trailofbits-solana-vulnerability-scanner
Trail of Bits skill scanning Solana/Anchor programs for 6 critical on-chain vulnerabilities.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for trailofbits-solana-vulnerability-scanner, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Security skill that scans Solana programs for arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Runs against Solana/Anchor source as its analysis surface; part of building-secure-contracts.
Key features and capabilities
- Solana/Anchor vulnerability scan
- PDA and signer/ownership checks
- Arbitrary-CPI and sysvar detection
Use cases
- Auditing Solana programs
- Pre-deploy smart-contract review