Ghost Scan Deps
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills cosmos-vulnerability-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .claude/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .claude/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills cosmos-vulnerability-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .agents/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .agents/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills cosmos-vulnerability-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .cursor/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .cursor/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills cosmos-vulnerability-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .gemini/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .gemini/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills cosmos-vulnerability-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .github/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .github/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills cosmos-vulnerability-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner .opencode/skills/cosmos-vulnerability-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner into .opencode/skills/cosmos-vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cosmos-vulnerability-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cosmos-vulnerability-scannerScans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.
The scan starts with a synchronous discovery phase, then spawns parallel agents that each specialize in a vulnerability category. They return findings to the main skill, which writes each as its own markdown file in an output directory, .bughunt_cosmos/ by default or one you name. Pattern sets cover 25 core, 16 IBC, 10 EVM and 3 CosmWasm issues.
Guiding principles: a bug matters only if it is reachable from the consensus path (BeginBlock, EndBlock, FinalizeBlock, message server handlers, the AnteHandler); non-determinism that changes state roots halts every validator; SDK versions in go.mod are checked before applying patterns; and false positives such as map iteration in a CLI command are avoided. It is not for pure Solidity audits, CometBFT internals or general Go review.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.cosmos.networkgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cosmos Vulnerability Scanner loads about 2.7k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 851 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 851 words, ~2,719 tokens.
.claude/skills/cosmos-vulnerability-scanner/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Scan Cosmos SDK modules and CosmWasm contracts for vulnerabilities that cause chain halts, consensus failures, or fund loss. Spawns parallel scanning agents — each specializing in a vulnerability category — that return findings to the main skill, which then writes them as individual markdown files to an output directory.
Output directory: defaults to .bughunt_cosmos/. If the user specifies a different directory in their prompt, use that instead.
x/ modules)go.mod versions before applying patterns.Entry: Target codebase path provided by user. Codebase contains Go source (e.g., x/ modules, go.mod) or Rust contracts with cosmwasm_std.
Run a synchronous subagent (Agent tool) with the full contents of DISCOVERY.md as its prompt. The agent must:
PLATFORM: pure-cosmos | evm | wasm (pick one; if multiple, comma-separated)
IBC_ENABLED: true | false
SDK_VERSION: <version from go.mod>
IBC_GO_VERSION: <version from go.mod, or "n/a">
CUSTOM_MODULES: <comma-separated list of x/* modules>After the subagent returns, you (the main skill) Write the CLAUDE.md to the target repo root. Save its path and the discovery values — these feed into Phase 2.
Exit: CLAUDE.md written by main skill. PLATFORM, IBC_ENABLED, SDK_VERSION, IBC_GO_VERSION, and CUSTOM_MODULES captured.
Spawn scanning agents in a single message for maximum parallelism. Use the Agent Prompt Template below, filling in the reference file for each agent. Subagents only need read access (Grep, Glob, Read) — they return findings in their response and the main skill writes the files.
Always spawn these 3 agents:
| Agent Name | Reference File | Scope |
|---|---|---|
core-scanner | VULNERABILITY_PATTERNS.md | §1-9: non-determinism, ABCI, signers, validation, handlers, ante security |
state-scanner | STATE_VULNERABILITY_PATTERNS.md | §11-23: bookkeeping, bank, pagination, events, tx replay, governance, arithmetic, encoding, deprecated modules |
advanced-scanner | ADVANCED_VULNERABILITY_PATTERNS.md | §24-27: storage keys, consensus validation, circuit breaker, crypto |
Spawn conditionally (in the same parallel message):
| Agent Name | Condition | Reference File |
|---|---|---|
evm-scanner | PLATFORM includes evm | EVM_VULNERABILITY_PATTERNS.md |
ibc-scanner | IBC_ENABLED is true | IBC_VULNERABILITY_PATTERNS.md |
cosmwasm-scanner | PLATFORM includes wasm | COSMWASM_VULNERABILITY_PATTERNS.md |
Construct each agent's prompt by replacing {REFERENCE_FILE_PATH} with the full path to the reference file (under {baseDir}/resources/) and {CLAUDE_MD_PATH} with the path to the CLAUDE.md written in Phase 1:
Perform a very thorough security scan of a Cosmos SDK codebase for specific vulnerability patterns.
CONTEXT:
Read {CLAUDE_MD_PATH} for codebase context (SDK version, modules, threat model, key files).
PATTERNS:
Read {REFERENCE_FILE_PATH} — it contains numbered vulnerability patterns. For EACH pattern:
1. Read the detection patterns and "What to Check" items
2. Use Grep and Glob to search the target codebase for each pattern
3. When a match is found, Read surrounding code to verify it's on a consensus-critical path (BeginBlock, EndBlock, FinalizeBlock, msg_server handlers, AnteHandler)
4. Classify severity per the guidelines below
RULES:
- Consensus path only: Only flag code reachable from consensus-critical execution. CLI/query/test code is NOT a finding.
- Check SDK version in go.mod before applying patterns (v0.47 removed GetSigners, v0.50 added ABCI 2.0, v0.53 deprecated ValidateBasic).
- Always use the Grep tool for searches, not bash grep. The reference file contains search patterns — use them directly with the Grep tool.
- Ignore cross-references to other resource files (e.g., links to IBC or COSMWASM patterns). Those patterns are covered by other scanning agents.
- Reject these rationalizations:
- "ValidateBasic catches this" — deprecated and facultative since SDK v0.53
- "Behind governance, so safe" — governance proposals can be malicious
- "IBC counterparty is trusted" — any chain can open a channel
- "Panic can't happen, input is validated" — trace the full call chain
- "Rounding error is only a few tokens" — compounds over time, can be looped
- "EVM precompile handles rollback" — many have incomplete rollback
SEVERITY:
- Critical (fund loss): signer mismatch, broken bookkeeping, AnteHandler bypass, bank keeper misuse, IBC token inflation, EVM/Cosmos desync, Merkle proof forgery, arithmetic overflow
- High (chain halt): non-determinism, ABCI panics, slow ABCI, non-deterministic IBC acks, consensus gaps, CacheContext event leak
- Medium (DoS): unbounded pagination, tx replay, missing validation, governance spam, rate limiting, circuit breaker bypass, storage key collisions
- Low (logic): rounding errors, stub handlers, event override, module ordering
OUTPUT — RETURN FORMAT:
Do NOT write any files. Return ALL findings and the summary in your response.
For each pattern, return one of:
§NUM PATTERN_NAME: Not applicable — [one-line reason]
§NUM PATTERN_NAME: FINDING (followed by the finding block below)
For each finding, include the full content using this template:
FINDING_FILE: {SEVERITY}-s{SECTION_NUM}-{kebab-description}.md
## [SEVERITY] Title
**Location**: `file:line`
**Description**: What the bug is and why it matters
**Vulnerable Code**: [snippet]
**Attack Scenario**: [numbered steps]
**Recommendation**: How to fix
**References**: [links to relevant advisories or building-secure-contracts]
You MUST report on ALL patterns in the reference file — do not skip any.Exit: All scanning agents returned. Each reported on every pattern in their reference file.
After all scanning agents return, write finding files to the output directory (default .bughunt_cosmos/):
FINDING_FILE: blocks{OUTPUT_DIR}/{filename} using the filename from FINDING_FILE:After writing all findings, verify every pattern was assessed:
core-scanner: 8 patterns (§1-9, excluding §8 legacy-only)state-scanner: 13 patterns (§11-23)advanced-scanner: 4 patterns (§24-27)evm-scanner (if spawned): 10 patterns (§1-10)ibc-scanner (if spawned): 16 patterns (§1-16)cosmwasm-scanner (if spawned): 3 patterns (§1-3)Glob for *.mdExit: All patterns accounted for. Finding files listed for the user.
building-secure-contracts/not-so-smart-contracts/cosmos/© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (assets) in plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Cosmos Vulnerability Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cosmos Vulnerability Scanner this skilltrailofbits/skills | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Ghost Scan Depsghostsecurity/skills | 408 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Time Aware Dependency Cve ScannerArabelaTso/Skills-4-SE | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Ethereum Smart Contract Vulnerability Analysistradecatlabs/vibe-coding-cn | 17k | 1 repos | ~738 | Automated safety check: Pass | Apache-2.0 | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Deepsec Vulnerability Scannervercel-labs/deepsec | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 |
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
ArabelaTso/Skills-4-SE
Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
vercel-labs/deepsec
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Works with
Categories
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. The scan starts with a synchronous discovery phase, then spawns parallel agents that each specialize in a vulnerability category.bughunt_cosmos/ by default or one you name.
Cosmos Vulnerability Scanner fits situations like: auditing custom x/ modules in a Cosmos SDK chain; reviewing IBC integrations and CosmWasm contracts; assessing chain security before a launch; investigating a chain halt incident.
Run `npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a claude-code`. Or copy the skill folder (plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner in trailofbits/skills) into .claude/skills/cosmos-vulnerability-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a codex`. Or copy the skill folder (plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner in trailofbits/skills) into .agents/skills/cosmos-vulnerability-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cosmos-vulnerability-scanner, .gemini/skills/cosmos-vulnerability-scanner, .github/skills/cosmos-vulnerability-scanner and .opencode/skills/cosmos-vulnerability-scanner in your project.
SKILL.md names no scripts, command-line tools or credentials: Cosmos Vulnerability Scanner is instructions for the agent only.
SKILL.md names 2 domains. As links in the text: docs.cosmos.network and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cosmos Vulnerability Scanner is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cosmos Vulnerability Scanner: Ghost Scan Deps (ghostsecurity/skills, 408 stars), Time Aware Dependency Cve Scanner (ArabelaTso/Skills-4-SE, 253 stars), Ethereum Smart Contract Vulnerability Analysis (tradecatlabs/vibe-coding-cn, 17k stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.