← Back to list

solana-security
by gmh5225
A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.
⭐ 2🍴 0📅 Jan 22, 2026
SKILL.md
name: solana-security description: Guide for Solana/Sealevel security research and where to organize Solana-specific resources in README.md.
Solana Security (Sealevel)
Scope
Use this skill for:
- Solana program auditing (Anchor/native)
- Solana account model pitfalls
- Solana-focused fuzzing / tooling / security references
Key Concepts
- Account model (mutable accounts, ownership, rent/exempt)
- Program Derived Addresses (PDA) and seeds
- Cross-Program Invocation (CPI) security
- Signer vs authority checks
- Serialization, discriminators, and account layout assumptions
Common Bug Classes
- Missing signer/authority validation
- Incorrect PDA derivation or seed collisions
- CPI to untrusted programs
- Account confusion (wrong account passed, mismatched owner)
- Arithmetic / precision issues in token math
Tooling
- Anchor framework and security patterns
- Fuzzers / harnesses (e.g., Trident)
- Program analyzers and disassemblers
Where to Add Links in README
- Solana SDKs/tools:
Development → SDK/Development → Tools - Solana audit checklists:
Security - Solana learning guides:
Blockchain Guide
Rules
- Use English descriptions
- Avoid duplicates across categories
Score
Total Score
60/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
✓最近の活動
1ヶ月以内に更新
+10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
○言語
プログラミング言語が設定されている
0/5
✓タグ
1つ以上のタグが設定されている
+5
Reviews
💬
Reviews coming soon
