Agent skill

Vulnhunter Solana

by mtarcure in mtarcure/claude-vibe-squad

A skill your agent uses when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds…

MITAuto-check passedSecurity

Install Vulnhunter Solana

skills CLI
$ npx skills add mtarcure/claude-vibe-squad --skill vulnhunter-solana -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mtarcure/claude-vibe-squad vulnhunter-solana --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vulnhunter-solana .claude/skills/vulnhunter-solana && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnhunter-solana
GitHub stars
165
Token cost
~2.1k tokens
SKILL.md length
978 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds…

  • Works in 5 steps: Grep the program source for AccountInfo… → Grep for invoke_signed usages. For each:… → Grep for arithmetic operators on… → …
  • Reviewing Solana program code for the account-model bug classes — unchecked account owner
  • SKILL.md covers High-priority vuln patterns, Order of ops, When to pivot and Anti-patterns, plus 3 more sections
  • Calls rg

What it does

Vulnhunter Solana is an agent skill from mtarcure/claude-vibe-squad. Use when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds, PDA-derivation collision, SPL arithmetic overflow, close-and-reinitialize revival, and duplicate-account aliasing — the pattern census that stands in for absent scanners.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Solana. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.

When your agent uses it

  • Reviewing Solana program code for the account-model bug classes — unchecked account owner
  • Discriminator confusion
  • Caller-controlled CPI seeds
  • PDA-derivation collision

Example prompts

  • “/vulnhunter-solana”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Grep the program source for AccountInfo usages. For each: verify owner check and signer check where required.
  2. Grep for invoke_signed usages. For each: trace the signer_seeds derivation — are any seeds caller-controlled?
  3. Grep for arithmetic operators on u64/u128 token amounts. For each: confirm checked_* or saturating_* is used.
  4. Review all #[derive(Accounts)] structs: for each AccountInfo<'info> field, check if an Account<'info, T> type with Anchor constraints…
  5. Review PDA seed construction: list all PDA seeds, confirm each includes a type prefix.

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnhunter Solana loads about 2.1k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 978 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 978 words, ~2,073 tokens.

Download SKILL.mdSave it as .claude/skills/vulnhunter-solana/SKILL.md (or your agent's skills folder).
name
vulnhunter-solana
description
Use when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds, PDA-derivation collision, SPL arithmetic overflow, close-and-reinitialize revival, and duplicate-account aliasing — the pattern census that stands in for absent scanners.
audience
specialist

vulnhunter-solana

Manual vulnerability pattern review for Solana Rust programs. Use this during solana-audit-flow. There is no Solana static-analysis step — Slither has zero Solana detectors (slither --list-detectors → 104, none for Solana), so any "slither Solana scan" is a fabricated capability. Manual pattern matching is the primary coverage on Solana; the automated Solana tooling is dynamic (anchor build warnings, litesvm/trident fuzzing), not static taint analysis.

High-priority vuln patterns

1. Missing owner / program-id check (CRITICAL) Every account deserialized from instruction accounts must have its owner validated against the expected program ID. Pattern: if account.owner != &expected_program_id { return Err(...) }. Anchor's #[account] constraint handles this — but bare AccountInfo usage does not. Grep for AccountInfo without adjacent owner check.

2. Missing signer check (HIGH) Privileged instructions must require is_signer on the authority account. Pattern: if !authority.is_signer { return Err(ErrorCode::Unauthorized.into()) }. Anchor's Signer<'info> type enforces this — but AccountInfo with manual check can omit it. Grep for privileged state mutations without is_signer guard.

3. Account discriminator bypass (HIGH) Anchor programs use 8-byte discriminators at the start of account data to prevent type confusion. An attacker can pass a different account type that happens to deserialize without error if the discriminator is not validated. Verify try_deserialize is used (not try_deserialize_unchecked) for sensitive account types. Also check: can two different account types be interchanged via a crafted buffer?

4. CPI signer / privilege escalation (CRITICAL) When making CPIs that require signing, the invoke_signed call must pass the correct signer_seeds. A bug where the caller-controlled account address matches a PDA derivation can allow privilege escalation. Pattern: verify invoke_signed uses program-controlled seeds, not caller-provided seeds, for authority PDAs.

5. SPL token arithmetic overflow (HIGH in pre-checked code) SPL token math (amounts, decimals, fee calculation) must use checked_* arithmetic (checked_add, checked_mul, checked_div). Grep for arithmetic operators (+, *, /) directly on u64 token amounts in pre-1.14 programs. Post-1.14, overflow-checks = true in Cargo.toml [profile.release] provides runtime protection; verify this is set.

6. PDA derivation collision / seed manipulation (HIGH) Two different logical accounts can derive to the same PDA if seed inputs are insufficiently discriminated. Pattern: PDA seeds that include only user-controlled data (e.g., just a user public key) without a type discriminator can collide across account types. Verify seeds include a fixed type-specific prefix.

7. Unchecked AccountInfo.data mutation (CRITICAL) Direct write to account.data.borrow_mut() bypasses Anchor's borsh serialization guarantees. Verify that data writes always go through account.exit() or Anchor's Account::serialize path.

8. Rent-exempt check missing (LOW-MEDIUM) Accounts that fall below rent-exempt minimum can be garbage-collected by the runtime. Verify that account creation always includes the rent-exempt minimum lamport balance. Missing this is usually LOW severity unless it can be weaponized to force a denial-of-service.

Order of ops

  1. Grep the program source for AccountInfo usages. For each: verify owner check and signer check where required.
  2. Grep for invoke_signed usages. For each: trace the signer_seeds derivation — are any seeds caller-controlled?
  3. Grep for arithmetic operators on u64/u128 token amounts. For each: confirm checked_* or saturating_* is used.
  4. Review all #[derive(Accounts)] structs: for each AccountInfo<'info> field, check if an Account<'info, T> type with Anchor constraints would be more appropriate.
  5. Review PDA seed construction: list all PDA seeds, confirm each includes a type prefix.

When to pivot

  • Program is not Anchor: apply the same patterns manually but via raw solana_program primitives. Owner checks are explicit if account.owner != &program_id. Signer checks are if !account.is_signer. There is no struct-level constraint validation.
  • Program is very large (> 5k LOC): focus on CPI-adjacent code and privileged instruction handlers first; those have the highest attack surface density.
Show full SKILL.md (399 more words)Show less

Anti-patterns

  • Do NOT report a "missing signer check" on accounts where the signer constraint is enforced at the Anchor struct level (Signer<'info>) and verified — only flag bare AccountInfo without manual check.
  • Do NOT flag arithmetic as a finding if overflow-checks = true is confirmed in the release profile AND the code is post-1.14.
  • Do NOT cite any Solana static-analysis detector (slither has none); if a step calls for one, it is stale — use manual review + dynamic fuzzing instead.

Example

Grepping for missing owner checks in an Anchor program:

bash
# Pattern 1: find bare AccountInfo usages
rg "AccountInfo<'info>" programs/ --type rust -n

# Pattern 3: find unchecked arithmetic on u64 token amounts
rg "[^a-z](\+|\*|/)[^=]" programs/ --type rust -n | grep -v "checked_"

# Pattern 4: find invoke_signed calls
rg "invoke_signed" programs/ --type rust -n

Recording (chrono-vault)

The task packet's injected memory contract owns the exact call shape, sequence, and fields - see wirework-reflect. Do not copy a record(...) example or add fields (including source_task) from memory; the server binds them, and a baked example violates the run's authenticated schema. Memory is best-effort telemetry and never gates the work. What is worth recording here is the task-specific outcome: patterns checked, findings per pattern, AccountInfo/invoke_signed usage totals.

Additional account / lifecycle / value classes

These extend the patterns above; the checklist duplicated the owner/signer/discriminator/CPI/PDA/arithmetic/rent classes already covered, so only the genuinely-additive classes are folded here.

  • Account substitution / missing relationship constraint (HIGH). Beyond owner+discriminator, verify the relationships between accounts are enforced: has_one, constraint = x.authority == user.key(), "this vault belongs to this config", "the mint matches". Without them an attacker swaps in their vault / their token account while every individual account still passes its own owner check.
  • close / re-initialization revival (CRITICAL). A closed account must have its lamports drained and its data zeroed / reassigned. Otherwise a closed account can be revived or re-initialized (reinit attack) into a privileged state.
  • Sysvar spoofing on native programs (MEDIUM–HIGH). On non-Anchor programs, clock/rent and other sysvars passed as AccountInfo can be spoofed; verify the account key against the real sysvar id before trusting its data.
  • Duplicate mutable accounts / aliasing (HIGH). The same account passed as two different AccountInfo params (aliasing) can defeat a balance/invariant check that assumes they are distinct. Reject or account for aliasing on mutable params.
  • Invariant preservation across EVERY path (CRITICAL for vaults/DEX/lending). The 1:1 backing / collateralization / k-invariant must hold across fees, refunds, AND gas/rent reimbursement. Historical: gas-reimbursement drawn from the vault broke a bridge's 1:1 backing.
  • Swap direction / parity / slippage. Can direction, price, or fee be manipulated (stale oracle, attacker-set rate, missing min_out slippage bound)?

Extra tooling beyond the flow's defaults: cargo-geiger (unsafe census), cargo-fuzz / trident (fuzz instruction handlers), cargo-audit (dependency CVEs). Related: [[known-advisory-backport-check]].

© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/vulnhunter-solana of mtarcure/claude-vibe-squad.

Open the folder on GitHubat commit 7bd69f8

Compare with similar skills

Vulnhunter Solana next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnhunter Solana compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnhunter Solana this skillmtarcure/claude-vibe-squad165—~2.1kAutomated safety check: PassMIT
Meme Coin Auditsickn33/agentic-awesome-skills47k1 repos~4.2kAutomated safety check: PassMIT
Meme Coin Security Auditawarexone/Agentic-Bug-Hunter5.3k1 repos~2.4kAutomated safety check: PassMIT
Gmgn TokenGMGNAI/gmgn-skills6091 repos~10kAutomated safety check: NotesMIT
Smart Contract Entry Point Analyzertrailofbits/skills7.5k1 repos~2.4kAutomated safety check: NotesCC-BY-SA-4.0
Solana Vulnerability Scannertrailofbits/skills7.5k—~3.6kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Meme Coin Audit

    sickn33/agentic-awesome-skills

    Meme coin and token security audit

    47k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Gmgn Token

    GMGNAI/gmgn-skills

    Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security audit (honeypot, rug pull risk, dev…

    609 GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check: notes
  • Official

    Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

    7.5k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Official

    Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

    7.5k GitHub stars~3.6k tokensUpdated today
    SecurityAuto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed

More from mtarcure/claude-vibe-squad

All 17 skills in this repo
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    165 GitHub stars~3.6k tokensUpdated 19 days ago
    Auto-check passed
  • Blind Rediscovery

    mtarcure/claude-vibe-squad

    Operational checklist + helper for blind-rediscovery fan-out work.

    165 GitHub stars~1.6k tokensUpdated 19 days ago
    Auto-check passed
  • Chain Construct Smart Contract

    mtarcure/claude-vibe-squad

    A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

    165 GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check passed
  • Compact Now

    mtarcure/claude-vibe-squad

    Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…

    165 GitHub stars~1.6k tokensUpdated 19 days ago
    Auto-check passed
  • Agent Prompt Engineering

    mtarcure/claude-vibe-squad

    A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.

    165 GitHub stars~872 tokensUpdated 19 days ago
    Auto-check: warnings
  • Defi Invariant Check

    mtarcure/claude-vibe-squad

    A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

    165 GitHub stars~2.5k tokensUpdated 19 days ago
    Auto-check passed

Works with

Categories

Questions about Vulnhunter Solana

What does Vulnhunter Solana do?

A skill your agent uses when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds…. Vulnhunter Solana is an agent skill from mtarcure/claude-vibe-squad. Use when reviewing Solana program code for the account-model bug classes — unchecked account owner, absent signer, discriminator confusion, caller-controlled CPI seeds, PDA-derivation collision, SPL arithmetic overflow, close-and-reinitialize revival, and duplicate-account aliasing — the pattern census that stands in for absent scanners.

When should I use Vulnhunter Solana?

Vulnhunter Solana fits situations like: reviewing Solana program code for the account-model bug classes — unchecked account owner; discriminator confusion; caller-controlled CPI seeds; PDA-derivation collision.

How do I install Vulnhunter Solana in Claude Code?

Run `npx skills add mtarcure/claude-vibe-squad --skill vulnhunter-solana -a claude-code`. Or copy the skill folder (.agents/skills/vulnhunter-solana in mtarcure/claude-vibe-squad) into .claude/skills/vulnhunter-solana in your project. Claude Code loads it when a task matches its description.

How do I install Vulnhunter Solana in Codex?

Run `npx skills add mtarcure/claude-vibe-squad --skill vulnhunter-solana -a codex`. Or copy the skill folder (.agents/skills/vulnhunter-solana in mtarcure/claude-vibe-squad) into .agents/skills/vulnhunter-solana in your project. Codex loads it when a task matches its description.

Can I use Vulnhunter Solana in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill vulnhunter-solana -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnhunter-solana, .gemini/skills/vulnhunter-solana, .github/skills/vulnhunter-solana and .opencode/skills/vulnhunter-solana in your project.

What does Vulnhunter Solana need to run?

Going by SKILL.md and its folder, Vulnhunter Solana needs the command-line tools its instructions call (rg).

Does Vulnhunter Solana access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vulnhunter Solana safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnhunter Solana use?

Vulnhunter Solana is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnhunter Solana use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnhunter Solana?

Skills that share tags, products or a category with Vulnhunter Solana: Meme Coin Audit (sickn33/agentic-awesome-skills, 47k stars), Meme Coin Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Gmgn Token (GMGNAI/gmgn-skills, 609 stars) and Smart Contract Entry Point Analyzer (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnhunter Solana?

mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 165 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.

Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.