Skip to content
appsgit

Algorand Vulnerability Scanner

Algorand Vulnerability Scanner is an agent skill (a SKILL.md file) from trailofbits/skills. Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. It works with Claude Code and Codex and has 7,400 GitHub stars across a repository of 4 listed skills.

github.com/trailofbits/skills/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner (opens in a new tab)

  • Official
  • Multi-skill repo
  • Plugin marketplace
  • Security
  • Actively maintained

Add this skill

Claude

This repository is a Claude Code plugin marketplace. In Claude Code:

/plugin marketplace add trailofbits/skills
/plugin install building-secure-contracts@trailofbits

In the Claude apps, zip the algorand-vulnerability-scanner folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner .agents/skills/algorand-vulnerability-scanner   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/trailofbits/skills.git
cp -r skills/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner .cursor/skills/algorand-vulnerability-scanner   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal). Systematically scan Algorand smart contracts (TEAL and PyTeal) for platform-specific security vulnerabilities documented in Trail of Bits' "Not So Smart Contracts" database. This skill encodes 11 critical vulnerability patterns unique to Algorand's transaction model.

When it triggers

  • Use when auditing Algorand projects (TEAL/PyTeal).

More skills in trailofbits/skills

4 skills are listed from this repository.

FAQ

Algorand Vulnerability Scanner FAQ

Still curious? Email info@appsgit.com.

What is the Algorand Vulnerability Scanner skill?

Algorand Vulnerability Scanner is an agent skill (a SKILL.md file) from trailofbits/skills. Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. It works with Claude Code and Codex and has 7,400 GitHub stars across a repository of 4 listed skills. Its SKILL.md lives at github.com/trailofbits/skills/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner.

How do I install the Algorand Vulnerability Scanner skill?

In Claude Code, run /plugin marketplace add trailofbits/skills and then /plugin install building-secure-contracts@trailofbits. For Codex or Cursor, copy the algorand-vulnerability-scanner folder into .agents/skills/ or .cursor/skills/.

Is the Algorand Vulnerability Scanner skill free?

Yes. The repository is open source under the CC-BY-SA-4.0 license.

Is Algorand Vulnerability Scanner maintained?

The repository's most recent commit was on Sep 28, 2026. appsgit only lists skills from repositories with a commit in the last six months.