newmanxbt/sealevel-guard · Archived

cpi-risk

Detects whether the program can invoke the wrong program, propagate too much privilege, or trust unsafe callback behavior. Internal specialist module for CPI risk review.

First seen Mar 27, 2026

Installation

$ npx skills add newmanxbt/sealevel-guard --skill cpi-risk

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from newmanxbt/sealevel-guard.

npx skills add newmanxbt/sealevel-guard

Browse all from newmanxbt/sealevel-guard

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 2
License LICENSE
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,850 B
  • docs SUMMARY.md 186 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

CPI Risk

Forked from Trail of Bits Solana security skills.
Original category alignment: arbitrary CPI, sysvar account checks, and
improper instruction introspection.
Modified by Sealevel Guard and distributed as skill text under CC BY-SA 4.0.

Cross-program invocation risk review skill.

Purpose

Detect whether the program can invoke the wrong program, propagate too much privilege, or trust unsafe callback behavior.

Focus

This skill is responsible for:

  • arbitrary CPI targets,
  • unvalidated program IDs,
  • privilege propagation mistakes,
  • unsafe callback assumptions,
  • and instruction-introspection-adjacent trust failures.

What To Look For

  • CPI destinations that are caller-controlled or weakly validated
  • program IDs trusted by convention rather than explicit checks
  • signer or authority privileges reused across unsafe invocation paths
  • logic that assumes downstream CPI behavior is trustworthy without evidence
  • instruction introspection or sysvar logic that supports fragile trust claims

Solana-Specific Heuristics

  • arbitrary CPI
  • sysvar-related trust assumptions
  • instruction introspection used as a security control
  • token or associated-token CPI targets not strongly bound

Output Shape

Each finding should include:

  • the invocation path,
  • why the CPI boundary is weak,
  • what hostile target or callback becomes possible,
  • and whether that should block shipping or integration.

Example Finding Themes

  • unvalidated CPI target
  • unsafe privilege propagation to downstream program
  • fragile instruction introspection gate
  • sysvar or callback trust misuse