substrate-vulnerability-scanner

by trailofbits 6.6k CC-BY-SA-4.0 Updated Aug 18, 2026
substrate-vulnerability-scanner skill by trailofbits
substrate-vulnerability-scanner — Security skill by trailofbits

substrate-vulnerability-scanner is an open-source security skill for Claude Code and compatible agents, published by trailofbits. Its author describes it as: “Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.”. The project has 6.6k stars on GitHub and is available under the CC-BY-SA-4.0 license. Add it to your setup with `/plugin marketplace add trailofbits/skills`.

What substrate-vulnerability-scanner does

Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause node crashes, DoS attacks, or unauthorized access. This skill encodes 7 critical vulnerability patterns unique to Substrate/FRAME-based chains.

Installation

Add substrate-vulnerability-scanner to your agent with:

/plugin marketplace add trailofbits/skills

Always review a skill's source before installing it. This command comes from the skill's public repository; the linked repo is the source of truth for exact setup steps.

What's inside

The SKILL.md for substrate-vulnerability-scanner is organised into these sections:

  • 1. Purpose
  • 2. When to Use This Skill
  • 3. Platform Detection
  • File Extensions & Indicators
  • Language/Framework Markers
  • Project Structure
  • Tool Support
  • 4. How This Skill Works
  • 5. Vulnerability Patterns (7 Critical Patterns)
  • Pattern Summary:
  • 6. Scanning Workflow
  • Step 1: Platform Identification

When to use it

Reach for substrate-vulnerability-scanner when you want security help from your agent without writing the same instructions every session. Load the skill and the agent picks it up automatically for relevant tasks.

Strengths

  • Clear CC-BY-SA-4.0 license — safe to read and adapt
  • Ships in trailofbits/skills, an established project with 6,646 GitHub stars
  • Actively maintained (recent commits)

Topics

agent-skills

Frequently asked questions

What does substrate-vulnerability-scanner do?
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
How do I install substrate-vulnerability-scanner?
Run /plugin marketplace add trailofbits/skills in your agent, then reload your skills. Review the source at https://github.com/trailofbits/skills before installing.
Is substrate-vulnerability-scanner free to use?
Yes. substrate-vulnerability-scanner is free and open source under the CC-BY-SA-4.0 license, so you can read, run, and adapt it within that license's terms.
Where does substrate-vulnerability-scanner come from?
substrate-vulnerability-scanner ships inside trailofbits/skills, a repository that contains 41 catalogued skills in total. The repository's 6,646 GitHub stars apply to that whole collection, not to this skill on its own.

Related skills

More Security →

Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations.

6.6k trailofbits CC-BY-SA-4.0

Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass.

6.6k trailofbits CC-BY-SA-4.0

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).

6.6k trailofbits CC-BY-SA-4.0

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).

6.6k trailofbits CC-BY-SA-4.0

Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.

6.6k trailofbits CC-BY-SA-4.0