Substrate Vulnerability Scanner skill: what it does and how to install it
Scans Substrate/FRAME pallets for arithmetic, panic, weight, origin, randomness and transaction-validation vulnerabilities.
Summary generated from the skill's documentation.
Warning. A security audit flagged this skill with a critical risk warning. Read its SKILL.md and scripts before you install it.
Install
$ npx skills add trailofbits/skills --skill substrate-vulnerability-scannerRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Scans Substrate/FRAME pallets and runtime code for seven vulnerability patterns, including arithmetic overflow, panic-based denial of service, incorrect weights, unsafe origins and unsigned transaction flaws. Reports file references, severity, fixes and a seven-row coverage table.
When to use it. For auditing custom pallets, reviewing runtime dispatchables, validating weights and origins, or assessing Substrate and Polkadot chains before launch.
History
Repo stars
7.4kAbout +216 since 9 Jul 2026
Before 1 Oct 2026 the curve is estimated from public event data.
Stars are counted for the whole repository, which holds 49 skills.
Show as a table
| Date | Repo stars |
|---|---|
| 5 Oct 2026 | 7,370 |
| 4 Oct 2026 | 7,355 |
| 3 Oct 2026 | 7,348 |
| 2 Oct 2026 | 7,340 |
| 1 Oct 2026 | 7,320 |
| 24 Sept 2026 (estimated) | 7,310 |
| 17 Sept 2026 (estimated) | 7,305 |
| 10 Sept 2026 (estimated) | 7,239 |
| 3 Sept 2026 (estimated) | 7,179 |
| 27 Aug 2026 (estimated) | 7,174 |
| 20 Aug 2026 (estimated) | 7,174 |
| 13 Aug 2026 (estimated) | 7,169 |
| 6 Aug 2026 (estimated) | 7,164 |
| 30 Jul 2026 (estimated) | 7,164 |
| 23 Jul 2026 (estimated) | 7,164 |
| 16 Jul 2026 (estimated) | 7,164 |
| 9 Jul 2026 (estimated) | 7,154 |
Installs
4.8k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- CodeQLScans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
- Improve Codebase ArchitectureScans a codebase for chances to deepen modules, shows them in an HTML report, then interviews you about the one you pick.
- Security and HardeningAudits and hardens code that handles user input, authentication, data storage or external integrations against common vulnerabilities.