@trailofbits

Ersteller · trailofbits

Letzte Aktualisierung · 24. Aug. 2026

cosmos-vulnerability-scanner

Prüfen · 63Im Registry indexiert

Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when auditing custom x/ modules, reviewing IBC integrations, or assessing pre-launch

OpenAgentSkill Trust Score
63/100

Nur Sandbox

Qualität85/100
Audit81/100
Stars6.8K
Verified installs0

Installationsziele

Codex-Installationsprompt

Install the "cosmos-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when auditing custom x/ modules, reviewing IBC integrations, or assessing pre-launch chain security. Updated for SDK v0.53.x. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-cosmos-vulnerability-scanner","task":"Install cosmos-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.

Asset-Profil

Coding- und Entwickler-Agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Bereich ansehen

Szenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent-Fit

Claude Code + CLI + Codex

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner

Wartung

Aktuell

Heute gepusht

Risiko

Prüfung nötig

Dependency or permission surface needs review

GitHub-Qualität

6.8K

85/100 Qualität · 71/100 Vertrauen

Abdeckungs-Tags

CodingGitHub automationSicherheitagent-skill

Review-Notizen

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Ausgezeichnet
85

High-confidence pick with strong adoption and healthy maintenance signals.

Vertrauen

Nur Sandbox
63

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

Audit

Prüfung nötig
81

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Menschliche Prüfung vor Installation

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

6.8K GitHub-Stars

Repository-Aktivität

6.8K Stars und 585 Forks

Wartung

Heute gepusht

Lizenz

CC-BY-SA-4.0

Installieren

npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

secrets or environment access, shell or command execution

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Usable metadata, review docs

Risikoübersicht

Vor Produktion prüfen

  • Minor inconsistency: description mentions 25 core patterns, but CHANGELOG refers to 28 core patterns. Clarify the count for accuracy.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist angegeben
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

View technical data+

Geeignete Aufgaben

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • Teams, die GitHub-Adoptionssignale schätzen
  • Inspect repository metadata

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLICLI

Installationsentscheidung

Befehl
npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner
Richtlinie
Blockieren
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
63/100
Audit
81/100
Risikoebene
Prüfung nötig

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • production agents without a repository review
  • Minor inconsistency: description mentions 25 core patterns, but CHANGELOG refers to 28 core patterns. Clarify the count for accuracy.
  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent-Sicherheit v2

37/100 · Automatische Installation vermeiden

Blocked for auto-installBlockieren

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Per API auflösen

Hoch

Shell- oder Befehlsausführung

Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

Hoch

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use cosmos-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20cosmos-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-cosmos-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use cosmos-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-cosmos-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

98/100

GitHub automation

Plattformen

Claude Code

Audit-Bericht

Prüfung nötig · 81/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Primäre Wahl für GitHub automation

Use this as a leading candidate, then validate the README and install path in your own agent stack.

98
Bereitschaft
Übernehmen
Phase

Rolle im Stack

Primäre Wahl

Primäre Eignung

GitHub automation

Vertrauenslabel

Produktionsbereit

Installationspfad

Befehl bereit

Verwenden wenn

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • Teams, die GitHub-Adoptionssignale schätzen

Evidenz

  • 6,823 GitHub-Stars
  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 85/100
  • 4 OpenAgentSkill-Interaktionen

zuerst prüfen

  • Minor inconsistency: description mentions 25 core patterns, but CHANGELOG refers to 28 core patterns. Clarify the count for accuracy.

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine GitHub automation-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Nur Sandbox

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

63
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Bestanden

6.8K GitHub-Stars

Star-/Fork-Aktivität

Bestanden

6.8K Stars und 585 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

Heute gepusht

Lizenzklarheit

Bestanden

CC-BY-SA-4.0

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Large GitHub adoption signal
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • Minor inconsistency: description mentions 25 core patterns, but CHANGELOG refers to 28 core patterns. Clarify the count for accuracy.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

Qualitätsprofil

Ausgezeichnet Kandidat für Agent-Workflows

High-confidence pick with strong adoption and healthy maintenance signals.

85
GitHub-Stars
6.8K
Aktualität
Heute
Installationsbereit
Ja
Lizenz
CC-BY-SA-4.0
Vor Installation prüfen: Minor inconsistency: description mentions 25 core patterns, but CHANGELOG refers to 28 core patterns. Clarify the count for accuracy.

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: cosmos-vulnerability-scanner description: "Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when auditing custom x/ modules, reviewing IBC integrations, or assessing pre-launch chain security. Updated for SDK v0.53.x." ---

# Cosmos Vulnerability Scanner

## Purpose

Scan Cosmos SDK modules and CosmWasm contracts for vulnerabilities that cause chain halts, consensus failures, or fund loss. Spawns parallel scanning agents — each specializing in a vulnerability category — that return findings to the main skill, which then writes them as individual markdown files to an output directory.

**Output directory**: defaults to `.bughunt_cosmos/`. If the user specifies a different directory in their prompt, use that instead.

## When to Use

- Auditing Cosmos SDK modules (custom `x/` modules) - Reviewing CosmWasm smart contracts - Pre-launch security assessment of Cosmos chains - Investigating chain halt incidents

## When NOT to Use

- Pure Solidity/EVM audits without Cosmos SDK — use Solidity-specific tools - CometBFT consensus engine internals — this covers SDK modules, not the consensus layer itself - General Go code review with no blockchain context - Cosmos SDK application logic that is not consensus-critical (e.g., CLI commands, REST endpoints) - CosmWasm contract-only audits on chains without custom SDK modules — use the CosmWasm checklist items alone

## Essential Principles

1. **Consensus path is king** — A bug only matters for chain halt/fund loss if it's on the consensus-critical execution path (BeginBlock, EndBlock, FinalizeBlock, msg_server handlers, AnteHandler). Always verify a finding is reachable from consensus before reporting it. 2. **State divergence = chain halt** — Any non-determinism that causes validators to compute different state roots will halt the chain. This is the highest-severity class because it affects all validators simultaneously. 3. **Check the version** — Cosmos SDK has breaking changes across major versions (v0.47 removed GetSigners, v0.50 added ABCI 2.0, v0.53 deprecated ValidateBasic). Always check `go.mod` versions before applying patterns. 4. **False positives waste audit time** — A map iteration in a CLI command is not a consensus bug. A panic in a query handler does not halt the chain. Verify the execution context before flagging. 5. **Cross-module interactions are where bugs hide** — The most severe findings (IBC reentrancy, EVM/Cosmos state desync, authz escalation) involve interactions between modules, not bugs within a single module.

## Scanning Workflow

### Phase 1: Discovery (synchronous)

**Entry**: Target codebase path provided by user. Codebase contains Go source (e.g., `x/` modules, `go.mod`) or Rust contracts with `cosmwasm_std`.

Run a **synchronous subagent** (Agent tool) with the full contents of [DISCOVERY.md](resources/DISCOVERY.md) as its prompt. The agent must:

1. Follow the Discovery workflow to explore the target codebase 2. Return the full CLAUDE.md content (the technical inventory and threat model) in its response 3. Return a structured summary with exactly these fields:

``` PLATFORM: pure-cosmos | evm | wasm (pick one; if multiple, comma-separated) IBC_ENABLED: true | false SDK_VERSION: <version from go.mod> IBC_GO_VERSION: <version from go.mod, or "n/a"> CUSTOM_MODULES: <comma-separated list of x/* modules> ```

After the subagent returns, **you** (the main skill) Write the CLAUDE.md to the target repo root. Save its path and the discovery values — these feed into Phase 2.

**Exit**: CLAUDE.md written by main skill. PLATFORM, IBC_ENABLED, SDK_VERSION, IBC_GO_VERSION, and CUSTOM_MODULES captured.

### Phase 2: Parallel Vulnerability Scan

Spawn scanning agents **in a single message** for maximum parallelism. Use the Agent Prompt Template below, filling in the reference file for each agent. Subagents only need read access (Grep, Glob, Read) — they return findings in their response and the main skill writes the files.

**Always spawn these 3 agents:**

| Agent Name | Reference File | Scope | |------------|---------------|-------| | `core-scanner` | `VULNERABILITY_PATTERNS.md` | §1-9: non-determinism, ABCI, signers, validation, handlers, ante security | | `state-scanner` | `STATE_VULNERABILITY_PATTERNS.md` | §11-23: bookkeeping, bank, pagination, events, tx replay, governance, arithmetic, encoding, deprecated modules | | `advanced-scanner` | `ADVANCED_VULNERABILITY_PATTERNS.md` | §24-27: storage keys, consensus validation, circuit breaker, crypto |

**Spawn conditionally (in the same parallel message):**

| Agent Name | Condition | Reference File | |------------|-----------|---------------| | `evm-scanner` | PLATFORM includes `evm` | `EVM_VULNERABILITY_PATTERNS.md` | | `ibc-scanner` | IBC_ENABLED is `true` | `IBC_VULNERABILITY_PATTERNS.md` | | `cosmwasm-scanner` | PLATFORM includes `wasm` | `COSMWASM_VULNERABILITY_PATTERNS.md` |

#### Agent Prompt Template

Construct each agent's prompt by replacing `{REFERENCE_FILE_PATH}` with the full path to the reference file (under `{baseDir}/resources/`) and `{CLAUDE_MD_PATH}` with the path to the CLAUDE.md written in Phase 1:

~~~ Perform a very thorough security scan of a Cosmos SDK codebase for specific vulnerability patterns.

CONTEXT: Read {CLAUDE_MD_PATH} for codebase context (SDK version, modules, threat model, key files).

PATTERNS: Read {REFERENCE_FILE_PATH} — it contains numbered vulnerability patterns. For EACH pattern: 1. Read the detection patterns and "What to Check" items 2. Use Grep and Glob to search the target codebase for each pattern 3. When a match is found, Read surrounding code to verify it's on a consensus-critical path (BeginBlock, EndBlock, FinalizeBlock, msg_server handlers, AnteHandler) 4. Classify severity per the guidelines below

RULES: - Consensus path only: Only flag code reachable from consensus-critical execution. CLI/query/test code is NOT a finding. - Check SDK version in go.mod before applying patterns (v0.47 removed GetSigners, v0.50 added ABCI 2.0, v0.53 deprecated ValidateBasic). - Always use the Grep tool for searches, not bash grep. The reference file contains search patterns — use them directly with the Grep tool. - Ignore cross-references to other resource files (e.g., links to IBC or COSMWASM patterns). Those patterns are covered by other scanning agents. - Reject these rationalizations: - "ValidateBasic catches this" — deprecated and facultative since SDK v0.53 - "Behind governance, so safe" — governance proposals can be malicious - "IBC counterparty is trusted" — any chain can open a channel - "Panic can't happen, input is validated" — trace the full call chain - "Rounding error is only a few tokens" — compounds over time, can be looped - "EVM precompile handles rollback" — many have incomplete rollback

SEVERITY: - Critical (fund loss): signer mismatch, broken bookkeeping, AnteHandler bypass, bank keeper misuse, IBC token inflation, EVM/Cosmos desync, Merkle proof forgery, arithmetic overflow - High (chain halt): non-determinism, ABCI panics, slow ABCI, non-deterministic IBC acks, consensus gaps, CacheContext event leak - Medium (DoS): unbounded pagination, tx replay, missing validation, governance spam, rate limiting, circuit breaker bypass, storage key collisions - Low (logic): rounding errors, stub handlers, event override, module ordering

OUTPUT — RETURN FORMAT: Do NOT write any files. Return ALL findings and the summary in your response.

For each pattern, return one of: §NUM PATTERN_NAME: Not applicable — [one-line reason] §NUM PATTERN_NAME: FINDING (followed by the finding block below)

For each finding, include the full content using this template:

FINDING_FILE: {SEVERITY}-s{SECTION_NUM}-{kebab-description}.md ## [SEVERITY] Title **Location**: `file:line` **Description**: What the bug is and why it matters **Vulnerable Code**: [snippet] **Attack Scenario**: [numbered steps] **Recommendation**: How to fix **References**: [links to relevant advisories or building-secure-contracts]

You MUST report on ALL patterns in the reference file — do not skip any. ~~~

**Exit**: All scanning agents returned. Each reported on every pattern in their reference file.

### Phase 3: Write Findings

After all scanning agents return, write finding files to the output directory (default `.bughunt_cosmos/`):

1. Parse each agent's response for `FINDING_FILE:` blocks 2. For each finding, Write the content to `{OUTPUT_DIR}/{filename}` using the filename from `FINDING_FILE:` 3. Create the output directory first if it doesn't exist

### Phase 4: Verify Completeness

After writing all findings, verify every pattern was assessed:

1. Collect the summary lines (§NUM entries) returned by each agent 2. Check pattern counts against expected totals: - `core-scanner`: 8 patterns (§1-9, excluding §8 legacy-only) - `state-scanner`: 13 patterns (§11-23) - `advanced-scanner`: 4 patterns (§24-27) - `evm-scanner` (if spawned): 10 patterns (§1-10) - `ibc-scanner` (if spawned): 16 patterns (§1-16) - `cosmwasm-scanner` (if spawned): 3 patterns (§1-3) 3. If any pattern is missing from a summary, flag it and re-prompt that agent 4. List all finding files written to the output directory with a `Glob` for `*.md`

**Exit**: All patterns accounted for. Finding files listed for the user.

---

## Success Criteria

- [ ] Discovery CLAUDE.md written with complete technical inventory and threat model - [ ] All scanning agents completed and reported on every pattern in their reference file - [ ] Pattern counts verified against expected totals (no patterns skipped) - [ ] All findings written to output directory as individual markdown files - [ ] Each finding file includes: severity, location, vulnerable code, attack scenario, recommendation

---

## Resources

- **Discovery & CLAUDE.md**: [DISCOVERY.md](resources/DISCOVERY.md) - **Core patterns (§1-9)**: [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md) - **State & module patterns (§11-23)**: [STATE_VULNERABILITY_PATTERNS.md](resources/STATE_VULNERABILITY_PATTERNS.md) - **Advanced patterns (§24-27)**: [ADVANCED_VULNERABILITY_PATTERNS.md](resources/ADVANCED_VULNERABILITY_PATTERNS.md) - **IBC vulnerabilities**: [IBC_VULNERABILITY_PATTERNS.md](resources/IBC_VULNERABILITY_PATTERNS.md) - **CosmWasm vulnerabilities**: [COSMWASM_VULNERABILITY_PATTERNS.md](resources/COSMWASM_VULNERABILITY_PATTERNS.md) - **EVM vulnerabilities**: [EVM_VULNERABILITY_PATTERNS.md](resources/EVM_VULNERABILITY_PATTERNS.md) - **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/cosmos/` - **Cosmos SDK Docs**: https://docs.cosmos.network/ - **CodeQL for Cosmos SDK**: https://github.com/crypto-com/cosmos-sdk-codeql

Technische Details

Version
1.0.0
Lizenz
CC-BY-SA-4.0
Letzte Aktualisierung
24. Aug. 2026
Veröffentlicht
24. Aug. 2026

Entscheidungsübersicht

Primäre Wahl

98
Bereit
Übernehmen
Phase

6,823 GitHub-Stars

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

81
Prüfung nötig
Sicherheit
72/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für cosmos-vulnerability-scanner, bereit für einen manuellen X-Post.

Kuratorenhinweis
cosmos-vulnerability-scanner: Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabili...

6.8K stars

https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for cosmos-vulnerability-scanner:
https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner?ref=x

Install: npx skills add trailofbits/skills --skill cosmos-vulnerability-scanner
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
trailofbits
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird trailofbits zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/trailofbits-cosmos-vulnerability-scanner?metric=listed&label=Listed)](https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/trailofbits-cosmos-vulnerability-scanner?metric=trust&label=Trust)](https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/trailofbits-cosmos-vulnerability-scanner?metric=audit&label=Audit)](https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/trailofbits-cosmos-vulnerability-scanner?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/trailofbits-cosmos-vulnerability-scanner)

Autor

T

trailofbits

@trailofbits

Plattform-Fit

Gesundheitssignale

GitHub-Stars
6.8K
Qualitätswert
50/100
Letzter GitHub-Push
24. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
4
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Nur Sandbox

63
  • GitHub-Akzeptanz6.8K GitHub-StarsBestanden
  • Star-/Fork-Aktivität6.8K Stars und 585 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarBestanden
  • Aktuelle WartungHeute gepushtBestanden
  • LizenzklarheitCC-BY-SA-4.0Bestanden
  • README/SKILL.md-VollständigkeitÖffentliche Metadaten benötigen mehr README/SKILL.md-KontextInfo
  • Abhängigkeits-/Laufzeitrisikocommand execution surface, credential or environment accessPrüfen