Search
Development · By trailofbits
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 2 | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. | trailofbits/ | 513 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 3 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 4 | Run the final scope-controlled review before committing, pushing, or opening a PR. | trailofbits/ | 767 | — | ~700 | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository. | trailofbits/ | 7.4k | — | ~2.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 6 | Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses. | trailofbits/ | 767 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging. | trailofbits/ | 7.4k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 8 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 9 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 10 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 11 | Triage and shepherd all open PRs owned by the current GitHub user, isolating each writable worker in its own worktree. | trailofbits/ | 767 | — | ~453 | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Use git worktrees when running multiple Claude Code instances in parallel for different features - creates isolated workspaces with separate branches and virtual environments | trailofbits/ | 128 | — | ~693 | Automated safety check: Warn | Apache-2.0 | 2 days ago |
| 13 | Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. | trailofbits/ | 767 | — | ~389 | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 15 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 16 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 17 | Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 18 | Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings. | trailofbits/ | 7.4k | — | ~1.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 19 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 20 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 21 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 22 | Structures Lean 4 proofs and library design along Mathlib conventions, from stating theorems to refactoring long tactic proofs and fixing slow or timing-out ones. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 23 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 513 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 24 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 25 | Triages open GitHub issues and pull requests with the gh CLI, optionally merging ready PRs, closing resolved issues with evidence and assigning local priority and size estimates. | trailofbits/ | 7.4k | — | ~5.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 26 | Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. | trailofbits/ | 7.4k | — | ~1.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 27 | Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. | trailofbits/ | 7.4k | — | ~311 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 28 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 29 | Use only when the user explicitly asks to stage, commit, push, and open a GitHub pull request in one flow using the GitHub CLI (gh). | trailofbits/ | 513 | 6 repos | ~474 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 30 | Extracts reusable skills from work sessions. An agent skill from trailofbits/skills-curated. | trailofbits/ | 513 | — | ~1.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |