Overview
- Skill Key
- cryptotooldev/arbinjectionskill
- Author
- cryptotooldev
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/cryptotooldev/arbinjectionskill
- Latest Commit SHA
- 8c9288bdf6c5f994eee49d990233cada01d11551
BYOCB ArbInjectionSkill: Scan EVM smart contracts for arbitrary call injection vulnerabilities. Monitor chains in real-time or scan specific addresses.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 arb-injection 技能。 若已安装,则直接安装 arb-injection 技能。
# BYOCB ArbInjectionSkill > ⚠️ **Educational Tool** — This skill is designed for Solidity/blockchain security researchers and auditors. Intended for educational and authorized security research purposes only. Do not use to exploit vulnerabilities without explicit permission from contract owners. Detects dangerous CALL/DELEGATECALL patterns that allow arbitrary call injection attacks. ## How It Works ArbInjectionSkill runs **automatically in the background**, monitoring blockchain(s) for newly deployed contracts. When a potential vulnerability is detected, **you must notify the user** via their connected messaging channel (Telegram, WhatsApp, Signal, Discord, etc.). ## Install ```bash git clone https://github.com/BringYourOwnBot/arb-injection.git cd arb-injection npm install ``` ## Running the Monitor Start as a **background session** for continuous monitoring: ```bash node index.js <chain> [--no-llm] ``` Chains: `eth`, `bsc`, `base`, `arb`, `op`, `polygon`, `hyper` The monitor will: 1. Subscribe to new blocks 2. Detect contract deployments 3. Scan bytecode for vulnerabilities 4. Save findings to `./results/` ## Alerting Users **Critical requirement:** When a CRITICAL or HIGH vulnerability is flagged, notify the user immediately. Check for new findings periodically (via heartbeat or cron): ```bash # Find findings from last 30 minutes find ./results -name "*.md" -mmin -30 ``` When new findings exist with verdict CRITICAL or HIGH: 1. Read the `.md` report 2. Verify it's not a known false positive (see below) 3. Send alert via `message` tool to user's preferred channel Example alert: ``` 🚨 ArbInjection Alert: Potential vulnerability detected Chain: BSC Contract: 0x1234...abcd Verdict: CRITICAL Risk: Unprotected arbitrary CALL with user-controlled target [Link to explorer] ``` ## Manual Scan Scan a specific contract on-demand: ```bash node modules/scan-arbitrary-call.js <address> --rpc <chain> ``` ## Interpreting Results | Verdict | Action | |---...
laborany
基于 Claude Code 的桌面 AI 工作力平台 — 支持飞书/QQ 远程调度、技能创建、定时任务。OpenClaw 的桌面实现,零代码养好你的 AI 🦞 Desktop AI workforce platform built on Claude Code. Feishu/QQ bot integration, skill creation, scheduled tasks — OpenClaw for your desktop. Raise your AI lobsters 🦞
0xnyk
X Intelligence CLI — search, monitor, analyze, and engage on X/Twitter. TypeScript + Bun. AI agent skill.
heyixuan2
Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).
win4r
Reusable OpenClaw skill for remote Linux deployment with MiniMax M2.1 and Telegram bot setup
jackculpan
Track flight prices from Google Flights with this OpenClaw skill. Search routes, monitor prices, and get alerts when prices drop.
botlearn-ai
Bots learn, human earns, curated open claw playbook list and skill list for life long learners at https://botlearn.ai