Solana Vulnerability Scanner
Solana Vulnerability Scanner is an agent skill (a SKILL.md file) from trailofbits/skills. Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. It works with Claude Code and Codex and has 7,400 GitHub stars across a repository of 4 listed skills.
- Official
- Multi-skill repo
- Plugin marketplace
- Security
- Actively maintained
Add this skill
Claude
This repository is a Claude Code plugin marketplace. In Claude Code:
/plugin marketplace add trailofbits/skills
/plugin install building-secure-contracts@trailofbitsIn the Claude apps, zip the solana-vulnerability-scanner folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).
ChatGPT / Codex
Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:
git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/solana-vulnerability-scanner .agents/skills/solana-vulnerability-scanner # repo; ~/.agents/skills for all projectsStandalone skills also load in the ChatGPT desktop app.
Cursor
Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:
git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/solana-vulnerability-scanner .cursor/skills/solana-vulnerability-scanner # project; ~/.cursor/skills for all projectsSource (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)
What this skill does
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs. Systematically scan Solana programs (native and Anchor framework) for platform-specific security vulnerabilities related to cross-program invocations, account validation, and program-derived addresses. This skill encodes 6 critical vulnerability patterns unique to Solana's account model.
When it triggers
- Use when auditing Solana/Anchor programs.
More skills in trailofbits/skills
4 skills are listed from this repository.
Similar skills
More security skills
Wizard
mattpocock/skills
Generate an interactive bash wizard that walks a human through steps only they can perform.
SecurityShellPostgres Patterns
affaan-m/ECC
PostgreSQL database patterns for query optimization, schema design, indexing, and security.
SecurityJavaScriptPonytail Audit
DietrichGebert/ponytail
Whole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents.
SecurityJavaScriptNext Bundle Optimizer
vercel/next.js
Audit and reduce Next.js browser initial-load work.
OfficialSecurityJavaScriptCloud
browser-use/browser-use
Documentation reference for using Browser Use Cloud — the hosted API and SDK for browser automation.
OfficialSecurityPythonSecurity And Hardening
addyosmani/agent-skills
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a…
SecurityJavaScript
What is the Solana Vulnerability Scanner skill?
Solana Vulnerability Scanner is an agent skill (a SKILL.md file) from trailofbits/skills. Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. It works with Claude Code and Codex and has 7,400 GitHub stars across a repository of 4 listed skills. Its SKILL.md lives at github.com/trailofbits/skills/plugins/building-secure-contracts/skills/solana-vulnerability-scanner.
How do I install the Solana Vulnerability Scanner skill?
In Claude Code, run /plugin marketplace add trailofbits/skills and then /plugin install building-secure-contracts@trailofbits. For Codex or Cursor, copy the solana-vulnerability-scanner folder into .agents/skills/ or .cursor/skills/.
Is the Solana Vulnerability Scanner skill free?
Yes. The repository is open source under the CC-BY-SA-4.0 license.
Is Solana Vulnerability Scanner maintained?
The repository's most recent commit was on Sep 28, 2026. appsgit only lists skills from repositories with a commit in the last six months.