Ersteller · trailofbits
Letzte Aktualisierung · 24. Aug. 2026
algorand-vulnerability-scanner
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
Nur Sandbox
Installationsziele
Codex-Installationsprompt
Install the "algorand-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal). After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-algorand-vulnerability-scanner","task":"Install algorand-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Asset-Profil
Coding- und Entwickler-Agents
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Szenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent-Fit
Claude Code + CLI + Codex
Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.
Installieren
Bereit
npx skills add trailofbits/skills --skill algorand-vulnerability-scanner
Wartung
Aktuell
Heute gepusht
Risiko
Riskant
Permission surface may require sandboxing
GitHub-Qualität
6.8K
86/100 Qualität · 82/100 Vertrauen
Abdeckungs-Tags
Review-Notizen
Permission surface may require sandboxing · Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
Agent-Adoptionskarte
Vertrauen, Audit und Installationsbereitschaft auf einen Blick
Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.
Qualität
AusgezeichnetHigh-confidence pick with strong adoption and healthy maintenance signals.
Vertrauen
Nur SandboxNützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.
Audit
RiskantMaschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
OpenAgentSkill Trust Score v5
Nur Sandbox
Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.
Stars
6.8K GitHub-Stars
Repository-Aktivität
6.8K Stars und 585 Forks
Wartung
Heute gepusht
Lizenz
CC-BY-SA-4.0
Installieren
npx skills add trailofbits/skills --skill algorand-vulnerability-scanner
Installationssicherheit
Standard-Paket- oder Laufzeit-Installationspfad
Berechtigungsfläche
shell or command execution, filesystem or document access
Agent-Ergebnisse
Noch keine Agent-Ergebnisdaten
Dokumentation
Starker README/SKILL.md-Kontext
Risikoübersicht
Vor Produktion prüfen
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Permission surface: shell or command execution, filesystem or document access
Installationsbereitschaft
Installationspfad verfügbar
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Lizenz ist angegeben
- Noch keine Agent-Proven-Ergebnisbelege
Agent-lesbare Metadaten
Maschinenlesbare Entscheidungsdaten für diesen Skill.
Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.
View technical data+
Agent-lesbare Metadaten
Maschinenlesbare Entscheidungsdaten für diesen Skill.
Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.
Geeignete Aufgaben
- GitHub automation-Workflows
- Claude-Code-Teams
- Teams, die GitHub-Adoptionssignale schätzen
- Inspect repository metadata
Geeignete Agents
Installationsentscheidung
- Befehl
- npx skills add trailofbits/skills --skill algorand-vulnerability-scanner
- Richtlinie
- Blockieren
- Menschliche Prüfung
- Ja
Vertrauen und Risiko
- Vertrauen
- 74/100
- Audit
- 87/100
- Risikoebene
- Riskant
Ergebnis-Loop
- Endpoint
- /api/agent/outcome
- Event-ID
- resolve
- Ergebnisse
- 5
Installationsbefehl
npx skills add trailofbits/skills --skill algorand-vulnerability-scannerNicht verwenden, wenn
- Teams, die ein vom Anbieter unterstütztes SLA benötigen
- Hochregulierte Umgebungen ohne interne Sicherheitsprüfung
- No OpenAgentSkill engagement data yet
- Audit risk risky exceeds max_risk=medium
- Hinweise auf Hochrisiko-Berechtigungen: Shell- oder Befehlsausführung
Agent-Sicherheit v2
55/100 · Automatische Installation vermeiden
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Hoch
Shell- oder Befehlsausführung
Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.
Mittel
Netzwerkzugriff
Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.
Mittel
Dateisystemzugriff
Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.
Mittel
Datenbankzugriff
Die Skill kann Schemata prüfen, Datenbanken abfragen oder mit persistenten Speichern arbeiten.
- Audit risk risky exceeds max_risk=medium
- Hinweise auf Hochrisiko-Berechtigungen: Shell- oder Befehlsausführung
- Permission surface may require sandboxing
Agent-Auflösungsplan
Lass einen Agent die Eignung vor der Installation prüfen.
Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.
JSON öffnen
/api/agent/resolve?task=Use%20algorand-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve-Text
/api/agent/resolve?task=Use%20algorand-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Installationsübergabe
/api/skills/trailofbits-algorand-vulnerability-scanner/install
Agent sollte prüfen
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Prompt kopieren
Task: Use algorand-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20algorand-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-algorand-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill algorand-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent-Übergabe
Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.
Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.
Installationsübergabe
/api/skills/trailofbits-algorand-vulnerability-scanner/install
LLM-Textformat
/api/skills/trailofbits-algorand-vulnerability-scanner/install?format=text
Alternativen finden
/api/skills/search?q=algorand-vulnerability-scanner&limit=3
Agent-Prompt
Use algorand-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-algorand-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill algorand-vulnerability-scannerRegistry-Metadaten
Agent-lesbares Profil für die automatische Skill-Auswahl.
Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.
Manifest
/api/registry/manifest/trailofbits-algorand-vulnerability-scanner
LLM-Text
/api/registry/manifest/trailofbits-algorand-vulnerability-scanner?format=text
Installationsalias
/api/registry/install/trailofbits-algorand-vulnerability-scanner
Empfehlen
/api/registry/recommend?task=Use%20algorand-vulnerability-scanner%20in%20an%20agent%20workflow&limit=3
Agent-Fit
GitHub automation
Use-Case-Tags
Plattformen
Claude Code
Audit-Bericht
Riskant · 87/100
Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
Agent-Entscheidungspanel
Primäre Wahl für GitHub automation
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Rolle im Stack
Primäre Wahl
Primäre Eignung
GitHub automation
Vertrauenslabel
Produktionsbereit
Installationspfad
Befehl bereit
Verwenden wenn
- GitHub automation-Workflows
- Claude-Code-Teams
- Teams, die GitHub-Adoptionssignale schätzen
Evidenz
- 6,823 GitHub-Stars
- recent repository activity
- install command or GitHub repo available
- Qualitätsprofil 86/100
zuerst prüfen
- No OpenAgentSkill engagement data yet
Implementierungspfad
- 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine GitHub automation-Aufgabe vollständig aus.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Vertrauensprofil
Nur Sandbox
Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.
GitHub-Akzeptanz
Bestanden6.8K GitHub-Stars
Star-/Fork-Aktivität
Bestanden6.8K Stars und 585 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar
Aktuelle Wartung
BestandenHeute gepusht
Lizenzklarheit
BestandenCC-BY-SA-4.0
Positive Signale
- KI-Prüfung genehmigt
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Kürzlich gewartetes Repository
- Large GitHub adoption signal
- Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
- Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf
Vor Installation prüfen
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Permission surface: shell or command execution, filesystem or document access
- Noch keine echten Agent-Ergebnisberichte
- Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich
Empfohlene Aktion
Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.
Qualitätsprofil
Ausgezeichnet Kandidat für Agent-Workflows
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow-Eignung
Diese Skill in diesen Szenarien nutzen
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow-Eignung
Zum vollständigen Workflow hinzufügen
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternativen-Shortlist
Vor Installation vergleichen
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Übersicht
--- name: algorand-vulnerability-scanner description: Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal). ---
# Algorand Vulnerability Scanner
## 1. Purpose
Systematically scan Algorand smart contracts (TEAL and PyTeal) for platform-specific security vulnerabilities documented in Trail of Bits' "Not So Smart Contracts" database. This skill encodes 11 critical vulnerability patterns unique to Algorand's transaction model.
## 2. When to Use This Skill
- Auditing Algorand smart contracts (stateful applications or smart signatures) - Reviewing TEAL assembly or PyTeal code - Pre-audit security assessment of Algorand projects - Validating fixes for reported Algorand vulnerabilities - Training team on Algorand-specific security patterns
## 3. Platform Detection
### File Extensions & Indicators - **TEAL files**: `.teal` - **PyTeal files**: `.py` with PyTeal imports
### Language/Framework Markers ```python # PyTeal indicators from pyteal import * from algosdk import *
# Common patterns Txn, Gtxn, Global, InnerTxnBuilder OnComplete, ApplicationCall, TxnType @router.method, @Subroutine ```
### Project Structure - `approval_program.py` / `clear_program.py` - `contract.teal` / `signature.teal` - References to Algorand SDK or Beaker framework
### Tool Support - **Tealer**: Trail of Bits static analyzer for Algorand - Installation: `uv tool install tealer` (ensure uv's tool bin dir is on PATH) - Usage: `tealer contract.teal --detect all`
---
## 4. How This Skill Works
When invoked, I will:
1. **Search your codebase** for TEAL/PyTeal files 2. **Analyze each file** for the 11 vulnerability patterns 3. **Report findings** with file references and severity 4. **Provide fixes** for each identified issue 5. **Run Tealer** (if installed) for automated detection
---
## 5. Example Output
When vulnerabilities are found, you'll get a report like this:
``` === ALGORAND VULNERABILITY SCAN RESULTS ===
Project: my-algorand-dapp Files Scanned: 3 (.teal, .py) Vulnerabilities Found: 2
---
[CRITICAL] Rekeying Attack File: contracts/approval.py:45 Pattern: Missing RekeyTo validation
Code: If(Txn.type_enum() == TxnType.Payment, Seq([ # Missing: Assert(Txn.rekey_to() == Global.zero_address()) App.globalPut(Bytes("balance"), balance + Txn.amount()), Approve() ]) )
Issue: The contract doesn't validate the RekeyTo field, allowing attackers to change account authorization and bypass restrictions. ```
---
## 6. Vulnerability Patterns (11 Patterns)
I check for 11 critical vulnerability patterns unique to Algorand. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
### Pattern Summary:
1. **Rekeying Vulnerability** ⚠️ CRITICAL - Unchecked RekeyTo field 2. **Missing Transaction Verification** ⚠️ CRITICAL - No GroupSize/GroupIndex checks 3. **Group Transaction Manipulation** ⚠️ HIGH - Unsafe group transaction handling 4. **Asset Clawback Risk** ⚠️ HIGH - Missing clawback address checks 5. **Application State Manipulation** ⚠️ MEDIUM - Unsafe global/local state updates 6. **Asset Opt-In Missing** ⚠️ HIGH - No asset opt-in validation 7. **Minimum Balance Violation** ⚠️ MEDIUM - Account below minimum balance 8. **Close Remainder To Check** ⚠️ HIGH - Unchecked CloseRemainderTo field 9. **Application Clear State** ⚠️ MEDIUM - Unsafe clear state program 10. **Atomic Transaction Ordering** ⚠️ HIGH - Assuming transaction order 11. **Logic Signature Reuse** ⚠️ HIGH - Logic sigs without uniqueness constraints
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
## 7. Scanning Workflow
### Step 1: Platform Identification 1. Confirm file extensions (`.teal`, `.py`) 2. Identify framework (PyTeal, Beaker, pure TEAL) 3. Determine contract type (stateful application vs smart signature) 4. Locate approval and clear state programs
### Step 2: Static Analysis with Tealer ```bash # Run Tealer on contract tealer contract.teal --detect all
# Or specific detectors tealer contract.teal --detect unprotected-rekey,group-size-check,update-application-check ```
### Step 3: Manual Vulnerability Sweep For each of the 11 vulnerabilities above: 1. Search for relevant transaction field usage 2. Verify validation logic exists 3. Check for bypass conditions 4. Validate inner transaction handling
### Step 4: Transaction Field Validation Matrix Create checklist for all transaction types used:
**Payment Transactions**: - [ ] RekeyTo validated - [ ] CloseRemainderTo validated - [ ] Fee validated (if smart signature)
**Asset Transfers**: - [ ] Asset ID validated - [ ] AssetCloseTo validated - [ ] RekeyTo validated
**Application Calls**: - [ ] OnComplete validated - [ ] Access controls enforced - [ ] Group size validated
**Inner Transactions**: - [ ] Fee explicitly set to 0 - [ ] RekeyTo not user-controlled (Teal v6+) - [ ] All fields validated
### Step 5: Group Transaction Analysis For atomic transaction groups: 1. Validate `Global.group_size()` checks 2. Review absolute vs relative indexing 3. Check for replay protection (Lease field) 4. Verify OnComplete fields for ApplicationCalls in group
### Step 6: Access Control Review - [ ] Creator/admin privileges properly enforced - [ ] Update/delete operations protected - [ ] Sensitive functions have authorization checks
---
## 8. Reporting Format
### Finding Template ````markdown ## [SEVERITY] Vulnerability Name (e.g., Missing RekeyTo Validation)
**Location**: `contract.teal:45-50` or `approval_program.py:withdraw()`
**Description**: The contract approves payment transactions without validating the RekeyTo field, allowing an attacker to rekey the account and bypass future authorization checks.
**Vulnerable Code**: ```python # approval_program.py, line 45 If(Txn.type_enum() == TxnType.Payment, Approve() # Missing RekeyTo check ) ```
**Attack Scenario**: 1. Attacker submits payment transaction with RekeyTo set to attacker's address 2. Contract approves transaction without checking RekeyTo 3. Account authorization is rekeyed to attacker 4. Attacker gains full control of account
**Recommendation**: Add explicit validation of the RekeyTo field: ```python If(And( Txn.type_enum() == TxnType.Payment, Txn.rekey_to() == Global.zero_address() ), Approve(), Reject()) ```
**References**: - building-secure-contracts/not-so-smart-contracts/algorand/rekeying - Tealer detector: `unprotected-rekey` ````
---
## 9. Priority Guidelines
### Critical (Immediate Fix Required) - Rekeying attacks - CloseRemainderTo / AssetCloseTo issues - Access control bypasses
### High (Fix Before Deployment) - Unchecked transaction fees - Asset ID validation issues - Group size validation - Clear state transaction checks
### Medium (Address in Audit) - Inner transaction fee issues - Time-based replay attacks - DoS via asset opt-in
---
## 10. Testing Recommendations
### Unit Tests Required - Test each vulnerability scenario with PoC exploit - Verify fixes prevent exploitation - Test edge cases (group size = 0, empty addresses, etc.)
### Tealer Integration ```bash # Add to CI/CD pipeline tealer approval.teal --detect all --json > tealer-report.json
# Fail build on critical findings tealer approval.teal --detect all --fail-on critical,high ```
### Scenario Testing - Submit transactions with all critical fields manipulated - Test atomic groups with unexpected sizes - Attempt access control bypasses - Verify inner transaction fee handling
---
## 11. Additional Resources
- **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/algorand/` - **Tealer Documentation**: https://github.com/crytic/tealer - **Algorand Developer Docs**: https://developer.algorand.org/docs/ - **PyTeal Documentation**: https://pyteal.readthedocs.io/
---
## 12. Quick Reference Checklist
Before completing Algorand audit, verify ALL items checked:
- [ ] RekeyTo validated in all transaction types - [ ] CloseRemainderTo validated in payment transactions - [ ] AssetCloseTo validated in asset transfers - [ ] Transaction fees validated (smart signatures) - [ ] Group size validated for atomic transactions - [ ] Lease field used for replay protection (where applicable) - [ ] Access controls on Update/Delete operations - [ ] Asset ID validated in all asset operations - [ ] Asset transfers use pull pattern to avoid DoS - [ ] Inner transaction fees explicitly set to 0 - [ ] OnComplete field validated for ApplicationCall transactions - [ ] Tealer scan completed with no critical/high findings - [ ] Unit tests cover all vulnerability scenarios
Technische Details
- Version
- 1.0.0
- Lizenz
- CC-BY-SA-4.0
- Letzte Aktualisierung
- 24. Aug. 2026
- Veröffentlicht
- 24. Aug. 2026
Entscheidungsübersicht
Primäre Wahl
6,823 GitHub-Stars
Audit
Installationsprüfung
Installations- und Adoptionsprüfung
- Sicherheit
- 82/100
- Wartung
- 100/100
- Installieren
- 92/100
Von Agent belegte Evidenz
Von Agent belegte Evidenz
Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.
- Erfolgsrate
- —
- Letzter Fehler
- —
- Ergebnisse
- 0
- Ausgabequalität
- —
- Fehlgeschlagen
- 0
- Nicht relevant
- 0
- Installationen
- 0
- Durch Risiko blockiert
- 0
- Einrichtung erforderlich
- 0
- Produktion
- 0
Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.
Installieren
Zum Agent-Workflow hinzufügen
Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.
Wachstums-Loop
Share-Kit
Szenariobasierter Entwurf für algorand-vulnerability-scanner, bereit für einen manuellen X-Post.
algorand-vulnerability-scanner: Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unch... 6.8K stars https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner?ref=x
Optionale Antwort mit Installationsbefehl
Listing + install path for algorand-vulnerability-scanner: https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner?ref=x Install: npx skills add trailofbits/skills --skill algorand-vulnerability-scanner
Quelle des Eintrags
Registry-indexiert
Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.
- Ersteller
- trailofbits
- Quelle
- trailofbits/skills
- Indexiert von
- OpenAgentSkill Community-Index
Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.
Diesen Skill beanspruchenEigentümeranspruch
Diesen Skill-Eintrag beanspruchen
Dieser Registry-indexiert-Eintrag wird trailofbits zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.
Creator-Backlink-Kit
Evidenz-Badges in deine README einfügen
Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.
[](https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner)
[](https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner)
[](https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner/audit)
[](https://www.openagentskill.com/skills/trailofbits-algorand-vulnerability-scanner)Autor
trailofbits
@trailofbits
Tags
Plattform-Fit
Gesundheitssignale
- GitHub-Stars
- 6.8K
- Qualitätswert
- 50/100
- Letzter GitHub-Push
- 24. Aug. 2026
- Framework-Hinweise
- Unbekannt
- OpenAgentSkill-Aufrufe
- 0
- Installationskopien
- 0
- Externe Klicks
- 0
Community-Signal
Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.
Vertrauen & Sicherheit
Nur Sandbox
- GitHub-Akzeptanz6.8K GitHub-StarsBestanden
- Star-/Fork-Aktivität6.8K Stars und 585 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarBestanden
- Aktuelle WartungHeute gepushtBestanden
- LizenzklarheitCC-BY-SA-4.0Bestanden
- README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
- Abhängigkeits-/Laufzeitrisikocommand execution surface, database surfaceInfo
Ähnliche Skills
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Stars