solana-vulnerability-scannerskills.sh · trailofbits
4,873 installsScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.
www.w3.orgwww.anchor-lang.comsolanacookbook.comEvidence lines
- generates_or_handles_keys — SKILL.md: const fakeTokenProgram = anchor.web3.Keypair.generate();
Our disclosure is a static description of what the skill declares and does; it is not a safety verdict. Source record: www.skills.sh/trailofbits/skills/solana-vulnerability-scanner. Targets trailofbits-skills.
Install
npx skills add trailofbits/skills@solana-vulnerability-scanner
Copied from the registry's documented install form. Read the disclosure above first; it is the whole point of this page.
Observed record
First seen 2026-09-07. The weekly re-scan will record install growth and any change to the skill's content hash; one observation so far.
Cite this page
Sato Hub. "solana-vulnerability-scanner — skill disclosure on Sato Hub." Sato Hub, updated 2026-09-14, accessed 2026-09-14. https://satohub.ai/skills/skillssh%3Atrailofbits%2Fskills%2Fsolana-vulnerability-scannerData last refreshed 2026-09-14; this page is rebuilt daily. Citations carry the date so a reader can tell which snapshot a claim came from. Catalog data is licensed CC-BY-4.0.