sentio.
Security scanner for Solana programs
sentio scans your Anchor programs for critical vulnerabilities — missing owner checks, unsafe account patterns, and more. Zero config. CLI-first.
$cargo install sentio-cli
sentio scan
$ sentio scan
══ FINDING 1: SW016 init_if_needed usage (manual review) ══
Severity: medium
Location: ./ralli-bet/programs/ralli-bet/src/instructions/create_lineV2.rs:27:1
Matched Because:
Account `line_pointer` uses `init_if_needed`; review for re-initialization or state-reset risk.
25 pub player_line: Account<'info, PlayerLine>,
26
27> #[account(
28 init_if_needed,
29 payer = admin,
Guidance: Prefer #[account(init, ...)] when possible. If init_if_needed is necessary, confirm the account cannot be abused to reset state.
══ FINDING 2: SW002 Missing owner check ══
Severity: critical
Location: ./ralli-bet/programs/ralli-bet/src/instructions/resolve_game_batch.rs:40:1
Matched Because:
Account `treasury` has no owner constraint and no owner guard in instruction logic; any program-owned account can be passed.
38 pub game_vault: Box<InterfaceAccount<'info, TokenAccount>>,
39
40> /// CHECK: Treasury account to receive fees
41 #[account(mut)]
42 pub treasury: AccountInfo<'info>,
Guidance: Add #[account(owner = expected_program::ID)] or verify account.owner explicitly in the instruction handler.
── Summary ──
Total findings: 3
Critical: 2
Medium: 1
What sentio catches
Rules targeting real Solana exploit patterns.