# Solana Vulnerability Scanner (agent skill)

> Solana Vulnerability Scanner is an agent skill (a SKILL.md file) from trailofbits/skills. Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. It works with Claude Code and Codex and has 7,400 GitHub stars across a repository of 4 listed skills.

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs. Systematically scan Solana programs (native and Anchor framework) for platform-specific security vulnerabilities related to cross-program invocations, account validation, and program-derived addresses. This skill encodes 6 critical vulnerability patterns unique to Solana's account model.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/trailofbits/skills |
| Skill path | plugins/building-secure-contracts/skills/solana-vulnerability-scanner/SKILL.md |
| Skill name | solana-vulnerability-scanner |
| GitHub stars | 7,400 |
| Installs on skills.sh | not listed |
| License | CC-BY-SA-4.0 |
| Skills in repo | 4 |
| Plugin marketplace | trailofbits |
| Official | yes |
| Works with | Claude Code, Codex |
| Category | Security |
| Last commit | Sep 28, 2026 |

## When it triggers

- Use when auditing Solana/Anchor programs.

## Add this skill

### Claude Code

```sh
/plugin marketplace add trailofbits/skills
/plugin install building-secure-contracts@trailofbits
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/solana-vulnerability-scanner .agents/skills/solana-vulnerability-scanner   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/solana-vulnerability-scanner .cursor/skills/solana-vulnerability-scanner   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/trailofbits-solana-vulnerability-scanner
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
