agentic-actions-audito…
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
$ npx -y skills add trailofbits/skills --skill algorand-vulnerability-scanner --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/algorand-vulnerability-scannerContext preview
The summary Claude sees to decide when to auto-load this skill.
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
name: algorand-vulnerability-scanner description: Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
Systematically scan Algorand smart contracts (TEAL and PyTeal) for platform-specific security vulnerabilities documented in Trail of Bits' "Not So Smart Contracts" database. This skill encodes 11 critical vulnerability patterns unique to Algorand's transaction model.
# PyTeal indicators from pyteal import * from algosdk import * # Common patterns Txn, Gtxn, Global, InnerTxnBuilder OnComplete, ApplicationCall, TxnType @router.method, @Subroutine
---
When invoked, I will:
1. **Search your codebase** for TEAL/PyTeal files 2. **Analyze each file** for the 11 vulnerability patterns 3. **Report findings** with file references and severity, above them a coverage table carrying a verdict for every pattern 4. **Provide fixes** for each identified issue 5. **Run Tealer** (if installed) for automated detection
---
When vulnerabilities are found, you'll get a report like this:
=== ALGORAND VULNERABILITY SCAN RESULTS ===
Project: my-algorand-dapp
Files Scanned: 3 (.teal, .py)
Vulnerabilities Found: 2
Coverage: 11/11 patterns reported
1 Rekeying Attack ................... found approval.py:45
2 Unchecked Transaction Fee ......... n/a stateful app, fees paid by sender
3 Closing Account ................... clear Assert(Txn.close_remainder_to() == Global.zero_address())
... one row per pattern, all 11 present ...
---
[CRITICAL] Rekeying Attack
File: contracts/approval.py:45
Pattern: Missing RekeyTo validation
Code:
If(Txn.type_enum() == TxnType.Payment,
Seq([
# Missing: Assert(Txn.rekey_to() == Global.zero_address())
App.globalPut(Bytes("balance"), balance + Txn.amount()),
Approve()
])
)
Issue: The contract doesn't validate the RekeyTo field, allowing attackers
to change account authorization and bypass restrictions.---
I check for 11 critical vulnerability patterns unique to Algorand. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
1. **Rekeying Attack** ⚠️ CRITICAL - Unchecked RekeyTo field 2. **Unchecked Transaction Fee** ⚠️ HIGH - Fee not validated in smart signatures 3. **Closing Account (CloseRemainderTo)** ⚠️ CRITICAL - Unchecked CloseRemainderTo drains the account 4. **Closing Asset (AssetCloseTo)** ⚠️ CRITICAL - Unchecked AssetCloseTo drains the asset holding 5. **Group Size Check** ⚠️ HIGH - No `Global.group_size()` validation on atomic groups 6. **Time-Based Replay Attack** ⚠️ MEDIUM - No lease or round-range bound 7. **Access Controls** ⚠️ CRITICAL - Update/delete and privileged calls unprotected 8. **Asset ID Verification** ⚠️ HIGH - Asset ID not validated in asset operations 9. **Denial of Service (Asset Opt-In)** ⚠️ MEDIUM - Push transfers strand on un-opted accounts 10. **Inner Transaction Fee** ⚠️ MEDIUM - Inner fee not explicitly set to 0 11. **Clear State Transaction** ⚠️ HIGH - Clear state program cannot reject, state left inconsistent
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
1. Confirm file extensions (`.teal`, `.py`) 2. Identify framework (PyTeal, Beaker, pure TEAL) 3. Determine contract type (stateful application vs smart signature) 4. Locate approval and clear state programs
# Run Tealer on contract tealer contract.teal --detect all # Or specific detectors tealer contract.teal --detect unprotected-rekey,group-size-check,update-application-check
For each of the 11 vulnerabilities above: 1. Search for relevant transaction field usage 2. Verify validation logic exists 3. Check for bypass conditions 4. Validate inner transaction handling
Create checklist for all transaction types used:
**Payment Transactions**:
**Asset Transfers**:
**Application Calls**:
**Inner Transactions**:
For atomic transaction groups: 1. Validate `Global.group_size()` checks 2. Review absolute vs relative indexing 3. Check for replay protection (Lease field) 4. Verify OnComplete fields for ApplicationCalls in group
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an…
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems,…
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…
Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC…