Agent skill

Solana Audit Flow

by mtarcure in mtarcure/claude-vibe-squad

A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…

MITAuto-check passedSecurity

Install Solana Audit Flow

skills CLI
$ npx skills add mtarcure/claude-vibe-squad --skill solana-audit-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mtarcure/claude-vibe-squad solana-audit-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/solana-audit-flow .claude/skills/solana-audit-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
solana-audit-flow
GitHub stars
164
Token cost
~1.4k tokens
SKILL.md length
655 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…

  • Works in 6 steps: Build and lint. anchor build (or cargo… → Manual vuln-pattern review (primary… → Unit test run. Run the existing suite… → …
  • Auditing an Anchor
  • SKILL.md covers Order of ops, When to pivot, Anti-patterns and Example, plus 1 more section
  • Calls cargo

What it does

Solana Audit Flow is an agent skill from mtarcure/claude-vibe-squad. Use when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source reading, LiteSVM and cargo tests, plus coverage-guided Trident and cargo-fuzz fuzzers before false-positive triage.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing and Static analysis and SAST. It works with Solana and Rust. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.

When your agent uses it

  • Auditing an Anchor
  • Bare-Rust Solana program end to end
  • Because Solana ships no static analyzers
  • The coverage strategy is compiler-warning triage

Example prompts

  • “/solana-audit-flow”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Build and lint. anchor build (or cargo build-sbf for a bare program) to confirm a
  2. Manual vuln-pattern review (primary coverage). Apply vulnhunter-solana: account
  3. Unit test run. Run the existing suite with cargo test (LiteSVM-backed tests are
  4. Coverage-guided fuzzing.
  5. Runtime/environment probing (optional). Use the solana CLI (solana --version,
  6. Finding triage. Feed combined manual + fuzzing output to the multi-model-fanout

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Solana Audit Flow loads about 1.4k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 655 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 655 words, ~1,427 tokens.

Download SKILL.mdSave it as .claude/skills/solana-audit-flow/SKILL.md (or your agent's skills folder).
name
solana-audit-flow
description
Use when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source reading, LiteSVM and cargo tests, plus coverage-guided Trident and cargo-fuzz fuzzers before false-positive triage.
audience
specialist

solana-audit-flow

Stateful Solana program audit pipeline from Anchor/Rust source through confirmed-finding delivery. Use for a Rust/Anchor workspace or a bare solana_program program. Every step runs a native host tool (anchor, cargo, trident, cargo-fuzz, solana) or a target- project dev-crate (litesvm, run via cargo test). There is no static-analysis step: Slither has zero Solana detectors, so any "slither Solana scan" is a fabricated capability — manual review (vulnhunter-solana) plus dynamic fuzzing is the coverage model on Solana.

Order of ops

  1. Build and lint. anchor build (or cargo build-sbf for a bare program) to confirm a clean compile. Surface ALL compiler warnings — Rust warnings on Solana programs often indicate logic bugs (unused return values, dead paths). Never dismiss #[allow(unused)] without checking what it suppresses. Confirm the toolchain version is already installed; do not run avm use <version> blindly — it can trigger an agave-install network download (no silent installs). If a version mismatch blocks the build, surface it as a ## NEEDS FROM CHRONO item rather than auto-installing.

  2. Manual vuln-pattern review (primary coverage). Apply vulnhunter-solana: account ownership checks (account.owner != program_id), discriminator validation on deserialized accounts, signer checks on privileged instructions, CPI signer validation (caller-controlled signer_seeds), SPL token math overflow, PDA seed collision, unchecked data.borrow_mut(). This is step 2 (not a late step) because there is no static tool to lean on first.

  3. Unit test run. Run the existing suite with cargo test (LiteSVM-backed tests are preferred over solana-program-test for speed; both run under cargo test). A failing test in a security-sensitive instruction is often a direct finding.

  4. Coverage-guided fuzzing.

    • Trident for Anchor-aware, IDL-driven fuzzing: trident fuzz run <target>. Trident generates fuzz instructions from the IDL and checks invariants; write custom FuzzInstruction impls for complex state-machine properties.
    • cargo-fuzz (libFuzzer) for bare parsing/deserialization surfaces and non-Anchor programs: cargo fuzz run <target>.
  5. Runtime/environment probing (optional). Use the solana CLI (solana --version, solana program dump, localnet via solana-test-validator) to reproduce on a controlled local cluster when a finding needs on-chain state. Keep it local; no mainnet writes.

  6. Finding triage. Feed combined manual + fuzzing output to the multi-model-fanout false-positive filter (Chrono dispatches a second model / skeptic stance), then to impact-validator for the G1–G4 impact gate. Focus triage on missing-check findings (confirm the instruction's security model — some privileged instructions are intentionally permissionless) and arithmetic findings (often protected by runtime checked_*).

Show full SKILL.md (270 more words)Show less

When to pivot

  • anchor build fails on version mismatch: read the declared CLI version in Anchor.toml; surface the mismatch (do not auto-avm use, do not modify Anchor.toml) unless the operator instructs. Never trigger a network install.
  • LiteSVM absent/stale: confirm via cargo tree that litesvm is a dev-dependency; if the project uses solana-program-test instead, run those tests via cargo test.
  • Trident coverage too low: add explicit FuzzInstruction variants for underrepresented state-transition sequences; or drop to cargo-fuzz for the raw deserialization surface.
  • Program is very large (>5k LOC): prioritize CPI-adjacent code and privileged instruction handlers — highest attack-surface density.

Anti-patterns

  • Do NOT cite any Solana static-analysis detector — slither_solana_scan / slither --detect solana does not exist; it is the fabricated capability this recreation removes.
  • Do NOT skip manual review (vulnhunter-solana) — it is the primary coverage, not a supplement.
  • Do NOT test Anchor programs with a plain unit runner that lacks CPI/PDA semantics — use LiteSVM or solana-program-test.
  • Do NOT report a "missing signer check" without confirming the instruction's intended security model.
  • Do NOT fuzz without a passing test suite — Trident relies on correct IDL deserialization; test failures indicate IDL drift.
  • Do NOT invoke dead tool_wrappers names (anchor_build, litesvm_test, trident_fuzz, slither_solana_scan); use the native tools above.

Example

bash
# Step 1: build and surface warnings
anchor build

# Step 3: unit tests (LiteSVM-backed run through cargo)
cargo test

# Step 4: Anchor-aware fuzzing
trident fuzz run fuzz_0
# ...and the raw deserialization surface
cargo fuzz run parse_ix

Recording (chrono-vault)

The task packet's injected memory contract owns the exact call shape, sequence, and fields - see wirework-reflect. Do not copy a record(...) example or add fields (including source_task) from memory; the server binds them, and a baked example violates the run's authenticated schema. Memory is best-effort telemetry and never gates the work. What is worth recording here is the task-specific outcome: finding count, missing-check/arithmetic counts, test failures, tools run.

© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/solana-audit-flow of mtarcure/claude-vibe-squad.

Open the folder on GitHubat commit 7bd69f8

Compare with similar skills

Solana Audit Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solana Audit Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solana Audit Flow this skillmtarcure/claude-vibe-squad164—~1.4kAutomated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0
Bom Evidencecdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0
Fuzzing Harness Designtrailofbits/skills7.4k1 repos~5.3kAutomated safety check: PassCC-BY-SA-4.0
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Fuzzing Harness Design

    trailofbits/skills

    Official

    Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

    7.4k GitHub starsUsed in 1 repo~5.3k tokens
    SecurityAuto-check passed
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

    7.4k GitHub stars~3.6k tokensUpdated yesterday
    SecurityAuto-check passed

More from mtarcure/claude-vibe-squad

All 17 skills in this repo
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    164 GitHub stars~3.6k tokensUpdated 18 days ago
    Auto-check passed
  • Blind Rediscovery

    mtarcure/claude-vibe-squad

    Operational checklist + helper for blind-rediscovery fan-out work.

    164 GitHub stars~1.6k tokensUpdated 18 days ago
    Auto-check passed
  • Chain Construct Smart Contract

    mtarcure/claude-vibe-squad

    A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

    164 GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check passed
  • Compact Now

    mtarcure/claude-vibe-squad

    Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…

    164 GitHub stars~1.6k tokensUpdated 18 days ago
    Auto-check passed
  • Agent Prompt Engineering

    mtarcure/claude-vibe-squad

    A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.

    164 GitHub stars~872 tokensUpdated 18 days ago
    Auto-check: warnings
  • Defi Invariant Check

    mtarcure/claude-vibe-squad

    A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

    164 GitHub stars~2.5k tokensUpdated 18 days ago
    Auto-check passed

Works with

Categories

Questions about Solana Audit Flow

What does Solana Audit Flow do?

A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…. Solana Audit Flow is an agent skill from mtarcure/claude-vibe-squad. Use when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source reading, LiteSVM and cargo tests, plus coverage-guided Trident and cargo-fuzz fuzzers before false-positive triage.

When should I use Solana Audit Flow?

Solana Audit Flow fits situations like: auditing an Anchor; bare-Rust Solana program end to end; because Solana ships no static analyzers; the coverage strategy is compiler-warning triage.

How do I install Solana Audit Flow in Claude Code?

Run `npx skills add mtarcure/claude-vibe-squad --skill solana-audit-flow -a claude-code`. Or copy the skill folder (.agents/skills/solana-audit-flow in mtarcure/claude-vibe-squad) into .claude/skills/solana-audit-flow in your project. Claude Code loads it when a task matches its description.

How do I install Solana Audit Flow in Codex?

Run `npx skills add mtarcure/claude-vibe-squad --skill solana-audit-flow -a codex`. Or copy the skill folder (.agents/skills/solana-audit-flow in mtarcure/claude-vibe-squad) into .agents/skills/solana-audit-flow in your project. Codex loads it when a task matches its description.

Can I use Solana Audit Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill solana-audit-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solana-audit-flow, .gemini/skills/solana-audit-flow, .github/skills/solana-audit-flow and .opencode/skills/solana-audit-flow in your project.

What does Solana Audit Flow need to run?

Going by SKILL.md and its folder, Solana Audit Flow needs the command-line tools its instructions call (cargo).

Does Solana Audit Flow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Solana Audit Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Solana Audit Flow use?

Solana Audit Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Solana Audit Flow use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Solana Audit Flow?

Skills that share tags, products or a category with Solana Audit Flow: Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Skeptic (RaoFoundation/subtensor, 389 stars), Bom Evidence (cdxgen/cdxgen, 1.1k stars) and Fuzzing Harness Design (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solana Audit Flow?

mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 164 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.

Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.