Search
Security · By trailofbits
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 2 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 3 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 4 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 5 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 6 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 7 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 8 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 9 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 10 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 11 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 12 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 13 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 14 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 15 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 16 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 17 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 18 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 19 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 20 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 21 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 22 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 23 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 24 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 25 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 26 | Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help. | trailofbits/ | 7.4k | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 27 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 28 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 29 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 513 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 30 | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. | trailofbits/ | 513 | 9 repos | ~1.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |
| 31 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 32 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 33 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 34 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 35 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.4k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 36 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 37 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 38 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 39 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 40 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 41 | Reviews a smart contract project against Trail of Bits development guidelines, covering documentation, architecture, upgradeability, implementation quality, dependencies and tests. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 42 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 43 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.4k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 44 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.4k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 45 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 46 | Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 47 | Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 48 | Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark… | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |