Back to the catalog

published by trailofbits

40 listings on this page, in order of arrival. Each one has its own page with README, repository facts and source links.

  1. property-based-testing ★ 6,975
    Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invari
  2. review-pr ★ 6,975
    Reviews the current branch's changes against its base branch as a pull request: correctness of new and modified code, test coverage for it,
  3. rust-review ★ 6,975
    Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-indu
  4. ruzzy ★ 6,975
    Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. Covers harness struct
  5. sarif-parsing ★ 6,975
    Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan r
  6. second-opinion ★ 6,975
    Runs external LLM code reviews (OpenAI Codex or Google Antigravity CLI) on uncommitted changes, branch diffs, or specific commits. Use when
  7. secure-workflow-guide ★ 6,975
    Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformanc
  8. semgrep ★ 6,975
    Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every
  9. semgrep-rule-creator ★ 6,975
    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or buil
  10. semgrep-rule-variant-creator ★ 6,975
    Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule a
  11. sharp-edges ★ 6,975
    Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, co
  12. skill-improver ★ 6,975
    Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings led
  13. slicing-code-context ★ 6,975
    Selects bounded, graph-informed source slices with Trailmark and delegates focused code analysis or patch-proposal work to a smaller subagen
  14. solana-vulnerability-scanner ★ 6,975
    Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and
  15. spec-to-code-compliance ★ 6,975
    Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the
  16. substrate-vulnerability-scanner ★ 6,975
    Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin
  17. supply-chain-risk-auditor ★ 6,975
    Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abando
  18. testing-handbook-generator ★ 6,975
    Generates Claude Code skills from the Trail of Bits Testing Handbook (appsec.guide), analyzing handbook pages and emitting SKILL.md files wi
  19. token-integration-analyzer ★ 6,975
    Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/
  20. ton-vulnerability-scanner ★ 6,975
    Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and
  21. trailmark ★ 6,975
    Builds and queries multi-language source and binary code graphs for security analysis. Includes pre-analysis passes for blast radius, taint
  22. trailmark-finding-triage ★ 6,975
    Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using
  23. trailmark-review-gate ★ 6,975
    Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, n
  24. trailmark-structural ★ 6,975
    Runs full Trailmark structural analysis by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege
  25. trailmark-summary ★ 6,975
    Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list. Use when vivisect
  26. trailmark-variant-neighborhood ★ 6,975
    Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, sha
  27. variant-analysis ★ 6,975
    Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. Use immediately after a vulnerabili
  28. vector-forge ★ 6,975
    Mutation-driven test vector generation. Finds implementations of a cryptographic algorithm or protocol, runs mutation testing to identify es
  29. vulnerability-triage-brocards ★ 6,975
    This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide
  30. writing-lean-proofs ★ 6,975
    Writes and reviews structured Lean 4 proofs and designs Lean libraries following Mathlib conventions. Use when proving theorems in Lean, for
  31. wycheproof ★ 6,975
    Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA
  32. yara-rule-authoring ★ 6,975
    Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. C
  33. zeroize-audit ★ 6,975
    Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-lev
  34. ask-questions-if-underspecified ★ 6,975
    trailofbits/skills · skills.sh
  35. insecure-defaults ★ 6,975
    6.506 instalações · trailofbits/skills
  36. git-cleanup ★ 6,975
    trailofbits/skills · skills.sh
  37. debug-buttercup ★ 6,975
    trailofbits/skills · skills.sh
  38. designing-workflow-skills ★ 6,975
    trailofbits/skills · skills.sh
  39. seatbelt-sandboxer ★ 6,975
    trailofbits/skills · skills.sh
  40. claude-in-chrome-troubleshooting ★ 6,975
    2.600 instalações · trailofbits/skills