cosmos-vulnerability-scanner

Scan Cosmos SDK and CosmWasm modules for consensus-critical vulnerabilities.

1|Updated Apr 7, 2026
One-click install
npx skills add https://github.com/rohanbhatia27/rohanstutoring-redesign --skill cosmos-vulnerability-scanner-rohanbhatia27
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cosmos-vulnerability-scanner
Source: https://github.com/rohanbhatia27/rohanstutoring-redesign/tree/main/.agents/skills/cosmos-vulnerability-scanner
Command: npx skills add https://github.com/rohanbhatia27/rohanstutoring-redesign --skill cosmos-vulnerability-scanner-rohanbhatia27

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires cosmossdk, ibc-go, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the scanning and auditing of Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities, providing efficient security assessment and chain halting prevention.

Core Features & Use Cases

  • Automated Scanning: Performs parallel scanning of codebases for 25+ vulnerability patterns.
  • Detailed Reporting: Generates comprehensive markdown reports with severity, location, and remediation recommendations.
  • Customization: Supports custom output directories and conditional scanning agents based on platform, SDK version, and IBC enablement.
  • Use Case: Before launching a new Cosmos chain or updating existing modules, use this Skill to ensure it is secure against known vulnerabilities.

Quick Start

Run the cosmos-vulnerability-scanner skill on the 'path/to/cosmos/codebase' directory.

Frequently Asked Questions about cosmos-vulnerability-scanner

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan Cosmos SDK modules for consensus-critical vulnerabilities?

To scan Cosmos SDK modules for consensus-critical vulnerabilities, you can automate security auditing by running parallel scanning agents against your codebase directory to detect known vulnerability patterns and prevent chain halting.

How does automated vulnerability scanning work for CosmWasm contracts?

Automated vulnerability scanning for CosmWasm contracts works by deploying multiple scanning agents in parallel to analyze codebases, checking for over 25 vulnerability patterns and generating markdown reports with severity and remediation steps.

Does this Cosmos blockchain vulnerability scanner support ibc-go version compatibility checks?

Yes, this Cosmos blockchain vulnerability scanner supports ibc-go version compatibility checks, automatically adjusting its conditional scanning agents based on the detected SDK version and IBC enablement in your codebase.

When do I need to audit a Cosmos blockchain codebase before launching a new chain?

You need to audit a Cosmos blockchain codebase before launching a new chain or updating existing modules to ensure security against known consensus-critical vulnerabilities, preventing potential chain halts and security breaches.

Can I customize the output directory and scanning conditions for Cosmos SDK security audits?

Yes, you can customize the output directory for your Cosmos SDK security audits and apply conditional scanning based on platform features, SDK version, and IBC enablement to target specific vulnerability patterns.

What is the best way to prevent chain halting in Cosmos SDK blockchains?

The best way to prevent chain halting in Cosmos SDK blockchains is to perform automated security auditing of modules and CosmWasm contracts, scanning for consensus-critical vulnerabilities before deployment and generating detailed remediation reports.