Official agent skill

Solana Vulnerability Scanner

by trailofbits in trailofbits/skills

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Solana Vulnerability Scanner

skills CLI
$ npx skills add trailofbits/skills --skill solana-vulnerability-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills solana-vulnerability-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/building-secure-contracts/skills/solana-vulnerability-scanner .claude/skills/solana-vulnerability-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
solana-vulnerability-scanner
GitHub stars
7.4k
Token cost
~3.6k tokens
SKILL.md length
1,129 words
Files
4 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

  • Works in 12 steps: Purpose → When to Use This Skill → Platform Detection → …
  • Auditing Solana/Anchor programs
  • SKILL.md covers 1. Purpose, 2. When to Use This Skill, 3. Platform Detection and 4. How This Skill Works, plus 6 more sections
  • Calls rg

What it does

Solana Vulnerability Scanner is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including assets (for example `agents/openai.yaml` and `resources/VULNERABILITY_PATTERNS.md`).

It sits in Security, covering Smart contract auditing and Smart contracts. It works with Solana and Rust. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Auditing Solana/Anchor programs
  • Tasks that involve Smart contract auditing
  • Tasks that involve Smart contracts

Example prompts

  • “Use the solana-vulnerability-scanner skill to scan Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation…”
  • “/solana-vulnerability-scanner”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Purpose
  2. When to Use This Skill
  3. Platform Detection
  4. How This Skill Works
  5. Example Output
  6. Vulnerability Patterns (6 Patterns)
  7. Scanning Workflow
  8. Reporting Format
  9. Priority Guidelines
  10. Testing Recommendations
  11. Additional Resources
  12. Quick Reference Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • anchor-lang.com
    • solanacookbook.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Solana Vulnerability Scanner loads about 3.6k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,129 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,129 words, ~3,606 tokens.

Download SKILL.mdSave it as .claude/skills/solana-vulnerability-scanner/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
solana-vulnerability-scanner
description
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.

Solana Vulnerability Scanner

1. Purpose

Systematically scan Solana programs (native and Anchor framework) for platform-specific security vulnerabilities related to cross-program invocations, account validation, and program-derived addresses. This skill encodes 6 critical vulnerability patterns unique to Solana's account model.

2. When to Use This Skill

  • Auditing Solana programs (native Rust or Anchor)
  • Reviewing cross-program invocation (CPI) logic
  • Validating program-derived address (PDA) implementations
  • Pre-launch security assessment of Solana protocols
  • Reviewing account validation patterns
  • Assessing instruction introspection logic

3. Platform Detection

File Extensions & Indicators
  • Rust files: .rs
Language/Framework Markers
rust
// Native Solana program indicators
use solana_program::{
    account_info::AccountInfo,
    entrypoint,
    entrypoint::ProgramResult,
    pubkey::Pubkey,
    program::invoke,
    program::invoke_signed,
};

entrypoint!(process_instruction);

// Anchor framework indicators
use anchor_lang::prelude::*;

#[program]
pub mod my_program {
    pub fn initialize(ctx: Context<Initialize>) -> Result<()> {
        // Program logic
    }
}

#[derive(Accounts)]
pub struct Initialize<'info> {
    #[account(mut)]
    pub authority: Signer<'info>,
}

// Common patterns
AccountInfo, Pubkey
invoke(), invoke_signed()
Signer<'info>, Account<'info>
#[account(...)] with constraints
seeds, bump
Project Structure
  • programs/*/src/lib.rs - Program implementation
  • Anchor.toml - Anchor configuration
  • Cargo.toml with solana-program or anchor-lang
  • tests/ - Program tests
Tool Support
  • Trail of Bits Solana Lints: Rust linters for Solana
  • Installation: Add to Cargo.toml
  • anchor test: Built-in testing framework
  • Solana Test Validator: Local testing environment

4. How This Skill Works

When invoked, I will:

  1. Search your codebase for Solana/Anchor programs
  2. Analyze each program for the 6 vulnerability patterns
  3. Report findings with file references and severity, above them a coverage table carrying a verdict for every pattern
  4. Provide fixes for each identified issue
  5. Check account validation and CPI security

5. Example Output


6. Vulnerability Patterns (6 Patterns)

I check for 6 critical vulnerability patterns unique to Solana. For detailed detection patterns, code examples, mitigations, and testing strategies, see VULNERABILITY_PATTERNS.md.

Pattern Summary:
  1. Arbitrary CPI ⚠️ CRITICAL - User-controlled program IDs in CPI calls
  2. Improper PDA Validation ⚠️ CRITICAL - Using create_program_address without canonical bump
  3. Missing Ownership Check ⚠️ HIGH - Deserializing accounts without owner validation
  4. Missing Signer Check ⚠️ CRITICAL - Authority operations without is_signer check
  5. Sysvar Account Check ⚠️ HIGH - Spoofed sysvar accounts (pre-Solana 1.8.1)
  6. Improper Instruction Introspection ⚠️ MEDIUM - Absolute indexes allowing reuse

For complete vulnerability patterns with code examples, see VULNERABILITY_PATTERNS.md.

7. Scanning Workflow

Step 1: Platform Identification
  1. Verify Solana program (native or Anchor)
  2. Check Solana version (1.8.1+ for sysvar security)
  3. Locate program source (programs/*/src/lib.rs)
  4. Identify framework (native vs Anchor)
Step 2: CPI Security Review
bash
# Find all CPI calls
rg "invoke\(|invoke_signed\(" programs/

# Check for program ID validation before each
# Should see program ID checks immediately before invoke

For each CPI:

  • Program ID validated before invocation
  • Cannot pass user-controlled program accounts
  • Anchor: Uses Program<'info, T> type
Step 3: PDA Validation Check
bash
# Find PDA usage
rg "find_program_address|create_program_address" programs/
rg "seeds.*bump" programs/

# Anchor: Check for seeds constraints
rg "#\[account.*seeds" programs/

For each PDA:

  • Uses find_program_address() or Anchor seeds constraint
  • Bump seed stored and reused
  • Not using user-provided bump
Step 4: Account Validation Sweep
bash
# Find account deserialization
rg "try_from_slice|try_deserialize" programs/

# Should see owner checks before deserialization
rg "\.owner\s*==|\.owner\s*!=" programs/

For each account used:

  • Owner validated before deserialization
  • Signer check for authority accounts
  • Anchor: Uses Account<'info, T> and Signer<'info>
Step 5: Instruction Introspection Review
bash
# Find instruction introspection usage
rg "load_instruction_at|load_current_index|get_instruction_relative" programs/

# Check for checked versions
rg "load_instruction_at_checked|load_current_index_checked" programs/
  • Using checked functions (Solana 1.8.1+)
  • Using relative indexing
  • Proper correlation validation
Step 6: Trail of Bits Solana Lints
toml
# Add to Cargo.toml
[dependencies]
solana-program = "1.17"  # Use latest version

[lints.clippy]
# Enable Solana-specific lints
# (Trail of Bits solana-lints if available)

8. Reporting Format

Coverage Table

Report on every pattern in §6, whether or not it turned anything up. Emit this table above the findings, with all 6 rows present:

#PatternVerdictEvidence
1Arbitrary CPIn/athis program makes no cross-program invocations
2Improper PDA Validation
3Missing Ownership Check
4Missing Signer Check
5Sysvar Account Check
6Improper Instruction Introspection

Each verdict is one of:

  • found — cite file:line and write the finding up in full below.
  • clear — the pattern applies to this program and the program handles it. Name the constraint, account type, or check you searched for, so a reader can repeat the search.
  • n/a — the pattern cannot apply here. Give the reason in one clause ("this program makes no CPI calls"). Not having looked is not n/a. Pattern 5 is version-scoped (pre-Solana 1.8.1): cite the solana-program version the program targets rather than dropping the row, since "targets 1.17, fixed upstream" and "did not look" are otherwise the same answer.

A table with fewer than 6 rows is an incomplete scan and must be reported as one. A row whose Verdict cell is empty is incomplete in the same way: row 1 above is filled in to show the shape, and every row is filled in the same way before the report is done. Six clear verdicts is a result a reader can act on. A report that covers two patterns and says nothing about the other four reads exactly like a clean program, and that is the failure this table exists to prevent.

Finding Template
markdown
## [CRITICAL] Arbitrary CPI - Unchecked Program ID

**Location**: `programs/vault/src/lib.rs:145-160` (withdraw function)

**Description**:
The `withdraw` function performs a CPI to transfer SPL tokens without validating that the provided `token_program` account is actually the SPL Token program. An attacker can provide a malicious program that appears to perform a transfer but actually steals tokens or performs unauthorized actions.

**Vulnerable Code**:
```rust
// lib.rs, line 145
pub fn withdraw(ctx: Context<Withdraw>, amount: u64) -> Result<()> {
    let token_program = &ctx.accounts.token_program;

    // WRONG: No validation of token_program.key()!
    invoke(
        &spl_token::instruction::transfer(...),
        &[
            ctx.accounts.vault.to_account_info(),
            ctx.accounts.destination.to_account_info(),
            ctx.accounts.authority.to_account_info(),
            token_program.to_account_info(),  // UNVALIDATED
        ],
    )?;
    Ok(())
}
```

**Attack Scenario**:
1. Attacker deploys malicious "token program" that logs transfer instruction but doesn't execute it
2. Attacker calls withdraw() providing malicious program as token_program
3. Vault's authority signs the transaction
4. Malicious program receives CPI with vault's signature
5. Malicious program can now impersonate vault and drain real tokens

**Recommendation**:
Use Anchor's `Program<'info, Token>` type:
```rust
use anchor_spl::token::{Token, Transfer};

#[derive(Accounts)]
pub struct Withdraw<'info> {
    #[account(mut)]
    pub vault: Account<'info, TokenAccount>,
    #[account(mut)]
    pub destination: Account<'info, TokenAccount>,
    pub authority: Signer<'info>,
    pub token_program: Program<'info, Token>,  // Validates program ID automatically
}

pub fn withdraw(ctx: Context<Withdraw>, amount: u64) -> Result<()> {
    let cpi_accounts = Transfer {
        from: ctx.accounts.vault.to_account_info(),
        to: ctx.accounts.destination.to_account_info(),
        authority: ctx.accounts.authority.to_account_info(),
    };

    let cpi_ctx = CpiContext::new(
        ctx.accounts.token_program.to_account_info(),
        cpi_accounts,
    );

    anchor_spl::token::transfer(cpi_ctx, amount)?;
    Ok(())
}
```

**References**:
- building-secure-contracts/not-so-smart-contracts/solana/arbitrary_cpi
- Trail of Bits lint: `unchecked-cpi-program-id`

9. Priority Guidelines

Show full SKILL.md (455 more words)Show less
Critical (Immediate Fix Required)
  • Arbitrary CPI (attacker-controlled program execution)
  • Improper PDA validation (account spoofing)
  • Missing signer check (unauthorized access)
High (Fix Before Launch)
  • Missing ownership check (fake account data)
  • Sysvar account check (authentication bypass, pre-1.8.1)
Medium (Address in Audit)
  • Improper instruction introspection (logic bypass)

10. Testing Recommendations

Unit Tests
rust
#[cfg(test)]
mod tests {
    use super::*;

    #[test]
    #[should_panic]
    fn test_rejects_wrong_program_id() {
        // Provide wrong program ID, should fail
    }

    #[test]
    #[should_panic]
    fn test_rejects_non_canonical_pda() {
        // Provide non-canonical bump, should fail
    }

    #[test]
    #[should_panic]
    fn test_requires_signer() {
        // Call without signature, should fail
    }
}
Integration Tests (Anchor)
typescript
import * as anchor from "@coral-xyz/anchor";

describe("security tests", () => {
  it("rejects arbitrary CPI", async () => {
    const fakeTokenProgram = anchor.web3.Keypair.generate();

    try {
      await program.methods
        .withdraw(amount)
        .accounts({
          tokenProgram: fakeTokenProgram.publicKey, // Wrong program
        })
        .rpc();

      assert.fail("Should have rejected fake program");
    } catch (err) {
      // Expected to fail
    }
  });
});
Solana Test Validator
bash
# Run local validator for testing
solana-test-validator

# Deploy and test program
anchor test

11. Additional Resources


12. Quick Reference Checklist

Before completing Solana program audit:

CPI Security (CRITICAL):

  • ALL CPI calls validate program ID before invoke()
  • Cannot use user-provided program accounts
  • Anchor: Uses Program<'info, T> type

PDA Security (CRITICAL):

  • PDAs use find_program_address() or Anchor seeds constraint
  • Bump seed stored and reused (not user-provided)
  • PDA accounts validated against canonical address

Account Validation (HIGH):

  • ALL accounts check owner before deserialization
  • Native: Validates account.owner == expected_program_id
  • Anchor: Uses Account<'info, T> type

Signer Validation (CRITICAL):

  • ALL authority accounts check is_signer
  • Native: Validates account.is_signer == true
  • Anchor: Uses Signer<'info> type

Sysvar Security (HIGH):

  • Using Solana 1.8.1+
  • Using checked functions: load_instruction_at_checked()
  • Sysvar addresses validated

Instruction Introspection (MEDIUM):

  • Using relative indexes for correlation
  • Proper validation between related instructions
  • Cannot reuse same instruction across multiple calls

Testing:

  • Unit tests cover all account validation
  • Integration tests with malicious inputs
  • Local validator testing completed
  • Trail of Bits lints enabled and passing
  • Coverage table emitted with all 6 rows, each carrying a verdict of found, clear or n/a with a reason

13. Rationalizations to Reject

  • "The program is small, so most patterns obviously don't apply." Obvious to whom? An n/a costs one clause and makes the judgment reviewable. Silence records nothing, and a reader cannot tell it apart from not having checked.
  • "The Trail of Bits lints pass, so the program is clean." The lints cover a subset of these 6 patterns. A clean lint run is one row of evidence, not a verdict on the patterns it never examined. Say which patterns it covered.
  • "I checked the patterns that matter for this program." Deciding which patterns matter is the scan, not a precondition for starting it. Rank by severity after the table is complete, not by leaving rows out.
  • "No findings, so there is nothing to report." A zero-finding scan still emits the full coverage table. That table is the deliverable: it is what distinguishes a program that was examined from one that was glanced at.
  • "Anchor handles account validation." Name the constraint. Anchor validates what the account struct declares and nothing more: #[account(mut)] is not an ownership check, and UncheckedAccount opts out entirely. Cite the attribute, not the framework.
  • "The PDA derivation makes it safe." Derivation is not validation. create_program_address without the canonical bump admits multiple valid addresses, which is pattern 2 in full.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (assets) in plugins/building-secure-contracts/skills/solana-vulnerability-scanner of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • resources/VULNERABILITY_PATTERNS.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Solana Vulnerability Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solana Vulnerability Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solana Vulnerability Scanner this skilltrailofbits/skills7.4k—~3.6kAutomated safety check: PassCC-BY-SA-4.0
Smart Contract Auditforefy/.context1521 repos~5.1kAutomated safety check: PassMIT
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Stellar DevVelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Safe Solana BuilderFrankcastleauditor/safe-solana-builder145—~3.6kAutomated safety check: PassNone

Similar skills

  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    SecurityAuto-check passed
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Stellar Dev

    VelaPayments/vela-payments

    End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

    131 GitHub stars~1.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Safe Solana Builder

    Frankcastleauditor/safe-solana-builder

    A skill your agent uses whenever the user wants to write, scaffold, or build a Solana smart contract or program from scratch.

    145 GitHub stars~3.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Wiremock Test

    OpenZeppelin/openzeppelin-relayer

    Manage WireMock proxy for RPC testing. An agent skill from OpenZeppelin/openzeppelin-relayer.

    153 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check: notes

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Solana Vulnerability Scanner

What does Solana Vulnerability Scanner do?

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Solana Vulnerability Scanner is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

When should I use Solana Vulnerability Scanner?

Solana Vulnerability Scanner fits situations like: auditing Solana/Anchor programs; tasks that involve Smart contract auditing; tasks that involve Smart contracts.

How do I install Solana Vulnerability Scanner in Claude Code?

Run `npx skills add trailofbits/skills --skill solana-vulnerability-scanner -a claude-code`. Or copy the skill folder (plugins/building-secure-contracts/skills/solana-vulnerability-scanner in trailofbits/skills) into .claude/skills/solana-vulnerability-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Solana Vulnerability Scanner in Codex?

Run `npx skills add trailofbits/skills --skill solana-vulnerability-scanner -a codex`. Or copy the skill folder (plugins/building-secure-contracts/skills/solana-vulnerability-scanner in trailofbits/skills) into .agents/skills/solana-vulnerability-scanner in your project. Codex loads it when a task matches its description.

Can I use Solana Vulnerability Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill solana-vulnerability-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solana-vulnerability-scanner, .gemini/skills/solana-vulnerability-scanner, .github/skills/solana-vulnerability-scanner and .opencode/skills/solana-vulnerability-scanner in your project.

What does Solana Vulnerability Scanner need to run?

Going by SKILL.md and its folder, Solana Vulnerability Scanner needs the command-line tools its instructions call (rg).

Does Solana Vulnerability Scanner access the network?

SKILL.md names 3 domains. As links in the text: github.com, anchor-lang.com and solanacookbook.com. This is read from the text; nothing was executed.

Is Solana Vulnerability Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Solana Vulnerability Scanner use?

Solana Vulnerability Scanner is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Solana Vulnerability Scanner use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Solana Vulnerability Scanner?

Skills that share tags, products or a category with Solana Vulnerability Scanner: Smart Contract Audit (forefy/.context, 152 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars), Stellar Dev (VelaPayments/vela-payments, 131 stars) and Radar (Auditware/radar, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solana Vulnerability Scanner?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.