substrate-vulnerability-scanner
An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, blockchain, polkadot, security, smart-contracts.
What it does
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner ~/.claude/skills/substrate-vulnerability-scanner
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/building-secure-contracts/skills/substrate-vulnerability-scanner/SKILL.md
- Branch
- main
- Collection
- building-secure-contracts
- Updated
- 2026-09-19
Related skills
- algorand-vulnerability-scanner — Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations.
- cairo-vulnerability-scanner — Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems.
- cosmos-vulnerability-scanner — Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence.
- solana-vulnerability-scanner — Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
- token-integration-analyzer — Token integration and implementation analyzer based on Trail of Bits' token integration checklist.
- ton-vulnerability-scanner — Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts.