Substrate pallet vulnerability scanner: 7 critical patterns
Audit Substrate/FRAME pallets for arithmetic overflow, panic DoS, bad weights, and bad origin checks — authorized assessments only
- What
- Audit Substrate/FRAME pallets for arithmetic overflow, panic DoS, bad weights, and bad origin checks — authorized assessments only
- Cost
- Free
- Needs
- a Substrate/FRAME Rust project to audit (pallets/*/lib.rs, runtime/lib.rs); ripgrep and a Rust toolchain. Authorized use only: audit your own pallets or code you are explicitly authorized to assess.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT** : a Trail of Bits skill for scanning Substrate/FRAME runtime pallets against 7 critical vulnerability patterns — arithmetic overflow in release-mode balance math, panic-based node DoS (`unwrap`/`expect`/unchecked indexing in dispatchables), incorrect weights enabling spam DoS, verify-first-write-last storage violations (pre-v0.9.25), unsigned transaction validation gaps, collusion-vulnerable randomness, and bad origin checks (`ensure_signed` where `ensure_root` belongs). The workflow runs platform detection, dispatchable-by-dispatchable analysis with ripgrep sweeps, weight and origin review, and emits a mandatory 7-row coverage table where every pattern gets a verdict — `found` (with file:line), `clear` (with the evidence you searched), or `n/a` (with the reason) — because a partial scan that stays silent about four patterns reads exactly like a clean pallet. **Kept by editorial choice as a borderline case: this is a defensive security-audit skill** — its stated purpose is auditing custom pallets and pre-launch security assessments of your own chains, with rationalizations to reject ("it's small so most patterns don't apply") — but the encoded exploit patterns are real offensive knowledge, so use it only on code you own or are authorized to assess. Honest caveats: patterns are Substrate/FRAME-specific; CC-BY-SA-4.0 licensed (share-alike applies to reuse of the content). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Substrate/FRAME Rust project to audit (pallets/*/lib.rs, runtime/lib.rs); ripgrep and a Rust toolchain. Authorized use only: audit your own pallets or code you are explicitly authorized to assess. Install "Substrate pallet vulnerability scanner: 7 critical patterns" for me. From Trail of Bits: scan Substrate/FRAME pallets against 7 critical vulnerability patterns (arithmetic overflow, panic DoS, bad weights, verify-first-write-last, unsigned validation, bad randomness, bad origin) and emit a mandatory 7-row coverage table with a verdict per pattern — CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "substrate-vulnerability-scanner". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point it at my own pallets directory — never run scans against chains or code you are not authorized to assess). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.