Solana vulnerability scanner: 6 critical audit patterns
Audit Solana and Anchor programs against 6 critical vulnerability patterns — arbitrary CPI, PDA validation, signer checks
- What
- Audit Solana and Anchor programs against 6 critical vulnerability patterns — arbitrary CPI, PDA validation, signer checks
- Cost
- Free
- Needs
- a Solana/Anchor program to audit (native Rust or Anchor) that you have the right to review; the rg CLI helpful for the sweep commands; no accounts or keys needed
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning** — a vulnerability scanner: use it only on code you have the right to audit. @trailofbits' systematic audit contract for Solana programs (native Rust and Anchor): detect the project (`.rs` sources, Anchor.toml, solana-program/anchor-lang markers, `programs/*/src/lib.rs` layout), then sweep 6 critical platform-specific patterns — arbitrary CPI (user-controlled program IDs), improper PDA validation (non-canonical bump), missing ownership check before deserialization, missing signer check on authorities, spoofed sysvar accounts (pre-Solana 1.8.1), improper instruction introspection — and emit a full 6-row coverage table where every pattern carries a `found`, `clear` or `n/a` verdict with evidence (silence is not a result), followed by file-and-line findings with attack scenarios and Anchor-idiomatic fixes, severity-ranked priorities (critical/high/medium), unit and integration test recommendations, and a final checklist covering every pattern. Includes rationalizations to reject ("the program is small so most patterns don't apply", "Anchor handles account validation" — name the constraint) and pointers to the Trail of Bits solana-lints and the Building Secure Contracts not-so-smart-contracts corpus. Honest caveats: built by the Trail of Bits team behind the Building Secure Contracts project; a clean scan is not a guarantee of safety — get a real audit before launch; CC-BY-SA-4.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Solana/Anchor program to audit (native Rust or Anchor) that you have the right to review; the rg CLI helpful for the sweep commands; no accounts or keys needed Install "Solana vulnerability scanner: 6 critical audit patterns" for me. A systematic audit contract for Solana programs: detect the project (Rust sources, Anchor.toml, solana-program/anchor-lang markers), then sweep 6 critical patterns — arbitrary CPI, improper PDA validation, missing ownership check, missing signer check, spoofed sysvar accounts, improper instruction introspection — emitting a full 6-row coverage table where every pattern carries a found/clear/n/a verdict with evidence, followed by file-and-line findings with attack scenarios and Anchor-idiomatic fixes, severity-ranked priorities, test recommendations and a final checklist. Includes rationalizations to reject and pointers to the Trail of Bits solana-lints and Building Secure Contracts corpus. Repository: https://github.com/trailofbits/skills/blob/main/plugins/building-secure-contracts/skills/solana-vulnerability-scanner/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "solana-vulnerability-scanner". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point it at a Solana program I have the right to audit; add the Trail of Bits solana-lints to Cargo.toml if wanted). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.