🔍
QualityPython

Algorand Vulnerability Scanner

by trailofbits

Algorand Vulnerability Scanner is a Quality skill for Claude Code, published by trailofbits in skills.

6.6K stars567 forkson trailofbits/skillsAdded 2026/08/15Repository updated 2026/08/14
agent-skills
Install in seconds
Install Algorand Vulnerability Scanner
Copy Algorand Vulnerability Scanner into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/algorand-vulnerability-scanner ~/.claude/skills/algorand-vulnerability-scanner

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/trailofbits/skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
plugins/building-secure-contracts/skills/algorand-vulnerability-scanner/SKILL.md in trailofbits/skills
Installs to
~/.claude/skills/algorand-vulnerability-scanner
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Algorand Vulnerability Scanner does

Algorand Vulnerability Scanner scans TEAL and PyTeal smart contracts for 11 common Algorand vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use it when auditing Algorand projects or training on Algorand-specific security patterns.

Algorand Vulnerability Scanner is cataloged under Quality on DirSkills. Algorand Vulnerability Scanner comes from a repository tagged agent-skills.

Documentation

README

Algorand Vulnerability Scanner

1. Purpose

Systematically scan Algorand smart contracts (TEAL and PyTeal) for platform-specific security vulnerabilities documented in Trail of Bits' "Not So Smart Contracts" database. This skill encodes 11 critical vulnerability patterns unique to Algorand's transaction model.

2. When to Use This Skill

  • Auditing Algorand smart contracts (stateful applications or smart signatures)
  • Reviewing TEAL assembly or PyTeal code
  • Pre-audit security assessment of Algorand projects
  • Validating fixes for reported Algorand vulnerabilities
  • Training team on Algorand-specific security patterns

3. Platform Detection

File Extensions & Indicators

  • TEAL files: .teal
  • PyTeal files: .py with PyTeal imports

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Algorand Vulnerability Scanner

  • What else does trailofbits publish alongside Algorand Vulnerability Scanner?

    Algorand Vulnerability Scanner is one of 25 skills that DirSkills catalogs from trailofbits/skills, the repository it ships in. Its siblings there include Agentic Actions Auditor, Audit Context Building and Audit Prep Assistant. Each one is a separate skill with its own page in this directory, installs the same way Algorand Vulnerability Scanner does, and is maintained by trailofbits in that same repository. The rest of the collection is listed on the trailofbits/skills page.

  • How does Algorand Vulnerability Scanner compare to other Quality skills?

    Algorand Vulnerability Scanner ranks #243 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Algorand Vulnerability Scanner against them. Open each page to compare what they document and how they install.

More from trailofbits/skills

Algorand Vulnerability Scanner is one of 25 skills cataloged on DirSkills from trailofbits/skills.

See all 25 skills
🛡️
2w ago

Agentic Actions Auditor

Agentic Actions Auditor provides static security analysis guidance for GitHub Actions workflows that invoke AI coding agents, detecting attack vectors where attacker-controlled input reaches an AI agent. Use it when auditing CI/CD pipeline security for prompt injection risks or evaluating agentic action configurations.
AI Engineering
6.6K567
🗺️
2w ago

Audit Context Building

Audit Context Building analyzes an unfamiliar codebase to map functions, assumptions, guarantees, and dependencies before any vulnerability hunting. Use it at the start of an audit, threat model, or architecture review to produce dossiers and open questions that feed later phases.
Quality
6.6K567
🛡️
2w ago

Audit Prep Assistant

Audit Prep Assistant prepares codebases for security reviews using Trail of Bits' checklist. It helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation.
Quality
6.6K567
🔎
2w ago

Burp Suite Project Parser

Burp Suite Project Parser searches and explores Burp Suite project files (.burp) from the command line. Use it when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
Quality
6.6K567
🛡️
2w ago

C/C++ Security Review

C/C++ Security Review performs comprehensive security audits of native C/C++ applications for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. Use it when auditing userspace daemons, services, or applications for memory safety issues.
Quality
6.6K567
🛡️
2w ago

Cairo StarkNet Vulnerability Scanner

Cairo StarkNet Vulnerability Scanner scans Cairo smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use it when auditing StarkNet projects.
Quality
6.6K567