Search
By trailofbits
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 2 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 3 | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. | trailofbits/ | 512 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 4 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 5 | Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 6 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 7 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 8 | Run the final scope-controlled review before committing, pushing, or opening a PR. | trailofbits/ | 762 | — | ~700 | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository. | trailofbits/ | 7.4k | — | ~2.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 10 | Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses. | trailofbits/ | 762 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging. | trailofbits/ | 7.4k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 12 | A skill your agent uses to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let… | trailofbits/ | 156 | — | ~988 | Automated safety check: Pass | AGPL-3.0 | today |
| 13 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 14 | A skill your agent uses when the task involves reading, creating, or editing .docx documents, especially when formatting or layout fidelity matters; prefer python-docx plus the bundled… | trailofbits/ | 512 | 5 repos | ~786 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 15 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 16 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 17 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 18 | Shepherd the current user's open PR through base updates, CI failures, and review feedback without rewriting history or merging. | trailofbits/ | 762 | — | ~625 | Automated safety check: Pass | Apache-2.0 | today |
| 19 | A skill your agent uses when the agent is building or iterating on a web game (HTML/JS) and needs a reliable development + testing loop: implement small changes, run a Playwright-based test script… | trailofbits/ | 512 | — | ~2.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 20 | Creates devcontainers with Claude Code, language-specific tooling (Python/Node/Rust/Go), and persistent volumes. | trailofbits/ | 7.4k | 3 repos | ~2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 21 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 22 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 23 | Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict. | trailofbits/ | 7.4k | 3 repos | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 24 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 25 | Triage and shepherd all open PRs owned by the current GitHub user, isolating each writable worker in its own worktree. | trailofbits/ | 762 | — | ~453 | Automated safety check: Pass | Apache-2.0 | today |
| 26 | A skill your agent uses when the user asks to create, scaffold, or edit Jupyter notebooks (.ipynb) for experiments, explorations, or tutorials; prefer the bundled templates and run the helper script… | trailofbits/ | 512 | — | ~1k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 27 | Interprets Culture Index surveys and behavioral profiles, from single-person readings to team composition, burnout risk, hiring profiles and interview analysis. | trailofbits/ | 7.4k | — | ~3.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 28 | Use git worktrees when running multiple Claude Code instances in parallel for different features - creates isolated workspaces with separate branches and virtual environments | trailofbits/ | 128 | — | ~693 | Automated safety check: Warn | Apache-2.0 | yesterday |
| 29 | A skill your agent uses when the task requires automating a real browser from the terminal (navigation, form filling, snapshots, screenshots, data extraction, UI-flow debugging) via playwright-cli… | trailofbits/ | 512 | — | ~945 | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 30 | Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. | trailofbits/ | 7.4k | 2 repos | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 31 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 32 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 33 | Run and interpret coop's VM integration suite locally on Lima or remotely on Firecracker. | trailofbits/ | 762 | — | ~227 | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Searches X/Twitter for real-time perspectives, dev discussions, product feedback, breaking news, and expert opinions using the X API v2. | trailofbits/ | 512 | — | ~1.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 35 | Teaches the user a new skill or concept over multiple sessions, using the current directory as a stateful teaching workspace with lessons, learning records, and reference materials. | trailofbits/ | 512 | 26 repos | ~2.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 36 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 37 | Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. | trailofbits/ | 762 | — | ~389 | Automated safety check: Pass | Apache-2.0 | today |
| 38 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 39 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 41 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 42 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 43 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 45 | Drafts a single-line /goal command for Claude Code or Codex goal mode, built around a checkable end state, a stated verification command and a stop condition. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 46 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 47 | Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 48 | Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants. | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |