Creator · trailofbits
Last updated · Sep 1, 2026
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
Creator · trailofbits
Last updated · Sep 1, 2026
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
Creator · trailofbits
Last updated · Sep 1, 2026
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
Creator · trailofbits
Last updated · Sep 1, 2026
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
Sandbox only
Install targets
Codex install prompt
Install the "substrate-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-substrate-vulnerability-scanner","task":"Install substrate-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Maintenance
fresh
13d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
6.8K
85/100 Quality · 70/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
6.8K GitHub stars
Repo activity
6.8K stars, 586 forks
Maintenance
13d since push
License
CC-BY-SA-4.0
Install
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add trailofbits/skills --skill substrate-vulnerability-scannerDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
Agent should check
Copy prompt
Task: Use substrate-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
LLM text format
/api/skills/trailofbits-substrate-vulnerability-scanner/install?format=text
Find alternatives
/api/skills/search?q=substrate-vulnerability-scanner&limit=3
Agent prompt
Use substrate-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill substrate-vulnerability-scannerRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner
LLM text
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner?format=text
Install alias
/api/registry/install/trailofbits-substrate-vulnerability-scanner
Recommend
/api/registry/recommend?task=Use%20substrate-vulnerability-scanner%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS6.8K GitHub stars
Stars/forks activity
PASS6.8K stars, 586 forks; issue activity unavailable in current metadata
Recent maintenance
PASS13d since push
License clarity
PASSCC-BY-SA-4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: substrate-vulnerability-scanner description: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. ---
# Substrate Vulnerability Scanner
## 1. Purpose
Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause node crashes, DoS attacks, or unauthorized access. This skill encodes 7 critical vulnerability patterns unique to Substrate/FRAME-based chains.
## 2. When to Use This Skill
- Auditing custom Substrate pallets - Reviewing FRAME runtime code - Pre-launch security assessment of Substrate chains (Polkadot parachains, standalone chains) - Validating dispatchable extrinsic functions - Reviewing weight calculation functions - Assessing unsigned transaction validation logic
## 3. Platform Detection
### File Extensions & Indicators - **Rust files**: `.rs`
### Language/Framework Markers ```rust // Substrate/FRAME indicators #[pallet] pub mod pallet { use frame_support::pallet_prelude::*; use frame_system::pallet_prelude::*;
#[pallet::config] pub trait Config: frame_system::Config { }
#[pallet::call] impl<T: Config> Pallet<T> { #[pallet::weight(10_000)] pub fn example_function(origin: OriginFor<T>) -> DispatchResult { } } }
// Common patterns DispatchResult, DispatchError ensure!, ensure_signed, ensure_root StorageValue, StorageMap, StorageDoubleMap #[pallet::storage] #[pallet::call] #[pallet::weight] #[pallet::validate_unsigned] ```
### Project Structure - `pallets/*/lib.rs` - Pallet implementations - `runtime/lib.rs` - Runtime configuration - `benchmarking.rs` - Weight benchmarks - `Cargo.toml` with `frame-*` dependencies
### Tool Support - **cargo-fuzz**: Fuzz testing for Rust - **test-fuzz**: Property-based testing framework - **benchmarking framework**: Built-in weight calculation - **try-runtime**: Runtime migration testing
---
## 4. How This Skill Works
When invoked, I will:
1. **Search your codebase** for Substrate pallets 2. **Analyze each pallet** for the 7 vulnerability patterns 3. **Report findings** with file references and severity 4. **Provide fixes** for each identified issue 5. **Check weight calculations** and origin validation
---
## 5. Vulnerability Patterns (7 Critical Patterns)
I check for 7 critical vulnerability patterns unique to Substrate/FRAME. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
### Pattern Summary:
1. **Arithmetic Overflow** ⚠️ CRITICAL - Direct `+`, `-`, `*`, `/` operators wrap in release mode - Must use `checked_*` or `saturating_*` methods - Affects balance/token calculations, reward/fee math
2. **Don't Panic** ⚠️ CRITICAL - DoS - Panics cause node to stop processing blocks - No `unwrap()`, `expect()`, array indexing without bounds check - All user input must be validated with `ensure!`
3. **Weights and Fees** ⚠️ CRITICAL - DoS - Incorrect weights allow spam attacks - Fixed weights for variable-cost operations enable DoS - Must use benchmarking framework, bound all input parameters
4. **Verify First, Write Last** ⚠️ HIGH (Pre-v0.9.25) - Storage writes before validation persist on error (pre-v0.9.25) - Pattern: validate → write → emit event - Upgrade to v0.9.25+ or use manual `#[transactional]`
5. **Unsigned Transaction Validation** ⚠️ HIGH - Insufficient validation allows spam/replay attacks - Prefer signed transactions - If unsigned: validate parameters, replay protection, authenticate source
6. **Bad Randomness** ⚠️ MEDIUM - `pallet_randomness_collective_flip` vulnerable to collusion - Must use BABE randomness (`pallet_babe::RandomnessFromOneEpochAgo`) - Use `random(subject)` not `random_seed()`
7. **Bad Origin** ⚠️ CRITICAL - `ensure_signed` allows any user for privileged operations - Must use `ensure_root` or custom origins (ForceOrigin, AdminOrigin) - Origin types must be properly configured in runtime
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
---
## 6. Scanning Workflow
### Step 1: Platform Identification 1. Verify Substrate/FRAME framework usage 2. Check Substrate version (v0.9.25+ has transactional storage) 3. Locate pallet implementations (`pallets/*/lib.rs`) 4. Identify runtime configuration (`runtime/lib.rs`)
### Step 2: Dispatchable Analysis For each `#[pallet::call]` function: - [ ] Arithmetic: Uses checked/saturating operations? - [ ] Panics: No unwrap/expect/indexing? - [ ] Weights: Proportional to cost, bounded inputs? - [ ] Origin: Appropriate validation level? - [ ] Validation: All checks before storage writes?
### Step 3: Panic Sweep ```bash # Search for panic-prone patterns rg "unwrap\(\)" pallets/ rg "expect\(" pallets/ rg "\[.*\]" pallets/ # Array indexing rg " as u\d+" pallets/ # Type casts rg "\.unwrap_or" pallets/ ```
### Step 4: Arithmetic Safety Check ```bash # Find direct arithmetic rg " \+ |\+=| - |-=| \* |\*=| / |/=" pallets/
# Should find checked/saturating alternatives instead rg "checked_add|checked_sub|checked_mul|checked_div" pallets/ rg "saturating_add|saturating_sub|saturating_mul" pallets/ ```
### Step 5: Weight Analysis - [ ] Run benchmarking: `cargo test --features runtime-benchmarks` - [ ] Verify weights match computational cost - [ ] Check for bounded input parameters - [ ] Review weight calculation functions
### Step 6: Origin & Privilege Review ```bash # Find privileged operations rg "ensure_signed" pallets/ | grep -E "pause|emergency|admin|force|sudo"
# Should use ensure_root or custom origins rg "ensure_root|ForceOrigin|AdminOrigin" pallets/ ```
### Step 7: Testing Review - [ ] Unit tests cover all dispatchables - [ ] Fuzz tests for panic conditions - [ ] Benchmarks for weight calculation - [ ] try-runtime tests for migrations
---
## 7. Priority Guidelines
### Critical (Immediate Fix Required) - Arithmetic overflow (token creation, balance manipulation) - Panic DoS (node crash risk) - Bad origin (unauthorized privileged operations)
### High (Fix Before Launch) - Incorrect weights (DoS via spam) - Verify-first violations (state corruption, pre-v0.9.25) - Unsigned validation issues (spam, replay attacks)
### Medium (Address in Audit) - Bad randomness (manipulation possible but limited impact)
---
## 8. Testing Recommendations
### Fuzz Testing ```rust // Use test-fuzz for property-based testing #[cfg(test)] mod tests { use test_fuzz::test_fuzz;
#[test_fuzz] fn fuzz_transfer(from: AccountId, to: AccountId, amount: u128) { // Should never panic let _ = Pallet::transfer(from, to, amount); }
#[test_fuzz] fn fuzz_no_panics(call: Call) { // No dispatchable should panic let _ = call.dispatch(origin); } } ```
### Benchmarking ```bash # Run benchmarks to generate weights cargo build --release --features runtime-benchmarks ./target/release/node benchmark pallet \ --chain dev \ --pallet pallet_example \ --extrinsic "*" \ --steps 50 \ --repeat 20 ```
### try-runtime ```bash # Test runtime upgrades cargo build --release --features try-runtime try-runtime --runtime ./target/release/wbuild/runtime.wasm \ on-runtime-upgrade live --uri wss://rpc.polkadot.io ```
---
## 9. Additional Resources
- **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/substrate/` - **Substrate Documentation**: https://docs.substrate.io/ - **FRAME Documentation**: https://paritytech.github.io/substrate/master/frame_support/ - **test-fuzz**: https://github.com/trailofbits/test-fuzz - **Substrate StackExchange**: https://substrate.stackexchange.com/
---
## 10. Quick Reference Checklist
Before completing Substrate pallet audit:
**Arithmetic Safety (CRITICAL)**: - [ ] No direct `+`, `-`, `*`, `/` operators in dispatchables - [ ] All arithmetic uses `checked_*` or `saturating_*` - [ ] Type conversions use `try_into()` with error handling
**Panic Prevention (CRITICAL)**: - [ ] No `unwrap()` or `expect()` in dispatchables - [ ] No direct array/slice indexing without bounds check - [ ] All user inputs validated with `ensure!` - [ ] Division operations check for zero divisor
**Weights & DoS (CRITICAL)**: - [ ] Weights proportional to computational cost - [ ] Input parameters have maximum bounds - [ ] Benchmarking used to determine weights - [ ] No free (zero-weight) expensive operations
**Access Control (CRITICAL)**: - [ ] Privileged operations use `ensure_root` or custom origins - [ ] `ensure_signed` only for user-level operations - [ ] Origin types properly configured in runtime - [ ] Sudo pallet removed before production
**Storage Safety (HIGH)**: - [ ] Using Substrate v0.9.25+ OR manual `#[transactional]` - [ ] Validation before storage writes - [ ] Events emitted after successful operations
**Other (MEDIUM)**: - [ ] Unsigned transactions use signed alternative if possible - [ ] If unsigned: proper validation, replay protection, authentication - [ ] BABE randomness used (not RandomnessCollectiveFlip) - [ ] Randomness uses `random(subject)` not `random_seed()`
**Testing**: - [ ] Unit tests for all dispatchables - [ ] Fuzz tests to find panics - [ ] Benchmarks generated and verified - [ ] try-runtime tests for migrations
Decision snapshot
6,844 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for substrate-vulnerability-scanner, ready for a manual X post.
substrate-vulnerability-scanner: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow... 6.8K stars https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x
Listing + install path for substrate-vulnerability-scanner: https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x Install: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to trailofbits but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner/audit)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)trailofbits
@trailofbits
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "substrate-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-substrate-vulnerability-scanner","task":"Install substrate-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Maintenance
fresh
13d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
6.8K
85/100 Quality · 70/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
6.8K GitHub stars
Repo activity
6.8K stars, 586 forks
Maintenance
13d since push
License
CC-BY-SA-4.0
Install
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add trailofbits/skills --skill substrate-vulnerability-scannerDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
Agent should check
Copy prompt
Task: Use substrate-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
LLM text format
/api/skills/trailofbits-substrate-vulnerability-scanner/install?format=text
Find alternatives
/api/skills/search?q=substrate-vulnerability-scanner&limit=3
Agent prompt
Use substrate-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill substrate-vulnerability-scannerRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner
LLM text
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner?format=text
Install alias
/api/registry/install/trailofbits-substrate-vulnerability-scanner
Recommend
/api/registry/recommend?task=Use%20substrate-vulnerability-scanner%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS6.8K GitHub stars
Stars/forks activity
PASS6.8K stars, 586 forks; issue activity unavailable in current metadata
Recent maintenance
PASS13d since push
License clarity
PASSCC-BY-SA-4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: substrate-vulnerability-scanner description: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. ---
# Substrate Vulnerability Scanner
## 1. Purpose
Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause node crashes, DoS attacks, or unauthorized access. This skill encodes 7 critical vulnerability patterns unique to Substrate/FRAME-based chains.
## 2. When to Use This Skill
- Auditing custom Substrate pallets - Reviewing FRAME runtime code - Pre-launch security assessment of Substrate chains (Polkadot parachains, standalone chains) - Validating dispatchable extrinsic functions - Reviewing weight calculation functions - Assessing unsigned transaction validation logic
## 3. Platform Detection
### File Extensions & Indicators - **Rust files**: `.rs`
### Language/Framework Markers ```rust // Substrate/FRAME indicators #[pallet] pub mod pallet { use frame_support::pallet_prelude::*; use frame_system::pallet_prelude::*;
#[pallet::config] pub trait Config: frame_system::Config { }
#[pallet::call] impl<T: Config> Pallet<T> { #[pallet::weight(10_000)] pub fn example_function(origin: OriginFor<T>) -> DispatchResult { } } }
// Common patterns DispatchResult, DispatchError ensure!, ensure_signed, ensure_root StorageValue, StorageMap, StorageDoubleMap #[pallet::storage] #[pallet::call] #[pallet::weight] #[pallet::validate_unsigned] ```
### Project Structure - `pallets/*/lib.rs` - Pallet implementations - `runtime/lib.rs` - Runtime configuration - `benchmarking.rs` - Weight benchmarks - `Cargo.toml` with `frame-*` dependencies
### Tool Support - **cargo-fuzz**: Fuzz testing for Rust - **test-fuzz**: Property-based testing framework - **benchmarking framework**: Built-in weight calculation - **try-runtime**: Runtime migration testing
---
## 4. How This Skill Works
When invoked, I will:
1. **Search your codebase** for Substrate pallets 2. **Analyze each pallet** for the 7 vulnerability patterns 3. **Report findings** with file references and severity 4. **Provide fixes** for each identified issue 5. **Check weight calculations** and origin validation
---
## 5. Vulnerability Patterns (7 Critical Patterns)
I check for 7 critical vulnerability patterns unique to Substrate/FRAME. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
### Pattern Summary:
1. **Arithmetic Overflow** ⚠️ CRITICAL - Direct `+`, `-`, `*`, `/` operators wrap in release mode - Must use `checked_*` or `saturating_*` methods - Affects balance/token calculations, reward/fee math
2. **Don't Panic** ⚠️ CRITICAL - DoS - Panics cause node to stop processing blocks - No `unwrap()`, `expect()`, array indexing without bounds check - All user input must be validated with `ensure!`
3. **Weights and Fees** ⚠️ CRITICAL - DoS - Incorrect weights allow spam attacks - Fixed weights for variable-cost operations enable DoS - Must use benchmarking framework, bound all input parameters
4. **Verify First, Write Last** ⚠️ HIGH (Pre-v0.9.25) - Storage writes before validation persist on error (pre-v0.9.25) - Pattern: validate → write → emit event - Upgrade to v0.9.25+ or use manual `#[transactional]`
5. **Unsigned Transaction Validation** ⚠️ HIGH - Insufficient validation allows spam/replay attacks - Prefer signed transactions - If unsigned: validate parameters, replay protection, authenticate source
6. **Bad Randomness** ⚠️ MEDIUM - `pallet_randomness_collective_flip` vulnerable to collusion - Must use BABE randomness (`pallet_babe::RandomnessFromOneEpochAgo`) - Use `random(subject)` not `random_seed()`
7. **Bad Origin** ⚠️ CRITICAL - `ensure_signed` allows any user for privileged operations - Must use `ensure_root` or custom origins (ForceOrigin, AdminOrigin) - Origin types must be properly configured in runtime
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
---
## 6. Scanning Workflow
### Step 1: Platform Identification 1. Verify Substrate/FRAME framework usage 2. Check Substrate version (v0.9.25+ has transactional storage) 3. Locate pallet implementations (`pallets/*/lib.rs`) 4. Identify runtime configuration (`runtime/lib.rs`)
### Step 2: Dispatchable Analysis For each `#[pallet::call]` function: - [ ] Arithmetic: Uses checked/saturating operations? - [ ] Panics: No unwrap/expect/indexing? - [ ] Weights: Proportional to cost, bounded inputs? - [ ] Origin: Appropriate validation level? - [ ] Validation: All checks before storage writes?
### Step 3: Panic Sweep ```bash # Search for panic-prone patterns rg "unwrap\(\)" pallets/ rg "expect\(" pallets/ rg "\[.*\]" pallets/ # Array indexing rg " as u\d+" pallets/ # Type casts rg "\.unwrap_or" pallets/ ```
### Step 4: Arithmetic Safety Check ```bash # Find direct arithmetic rg " \+ |\+=| - |-=| \* |\*=| / |/=" pallets/
# Should find checked/saturating alternatives instead rg "checked_add|checked_sub|checked_mul|checked_div" pallets/ rg "saturating_add|saturating_sub|saturating_mul" pallets/ ```
### Step 5: Weight Analysis - [ ] Run benchmarking: `cargo test --features runtime-benchmarks` - [ ] Verify weights match computational cost - [ ] Check for bounded input parameters - [ ] Review weight calculation functions
### Step 6: Origin & Privilege Review ```bash # Find privileged operations rg "ensure_signed" pallets/ | grep -E "pause|emergency|admin|force|sudo"
# Should use ensure_root or custom origins rg "ensure_root|ForceOrigin|AdminOrigin" pallets/ ```
### Step 7: Testing Review - [ ] Unit tests cover all dispatchables - [ ] Fuzz tests for panic conditions - [ ] Benchmarks for weight calculation - [ ] try-runtime tests for migrations
---
## 7. Priority Guidelines
### Critical (Immediate Fix Required) - Arithmetic overflow (token creation, balance manipulation) - Panic DoS (node crash risk) - Bad origin (unauthorized privileged operations)
### High (Fix Before Launch) - Incorrect weights (DoS via spam) - Verify-first violations (state corruption, pre-v0.9.25) - Unsigned validation issues (spam, replay attacks)
### Medium (Address in Audit) - Bad randomness (manipulation possible but limited impact)
---
## 8. Testing Recommendations
### Fuzz Testing ```rust // Use test-fuzz for property-based testing #[cfg(test)] mod tests { use test_fuzz::test_fuzz;
#[test_fuzz] fn fuzz_transfer(from: AccountId, to: AccountId, amount: u128) { // Should never panic let _ = Pallet::transfer(from, to, amount); }
#[test_fuzz] fn fuzz_no_panics(call: Call) { // No dispatchable should panic let _ = call.dispatch(origin); } } ```
### Benchmarking ```bash # Run benchmarks to generate weights cargo build --release --features runtime-benchmarks ./target/release/node benchmark pallet \ --chain dev \ --pallet pallet_example \ --extrinsic "*" \ --steps 50 \ --repeat 20 ```
### try-runtime ```bash # Test runtime upgrades cargo build --release --features try-runtime try-runtime --runtime ./target/release/wbuild/runtime.wasm \ on-runtime-upgrade live --uri wss://rpc.polkadot.io ```
---
## 9. Additional Resources
- **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/substrate/` - **Substrate Documentation**: https://docs.substrate.io/ - **FRAME Documentation**: https://paritytech.github.io/substrate/master/frame_support/ - **test-fuzz**: https://github.com/trailofbits/test-fuzz - **Substrate StackExchange**: https://substrate.stackexchange.com/
---
## 10. Quick Reference Checklist
Before completing Substrate pallet audit:
**Arithmetic Safety (CRITICAL)**: - [ ] No direct `+`, `-`, `*`, `/` operators in dispatchables - [ ] All arithmetic uses `checked_*` or `saturating_*` - [ ] Type conversions use `try_into()` with error handling
**Panic Prevention (CRITICAL)**: - [ ] No `unwrap()` or `expect()` in dispatchables - [ ] No direct array/slice indexing without bounds check - [ ] All user inputs validated with `ensure!` - [ ] Division operations check for zero divisor
**Weights & DoS (CRITICAL)**: - [ ] Weights proportional to computational cost - [ ] Input parameters have maximum bounds - [ ] Benchmarking used to determine weights - [ ] No free (zero-weight) expensive operations
**Access Control (CRITICAL)**: - [ ] Privileged operations use `ensure_root` or custom origins - [ ] `ensure_signed` only for user-level operations - [ ] Origin types properly configured in runtime - [ ] Sudo pallet removed before production
**Storage Safety (HIGH)**: - [ ] Using Substrate v0.9.25+ OR manual `#[transactional]` - [ ] Validation before storage writes - [ ] Events emitted after successful operations
**Other (MEDIUM)**: - [ ] Unsigned transactions use signed alternative if possible - [ ] If unsigned: proper validation, replay protection, authentication - [ ] BABE randomness used (not RandomnessCollectiveFlip) - [ ] Randomness uses `random(subject)` not `random_seed()`
**Testing**: - [ ] Unit tests for all dispatchables - [ ] Fuzz tests to find panics - [ ] Benchmarks generated and verified - [ ] try-runtime tests for migrations
Decision snapshot
6,844 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for substrate-vulnerability-scanner, ready for a manual X post.
substrate-vulnerability-scanner: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow... 6.8K stars https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x
Listing + install path for substrate-vulnerability-scanner: https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x Install: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to trailofbits but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner/audit)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)trailofbits
@trailofbits
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "substrate-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-substrate-vulnerability-scanner","task":"Install substrate-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Maintenance
fresh
13d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
6.8K
85/100 Quality · 70/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
6.8K GitHub stars
Repo activity
6.8K stars, 586 forks
Maintenance
13d since push
License
CC-BY-SA-4.0
Install
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add trailofbits/skills --skill substrate-vulnerability-scannerDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
Agent should check
Copy prompt
Task: Use substrate-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
LLM text format
/api/skills/trailofbits-substrate-vulnerability-scanner/install?format=text
Find alternatives
/api/skills/search?q=substrate-vulnerability-scanner&limit=3
Agent prompt
Use substrate-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill substrate-vulnerability-scannerRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner
LLM text
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner?format=text
Install alias
/api/registry/install/trailofbits-substrate-vulnerability-scanner
Recommend
/api/registry/recommend?task=Use%20substrate-vulnerability-scanner%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS6.8K GitHub stars
Stars/forks activity
PASS6.8K stars, 586 forks; issue activity unavailable in current metadata
Recent maintenance
PASS13d since push
License clarity
PASSCC-BY-SA-4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: substrate-vulnerability-scanner description: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. ---
# Substrate Vulnerability Scanner
## 1. Purpose
Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause node crashes, DoS attacks, or unauthorized access. This skill encodes 7 critical vulnerability patterns unique to Substrate/FRAME-based chains.
## 2. When to Use This Skill
- Auditing custom Substrate pallets - Reviewing FRAME runtime code - Pre-launch security assessment of Substrate chains (Polkadot parachains, standalone chains) - Validating dispatchable extrinsic functions - Reviewing weight calculation functions - Assessing unsigned transaction validation logic
## 3. Platform Detection
### File Extensions & Indicators - **Rust files**: `.rs`
### Language/Framework Markers ```rust // Substrate/FRAME indicators #[pallet] pub mod pallet { use frame_support::pallet_prelude::*; use frame_system::pallet_prelude::*;
#[pallet::config] pub trait Config: frame_system::Config { }
#[pallet::call] impl<T: Config> Pallet<T> { #[pallet::weight(10_000)] pub fn example_function(origin: OriginFor<T>) -> DispatchResult { } } }
// Common patterns DispatchResult, DispatchError ensure!, ensure_signed, ensure_root StorageValue, StorageMap, StorageDoubleMap #[pallet::storage] #[pallet::call] #[pallet::weight] #[pallet::validate_unsigned] ```
### Project Structure - `pallets/*/lib.rs` - Pallet implementations - `runtime/lib.rs` - Runtime configuration - `benchmarking.rs` - Weight benchmarks - `Cargo.toml` with `frame-*` dependencies
### Tool Support - **cargo-fuzz**: Fuzz testing for Rust - **test-fuzz**: Property-based testing framework - **benchmarking framework**: Built-in weight calculation - **try-runtime**: Runtime migration testing
---
## 4. How This Skill Works
When invoked, I will:
1. **Search your codebase** for Substrate pallets 2. **Analyze each pallet** for the 7 vulnerability patterns 3. **Report findings** with file references and severity 4. **Provide fixes** for each identified issue 5. **Check weight calculations** and origin validation
---
## 5. Vulnerability Patterns (7 Critical Patterns)
I check for 7 critical vulnerability patterns unique to Substrate/FRAME. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
### Pattern Summary:
1. **Arithmetic Overflow** ⚠️ CRITICAL - Direct `+`, `-`, `*`, `/` operators wrap in release mode - Must use `checked_*` or `saturating_*` methods - Affects balance/token calculations, reward/fee math
2. **Don't Panic** ⚠️ CRITICAL - DoS - Panics cause node to stop processing blocks - No `unwrap()`, `expect()`, array indexing without bounds check - All user input must be validated with `ensure!`
3. **Weights and Fees** ⚠️ CRITICAL - DoS - Incorrect weights allow spam attacks - Fixed weights for variable-cost operations enable DoS - Must use benchmarking framework, bound all input parameters
4. **Verify First, Write Last** ⚠️ HIGH (Pre-v0.9.25) - Storage writes before validation persist on error (pre-v0.9.25) - Pattern: validate → write → emit event - Upgrade to v0.9.25+ or use manual `#[transactional]`
5. **Unsigned Transaction Validation** ⚠️ HIGH - Insufficient validation allows spam/replay attacks - Prefer signed transactions - If unsigned: validate parameters, replay protection, authenticate source
6. **Bad Randomness** ⚠️ MEDIUM - `pallet_randomness_collective_flip` vulnerable to collusion - Must use BABE randomness (`pallet_babe::RandomnessFromOneEpochAgo`) - Use `random(subject)` not `random_seed()`
7. **Bad Origin** ⚠️ CRITICAL - `ensure_signed` allows any user for privileged operations - Must use `ensure_root` or custom origins (ForceOrigin, AdminOrigin) - Origin types must be properly configured in runtime
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
---
## 6. Scanning Workflow
### Step 1: Platform Identification 1. Verify Substrate/FRAME framework usage 2. Check Substrate version (v0.9.25+ has transactional storage) 3. Locate pallet implementations (`pallets/*/lib.rs`) 4. Identify runtime configuration (`runtime/lib.rs`)
### Step 2: Dispatchable Analysis For each `#[pallet::call]` function: - [ ] Arithmetic: Uses checked/saturating operations? - [ ] Panics: No unwrap/expect/indexing? - [ ] Weights: Proportional to cost, bounded inputs? - [ ] Origin: Appropriate validation level? - [ ] Validation: All checks before storage writes?
### Step 3: Panic Sweep ```bash # Search for panic-prone patterns rg "unwrap\(\)" pallets/ rg "expect\(" pallets/ rg "\[.*\]" pallets/ # Array indexing rg " as u\d+" pallets/ # Type casts rg "\.unwrap_or" pallets/ ```
### Step 4: Arithmetic Safety Check ```bash # Find direct arithmetic rg " \+ |\+=| - |-=| \* |\*=| / |/=" pallets/
# Should find checked/saturating alternatives instead rg "checked_add|checked_sub|checked_mul|checked_div" pallets/ rg "saturating_add|saturating_sub|saturating_mul" pallets/ ```
### Step 5: Weight Analysis - [ ] Run benchmarking: `cargo test --features runtime-benchmarks` - [ ] Verify weights match computational cost - [ ] Check for bounded input parameters - [ ] Review weight calculation functions
### Step 6: Origin & Privilege Review ```bash # Find privileged operations rg "ensure_signed" pallets/ | grep -E "pause|emergency|admin|force|sudo"
# Should use ensure_root or custom origins rg "ensure_root|ForceOrigin|AdminOrigin" pallets/ ```
### Step 7: Testing Review - [ ] Unit tests cover all dispatchables - [ ] Fuzz tests for panic conditions - [ ] Benchmarks for weight calculation - [ ] try-runtime tests for migrations
---
## 7. Priority Guidelines
### Critical (Immediate Fix Required) - Arithmetic overflow (token creation, balance manipulation) - Panic DoS (node crash risk) - Bad origin (unauthorized privileged operations)
### High (Fix Before Launch) - Incorrect weights (DoS via spam) - Verify-first violations (state corruption, pre-v0.9.25) - Unsigned validation issues (spam, replay attacks)
### Medium (Address in Audit) - Bad randomness (manipulation possible but limited impact)
---
## 8. Testing Recommendations
### Fuzz Testing ```rust // Use test-fuzz for property-based testing #[cfg(test)] mod tests { use test_fuzz::test_fuzz;
#[test_fuzz] fn fuzz_transfer(from: AccountId, to: AccountId, amount: u128) { // Should never panic let _ = Pallet::transfer(from, to, amount); }
#[test_fuzz] fn fuzz_no_panics(call: Call) { // No dispatchable should panic let _ = call.dispatch(origin); } } ```
### Benchmarking ```bash # Run benchmarks to generate weights cargo build --release --features runtime-benchmarks ./target/release/node benchmark pallet \ --chain dev \ --pallet pallet_example \ --extrinsic "*" \ --steps 50 \ --repeat 20 ```
### try-runtime ```bash # Test runtime upgrades cargo build --release --features try-runtime try-runtime --runtime ./target/release/wbuild/runtime.wasm \ on-runtime-upgrade live --uri wss://rpc.polkadot.io ```
---
## 9. Additional Resources
- **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/substrate/` - **Substrate Documentation**: https://docs.substrate.io/ - **FRAME Documentation**: https://paritytech.github.io/substrate/master/frame_support/ - **test-fuzz**: https://github.com/trailofbits/test-fuzz - **Substrate StackExchange**: https://substrate.stackexchange.com/
---
## 10. Quick Reference Checklist
Before completing Substrate pallet audit:
**Arithmetic Safety (CRITICAL)**: - [ ] No direct `+`, `-`, `*`, `/` operators in dispatchables - [ ] All arithmetic uses `checked_*` or `saturating_*` - [ ] Type conversions use `try_into()` with error handling
**Panic Prevention (CRITICAL)**: - [ ] No `unwrap()` or `expect()` in dispatchables - [ ] No direct array/slice indexing without bounds check - [ ] All user inputs validated with `ensure!` - [ ] Division operations check for zero divisor
**Weights & DoS (CRITICAL)**: - [ ] Weights proportional to computational cost - [ ] Input parameters have maximum bounds - [ ] Benchmarking used to determine weights - [ ] No free (zero-weight) expensive operations
**Access Control (CRITICAL)**: - [ ] Privileged operations use `ensure_root` or custom origins - [ ] `ensure_signed` only for user-level operations - [ ] Origin types properly configured in runtime - [ ] Sudo pallet removed before production
**Storage Safety (HIGH)**: - [ ] Using Substrate v0.9.25+ OR manual `#[transactional]` - [ ] Validation before storage writes - [ ] Events emitted after successful operations
**Other (MEDIUM)**: - [ ] Unsigned transactions use signed alternative if possible - [ ] If unsigned: proper validation, replay protection, authentication - [ ] BABE randomness used (not RandomnessCollectiveFlip) - [ ] Randomness uses `random(subject)` not `random_seed()`
**Testing**: - [ ] Unit tests for all dispatchables - [ ] Fuzz tests to find panics - [ ] Benchmarks generated and verified - [ ] try-runtime tests for migrations
Decision snapshot
6,844 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for substrate-vulnerability-scanner, ready for a manual X post.
substrate-vulnerability-scanner: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow... 6.8K stars https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x
Listing + install path for substrate-vulnerability-scanner: https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x Install: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to trailofbits but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner/audit)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)trailofbits
@trailofbits
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "substrate-vulnerability-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/substrate-vulnerability-scanner. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-substrate-vulnerability-scanner","task":"Install substrate-vulnerability-scanner","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Maintenance
fresh
13d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
6.8K
85/100 Quality · 70/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
6.8K GitHub stars
Repo activity
6.8K stars, 586 forks
Maintenance
13d since push
License
CC-BY-SA-4.0
Install
npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add trailofbits/skills --skill substrate-vulnerability-scannerDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
Agent should check
Copy prompt
Task: Use substrate-vulnerability-scanner in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20substrate-vulnerability-scanner%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install
Install command: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/trailofbits-substrate-vulnerability-scanner/install
LLM text format
/api/skills/trailofbits-substrate-vulnerability-scanner/install?format=text
Find alternatives
/api/skills/search?q=substrate-vulnerability-scanner&limit=3
Agent prompt
Use substrate-vulnerability-scanner for this task. Review https://www.openagentskill.com/api/skills/trailofbits-substrate-vulnerability-scanner/install, then install with: npx skills add trailofbits/skills --skill substrate-vulnerability-scannerRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner
LLM text
/api/registry/manifest/trailofbits-substrate-vulnerability-scanner?format=text
Install alias
/api/registry/install/trailofbits-substrate-vulnerability-scanner
Recommend
/api/registry/recommend?task=Use%20substrate-vulnerability-scanner%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS6.8K GitHub stars
Stars/forks activity
PASS6.8K stars, 586 forks; issue activity unavailable in current metadata
Recent maintenance
PASS13d since push
License clarity
PASSCC-BY-SA-4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: substrate-vulnerability-scanner description: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets. ---
# Substrate Vulnerability Scanner
## 1. Purpose
Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause node crashes, DoS attacks, or unauthorized access. This skill encodes 7 critical vulnerability patterns unique to Substrate/FRAME-based chains.
## 2. When to Use This Skill
- Auditing custom Substrate pallets - Reviewing FRAME runtime code - Pre-launch security assessment of Substrate chains (Polkadot parachains, standalone chains) - Validating dispatchable extrinsic functions - Reviewing weight calculation functions - Assessing unsigned transaction validation logic
## 3. Platform Detection
### File Extensions & Indicators - **Rust files**: `.rs`
### Language/Framework Markers ```rust // Substrate/FRAME indicators #[pallet] pub mod pallet { use frame_support::pallet_prelude::*; use frame_system::pallet_prelude::*;
#[pallet::config] pub trait Config: frame_system::Config { }
#[pallet::call] impl<T: Config> Pallet<T> { #[pallet::weight(10_000)] pub fn example_function(origin: OriginFor<T>) -> DispatchResult { } } }
// Common patterns DispatchResult, DispatchError ensure!, ensure_signed, ensure_root StorageValue, StorageMap, StorageDoubleMap #[pallet::storage] #[pallet::call] #[pallet::weight] #[pallet::validate_unsigned] ```
### Project Structure - `pallets/*/lib.rs` - Pallet implementations - `runtime/lib.rs` - Runtime configuration - `benchmarking.rs` - Weight benchmarks - `Cargo.toml` with `frame-*` dependencies
### Tool Support - **cargo-fuzz**: Fuzz testing for Rust - **test-fuzz**: Property-based testing framework - **benchmarking framework**: Built-in weight calculation - **try-runtime**: Runtime migration testing
---
## 4. How This Skill Works
When invoked, I will:
1. **Search your codebase** for Substrate pallets 2. **Analyze each pallet** for the 7 vulnerability patterns 3. **Report findings** with file references and severity 4. **Provide fixes** for each identified issue 5. **Check weight calculations** and origin validation
---
## 5. Vulnerability Patterns (7 Critical Patterns)
I check for 7 critical vulnerability patterns unique to Substrate/FRAME. For detailed detection patterns, code examples, mitigations, and testing strategies, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
### Pattern Summary:
1. **Arithmetic Overflow** ⚠️ CRITICAL - Direct `+`, `-`, `*`, `/` operators wrap in release mode - Must use `checked_*` or `saturating_*` methods - Affects balance/token calculations, reward/fee math
2. **Don't Panic** ⚠️ CRITICAL - DoS - Panics cause node to stop processing blocks - No `unwrap()`, `expect()`, array indexing without bounds check - All user input must be validated with `ensure!`
3. **Weights and Fees** ⚠️ CRITICAL - DoS - Incorrect weights allow spam attacks - Fixed weights for variable-cost operations enable DoS - Must use benchmarking framework, bound all input parameters
4. **Verify First, Write Last** ⚠️ HIGH (Pre-v0.9.25) - Storage writes before validation persist on error (pre-v0.9.25) - Pattern: validate → write → emit event - Upgrade to v0.9.25+ or use manual `#[transactional]`
5. **Unsigned Transaction Validation** ⚠️ HIGH - Insufficient validation allows spam/replay attacks - Prefer signed transactions - If unsigned: validate parameters, replay protection, authenticate source
6. **Bad Randomness** ⚠️ MEDIUM - `pallet_randomness_collective_flip` vulnerable to collusion - Must use BABE randomness (`pallet_babe::RandomnessFromOneEpochAgo`) - Use `random(subject)` not `random_seed()`
7. **Bad Origin** ⚠️ CRITICAL - `ensure_signed` allows any user for privileged operations - Must use `ensure_root` or custom origins (ForceOrigin, AdminOrigin) - Origin types must be properly configured in runtime
For complete vulnerability patterns with code examples, see [VULNERABILITY_PATTERNS.md](resources/VULNERABILITY_PATTERNS.md).
---
## 6. Scanning Workflow
### Step 1: Platform Identification 1. Verify Substrate/FRAME framework usage 2. Check Substrate version (v0.9.25+ has transactional storage) 3. Locate pallet implementations (`pallets/*/lib.rs`) 4. Identify runtime configuration (`runtime/lib.rs`)
### Step 2: Dispatchable Analysis For each `#[pallet::call]` function: - [ ] Arithmetic: Uses checked/saturating operations? - [ ] Panics: No unwrap/expect/indexing? - [ ] Weights: Proportional to cost, bounded inputs? - [ ] Origin: Appropriate validation level? - [ ] Validation: All checks before storage writes?
### Step 3: Panic Sweep ```bash # Search for panic-prone patterns rg "unwrap\(\)" pallets/ rg "expect\(" pallets/ rg "\[.*\]" pallets/ # Array indexing rg " as u\d+" pallets/ # Type casts rg "\.unwrap_or" pallets/ ```
### Step 4: Arithmetic Safety Check ```bash # Find direct arithmetic rg " \+ |\+=| - |-=| \* |\*=| / |/=" pallets/
# Should find checked/saturating alternatives instead rg "checked_add|checked_sub|checked_mul|checked_div" pallets/ rg "saturating_add|saturating_sub|saturating_mul" pallets/ ```
### Step 5: Weight Analysis - [ ] Run benchmarking: `cargo test --features runtime-benchmarks` - [ ] Verify weights match computational cost - [ ] Check for bounded input parameters - [ ] Review weight calculation functions
### Step 6: Origin & Privilege Review ```bash # Find privileged operations rg "ensure_signed" pallets/ | grep -E "pause|emergency|admin|force|sudo"
# Should use ensure_root or custom origins rg "ensure_root|ForceOrigin|AdminOrigin" pallets/ ```
### Step 7: Testing Review - [ ] Unit tests cover all dispatchables - [ ] Fuzz tests for panic conditions - [ ] Benchmarks for weight calculation - [ ] try-runtime tests for migrations
---
## 7. Priority Guidelines
### Critical (Immediate Fix Required) - Arithmetic overflow (token creation, balance manipulation) - Panic DoS (node crash risk) - Bad origin (unauthorized privileged operations)
### High (Fix Before Launch) - Incorrect weights (DoS via spam) - Verify-first violations (state corruption, pre-v0.9.25) - Unsigned validation issues (spam, replay attacks)
### Medium (Address in Audit) - Bad randomness (manipulation possible but limited impact)
---
## 8. Testing Recommendations
### Fuzz Testing ```rust // Use test-fuzz for property-based testing #[cfg(test)] mod tests { use test_fuzz::test_fuzz;
#[test_fuzz] fn fuzz_transfer(from: AccountId, to: AccountId, amount: u128) { // Should never panic let _ = Pallet::transfer(from, to, amount); }
#[test_fuzz] fn fuzz_no_panics(call: Call) { // No dispatchable should panic let _ = call.dispatch(origin); } } ```
### Benchmarking ```bash # Run benchmarks to generate weights cargo build --release --features runtime-benchmarks ./target/release/node benchmark pallet \ --chain dev \ --pallet pallet_example \ --extrinsic "*" \ --steps 50 \ --repeat 20 ```
### try-runtime ```bash # Test runtime upgrades cargo build --release --features try-runtime try-runtime --runtime ./target/release/wbuild/runtime.wasm \ on-runtime-upgrade live --uri wss://rpc.polkadot.io ```
---
## 9. Additional Resources
- **Building Secure Contracts**: `building-secure-contracts/not-so-smart-contracts/substrate/` - **Substrate Documentation**: https://docs.substrate.io/ - **FRAME Documentation**: https://paritytech.github.io/substrate/master/frame_support/ - **test-fuzz**: https://github.com/trailofbits/test-fuzz - **Substrate StackExchange**: https://substrate.stackexchange.com/
---
## 10. Quick Reference Checklist
Before completing Substrate pallet audit:
**Arithmetic Safety (CRITICAL)**: - [ ] No direct `+`, `-`, `*`, `/` operators in dispatchables - [ ] All arithmetic uses `checked_*` or `saturating_*` - [ ] Type conversions use `try_into()` with error handling
**Panic Prevention (CRITICAL)**: - [ ] No `unwrap()` or `expect()` in dispatchables - [ ] No direct array/slice indexing without bounds check - [ ] All user inputs validated with `ensure!` - [ ] Division operations check for zero divisor
**Weights & DoS (CRITICAL)**: - [ ] Weights proportional to computational cost - [ ] Input parameters have maximum bounds - [ ] Benchmarking used to determine weights - [ ] No free (zero-weight) expensive operations
**Access Control (CRITICAL)**: - [ ] Privileged operations use `ensure_root` or custom origins - [ ] `ensure_signed` only for user-level operations - [ ] Origin types properly configured in runtime - [ ] Sudo pallet removed before production
**Storage Safety (HIGH)**: - [ ] Using Substrate v0.9.25+ OR manual `#[transactional]` - [ ] Validation before storage writes - [ ] Events emitted after successful operations
**Other (MEDIUM)**: - [ ] Unsigned transactions use signed alternative if possible - [ ] If unsigned: proper validation, replay protection, authentication - [ ] BABE randomness used (not RandomnessCollectiveFlip) - [ ] Randomness uses `random(subject)` not `random_seed()`
**Testing**: - [ ] Unit tests for all dispatchables - [ ] Fuzz tests to find panics - [ ] Benchmarks generated and verified - [ ] try-runtime tests for migrations
Decision snapshot
6,844 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for substrate-vulnerability-scanner, ready for a manual X post.
substrate-vulnerability-scanner: Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow... 6.8K stars https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x
Listing + install path for substrate-vulnerability-scanner: https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=x Install: npx skills add trailofbits/skills --skill substrate-vulnerability-scanner
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to trailofbits but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner/audit)
[](https://www.openagentskill.com/skills/trailofbits-substrate-vulnerability-scanner?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)trailofbits
@trailofbits
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness