Cosmos Vulnerability Scanner skill: what it does and how to install it
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical bugs causing chain halts, state divergence or fund loss.
Summary generated from the skill's documentation.
Install
$ npx skills add trailofbits/skills --skill cosmos-vulnerability-scannerRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Builds a technical inventory and threat model, checks SDK versions, then runs parallel scanners for core, state, advanced, IBC, EVM and CosmWasm patterns. It verifies consensus-path reachability, writes each finding as a markdown file and checks that all patterns were assessed.
When to use it. For auditing custom Cosmos SDK modules, reviewing IBC or CosmWasm integrations, investigating chain halts or assessing a chain before launch. It does not cover pure Solidity audits, CometBFT internals, general Go code or non-consensus application logic.
History
Repo stars
7.4kAbout +216 since 9 Jul 2026
Before 1 Oct 2026 the curve is estimated from public event data.
Stars are counted for the whole repository, which holds 49 skills.
Show as a table
| Date | Repo stars |
|---|---|
| 5 Oct 2026 | 7,370 |
| 4 Oct 2026 | 7,355 |
| 3 Oct 2026 | 7,348 |
| 2 Oct 2026 | 7,340 |
| 1 Oct 2026 | 7,320 |
| 24 Sept 2026 (estimated) | 7,310 |
| 17 Sept 2026 (estimated) | 7,305 |
| 10 Sept 2026 (estimated) | 7,239 |
| 3 Sept 2026 (estimated) | 7,179 |
| 27 Aug 2026 (estimated) | 7,174 |
| 20 Aug 2026 (estimated) | 7,174 |
| 13 Aug 2026 (estimated) | 7,169 |
| 6 Aug 2026 (estimated) | 7,164 |
| 30 Jul 2026 (estimated) | 7,164 |
| 23 Jul 2026 (estimated) | 7,164 |
| 16 Jul 2026 (estimated) | 7,164 |
| 9 Jul 2026 (estimated) | 7,154 |
Installs
5k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Improve Codebase ArchitectureScans a codebase for chances to deepen modules, shows them in an HTML report, then interviews you about the one you pick.
- API and Interface DesignGuides the design of stable APIs and module boundaries, covering REST and GraphQL endpoints and type contracts between modules.
- Dispatching Parallel AgentsSplits two or more independent tasks across parallel agents when they share no state.