Project overview
Scan Solana code for return-data spoofing, arbitrary program invocation, stale account state after CPI, and unsafe PDA signing. The skill routes findings to Anchor or native Pinocchio guidance, explains the exploit path, and proposes concrete remediations through an audit command and dedicated agent. Runnable LiteSVM proof-of-concept suites demonstrate vulnerable, defended, and positive-control cases, with especially detailed coverage of spoofed CPI return data.
Repository facts
- Primary language
- TypeScript
- License
- MIT
- Repository updated
- Jun 24, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals