Search

Security · By trailofbits

60 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.02 days ago
2

Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

trailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.02 days ago
3

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.02 days ago
4

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.02 days ago
5

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k3 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.02 days ago
6

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.02 days ago
7

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
8

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
9

Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed.

trailofbits/skills7.4k—~3.8kAutomated safety check: NotesCC-BY-SA-4.02 days ago
10

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

trailofbits/skills7.4k3 repos~3kAutomated safety check: PassCC-BY-SA-4.02 days ago
11

Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

trailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.02 days ago
12
12.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
13

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

trailofbits/skills7.4k—~1.7kAutomated safety check: NotesCC-BY-SA-4.02 days ago
14

Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

trailofbits/skills7.4k1 repo~2.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
15

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

trailofbits/skills7.4k—~5.9kAutomated safety check: PassCC-BY-SA-4.02 days ago
16

Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

trailofbits/skills7.4k1 repo~5.3kAutomated safety check: PassCC-BY-SA-4.02 days ago
17

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.4k—~2.3kAutomated safety check: PassCC-BY-SA-4.02 days ago
18

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.02 days ago
19

Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

trailofbits/skills7.4k—~4.6kAutomated safety check: PassCC-BY-SA-4.02 days ago
20

Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.

trailofbits/skills7.4k—~4.5kAutomated safety check: PassCC-BY-SA-4.02 days ago
21

Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.

trailofbits/skills7.4k—~1.8kAutomated safety check: PassCC-BY-SA-4.02 days ago
22

Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets.

trailofbits/skills7.4k—~3.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
23

Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy.

trailofbits/skills7.4k—~4.5kAutomated safety check: PassCC-BY-SA-4.02 days ago
24

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.4k—~4.3kAutomated safety check: PassCC-BY-SA-4.02 days ago
25

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

trailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.02 days ago
26

Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help.

trailofbits/skills7.4k—~4.8kAutomated safety check: PassCC-BY-SA-4.02 days ago
27

Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus.

trailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
28

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.

trailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
29

Perform language and framework specific security best-practice reviews and suggest improvements.

trailofbits/skills-curated5139 repos~2.2kAutomated safety check: NotesCC-BY-SA-4.02 mo ago
30

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model.

trailofbits/skills-curated5139 repos~1.4kAutomated safety check: PassCC-BY-SA-4.02 mo ago
31

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

trailofbits/skills7.4k—~3.6kAutomated safety check: PassCC-BY-SA-4.02 days ago
32

Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.

trailofbits/skills7.4k—~3.1kAutomated safety check: PassCC-BY-SA-4.02 days ago
33

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.02 days ago
34

Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.

trailofbits/skills7.4k—~3.3kAutomated safety check: PassCC-BY-SA-4.02 days ago
35

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

trailofbits/skills7.4k—~2.9kAutomated safety check: PassCC-BY-SA-4.02 days ago
36

Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap.

trailofbits/skills7.4k—~1.8kAutomated safety check: PassCC-BY-SA-4.02 days ago
37

Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.

trailofbits/skills7.4k—~2.7kAutomated safety check: PassCC-BY-SA-4.02 days ago
38

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

trailofbits/skills7.4k—~1.8kAutomated safety check: NotesCC-BY-SA-4.02 days ago
39

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.02 days ago
40

Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.

trailofbits/skills7.4k—~4kAutomated safety check: PassCC-BY-SA-4.02 days ago
41

Reviews a smart contract project against Trail of Bits development guidelines, covering documentation, architecture, upgradeability, implementation quality, dependencies and tests.

trailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
42
42.LibaflOfficial

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

trailofbits/skills7.4k—~4.3kAutomated safety check: NotesCC-BY-SA-4.02 days ago
43
43.OssfuzzOfficial

Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.

trailofbits/skills7.4k—~4.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
44
44.RuzzyOfficial

Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language.

trailofbits/skills7.4k—~3kAutomated safety check: PassCC-BY-SA-4.02 days ago
45

Guides through Trail of Bits' 5-step secure development workflow.

trailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.02 days ago
46

Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks.

trailofbits/skills7.4k—~3.2kAutomated safety check: PassCC-BY-SA-4.02 days ago
47

Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks.

trailofbits/skills7.4k—~3.8kAutomated safety check: PassCC-BY-SA-4.02 days ago
48

Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

trailofbits/skills7.4k—~1.5kAutomated safety check: NotesCC-BY-SA-4.02 days ago