GitHub organization
Agent skills by trailofbits, page 2
Skills by trailofbits, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings. | trailofbits/ | 7.4k | — | ~1.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 50 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 51 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 52 | Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help. | trailofbits/ | 7.4k | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 53 | A skill your agent uses when tasks involve reading, creating, or reviewing PDF files where rendering and layout matter; prefer visual checks by rendering pages (Poppler) and use Python tools such as… | trailofbits/ | 512 | 9 repos | ~669 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 54 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 55 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 56 | Structures Lean 4 proofs and library design along Mathlib conventions, from stating theorems to refactoring long tactic proofs and fixing slow or timing-out ones. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 57 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 512 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 58 | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. | trailofbits/ | 512 | 9 repos | ~1.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |
| 59 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 60 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 61 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 62 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 63 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.4k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 64 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 65 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 66 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 67 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 68 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 69 | Triages open GitHub issues and pull requests with the gh CLI, optionally merging ready PRs, closing resolved issues with evidence and assigning local priority and size estimates. | trailofbits/ | 7.4k | — | ~5.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 70 | Reviews a smart contract project against Trail of Bits development guidelines, covering documentation, architecture, upgradeability, implementation quality, dependencies and tests. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 71 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 72 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.4k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 73 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.4k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 74 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 75 | Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 76 | Token integration and implementation analyzer based on Trail of Bits' token integration checklist. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 77 | Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 78 | Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark… | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 79 | Runs a Trailmark summary analysis on a codebase. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | — | ~926 | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 80 | Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA, ECDSA, ECDH, and more. | trailofbits/ | 7.4k | — | ~4.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 81 | Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 82 | Runs an autonomous review-and-fix improvement loop over any code target — a skill, plugin, module, or directory — using a reviewer the user names: any installed skill or agent. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 83 | Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. | trailofbits/ | 7.4k | — | ~1.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 84 | Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 85 | Generates an interactive HTML walkthrough for reviewing code changes. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 86 | Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings ledger, escalation when fixes stop converging, and a… | trailofbits/ | 7.4k | — | ~2.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 87 | Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common… | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 88 | Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. | trailofbits/ | 7.4k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 89 | Measures timing side channels in cryptographic implementations by running them, using dudect for statistical analysis and Timecop over Valgrind for dynamic tracing. | trailofbits/ | 7.4k | — | ~5.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 90 | Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output. | trailofbits/ | 7.4k | — | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 91 | Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. | trailofbits/ | 7.4k | — | ~311 | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 92 | Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang. | trailofbits/ | 7.4k | — | ~6.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 93 | A skill your agent uses when the user explicitly asks for a desktop or system screenshot (full screen, specific app or window, or a pixel region), or when tool-specific capture capabilities are… | trailofbits/ | 512 | — | ~2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 94 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 95 | Analyzes DWARF debug information in compiled binaries. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 96 | Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. | trailofbits/ | 7.4k | — | ~11k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |