Borrowing it
Nothing to install: this file belongs to solanabr/solana-vault-standard. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/solanabr/solana-vault-standard/main/.claude/commands/audit-solana.mdgit clone --depth 1 https://github.com/solanabr/solana-vault-standardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/solanabr/solana-vault-standard/audit-solana)<a href="https://agentmods.dev/commands/solanabr/solana-vault-standard/audit-solana"><img src="https://agentmods.dev/badge/commands/solanabr/solana-vault-standard/audit-solana/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/solanabr/solana-vault-standard/audit-solana"><img src="https://agentmods.dev/badge/commands/solanabr/solana-vault-standard/audit-solana.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00010 | $0.02831 |
| Opus 5 | $0.00005 | $0.01416 |
| Sonnet 5 | $0.00002 | $0.00566 |
| Haiku 4.5 | $0.00001 | $0.00283 |
Grade A, and why
audit-solana scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Strips warnings and disclaimerslowAnti-refusal
Omitting safety caveats hides risk from the user and is a common jailbreak preamble.
- [ ] Code compiles without warnings Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
This is a copy
100% identical to audit-solana — 8 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 453 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are conducting a security audit for Solana programs. This is CRITICAL - take your time.
Related Skills
- security.md - Comprehensive security checklist
- programs/anchor.md - Anchor security patterns
- programs/pinocchio.md - Pinocchio security patterns
- testing.md - Fuzz testing with Trident
Pre-Audit Checklist
- All tests passing
- Code compiles without warnings
- Documentation complete
- No hardcoded keys or secrets
Step 1: Automated Analysis
echo "🔍 Running automated security analysis..."
# Dependency audit (check for known vulnerabilities)
echo " 📦 Checking dependencies..."
cargo audit
# Supply chain security (check for malicious dependencies)
if command -v cargo-geiger >/dev/null 2>&1; then
echo " ☢️ Checking unsafe code usage..."
cargo geiger
fi
# Clippy with strict security lints
echo " 🔎 Running clippy security lints..."
cargo clippy --all-targets -- \
-W clippy::all \
-W clippy::pedantic \
-W clippy::unwrap_used \
-W clippy::expect_used \
-W clippy::panic \
-W clippy::arithmetic_side_effects \
-D warnings
# Format check
echo " 📝 Checking format..."
cargo fmt --check
# Run full test suite
echo " 🧪 Running tests..."
if [ -f "Anchor.toml" ]; then
anchor build && anchor test
else
cargo build-sbf && cargo test
fi
echo "✅ Automated analysis complete"
Step 2: Account Validation Review
CRITICAL: Every account MUST be validated. Check each instruction:
Owner Checks
// ✓ CORRECT: Validate account owner
if *account.owner != expected_program_id {
return Err(ProgramError::IncorrectProgramId);
}
// ✗ WRONG: Assuming owner without check
Signer Checks
// ✓ CORRECT: Verify signer
if !authority.is_signer {
return Err(ProgramError::MissingRequiredSignature);
}
// ✗ WRONG: Privileged operation without signer check
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 453 lines · 10 tokens per session scan A 44a93d69507a
audit-solana is a command published in the GitHub repository solanabr/solana-vault-standard (24 stars, last pushed 5mo ago), licensed MIT. It adds 10 tokens to every session and 2,831 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (strips warnings and disclaimers). It is 100% identical to audit-solana, differing in 8 lines, and is treated as a copy.
Other commands, from other repositories
auditor:audit-assist
Flow B — AI-assisted iterative audit with a human in the loop. Same lifecycle as audit-cycle, but pauses at checkpoints to surface confirmed findings, the next-focus plan, and targeted questions only the human can answer (business context, trust model, severity calls). The human steers; the agent re-synthesizes toward…
auditor:intake
Interactive engagement intake (alias /scope). Walks QUESTIONS.md and persists the answers to audit /intake.md — the durable intake artifact both audit-cycle and audit-assist read, instead of answers living only in conversation state. Captures scope + commit pin, languages/frameworks, protocol class, compliance…
auditor:economic-sim
Quantify a candidate economic finding — compute attack cost vs extractable value and, when possible, reproduce deposit→manipulate→withdraw against a Surfpool mainnet-fork for a real P/L figure.
deploy
Deploy Solana program (devnet first, then mainnet).
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.