Edge Copy setup link
Skill evidence / canister-security
Skill profile

canister-security

IC-specific security patterns for canister development in Motoko and Rust.

What this skill does for you

IC-specific security patterns for canister development in Motoko and Rust. Covers access control, anonymous principal rejection, reentrancy prevention (CallerGuard pattern), async safety (saga pattern), callback trap handling, cycle drain protection, and safe upgrade patterns. Use when writing or modifying any canister that modifies state, handles tokens, makes inter-canister calls, or implements access control.

Quoted from the skill description in the pinned source

Who made it

Publisherdfinity
Repositoryicskills
Installs286as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the canister-security skill from dfinity/icskills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: eb72d4ec81c01ec4ae55c7f33962f8ac12ba1ceb. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: eb72d4ec81c01ec4ae55c7f33962f8ac12ba1ceb. Raw findings: 1. Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: eb72d4ec81c01ec4ae55c7f33962f8ac12ba1ceb. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/dfinity/icskills
Pinned skill file
View source at revision
Revision
eb72d4ec81c01ec4ae55c7f33962f8ac12ba1ceb
Package hash
sha256:4f976f32e7db7a81adecc5455c9628413d0c8ea0e01c854bf675558a392de6d8
Licence
Apache-2.0