Back to list
gmh5225

solana-security

by gmh5225

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

2🍴 0📅 Jan 22, 2026

SKILL.md


name: solana-security description: Guide for Solana/Sealevel security research and where to organize Solana-specific resources in README.md.

Solana Security (Sealevel)

Scope

Use this skill for:

  • Solana program auditing (Anchor/native)
  • Solana account model pitfalls
  • Solana-focused fuzzing / tooling / security references

Key Concepts

  • Account model (mutable accounts, ownership, rent/exempt)
  • Program Derived Addresses (PDA) and seeds
  • Cross-Program Invocation (CPI) security
  • Signer vs authority checks
  • Serialization, discriminators, and account layout assumptions

Common Bug Classes

  • Missing signer/authority validation
  • Incorrect PDA derivation or seed collisions
  • CPI to untrusted programs
  • Account confusion (wrong account passed, mismatched owner)
  • Arithmetic / precision issues in token math

Tooling

  • Anchor framework and security patterns
  • Fuzzers / harnesses (e.g., Trident)
  • Program analyzers and disassemblers
  • Solana SDKs/tools: Development → SDK / Development → Tools
  • Solana audit checklists: Security
  • Solana learning guides: Blockchain Guide

Rules

  • Use English descriptions
  • Avoid duplicates across categories

Score

Total Score

60/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

1ヶ月以内に更新

+10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

0/5
タグ

1つ以上のタグが設定されている

+5

Reviews

💬

Reviews coming soon