跳转到主要内容
此内容尚未提供您的语言版本,正在以英文显示。

Building Secure Contracts

插件 已验证 活跃

Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.

11 个 Skill 0 个 MCP
目的

To enhance the security of smart contracts by providing specialized scanning tools and best practice guidance for multiple blockchain ecosystems.

功能

  • Vulnerability scanners for 6 blockchains
  • Development guideline assistants
  • Platform-specific analysis (Solana, Cairo, Cosmos, etc.)
  • Code maturity assessment
  • Audit preparation assistance

使用场景

  • Auditing smart contracts before deployment
  • Reviewing existing code for security vulnerabilities
  • Improving smart contract development practices
  • Preparing codebases for formal security reviews

非目标

  • Performing live network exploits
  • Replacing formal, human-led security audits
  • Analyzing non-smart contract code (e.g., general backend services)

Scope

  • info:Tool surface sizeThe plugin exposes 11 distinct skills, which is slightly more than the ideal range but manageable given their specialized security focus.

安装

请先添加 Marketplace

/plugin marketplace add trailofbits/skills
/plugin install building-secure-contracts@trailofbits

包含 11 个扩展

Skill (11)

Algorand Vulnerability Scanner 技能

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).

75
Audit Prep Assistant 技能

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).

95
Cairo/StarkNet Vulnerability Scanner 技能

Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.

95
Code Maturity Assessor 技能

Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing. Produces professional scorecard with evidence-based ratings and actionable recommendations.

75
Cosmos Vulnerability Scanner 技能

Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when auditing custom x/ modules, reviewing IBC integrations, or assessing pre-launch chain security. Updated for SDK v0.53.x.

78
Guidelines Advisor 技能

Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.

94
Secure Workflow Guide 技能

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas.

75
Solana Vulnerability Scanner 技能

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.

78
Substrate Vulnerability Scanner 技能

Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.

92
Token Integration Analyzer 技能

Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Context-aware for both token implementations and token integrations.

78
Ton Vulnerability Scanner 技能

Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.

75

质量评分

已验证
95 /100
1 day ago 分析

信任信号

最近提交3 days ago
星标5.2k
许可证CC-BY-SA-4.0
状态
查看源代码