradecatlabs/vibe-coding-cn · website |
|---|---|
| GitHub stars | 17,270 |
| Skills | 24 |
| Category | Software engineering |
| License | MIT |
| Last updated | Oct 8, 2026 |
| Install counts | tradecatlabs/vibe-coding-cn on skills.sh, Vercel's skills directory, which shows installs and security audits per skill |
Install tradecatlabs/vibe-coding-cn
| All skills, any agent | npx skills add tradecatlabs/vibe-coding-cn |
|---|---|
| One skill | npx skills add tradecatlabs/vibe-coding-cn --skill analyzing-ethereum-smart-contract-vulnerabilities |
| Only for Claude Code | npx skills add tradecatlabs/vibe-coding-cn -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project) |
npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.
Skills in tradecatlabs/vibe-coding-cn
| Skill | What it does |
|---|---|
| analyzing-ethereum-smart-contract-vulnerabilities | Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet. |
| auditing-foundry-smart-contract-security | Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and… |
| web3-ai-tools | AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery. |
| web3-bug-classes | Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or… |
| web3-case-study-role-misconfig | Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a template for applying all 10 bug classes to a single target. |
| web3-grep-arsenal | Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes. |
| web3-hunt-foundation | Hunter mindset, recon setup, and target scoring for Web3 bug bounty. Use at the START of any new protocol hunt - scoring targets, setting up environment, understanding architecture. |
| web3-hunt-zksync-era | ZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a target. Contains architecture breakdown, 25 tested attack vectors, and pre-dive… |
| web3-methodology-research | External research synthesis from Trail of Bits, SlowMist, ConsenSys, Immunefi, and Cyfrin. Use this for advanced audit methodology, Echidna/Medusa fuzzing setup, Slither custom detector writing, attack pattern deep dives, or the 4-phase learning roadmap. |
| web3-poc-foundry | Complete Foundry PoC writing guide + all cheatcodes + DeFiHackLabs reproduction patterns. Use this when building a proof of concept exploit, setting up a fork test, using Foundry cheatcodes, or reproducing a known DeFi hack for learning. |
| web3-solidity-audit-mcp | MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow. |
| web3-start-here | Master index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT. |
| web3-triage-report | Bug triage validation system, Immunefi report format, and 20 real paid bounty examples dissected. Use this when validating a finding before submitting, writing an Immunefi report, checking if a bug is actually valid, or studying real examples of paid vulnerabilities. |
| math-computation | 可重跑的数学计算与反例实验。用于 SymPy 精确代数/微积分/方程/矩阵、NumPy/SciPy 数值方法、mpmath 高精度交叉检查、OEIS 序列识别、有限范围反例搜索和计算证据记录。 |
| math-derivation | 数学公式与理论线推导。用于整理散乱公式、固定不变量和记号、推导恒等式/近似/局部命题、检查隐藏假设,或把理论笔记变成可审计推导包。 |
| math-discovery | 数学问题发现与证据检索。用于界定研究问题、查定义/定理谱系、检索 arXiv/Scholar/OpenAlex/Crossref、建立来源账本、证据图、查新或从证据缺口生成可证伪猜想。 |
| math-formalization | 数学形式化与 proof-assistant 验证。用户要求 Lean 4/Mathlib、formal proof、kernel check、无 sorry 编译,或需要把自然语言定理切成可形式化定义和引理时使用。缺少 Lean 工具链时必须 fail-closed。 |
| math-proof | 严格自然语言数学证明。用于证明或审查 theorem/lemma/proposition、补齐证明草稿、构建证明义务与依赖图、寻找反例、检查量词/常数/边界情况,或判断命题是否必须削弱。 |
| vibe-mathing-router | 数学研究任务路由器。用户提出找问题、查文献、推公式、做计算、写证明或形式化验证,但当前瓶颈尚未明确时使用;每次只选择一个主 skill。 |
| anmath-methods | Use when laying out the proof strategy of a pure-mathematics manuscript for Annals of Mathematics — the architecture of the argument, the key lemmas and propositions, the novel technique, and where the difficulty lies. Designs and exposes the proof plan; does not check final correctness… |
| anmath-referee-strategy | Use when anticipating how an expert Annals of Mathematics referee will verify a proof — stress-testing the argument for gaps, checking external dependencies, and pre-empting the questions a careful reader will ask. Hardens the manuscript before submission; does not write the rebuttal… |
| anmath-writing-style | Use when polishing the prose and rigor of a pure-mathematics manuscript for Annals of Mathematics — eliminating gaps, removing "clearly"/"it is easy to see", precise quantifiers, and consistent mathematical English. Late-stage polish; run only after the proof and architecture are fixed. |
| auto-skill | Claude Skills meta-skill: extract domain material (docs/APIs/code/specs) into a reusable Skill (SKILL.md + references/scripts/assets), and refactor existing Skills for clarity, activation reliability, and quality gates. |
| auto-tmux | tmux 自动化操控:用 scripts/auto-tmux.sh 安全读取、发送、巡检、救援、录制 session|window|pane,用 swarm-state.sh 管理蜂群任务/锁/状态,并基于 oh-my-tmux 组织多 AI 终端协作。触发:capture-pane、send-keys、批量巡检、蜂群 AI 协作、卡死救援、tmux 工作台初始化。 |
Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.
More software engineering skill packs
| # | Skill pack | Skills | GitHub stars | Updated |
|---|---|---|---|---|
| 1 |
obra/superpowers An agentic skills framework & software development methodology that works.
|
15 | 297K | 2026-10-08 |
| 2 |
mattpocock/skills Skills for Real Engineers. Straight from my .agents directory.
|
38 | 281K | 2026-10-08 |
| 3 |
addyosmani/agent-skills Production-grade engineering skills for AI coding agents.
|
25 | 103K | 2026-10-03 |
| 4 |
ComposioHQ/awesome-claude-skills A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows
|
864 | 76.7K | 2026-09-18 |
| 5 |
github/awesome-copilot Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.
|
445 | 39.8K | 2026-10-08 |
| 6 |
anthropics/claude-plugins-official Official, Anthropic-managed directory of high quality Claude Code Plugins.
|
33 | 37.6K | 2026-10-08 |