solana-vulnerability-scanner
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.
Security Assessment
About solana-vulnerability-scanner
The Solana Vulnerability Scanner skill is designed to systematically audit Solana programs, both native Rust implementations and those built with the Anchor framework, for critical security vulnerabilities. It focuses on identifying six high-priority issues that are unique to Solana's account model, including arbitrary cross-program invocations (CPI), improper validation of program-derived addresses (PDA), missing ownership or signer checks, and potential sysvar spoofing. By detecting these vulnerabilities, the skill helps developers and security auditors mitigate risks that could otherwise compromise program integrity or user assets on the Solana blockchain.
The skill provides a structured approach to scanning and analysis. It identifies relevant Rust source files, recognizes framework-specific markers, and inspects CPI calls, account validations, and instruction introspection logic. For each detected vulnerability, it reports findings with file references and severity levels, and offers guidance for remediation. The tool also supports integration with testing frameworks and Solana-specific tools such as Anchor test, Solana Test Validator, and Trail of Bits Solana Lints, making it a comprehensive solution for pre-launch security assessments and continuous code audits.
This skill is particularly useful for blockchain developers, security auditors, and teams preparing Solana programs for deployment. Use cases include auditing CPI logic, validating PDA implementations, reviewing account ownership and signer checks, and ensuring instruction introspection is secure. By targeting both native and Anchor-based programs, it serves a wide audience of Solana developers seeking to enforce robust security practices and reduce the likelihood of exploits in deployed smart contracts.
FAQ
Which types of Solana programs can this skill scan?
It can scan both native Rust Solana programs and programs built using the Anchor framework.
What vulnerabilities does this skill detect?
It detects six critical vulnerability patterns: arbitrary CPI, improper PDA validation, missing ownership checks, missing signer checks, sysvar account spoofing, and improper instruction introspection.
Are there any specific file or project structures required?
Yes. The skill looks for Rust files (.rs), particularly in program source directories like programs/*/src/lib.rs, and may also check for Anchor project files such as Anchor.toml and Cargo.toml with solana-program or anchor-lang dependencies.
Does it provide remediation guidance?
Yes. For each identified vulnerability, the skill reports the issue with severity and provides recommended fixes or mitigations.
Is there a minimum Solana version requirement?
The skill notes that sysvar account security issues are specific to versions before Solana 1.8.1, so version awareness is part of the assessment.
Install solana-vulnerability-scanner
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
trailofbits/skills