{"id":"a35ccd58-0c1a-4a2c-aeab-dad05d5d482e","entityType":"agent","slug":"clawhub-n8gendegen-atlas-bounty-triage","name":"DeFi Audit & Smart Contract Bounty Triage","canonicalUrl":"https://www.xpersona.co/agent/clawhub-n8gendegen-atlas-bounty-triage","canonicalPath":"/agent/clawhub-n8gendegen-atlas-bounty-triage","generatedAt":"2026-10-11T00:35:36.512Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":null},"description":"Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surfa...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s178kk8n3h54fa7qzx3gsf72md85y3vm:atlas-bounty-triage","sourceUrl":"https://clawhub.ai/n8gendegen/atlas-bounty-triage","homepage":"https://clawhub.ai/n8gendegen/skills/atlas-bounty-triage","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/n8gendegen/atlas-bounty-triage","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/n8gendegen/skills/atlas-bounty-triage","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"DeFi Audit & Smart Contract Bounty Triage technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":null},"stars":null,"forks":null,"downloads":1243,"packageName":null,"latestVersion":"1.0.4","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:23:03.341Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T22:23:03.406Z","lastCrawledAt":"2026-10-10T22:23:03.341Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T22:23:03.341Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.4","createdAt":"2026-05-17T14:36:17.732Z","changelog":"Conversion SEO v1.0.4: exact-match DeFi audit title, smart contract audit keywords, stronger star/download CTA, and paid ZIP funnel copy.","fileCount":4,"zipByteSize":5392},{"version":"1.0.3","createdAt":"2026-05-17T03:17:58.576Z","changelog":"- Added new calls to action (CTAs) for bug bounty triage, Code4rena, Sherlock, HackenProof, and DeFi bounty workflows. - Updated homepage URL tracking for paid Starter/Pro package promotion. - Enhanced search keywords and use cases for improved conversion SEO. - Added details and direct links for paid Atlas Starter/Pro ZIP Packs. - Expanded feature and upsell descriptions to highlight bounty and audit workflow scenarios.","fileCount":3,"zipByteSize":3980},{"version":"1.0.2","createdAt":"2026-05-10T14:28:03.522Z","changelog":"- Added UTM tracking parameters to homepage link for improved download attribution. - Updated version to 1.0.2. - No changes to workflow or core functionality.","fileCount":3,"zipByteSize":3645},{"version":"1.0.1","createdAt":"2026-05-02T17:32:46.176Z","changelog":"SEO update for smart contract audit and DeFi audit search discovery","fileCount":3,"zipByteSize":3634},{"version":"1.0.0","createdAt":"2026-05-02T16:01:00.552Z","changelog":"Initial free lead-magnet release","fileCount":3,"zipByteSize":2861}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s178kk8n3h54fa7qzx3gsf72md85y3vm:atlas-bounty-triage","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s178kk8n3h54fa7qzx3gsf72md85y3vm:atlas-bounty-triage` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/n8gendegen/atlas-bounty-triage before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T00:35:36.511Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-n8gendegen-atlas-bounty-triage/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":null},"readme":"Skill: DeFi Audit & Smart Contract Bounty Triage\n\nOwner: n8gendegen\n\nSummary: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surfa...\n\nTags: atlas:1.0.4, audit:1.0.1, bug-bounty:1.0.4, code4rena:1.0.4, defi:1.0.1, defi-audit:1.0.4, evm:1.0.1, hackenproof:1.0.4, latest:1.0.4, security:1.0.1, sherlock:1.0.4, smart-contract:1.0.1, smart-contract-audit:1.0.4, solidity:1.0.1, solidity-audit:1.0.4, vulnerability-scanner:1.0.1\n\nVersion history:\n\nv1.0.4 | 2026-05-17T14:36:17.732Z | user\n\nConversion SEO v1.0.4: exact-match DeFi audit title, smart contract audit keywords, stronger star/download CTA, and paid ZIP funnel copy.\n\nv1.0.3 | 2026-05-17T03:17:58.576Z | auto\n\n- Added new calls to action (CTAs) for bug bounty triage, Code4rena, Sherlock, HackenProof, and DeFi bounty workflows.\n- Updated homepage URL tracking for paid Starter/Pro package promotion.\n- Enhanced search keywords and use cases for improved conversion SEO.\n- Added details and direct links for paid Atlas Starter/Pro ZIP Packs.\n- Expanded feature and upsell descriptions to highlight bounty and audit workflow scenarios.\n\nv1.0.2 | 2026-05-10T14:28:03.522Z | auto\n\n- Added UTM tracking parameters to homepage link for improved download attribution.\n- Updated version to 1.0.2.\n- No changes to workflow or core functionality.\n\nv1.0.1 | 2026-05-02T17:32:46.176Z | user\n\nSEO update for smart contract audit and DeFi audit search discovery\n\nv1.0.0 | 2026-05-02T16:01:00.552Z | user\n\nInitial free lead-magnet release\n\nArchive index:\n\nArchive v1.0.4: 4 files, 5392 bytes\n\nFiles: _meta.json (138b), README.md (691b), skill-card.md (2095b), SKILL.md (8776b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: DeFi Audit & Smart Contract Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.4\ndescription: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\nhomepage: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nchangelog: \"Conversion SEO v1.0.4: exact-match DeFi audit title, smart contract audit keywords, stronger star/download CTA, and paid ZIP funnel copy.\"\ntags:\n  - security\n  - audit\n  - smart-contract\n  - smart-contract-audit\n  - defi\n  - defi-audit\n  - solidity\n  - evm\n  - vulnerability-scanner\n  - bug-bounty\n  - code4rena\n  - sherlock\n  - hackenproof\n  - defi-security\n  - solidity-audit\n  - smart-contract-security\n  - defi-bounty\n  - audit-checklist\n  - latest\n  - atlas\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    use_cases:\n      - smart contract audit triage\n      - DeFi protocol audit checklist\n      - Solidity vulnerability review\n      - EVM security research\n      - bug bounty target prioritization\n    upsells:\n      - \"Atlas Starter/Pro ZIP Packs ($49/$150): https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n---\n\n# DeFi Audit & Smart Contract Bounty Triage\n\nA lightweight **smart contract audit** and **DeFi security triage** skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.\n\nUse this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.\n\n## Search Keywords / Best Use Cases\n\n- paid security skill pack\n- DeFi audit workflow\n- DeFi audit checklist\n- DeFi audit template\n- smart contract audit workflow\n- smart contract audit checklist\n- smart contract audit template\n- smart contract bounty triage\n- DeFi bounty triage\n- Solidity bug bounty workflow\n- Code4rena smart contract audit\n- Sherlock smart contract audit\n- HackenProof DeFi bounty\n- paid DeFi audit pack\n- Atlas bounty skill pack\n- Solidity audit template\n- DeFi audit checklist\n- bug bounty report template\n- Code4rena audit prep\n- Sherlock audit prep\n- HackenProof bounty workflow\n\n- smart contract audit\n- DeFi audit\n- DeFi security audit\n- Solidity audit\n- EVM audit\n- vulnerability scanner\n- smart contract vulnerability triage\n- bug bounty triage\n- Code4rena audit workflow\n- Sherlock audit workflow\n- HackenProof bounty workflow\n- access control review\n- oracle manipulation review\n- reentrancy checklist\n- upgradeable proxy review\n\n## When to Use\n\n- New smart contract audit target assigned\n- DeFi contest just opened and you need to prioritize files\n- Bug bounty scope includes Solidity/EVM contracts\n- You need a structured first-pass vulnerability checklist\n- You want to map attack surface before deep manual review\n\n## What It Produces\n\nA structured markdown audit triage report with:\n\n- Target overview\n- Protocol type and contract categories\n- Attack surface map\n- High-priority vulnerability classes\n- Contract-by-contract checklist\n- Recommended deep-dive order\n- Quick-win review items\n\n## Workflow\n\n### Phase 1: Smart Contract Scope Mapping\n\nFor each contract in scope:\n\n1. Identify protocol type: lending, AMM, vault, staking, bridge, oracle, governance, NFT, account abstraction\n2. Identify external integrations: Chainlink, Uniswap, Curve, ERC20 tokens, bridges, routers, keepers\n3. Flag proxy/upgrade patterns: `EIP1967`, `UUPS`, transparent proxy, beacon proxy, clones\n4. Identify privileged roles: owner, admin, guardian, pauser, timelock, operator\n5. Note novel or high-risk mechanisms: custom accounting, share pricing, liquidation math, rewards, TWAPs\n\n### Phase 2: DeFi Vulnerability Prioritization\n\nScore each vulnerability class by **likelihood × impact**:\n\n```text\nHIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction\n```\n\n### Phase 3: Contract-by-Contract Checklist\n\n```markdown\n## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?\n```\n\n### Phase 4: Audit Triage Report\n\n```markdown\n# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n```\n\n## Guardrails\n\nThis is a **triage and audit workflow**, not a guaranteed vulnerability finder. It helps prioritize manual review and produce better audit notes. Always verify candidate findings with a proof of concept before submission.\n\n## Get the Full Atlas Agent Suite\n\nThe full Atlas Bounty Ops workflow includes:\n\n- Contest monitoring for Code4rena, Sherlock, HackenProof\n- Target scoring and prioritization\n- Daily vulnerability pattern promotion\n- Finding writeup templates\n- Scheduled research briefings\n- Revenue ops and marketing agents\n\n👉 https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\n\n## Star + Download CTA\n\nIf this free DeFi audit and bounty triage workflow helped, please **star it on ClawHub** and leave a short comment. Stars/comments help other wardens find it for `defi audit`, `smart contract audit`, and `bug bounty` searches.\n\nFor production-ready templates, use the Atlas paid ZIP packs: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\n## Upgrade: Atlas Paid ZIP Packs ($49 / $150)\n\nThis free ClawHub skill is the discovery layer. If you want the ready-to-run premium workflow, Atlas has two small ZIP packages:\n\n- **Starter — $49:** prompt pack, triage checklist, markdown report templates, and setup guide.\n- **Pro — $150:** everything in Starter plus advanced DeFi modules, risk scoring rubric, bounty-readiness checklist, and reusable audit workspace template.\n\nGet the paid packs here: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nIf this free skill helped, please star/comment on ClawHub so other builders can find it.\n\nFile v1.0.4:README.md\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nFree lightweight smart contract audit and DeFi security triage skill from Atlas Agent Suite.\n\nUse it to map a Solidity/EVM target, prioritize vulnerability classes, and generate a structured first-pass smart contract audit report.\n\nKeywords: smart contract audit, DeFi audit, Solidity audit, EVM security, vulnerability scanner, bug bounty, Code4rena, Sherlock, HackenProof.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nConcierge install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1779028577732\n}\n\nFile v1.0.4:skill-card.md\n\n## Description:\n\nA smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof that maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[n8gendegen](https://clawhub.ai/user/n8gendegen)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security reviewers, and bug bounty researchers use this skill to map Solidity/EVM protocol scope, prioritize DeFi vulnerability classes, and produce a structured first-pass smart contract audit triage report.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Generated reports may include Atlas attribution and paid-product links that are not appropriate for every external audit deliverable.\n\nMitigation: Remove the Atlas footer and paid-product links before sharing reports externally unless that attribution is intentional.\n\nRisk: The workflow helps prioritize manual review but does not guarantee vulnerability discovery or finding correctness.\n\nMitigation: Verify candidate findings with manual analysis and a proof of concept before bounty or audit submission.\n\n## Reference(s):\n\n- [Atlas Agent Suite skill page](https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Guidance, Analysis]\n\n**Output Format:** [Markdown audit triage report with checklists and prioritized review sections]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Non-executable workflow guidance; candidate findings should be manually verified before submission.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.3: 3 files, 3980 bytes\n\nFiles: _meta.json (138b), README.md (691b), SKILL.md (7856b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: Atlas Smart Contract Audit & DeFi Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.3\ndescription: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\nhomepage: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nchangelog: \"Conversion SEO v1.0.3: added bug bounty triage, Code4rena, Sherlock, HackenProof, DeFi bounty, and paid Starter/Pro package CTAs\"\ntags:\n  - security\n  - audit\n  - smart-contract\n  - smart-contract-audit\n  - defi\n  - defi-audit\n  - solidity\n  - evm\n  - vulnerability-scanner\n  - bug-bounty\n  - code4rena\n  - sherlock\n  - hackenproof\n  - atlas\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    use_cases:\n      - smart contract audit triage\n      - DeFi protocol audit checklist\n      - Solidity vulnerability review\n      - EVM security research\n      - bug bounty target prioritization\n    upsells:\n      - \"Atlas Starter/Pro ZIP Packs ($49/$150): https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n---\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nA lightweight **smart contract audit** and **DeFi security triage** skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.\n\nUse this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.\n\n## Search Keywords / Best Use Cases\n\n- paid security skill pack\n- Solidity audit template\n- DeFi audit checklist\n- bug bounty report template\n- Code4rena audit prep\n- Sherlock audit prep\n- HackenProof bounty workflow\n\n- smart contract audit\n- DeFi audit\n- DeFi security audit\n- Solidity audit\n- EVM audit\n- vulnerability scanner\n- smart contract vulnerability triage\n- bug bounty triage\n- Code4rena audit workflow\n- Sherlock audit workflow\n- HackenProof bounty workflow\n- access control review\n- oracle manipulation review\n- reentrancy checklist\n- upgradeable proxy review\n\n## When to Use\n\n- New smart contract audit target assigned\n- DeFi contest just opened and you need to prioritize files\n- Bug bounty scope includes Solidity/EVM contracts\n- You need a structured first-pass vulnerability checklist\n- You want to map attack surface before deep manual review\n\n## What It Produces\n\nA structured markdown audit triage report with:\n\n- Target overview\n- Protocol type and contract categories\n- Attack surface map\n- High-priority vulnerability classes\n- Contract-by-contract checklist\n- Recommended deep-dive order\n- Quick-win review items\n\n## Workflow\n\n### Phase 1: Smart Contract Scope Mapping\n\nFor each contract in scope:\n\n1. Identify protocol type: lending, AMM, vault, staking, bridge, oracle, governance, NFT, account abstraction\n2. Identify external integrations: Chainlink, Uniswap, Curve, ERC20 tokens, bridges, routers, keepers\n3. Flag proxy/upgrade patterns: `EIP1967`, `UUPS`, transparent proxy, beacon proxy, clones\n4. Identify privileged roles: owner, admin, guardian, pauser, timelock, operator\n5. Note novel or high-risk mechanisms: custom accounting, share pricing, liquidation math, rewards, TWAPs\n\n### Phase 2: DeFi Vulnerability Prioritization\n\nScore each vulnerability class by **likelihood × impact**:\n\n```text\nHIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction\n```\n\n### Phase 3: Contract-by-Contract Checklist\n\n```markdown\n## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?\n```\n\n### Phase 4: Audit Triage Report\n\n```markdown\n# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n```\n\n## Guardrails\n\nThis is a **triage and audit workflow**, not a guaranteed vulnerability finder. It helps prioritize manual review and produce better audit notes. Always verify candidate findings with a proof of concept before submission.\n\n## Get the Full Atlas Agent Suite\n\nThe full Atlas Bounty Ops workflow includes:\n\n- Contest monitoring for Code4rena, Sherlock, HackenProof\n- Target scoring and prioritization\n- Daily vulnerability pattern promotion\n- Finding writeup templates\n- Scheduled research briefings\n- Revenue ops and marketing agents\n\n👉 https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\n\n## Upgrade: Atlas Paid ZIP Packs ($49 / $150)\n\nThis free ClawHub skill is the discovery layer. If you want the ready-to-run premium workflow, Atlas has two small ZIP packages:\n\n- **Starter — $49:** prompt pack, triage checklist, markdown report templates, and setup guide.\n- **Pro — $150:** everything in Starter plus advanced DeFi modules, risk scoring rubric, bounty-readiness checklist, and reusable audit workspace template.\n\nGet the paid packs here: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nIf this free skill helped, please star/comment on ClawHub so other builders can find it.\n\nFile v1.0.3:README.md\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nFree lightweight smart contract audit and DeFi security triage skill from Atlas Agent Suite.\n\nUse it to map a Solidity/EVM target, prioritize vulnerability classes, and generate a structured first-pass smart contract audit report.\n\nKeywords: smart contract audit, DeFi audit, Solidity audit, EVM security, vulnerability scanner, bug bounty, Code4rena, Sherlock, HackenProof.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nConcierge install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1778987878576\n}\n\nArchive v1.0.2: 3 files, 3645 bytes\n\nFiles: _meta.json (138b), README.md (691b), SKILL.md (6924b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: Atlas Smart Contract Audit & DeFi Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.2\ndescription: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\nhomepage: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_content=atlas-bounty-triage\nchangelog: \"UTM v1.0.2: added UTM tracking for download attribution\"\ntags:\n  - security\n  - audit\n  - smart-contract\n  - smart-contract-audit\n  - defi\n  - defi-audit\n  - solidity\n  - evm\n  - vulnerability-scanner\n  - bug-bounty\n  - code4rena\n  - sherlock\n  - hackenproof\n  - atlas\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    use_cases:\n      - smart contract audit triage\n      - DeFi protocol audit checklist\n      - Solidity vulnerability review\n      - EVM security research\n      - bug bounty target prioritization\n    upsells:\n      - \"Full Atlas Bounty Ops: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n---\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nA lightweight **smart contract audit** and **DeFi security triage** skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.\n\nUse this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.\n\n## Search Keywords / Best Use Cases\n\n- smart contract audit\n- DeFi audit\n- DeFi security audit\n- Solidity audit\n- EVM audit\n- vulnerability scanner\n- smart contract vulnerability triage\n- bug bounty triage\n- Code4rena audit workflow\n- Sherlock audit workflow\n- HackenProof bounty workflow\n- access control review\n- oracle manipulation review\n- reentrancy checklist\n- upgradeable proxy review\n\n## When to Use\n\n- New smart contract audit target assigned\n- DeFi contest just opened and you need to prioritize files\n- Bug bounty scope includes Solidity/EVM contracts\n- You need a structured first-pass vulnerability checklist\n- You want to map attack surface before deep manual review\n\n## What It Produces\n\nA structured markdown audit triage report with:\n\n- Target overview\n- Protocol type and contract categories\n- Attack surface map\n- High-priority vulnerability classes\n- Contract-by-contract checklist\n- Recommended deep-dive order\n- Quick-win review items\n\n## Workflow\n\n### Phase 1: Smart Contract Scope Mapping\n\nFor each contract in scope:\n\n1. Identify protocol type: lending, AMM, vault, staking, bridge, oracle, governance, NFT, account abstraction\n2. Identify external integrations: Chainlink, Uniswap, Curve, ERC20 tokens, bridges, routers, keepers\n3. Flag proxy/upgrade patterns: `EIP1967`, `UUPS`, transparent proxy, beacon proxy, clones\n4. Identify privileged roles: owner, admin, guardian, pauser, timelock, operator\n5. Note novel or high-risk mechanisms: custom accounting, share pricing, liquidation math, rewards, TWAPs\n\n### Phase 2: DeFi Vulnerability Prioritization\n\nScore each vulnerability class by **likelihood × impact**:\n\n```text\nHIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction\n```\n\n### Phase 3: Contract-by-Contract Checklist\n\n```markdown\n## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?\n```\n\n### Phase 4: Audit Triage Report\n\n```markdown\n# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n```\n\n## Guardrails\n\nThis is a **triage and audit workflow**, not a guaranteed vulnerability finder. It helps prioritize manual review and produce better audit notes. Always verify candidate findings with a proof of concept before submission.\n\n## Get the Full Atlas Agent Suite\n\nThe full Atlas Bounty Ops workflow includes:\n\n- Contest monitoring for Code4rena, Sherlock, HackenProof\n- Target scoring and prioritization\n- Daily vulnerability pattern promotion\n- Finding writeup templates\n- Scheduled research briefings\n- Revenue ops and marketing agents\n\n👉 https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.2:README.md\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nFree lightweight smart contract audit and DeFi security triage skill from Atlas Agent Suite.\n\nUse it to map a Solidity/EVM target, prioritize vulnerability classes, and generate a structured first-pass smart contract audit report.\n\nKeywords: smart contract audit, DeFi audit, Solidity audit, EVM security, vulnerability scanner, bug bounty, Code4rena, Sherlock, HackenProof.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nConcierge install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778423283522\n}\n\nArchive v1.0.1: 3 files, 3634 bytes\n\nFiles: README.md (691b), SKILL.md (6898b), _meta.json (138b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: Atlas Smart Contract Audit & DeFi Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.1\ndescription: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\nhomepage: https://atlasagentsuite.com/skills.html\nchangelog: \"SEO update: added smart contract audit, DeFi audit, Solidity, EVM, vulnerability scanner keywords\"\ntags:\n  - security\n  - audit\n  - smart-contract\n  - smart-contract-audit\n  - defi\n  - defi-audit\n  - solidity\n  - evm\n  - vulnerability-scanner\n  - bug-bounty\n  - code4rena\n  - sherlock\n  - hackenproof\n  - atlas\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    use_cases:\n      - smart contract audit triage\n      - DeFi protocol audit checklist\n      - Solidity vulnerability review\n      - EVM security research\n      - bug bounty target prioritization\n    upsells:\n      - \"Full Atlas Bounty Ops: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n---\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nA lightweight **smart contract audit** and **DeFi security triage** skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.\n\nUse this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.\n\n## Search Keywords / Best Use Cases\n\n- smart contract audit\n- DeFi audit\n- DeFi security audit\n- Solidity audit\n- EVM audit\n- vulnerability scanner\n- smart contract vulnerability triage\n- bug bounty triage\n- Code4rena audit workflow\n- Sherlock audit workflow\n- HackenProof bounty workflow\n- access control review\n- oracle manipulation review\n- reentrancy checklist\n- upgradeable proxy review\n\n## When to Use\n\n- New smart contract audit target assigned\n- DeFi contest just opened and you need to prioritize files\n- Bug bounty scope includes Solidity/EVM contracts\n- You need a structured first-pass vulnerability checklist\n- You want to map attack surface before deep manual review\n\n## What It Produces\n\nA structured markdown audit triage report with:\n\n- Target overview\n- Protocol type and contract categories\n- Attack surface map\n- High-priority vulnerability classes\n- Contract-by-contract checklist\n- Recommended deep-dive order\n- Quick-win review items\n\n## Workflow\n\n### Phase 1: Smart Contract Scope Mapping\n\nFor each contract in scope:\n\n1. Identify protocol type: lending, AMM, vault, staking, bridge, oracle, governance, NFT, account abstraction\n2. Identify external integrations: Chainlink, Uniswap, Curve, ERC20 tokens, bridges, routers, keepers\n3. Flag proxy/upgrade patterns: `EIP1967`, `UUPS`, transparent proxy, beacon proxy, clones\n4. Identify privileged roles: owner, admin, guardian, pauser, timelock, operator\n5. Note novel or high-risk mechanisms: custom accounting, share pricing, liquidation math, rewards, TWAPs\n\n### Phase 2: DeFi Vulnerability Prioritization\n\nScore each vulnerability class by **likelihood × impact**:\n\n```text\nHIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction\n```\n\n### Phase 3: Contract-by-Contract Checklist\n\n```markdown\n## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?\n```\n\n### Phase 4: Audit Triage Report\n\n```markdown\n# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n```\n\n## Guardrails\n\nThis is a **triage and audit workflow**, not a guaranteed vulnerability finder. It helps prioritize manual review and produce better audit notes. Always verify candidate findings with a proof of concept before submission.\n\n## Get the Full Atlas Agent Suite\n\nThe full Atlas Bounty Ops workflow includes:\n\n- Contest monitoring for Code4rena, Sherlock, HackenProof\n- Target scoring and prioritization\n- Daily vulnerability pattern promotion\n- Finding writeup templates\n- Scheduled research briefings\n- Revenue ops and marketing agents\n\n👉 https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.1:README.md\n\n# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nFree lightweight smart contract audit and DeFi security triage skill from Atlas Agent Suite.\n\nUse it to map a Solidity/EVM target, prioritize vulnerability classes, and generate a structured first-pass smart contract audit report.\n\nKeywords: smart contract audit, DeFi audit, Solidity audit, EVM security, vulnerability scanner, bug bounty, Code4rena, Sherlock, HackenProof.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nConcierge install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1777743166176\n}\n\nArchive v1.0.0: 3 files, 2861 bytes\n\nFiles: README.md (335b), SKILL.md (4600b), _meta.json (138b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: Atlas Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.0\ndescription: Lightweight bug bounty triage agent. Scans target scope, maps attack surface, prioritizes high-value vulnerability classes, and generates a structured triage report. Works with Code4rena, Sherlock, and HackenProof formats.\nhomepage: https://atlasagentsuite.com/skills.html\nchangelog: \"Initial release\"\ntags:\n  - security\n  - bug-bounty\n  - smart-contract-audit\n  - vulnerability-scanning\n  - automation\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    upsells:\n      - \"Full Atlas Bounty Ops: https://atlasagentsuite.com/skills.html\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html\"\n---\n\n# Atlas Bounty Triage\n\nA lightweight triage agent for bug bounty researchers. Use this to quickly scope a target, identify high-probability vulnerability classes, and produce a structured report before starting your deep-dive audit.\n\n## When to Use\n\n- New target assigned, need fast attack surface map\n- Contest just started, need to prioritize where to look first\n- Wrapping up a triage session, need a clean report to share\n\n## Run Format\n\n```bash\n# Minimal run\nbounty-triage <target-name> \"<scope-description>\"\n\n# Full run with protocol type\nbounty-triage <target-name> \"<scope-description>\" --protocol defi --output report.md\n```\n\n## Workflow\n\n### Phase 1: Scope Mapping\n\nFor each contract in scope:\n\n1. Note its primary function families (ERC20, lending, AMM, governance, etc.)\n2. Identify external integrations (oracles, other protocols, token contracts)\n3. Flag any proxy patterns (`EIP1967`, `EIP1167`, upgradeable proxies)\n4. Identify privileged roles (Owner, Admin, Timelock, Guardian)\n5. Note any novel mechanisms unique to this protocol\n\n### Phase 2: Vulnerability Class Prioritization\n\nScore each class by **likelihood × impact**. Prioritize:\n\n```\nHIGH PRIORITY\n- Reentrancy (external calls + state changes)\n- Access control gaps (missing modifiers, role confusion)\n- Oracle manipulation (price feeds, TWAP, Chainlink reads)\n- Logic errors (missing checks, wrong calculations)\n\nMEDIUM PRIORITY\n- Token handling edge cases (fee-on-transfer, rebasing, snapshots)\n- Front-running / MEV exposure\n- Upgradeable proxy risks (storage collisions, initializer front-running)\n- Settlement / reconciliation bugs\n\nLOW PRIORITY (but check anyway)\n- Input validation edge cases\n- DOS / gas limit exploitation\n- Griefing / spam vectors\n```\n\n### Phase 3: Quick Audit Checklist\n\nGenerate a per-contract checklist:\n\n```markdown\n## Contract: <Name>\n### External Calls\n- [ ] Reentrancy guard present on all external calls?\n- [ ] Callback targets trusted or validated?\n### Access Control\n- [ ] All privileged functions have correct modifiers?\n- [ ] Role assignments follow least privilege?\n### Math\n- [ ] Safemath / checked math used throughout?\n- [ ] Precision loss understood and documented?\n### Upgrade Pattern\n- [ ] Proxy storage layout verified?\n- [ ] Initializer properly guarded?\n```\n\n### Phase 4: Triage Report\n\nOutput a structured markdown report:\n\n```markdown\n# Bounty Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Total contracts in scope:\n\n## Attack Surface Summary\n- External integrations:\n- Novel mechanisms:\n- Privileged roles:\n\n## Priority Finding Classes\n1. [HIGH] <class> — <why>\n2. [HIGH] <class> — <why>\n3. [MEDIUM] <class> — <why>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vuln class>\n2. <contract> — focus on <vuln class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy audit of <contract>\n- [ ] Access control review of <contract>\n- [ ] Oracle integration check\n\n---\n*Report generated by Atlas Bounty Triage. Get the full Atlas Bounty Ops agent at atlasagentsuite.com/skills.html*\n```\n\n## Tips\n\n- Start with external calls — they're the most common root cause of high-severity findings\n- Always check proxy implementations for storage collisions before anything else\n- For lending protocols, focus on liquidation logic and collateral factor interactions\n- In AMMs, check fee-on-transfer and transfer-while-minting edge cases\n\n## Limitations\n\nThis is a **lightweight triage tool**. It does not replace a full audit. It helps you focus your time on the highest-probability areas. Always do a manual deep-dive on anything flagged HIGH priority.\n\n## Get the Full Suite\n\nAtlas Bounty Ops adds:\n- Automated contest monitoring (Code4rena, Sherlock, HackenProof)\n- Daily pattern promotion from your own submissions\n- Target prioritization scoring\n- Full finding writeup templates\n- Scheduled daily briefings\n\n👉 https://atlasagentsuite.com/skills.html\n\nFile v1.0.0:README.md\n\n# Atlas Bounty Triage\n\nFree lightweight triage skill from Atlas Agent Suite.\n\nUse it to map a new bounty or audit target, prioritize vulnerability classes, and generate a structured first-pass review report.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html\nConcierge install: https://atlasagentsuite.com/concierge.html\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777737660552\n}","readmeExcerpt":"Skill: DeFi Audit & Smart Contract Bounty Triage Owner: n8gendegen Summary: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surfa... Tags: atlas:1.0.4, audit:1.0.1, bug-bounty:1.0.4, code4rena:1.0.4, defi:1.0.1, defi-audit:1.0.4, evm:1.0.1, hackenproof:1.0.4, latest:1.0.4, security:1.0.1, sherlock:1.0.4, smart-cont","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"HIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction"},{"language":"markdown","snippet":"## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?"},{"language":"markdown","snippet":"# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage"},{"language":"text","snippet":"HIGH PRIORITY\n- Reentrancy: external calls + state changes + callbacks\n- Access control: missing modifiers, wrong role assumptions, admin bypass\n- Oracle manipulation: stale price, TWAP manipulation, decimal mismatch, fallback oracle bugs\n- Accounting bugs: share price drift, rounding loss, fee math, collateral/debt mismatch\n- Liquidation bugs: bad health factor math, stale collateral values, griefable liquidation paths\n- Upgradeability bugs: unprotected initializer, storage collision, implementation takeover\n\nMEDIUM PRIORITY\n- Fee-on-transfer / rebasing token edge cases\n- ERC777 / callback-enabled token surprises\n- Sandwich / MEV-sensitive pricing\n- DOS via unbounded loops or griefable state\n- Signature replay / permit domain separator issues\n\nLOW PRIORITY BUT CHECK\n- Input validation gaps\n- Event/reporting mismatch\n- Gas griefing\n- Minor precision loss without exploitable value extraction"},{"language":"markdown","snippet":"## Contract: <Name>\n\n### External Calls / Reentrancy\n- [ ] External calls happen after state updates?\n- [ ] Reentrancy guard exists where callbacks are possible?\n- [ ] ERC777 / ERC721 receiver / flash loan callbacks considered?\n\n### Access Control\n- [ ] Privileged functions use correct modifier?\n- [ ] Timelock/owner/admin boundaries are clear?\n- [ ] Emergency functions cannot steal user funds?\n\n### Oracle / Pricing\n- [ ] Oracle freshness checked?\n- [ ] Decimal normalization correct?\n- [ ] Fallback oracle cannot be manipulated?\n- [ ] TWAP window long enough for protocol value at risk?\n\n### Accounting\n- [ ] Shares/assets conversion handles rounding direction correctly?\n- [ ] Fee calculations cannot drain or brick accounting?\n- [ ] Deposits/withdrawals preserve invariants?\n\n### Upgradeability\n- [ ] Initializers protected?\n- [ ] Storage layout compatible?\n- [ ] Implementation cannot be selfdestructed or hijacked?"},{"language":"markdown","snippet":"# Smart Contract Audit Triage: <Target>\n\n## Target Overview\n- Protocol type:\n- Chain(s):\n- Contracts in scope:\n- Highest-value assets:\n\n## Attack Surface Summary\n- External integrations:\n- Oracle dependencies:\n- Upgrade pattern:\n- Privileged roles:\n\n## Top Vulnerability Classes to Review\n1. [HIGH] <class> — <why this target is exposed>\n2. [HIGH] <class> — <why this target is exposed>\n3. [MEDIUM] <class> — <why this target is exposed>\n\n## Recommended Deep-Dive Order\n1. <contract> — focus on <vulnerability class>\n2. <contract> — focus on <vulnerability class>\n3. <contract> — focus on <vulnerability class>\n\n## Quick Wins Checklist\n- [ ] Reentrancy review\n- [ ] Access control review\n- [ ] Oracle manipulation review\n- [ ] Upgradeability review\n- [ ] Accounting invariant review\n\n---\nGenerated by Atlas Smart Contract Audit & DeFi Bounty Triage.\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: DeFi Audit & Smart Contract Bounty Triage\nslug: atlas-bounty-triage\nversion: 1.0.4\ndescription: Smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof. Maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\nhomepage: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nchangelog: \"Conversion SEO v1.0.4: exact-match DeFi audit title, smart contract audit keywords, stronger star/download CTA, and paid ZIP funnel copy.\"\ntags:\n  - security\n  - audit\n  - smart-contract\n  - smart-contract-audit\n  - defi\n  - defi-audit\n  - solidity\n  - evm\n  - vulnerability-scanner\n  - bug-bounty\n  - code4rena\n  - sherlock\n  - hackenproof\n  - defi-security\n  - solidity-audit\n  - smart-contract-security\n  - defi-bounty\n  - audit-checklist\n  - latest\n  - atlas\nmetadata:\n  AtlasAgentSuite:\n    tier: free\n    use_cases:\n      - smart contract audit triage\n      - DeFi protocol audit checklist\n      - Solidity vulnerability review\n      - EVM security research\n      - bug bounty target prioritization\n    upsells:\n      - \"Atlas Starter/Pro ZIP Packs ($49/$150): https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n      - \"Concierge Install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\"\n---\n\n# DeFi Audit & Smart Contract Bounty Triage\n\nA lightweight **smart contract audit** and **DeFi security triage** skill for Solidity/EVM protocols, bug bounty hunters, Code4rena wardens, Sherlock auditors, and HackenProof researchers.\n\nUse this when you need a fast first-pass review of a DeFi protocol or smart contract scope before committing hours to a manual audit.\n\n## Search Keywords / Best Use Cases\n\n- paid security skill pack\n- DeFi audit workflow\n- DeFi audit checklist\n- DeFi audit template\n- smart contract audit workflow\n- smart contract audit checklist\n- smart contract audit template\n- smart contract bounty triage\n- DeFi bounty triage\n- Solidity bug bounty workflow\n- Code4rena smart contract audit\n- Sherlock smart contract audit\n- HackenProof DeFi bounty\n- paid DeFi audit pack\n- Atlas bounty skill pack\n- Solidity audit template\n- DeFi audit checklist\n- bug bounty report template\n- Code4rena audit prep\n- Sherlock audit prep\n- HackenProof bounty workflow\n\n- smart contract audit\n- DeFi audit\n- DeFi security audit\n- Solidity audit\n- EVM audit\n- vulnerability scanner\n- smart contract vulnerability triage\n- bug bounty triage\n- Code4rena audit workflow\n- Sherlock audit workflow\n- HackenProof bounty workflow\n- access control review\n- oracle manipulation review\n- reentrancy checklist\n- upgradeable proxy review\n\n## When to Use\n\n- New smart contract audit target assigned\n- DeFi contest just opened and you need to prioritize files\n- Bug bounty scope includes Solidity/EVM contract"},{"path":"README.md","content":"# Atlas Smart Contract Audit & DeFi Bounty Triage\n\nFree lightweight smart contract audit and DeFi security triage skill from Atlas Agent Suite.\n\nUse it to map a Solidity/EVM target, prioritize vulnerability classes, and generate a structured first-pass smart contract audit report.\n\nKeywords: smart contract audit, DeFi audit, Solidity audit, EVM security, vulnerability scanner, bug bounty, Code4rena, Sherlock, HackenProof.\n\nFull Atlas Agent Suite: https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage\nConcierge install: https://atlasagentsuite.com/concierge.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn781dbr70kzecrypxr3g90ckn85y6ma\",\n  \"slug\": \"atlas-bounty-triage\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1779028577732\n}"},{"path":"skill-card.md","content":"## Description:\n\nA smart contract audit and DeFi security triage skill for Solidity, EVM protocols, bug bounty programs, Code4rena, Sherlock, and HackenProof that maps attack surface, prioritizes vulnerabilities, and generates a structured audit checklist/report.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[n8gendegen](https://clawhub.ai/user/n8gendegen)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security reviewers, and bug bounty researchers use this skill to map Solidity/EVM protocol scope, prioritize DeFi vulnerability classes, and produce a structured first-pass smart contract audit triage report.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Generated reports may include Atlas attribution and paid-product links that are not appropriate for every external audit deliverable.\n\nMitigation: Remove the Atlas footer and paid-product links before sharing reports externally unless that attribution is intentional.\n\nRisk: The workflow helps prioritize manual review but does not guarantee vulnerability discovery or finding correctness.\n\nMitigation: Verify candidate findings with manual analysis and a proof of concept before bounty or audit submission.\n\n## Reference(s):\n\n- [Atlas Agent Suite skill page](https://atlasagentsuite.com/skills.html?utm_source=clawhub&utm_medium=skill&utm_campaign=atlas-bounty-triage)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Guidance, Analysis]\n\n**Output Format:** [Markdown audit triage report with checklists and prioritized review sections]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Non-executable workflow guidance; candidate findings should be manually verified before submission.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1265,"uniquenessScore":38,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:23:03.406Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T00:35:36.512Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}