published by trailofbits
40 listings on this page, in order of arrival. Each one has its own page with README, repository facts and source links.
- property-based-testing ★ 6,975
Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invari - review-pr ★ 6,975
Reviews the current branch's changes against its base branch as a pull request: correctness of new and modified code, test coverage for it, - rust-review ★ 6,975
Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-indu - ruzzy ★ 6,975
Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. Covers harness struct - sarif-parsing ★ 6,975
Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan r - second-opinion ★ 6,975
Runs external LLM code reviews (OpenAI Codex or Google Antigravity CLI) on uncommitted changes, branch diffs, or specific commits. Use when - secure-workflow-guide ★ 6,975
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformanc - semgrep ★ 6,975
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every - semgrep-rule-creator ★ 6,975
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or buil - semgrep-rule-variant-creator ★ 6,975
Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule a - sharp-edges ★ 6,975
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, co - skill-improver ★ 6,975
Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings led - slicing-code-context ★ 6,975
Selects bounded, graph-informed source slices with Trailmark and delegates focused code analysis or patch-proposal work to a smaller subagen - solana-vulnerability-scanner ★ 6,975
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and - spec-to-code-compliance ★ 6,975
Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the - substrate-vulnerability-scanner ★ 6,975
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin - supply-chain-risk-auditor ★ 6,975
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abando - testing-handbook-generator ★ 6,975
Generates Claude Code skills from the Trail of Bits Testing Handbook (appsec.guide), analyzing handbook pages and emitting SKILL.md files wi - token-integration-analyzer ★ 6,975
Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ - ton-vulnerability-scanner ★ 6,975
Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and - trailmark ★ 6,975
Builds and queries multi-language source and binary code graphs for security analysis. Includes pre-analysis passes for blast radius, taint - trailmark-finding-triage ★ 6,975
Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using - trailmark-review-gate ★ 6,975
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, n - trailmark-structural ★ 6,975
Runs full Trailmark structural analysis by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege - trailmark-summary ★ 6,975
Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list. Use when vivisect - trailmark-variant-neighborhood ★ 6,975
Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, sha - variant-analysis ★ 6,975
Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. Use immediately after a vulnerabili - vector-forge ★ 6,975
Mutation-driven test vector generation. Finds implementations of a cryptographic algorithm or protocol, runs mutation testing to identify es - vulnerability-triage-brocards ★ 6,975
This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide - writing-lean-proofs ★ 6,975
Writes and reviews structured Lean 4 proofs and designs Lean libraries following Mathlib conventions. Use when proving theorems in Lean, for - wycheproof ★ 6,975
Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA - yara-rule-authoring ★ 6,975
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. C - zeroize-audit ★ 6,975
Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-lev - ask-questions-if-underspecified ★ 6,975
trailofbits/skills · skills.sh - insecure-defaults ★ 6,975
6.506 instalações · trailofbits/skills - git-cleanup ★ 6,975
trailofbits/skills · skills.sh - debug-buttercup ★ 6,975
trailofbits/skills · skills.sh - designing-workflow-skills ★ 6,975
trailofbits/skills · skills.sh - seatbelt-sandboxer ★ 6,975
trailofbits/skills · skills.sh - claude-in-chrome-troubleshooting ★ 6,975
2.600 instalações · trailofbits/skills