Search

trailofbits/skills

79 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
2

Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

trailofbits/skills7.5k—~1.7kAutomated safety check: PassCC-BY-SA-4.0yesterday
3

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.5k—~3.4kAutomated safety check: PassCC-BY-SA-4.0yesterday
4
4.Let Fate DecideOfficial

Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

trailofbits/skills7.5k—~2.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday
5

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
6

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.5k3 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.0yesterday
7

Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.

trailofbits/skills7.5k—~2.1kAutomated safety check: PassCC-BY-SA-4.0yesterday
8

Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging.

trailofbits/skills7.5k—~2.6kAutomated safety check: PassCC-BY-SA-4.0yesterday
9

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.5k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday
10

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.5k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
11

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
12

Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed.

trailofbits/skills7.5k—~3.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday
13

Creates devcontainers with Claude Code, language-specific tooling (Python/Node/Rust/Go), and persistent volumes.

trailofbits/skills7.5k3 repos~2kAutomated safety check: PassCC-BY-SA-4.0yesterday
14

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

trailofbits/skills7.5k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0yesterday
15

Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

trailofbits/skills7.5k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
16

Diagnoses why the Claude in Chrome MCP tools report the browser extension as not connected, with macOS-specific checks and a fix for the Claude.app native host conflict.

trailofbits/skills7.5k3 repos~2.6kAutomated safety check: PassCC-BY-SA-4.0yesterday
17
17.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.5k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
18

Interprets Culture Index surveys and behavioral profiles, from single-person readings to team composition, burnout risk, hiring profiles and interview analysis.

trailofbits/skills7.5k—~3.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
19
19.Fp CheckOfficial

Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.

trailofbits/skills7.5k2 repos~1.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
20

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

trailofbits/skills7.5k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
21

Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions.

trailofbits/skills7.5k1 repo~2.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
22

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

trailofbits/skills7.5k—~5.9kAutomated safety check: PassCC-BY-SA-4.0yesterday
23

Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

trailofbits/skills7.5k1 repo~5.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
24

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.5k—~2.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
25

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.5k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
26

Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

trailofbits/skills7.5k—~4.6kAutomated safety check: PassCC-BY-SA-4.0yesterday
27

Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.

trailofbits/skills7.5k—~4.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
28

Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.

trailofbits/skills7.5k—~1.8kAutomated safety check: PassCC-BY-SA-4.0yesterday
29

Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets.

trailofbits/skills7.5k—~3.2kAutomated safety check: PassCC-BY-SA-4.0yesterday
30

Drafts a single-line /goal command for Claude Code or Codex goal mode, built around a checkable end state, a stated verification command and a stop condition.

trailofbits/skills7.5k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday
31

Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy.

trailofbits/skills7.5k—~4.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
32

Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black.

trailofbits/skills7.5k—~2.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
33

Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants.

trailofbits/skills7.5k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday
34

Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings.

trailofbits/skills7.5k—~1.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
35

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.5k—~4.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
36

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

trailofbits/skills7.5k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0yesterday
37

Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help.

trailofbits/skills7.5k—~4.8kAutomated safety check: PassCC-BY-SA-4.0yesterday
38

Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus.

trailofbits/skills7.5k—~2.2kAutomated safety check: PassCC-BY-SA-4.0yesterday
39

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.

trailofbits/skills7.5k—~2.2kAutomated safety check: PassCC-BY-SA-4.0yesterday
40

Structures Lean 4 proofs and library design along Mathlib conventions, from stating theorems to refactoring long tactic proofs and fixing slow or timing-out ones.

trailofbits/skills7.5k—~4kAutomated safety check: PassCC-BY-SA-4.0yesterday
41

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.

trailofbits/skills7.5k—~3.6kAutomated safety check: PassCC-BY-SA-4.0yesterday
42

Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.

trailofbits/skills7.5k—~3.1kAutomated safety check: PassCC-BY-SA-4.0yesterday
43

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.5k—~2.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
44

Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.

trailofbits/skills7.5k—~3.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
45

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

trailofbits/skills7.5k—~2.9kAutomated safety check: PassCC-BY-SA-4.0yesterday
46

Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap.

trailofbits/skills7.5k—~1.8kAutomated safety check: PassCC-BY-SA-4.0yesterday
47

Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.

trailofbits/skills7.5k—~2.7kAutomated safety check: PassCC-BY-SA-4.0yesterday
48

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

trailofbits/skills7.5k—~1.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday