Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/solanabr/solana-vault-standard/build-programgit clone --depth 1 https://github.com/solanabr/solana-vault-standardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/solanabr/solana-vault-standard/build-program)<a href="https://agentmods.dev/commands/solanabr/solana-vault-standard/build-program"><img src="https://agentmods.dev/badge/commands/solanabr/solana-vault-standard/build-program.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.00991 |
| Opus 5 | $0.00005 | $0.00495 |
| Sonnet 5 | $0.00002 | $0.00198 |
| Haiku 4.5 | $0.00001 | $0.00099 |
Grade A, and why
build-program scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to build-program — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 189 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are building a Solana program. Follow these steps:
Related Skills
- programs/anchor.md - Anchor build patterns
- programs/pinocchio.md - Pinocchio build optimization
Step 1: Identify Program Type
Check which framework is being used:
# Check for Anchor
if [ -f "Anchor.toml" ]; then
echo "Anchor program detected"
fi
# Check for Cargo
if [ -f "Cargo.toml" ]; then
echo "Native Rust program detected"
fi
Step 2: Build Program
For Anchor Programs
# Clean build
anchor clean
anchor build
# Build specific program
anchor build -p program-name
# Build with verifiable build
anchor build --verifiable
# Check build output
ls -lh target/deploy/*.so
For Native Rust Programs
# Build BPF program
cargo build-sbf
# Build with specific BPF SDK
cargo build-sbf --bpf-sdk /path/to/bpf-sdk
# Check output
ls -lh target/deploy/*.so
Step 3: Verify Build
# Check program size (should be < 400KB ideally)
ls -lh target/deploy/*.so | awk '{print $5, $9}'
# Verify program ID
solana address -k target/deploy/program-keypair.json
# If Anchor, verify IDL generated
ls -lh target/idl/*.json
Step 4: Run Format and Lint
After successful build:
# Format code
cargo fmt
# Run clippy
cargo clippy -- -W clippy::all
# Check for warnings
cargo clippy --all-targets --all-features -- -D warnings
Common Build Issues
Compilation Errors
- Check Rust version:
rustc --version(need 1.79+) - Update dependencies:
cargo update - Clean and rebuild:
anchor clean && anchor build
Binary Size Too Large
# Check current size
ls -lh target/deploy/*.so
# Optimize in Cargo.toml:
# [profile.release]
# opt-level = "z"
# lto = "fat"
# codegen-units = 1
Missing Dependencies
# For Anchor
npm install
# For Rust
cargo fetch
BPF SDK Issues
# Update Solana CLI
agave-install update
# Reinstall BPF SDK
cargo build-sbf --force-tools-install
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 189 lines · 9 tokens per session scan A 5c2d2bcdd5a7
build-program is a command published in the GitHub repository solanabr/solana-vault-standard (23 stars, last pushed 4mo ago), licensed MIT. It adds 9 tokens to every session and 991 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to build-program, differing in 0 lines, and is treated as a copy.
Other commands, from other repositories
auditor:audit-assist
Flow B — AI-assisted iterative audit with a human in the loop. Same lifecycle as audit-cycle, but pauses at checkpoints to surface confirmed findings, the next-focus plan, and targeted questions only the human can answer (business context, trust model, severity calls). The human steers; the agent re-synthesizes toward…
auditor:intake
Interactive engagement intake (alias /scope). Walks QUESTIONS.md and persists the answers to audit /intake.md — the durable intake artifact both audit-cycle and audit-assist read, instead of answers living only in conversation state. Captures scope + commit pin, languages/frameworks, protocol class, compliance…
auditor:economic-sim
Quantify a candidate economic finding — compute attack cost vs extractable value and, when possible, reproduce deposit→manipulate→withdraw against a Surfpool mainnet-fork for a real P/L figure.
setup-ci-cd
Setup CI/CD pipeline with automated security checks for Solana programs.
audit-solana
Security audit for Solana programs (Anchor/native).
generate-idl-client
Generate TypeScript client from Solana program IDL using Codama or Anchor.