Back to Skills

algorand-vulnerability-scanner

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).

5,355stars472forksUpdated 5/24/2026

Security Assessment

Safe(100/100)
Security Score100/100

About algorand-vulnerability-scanner

The algorand-vulnerability-scanner skill is designed to analyze Algorand smart contracts written in TEAL and PyTeal for security weaknesses specific to the Algorand ecosystem. It addresses the need for specialized auditing in blockchain applications where transaction logic, state management, and asset handling introduce unique attack surfaces that are not covered by generic smart contract analysis tools. By focusing on platform-specific risks, it helps developers and auditors identify vulnerabilities early in the development lifecycle and reduce the likelihood of exploits in production contracts.

This skill performs structured scanning across contract files to detect a set of 11 known vulnerability patterns associated with Algorand’s transaction model. It examines code for issues such as unsafe rekeying behavior, missing transaction validation, improper group transaction handling, asset-related security flaws, and unsafe application state updates. The scanner can also leverage static analysis tooling like Tealer when available to complement manual pattern detection. Findings are presented with contextual references to affected files, severity indicators, and explanations of the security implications, along with suggested remediation strategies.

It is primarily intended for blockchain developers, security auditors, and engineering teams building or reviewing Algorand-based decentralized applications. It is useful during pre-deployment audits, post-incident vulnerability reviews, and educational contexts where teams are learning Algorand security best practices. By systematizing detection of common and critical vulnerabilities, the skill helps improve the overall security posture of Algorand smart contract projects and supports more reliable decentralized application development.

FAQ

What types of files can the scanner analyze?

It analyzes Algorand smart contract files written in TEAL (.teal) and PyTeal (.py) that use Algorand-specific frameworks or SDK patterns.

Does it require external tools to function?

No external tools are strictly required, but it can optionally use Tealer for static analysis if it is installed in the environment.

What kinds of vulnerabilities does it detect?

It detects 11 platform-specific vulnerability patterns including rekeying risks, transaction validation issues, group transaction manipulation, asset-related flaws, and unsafe state changes.

Can it automatically fix vulnerabilities?

It does not automatically modify code, but it provides detailed explanations and suggested fixes for each identified issue.

Who should use this tool?

It is intended for developers, auditors, and security teams working on Algorand smart contracts who need specialized security analysis.

All Files

2 files
resources/VULNERABILITY_PATTERNS.md12.3 KB
View
SKILL.md8.6 KB
View

Install algorand-vulnerability-scanner

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill