Repository
trailofbits/skills agent skills
- skills
- 79
- official
- 79
- GitHub stars
- 7.4k
GitHub description: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
- Stars
- 7,400 (633 forks)
- Licence
- CC-BY-SA-4.0
- Last push
- Oct 2026
- Created
- Jan 2026
- agent-skills
Install all skills
npx skills add trailofbits/skillsAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in trailofbits/skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 2 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 3 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 4 | Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 5 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 6 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 7 | Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository. | trailofbits/ | 7.4k | — | ~2.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 8 | Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging. | trailofbits/ | 7.4k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 9 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 10 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 11 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 12 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 13 | Creates devcontainers with Claude Code, language-specific tooling (Python/Node/Rust/Go), and persistent volumes. | trailofbits/ | 7.4k | 3 repos | ~2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 14 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 15 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 16 | Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict. | trailofbits/ | 7.4k | 3 repos | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 17 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 18 | Interprets Culture Index surveys and behavioral profiles, from single-person readings to team composition, burnout risk, hiring profiles and interview analysis. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 19 | Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. | trailofbits/ | 7.4k | 2 repos | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 20 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 21 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 22 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 23 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 24 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 25 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 26 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 27 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 28 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 29 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 30 | Drafts a single-line /goal command for Claude Code or Codex goal mode, built around a checkable end state, a stated verification command and a stop condition. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 31 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 32 | Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 33 | Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 34 | Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings. | trailofbits/ | 7.4k | — | ~1.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 35 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 36 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 37 | Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help. | trailofbits/ | 7.4k | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 38 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 39 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | Structures Lean 4 proofs and library design along Mathlib conventions, from stating theorems to refactoring long tactic proofs and fixing slow or timing-out ones. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 41 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 42 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 43 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 45 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.4k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 46 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 47 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 48 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
Questions, answered from the data.
What is the best skill in trailofbits/skills?
CodeQL Security Scan (official) from trailofbits/skills ranks first of the 79 skills in trailofbits/skills listed here, with the highest score: its repository has 7.4k GitHub stars, its SKILL.md loads about 4.6k tokens and it has informational notes only in the automated safety check. Next come Code Graph Mermaid Diagrams and Trailmark Graph Evolution.
Are the skills in trailofbits/skills official?
79 of the 79 skills in trailofbits/skills are official, published by the vendor's own GitHub organization: CodeQL Security Scan, Code Graph Mermaid Diagrams, Trailmark Graph Evolution, Let Fate Decide, Semgrep Security Scan and 74 more.
How do I install all skills from trailofbits/skills?
Run npx skills add trailofbits/skills in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.