GitHub organization
Agent skills by trailofbits
- skills
- 111
- official
- 111
- repositories
- 5
Repositories by trailofbits
- skillsOfficialTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows7.4k stars · 79 skills
- skills-curatedOfficialCurated, community-vetted Claude Code plugin marketplace512 stars · 24 skills
- coopOfficialIsolated VM environment for running Claude Code and Codex762 stars · 6 skills
- dropkitOfficialA CLI tool for managing DigitalOcean droplets with automated setup, SSH configuration, and lifecycle management.128 stars · 1 skill
- necessistOfficialA mutation-based tool for finding bugs in tests156 stars · 1 skill
Skills by trailofbits, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 2 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 3 | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. | trailofbits/ | 512 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 4 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 5 | Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 6 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 7 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 8 | Run the final scope-controlled review before committing, pushing, or opening a PR. | trailofbits/ | 762 | — | ~700 | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository. | trailofbits/ | 7.4k | — | ~2.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 10 | Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses. | trailofbits/ | 762 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging. | trailofbits/ | 7.4k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 12 | A skill your agent uses to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let… | trailofbits/ | 156 | — | ~988 | Automated safety check: Pass | AGPL-3.0 | today |
| 13 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 14 | A skill your agent uses when the task involves reading, creating, or editing .docx documents, especially when formatting or layout fidelity matters; prefer python-docx plus the bundled… | trailofbits/ | 512 | 5 repos | ~786 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 15 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 16 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 17 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 18 | Shepherd the current user's open PR through base updates, CI failures, and review feedback without rewriting history or merging. | trailofbits/ | 762 | — | ~625 | Automated safety check: Pass | Apache-2.0 | today |
| 19 | A skill your agent uses when the agent is building or iterating on a web game (HTML/JS) and needs a reliable development + testing loop: implement small changes, run a Playwright-based test script… | trailofbits/ | 512 | — | ~2.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 20 | Creates devcontainers with Claude Code, language-specific tooling (Python/Node/Rust/Go), and persistent volumes. | trailofbits/ | 7.4k | 3 repos | ~2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 21 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 22 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 23 | Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict. | trailofbits/ | 7.4k | 3 repos | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 24 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 25 | Triage and shepherd all open PRs owned by the current GitHub user, isolating each writable worker in its own worktree. | trailofbits/ | 762 | — | ~453 | Automated safety check: Pass | Apache-2.0 | today |
| 26 | A skill your agent uses when the user asks to create, scaffold, or edit Jupyter notebooks (.ipynb) for experiments, explorations, or tutorials; prefer the bundled templates and run the helper script… | trailofbits/ | 512 | — | ~1k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 27 | Interprets Culture Index surveys and behavioral profiles, from single-person readings to team composition, burnout risk, hiring profiles and interview analysis. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 28 | Use git worktrees when running multiple Claude Code instances in parallel for different features - creates isolated workspaces with separate branches and virtual environments | trailofbits/ | 128 | — | ~693 | Automated safety check: Warn | Apache-2.0 | yesterday |
| 29 | A skill your agent uses when the task requires automating a real browser from the terminal (navigation, form filling, snapshots, screenshots, data extraction, UI-flow debugging) via playwright-cli… | trailofbits/ | 512 | — | ~945 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 30 | Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. | trailofbits/ | 7.4k | 2 repos | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 31 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 32 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 33 | Run and interpret coop's VM integration suite locally on Lima or remotely on Firecracker. | trailofbits/ | 762 | — | ~227 | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Searches X/Twitter for real-time perspectives, dev discussions, product feedback, breaking news, and expert opinions using the X API v2. | trailofbits/ | 512 | — | ~1.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 35 | Teaches the user a new skill or concept over multiple sessions, using the current directory as a stateful teaching workspace with lessons, learning records, and reference materials. | trailofbits/ | 512 | 26 repos | ~2.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 36 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 37 | Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. | trailofbits/ | 762 | — | ~389 | Automated safety check: Pass | Apache-2.0 | today |
| 38 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 39 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 41 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 42 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 43 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 45 | Drafts a single-line /goal command for Claude Code or Codex goal mode, built around a checkable end state, a stated verification command and a stop condition. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 46 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 47 | Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 48 | Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
Questions, answered from the data.
What is the best skill by trailofbits?
CodeQL Security Scan (official) from trailofbits/skills ranks first of the 111 skills by trailofbits listed here, with the highest score: its repository has 7.4k GitHub stars, its SKILL.md loads about 4.6k tokens and it has informational notes only in the automated safety check. Next come Code Graph Mermaid Diagrams and Openai Security Ownership Map.
Are trailofbits's skills official?
111 of the 111 skills by trailofbits are official, published by the vendor's own GitHub organization: CodeQL Security Scan, Code Graph Mermaid Diagrams, Openai Security Ownership Map, Trailmark Graph Evolution, Let Fate Decide and 106 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.