Building Secure Contracts
Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 1.2.2
- Author
- Omar Inuwa && Paweł Płatek
What Building Secure Contracts is
Building Secure Contracts is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Building Secure Contracts adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Building Secure Contracts
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install building-secure-contracts@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Building Secure Contracts in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/building-secure-contracts/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework.
Author: Omar Inuwa
Overview
This plugin provides 11 specialized skills for smart contract security across multiple blockchain platforms:
- 6 Vulnerability Scanners for platform-specific attack patterns
- 5 Development Guidelines Assistants for secure development practices
Installation
/plugin install trailofbits/skills/plugins/building-secure-contractsVulnerability Scanners
Platform-specific vulnerability detection based on Trail of Bits' Not So Smart Contracts repository.
Algorand Vulnerability Scanner
Skill: /building-secure-contracts:algorand-vulnerability-scanner
Scans Algorand/TEAL codebases for 11 vulnerability patterns including:
- Rekeying vulnerabilities
- Unchecked transaction fees
- Asset closing issues
- Group size checks
- Time-based replay attacks
- And 6 more patterns
Cairo Vulnerability Scanner
Skill: /building-secure-contracts:cairo-vulnerability-scanner
Analyzes StarkNet/Cairo smart contracts for 6 vulnerability patterns:
- Felt252 arithmetic overflow/underflow
- L1 to L2 address conversion
- L1 to L2 message failure
- Overconstrained L1 <-> L2 interaction
- Signature replay protection
- Unchecked from_address in L1 handler
Cosmos Vulnerability Scanner
Skill: /building-secure-contracts:cosmos-vulnerability-scanner
Detects security issues in Cosmos SDK modules for 9 patterns:
- Undelegation time validation
- Amount validation
- Unbonding validation
- Rounding issues
- And 5 more patterns
Solana Vulnerability Scanner
Skill: /building-secure-contracts:solana-vulnerability-scanner
Scans Solana/Anchor programs for 6 critical vulnerabilities:
- Arbitrary CPI
- Improper PDA validation
- Missing ownership checks
- Signer authorization
- And 2 more patterns
Substrate Vulnerability Scanner
Skill: /building-secure-contracts:substrate-vulnerability-scanner
Analyzes Substrate pallets for 7 security issues:
- BadOrigin handling
- Insufficient weight
- Panics on overflow
- Unsigned transaction validation
- And 3 more patterns
TON Vulnerability Scanner
Skill: /building-secure-contracts:ton-vulnerability-scanner
Detects vulnerabilities in TON smart contracts for 3 patterns:
- Integer as boolean (FunC's true is -1)
- Fake Jetton contract
- Forward TON without gas check
Development Guidelines Assistants
Based on Trail of Bits' Development Guidelines.
Audit Prep Assistant
Skill: /building-secure-contracts:audit-prep-assistant
Prepare your codebase for security reviews with a comprehensive checklist:
- Set review goals - Define objectives and concerns
- Resolve easy issues - Run static analysis (Slither, dylint, golangci-lint)
- Ensure accessibility - Build instructions, frozen commits, scope clarity
- Generate documentation - Flowcharts, user stories, glossaries
Use this: 1-2 weeks before your audit to maximize review effectiveness.
Code Maturity Assessor
Skill: /building-secure-contracts:code-maturity-assessor
Systematic code maturity evaluation using Trail of Bits' 9-category framework:
- Arithmetic safety
- Auditing practices
- Authentication/Access controls
- Complexity management
- Decentralization
- Documentation quality
- Transaction ordering risks
- Low-level manipulation
- Testing and verification
Output: Maturity scorecard with evidence-based ratings and a priority-ordered improvement roadmap.
Guidelines Advisor
Skill: /building-secure-contracts:guidelines-advisor
Comprehensive development best practices advisor covering:
- Documentation & Specifications - Generate system descriptions and architectural diagrams
- Architecture Analysis - Optimize on-chain/off-chain distribution
- Upgradeability Review - Assess upgrade patterns and delegatecall proxies
- Implementation Quality - Review functions, inheritance, events
- Common Pitfalls - Identify security anti-patterns
- Dependencies - Evaluate library usage
- Testing - Suggest improvements
Use this: Throughout development for architectural and implementation guidance.
Secure Workflow Guide
Skill: /building-secure-contracts:secure-workflow-guide
Interactive 5-step secure development workflow:
- Known Security Issues - Run Slither with 70+ detectors
- Special Features - Check upgradeability, ERC conformance, token integration
- Visual Inspection - Generate inheritance graphs, function summaries, authorization maps
- Security Properties - Document properties, set up Echidna/Manticore
- Manual Review - Analyze privacy, front-running, cryptography, DeFi risks
Use this: On every check-in or before deployment for continuous security validation.
Token Integration Analyzer
Skill: /building-secure-contracts:token-integration-analyzer
Comprehensive token security analysis for both implementations and integrations:
- ERC20/ERC721 Conformity - Validate standard compliance
- Contract Composition - Assess complexity and SafeMath usage
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Building Secure Contracts?
Building Secure Contracts is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.
How do I install Building Secure Contracts in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install building-secure-contracts@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Building Secure Contracts in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Building Secure Contracts in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Building Secure Contracts safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Trailofbits:Audit Context Builds deep architectural context before vulnerability hunting Slash Command · trailofbits/skills
- Trailofbits:Burp Search Searches Burp Suite project files for security analysis Slash Command · trailofbits/skills
- Trailofbits:Diff Review Performs security-focused differential review of code changes Slash Command · trailofbits/skills
- Trailofbits:Scan Apk Scans Android APKs for Firebase security misconfigurations Slash Command · trailofbits/skills
- Burpsuite Project Parser Search and extract data from Burp Suite project files (.burp) for security analysis Plugin · trailofbits/skills
- Audit Context Building Understand a codebase before looking for bugs in it. Reads it function by function, records what each one assumes and depends on, and saves the write-ups to files instead of filling up the conversation. Plugin · trailofbits/skills
- C Review Comprehensive C/C++ security code review, with coverage verified against a parse of the source Plugin · trailofbits/skills
- Ask Questions If Underspecified Clarify ambiguous requirements by asking questions before implementing. Only when invoked explicitly. Plugin · trailofbits/skills