CantonGuard — Development skill for Claude Code
A Claude/Codex skill to find vulnerabilities in daml contracts.
How to install CantonGuard
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open SCAuditStudio/CantonGuard and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What CantonGuard does
A Claude/Codex skill to find vulnerabilities in daml contracts.
Alternatives in Development
- Root Cause Tracing — Use when errors occur deep in execution and you need to trace back to find the original trigger 102.5k ★
- Review Claudemd — Review recent conversations to find improvements for CLAUDE.md files 6.5k ★
- Find Todos — Find Development Tasks 2.8k ★
README
Canton Guard by SCAS
A security agent for finding potential vulnerabilities in Daml.
Built for:
- Daml developers who want a security check before shipping workflow changes
- Canton teams reviewing authorization, privacy, and contract-key logic
- Security researchers looking for fast, Daml-native audit hypotheses before manual review
Installation
Open claude/codex and paste this prompt ```Install this skill: https://github.com/SCAuditStudio/CantonGuard```
To use the skill in github copilot, clone the repo to the `.github/copilot-skills` folder.
Usage
Use $canton-guard-by-scas to review the codebase
Use $canton-guard-by-scas on specified .daml files
Use $canton-guard-by-scas --include-tests when workflow intent lives in Daml Script or test modules
Use ./github/copilot-skills/canton-guard-by-scas to review the codebase
Tips
- Target hot modules. Point the skill at the contracts or workflows you are actively changing instead of scanning a large repo blindly.
- Run more than once. Different passes often surface different authorization and privacy issues.
- Include tests when needed. In Daml, test and script modules often reveal the intended party flow, deadline logic, and failure cases.
Contact
If you are looking to explore strategies for securing your project, reach out for a chat on [scauditstudio.com](https://scauditstudio.com/contact).
Related Skills
Census
Reconcile corpus populations, distinct vulnerabilities, and duplication across findings trees.
Embedded Agent Skills
Agent skills (SKILL.md) for embedded software development — build/flash/debug/observe/trace with honest declar
Dsh Skill
Official plugin & skill development kit for DeepSeek Harness (DSH). Grounded in core runtime contracts for Cla
Docmancer
Find out what your coding agents already know. Docmancer indexes the memory, rules, and instructions Claude Co
Zehn
Fuzzy-find any prompt across claude, codex, pi & opencode histories, then resume that session. Fast Zig TUI.
Herdr Omni
One search for Herdr workspaces, actions, and live or saved Codex & Claude sessions. Fuzzy-find by name, searc
Related Agents
Security Sentinel
Deep security review focused on OWASP Top 10, injection, auth/authz, data exposure, and dependency vulnerabili
Runtime Bug Audit
Find runtime bugs and error handling issues. NOT for security vulnerabilities (use security-auditor for that).
Sec Red Teamer
Adversarial security analyst that attacks code from the attacker's perspective to find exploitable vulnerabili