Official agent skill

Audit Prep Assistant

by trailofbits in trailofbits/skills

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Audit Prep Assistant

skills CLI
$ npx skills add trailofbits/skills --skill audit-prep-assistant -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills audit-prep-assistant --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/building-secure-contracts/skills/audit-prep-assistant .claude/skills/audit-prep-assistant && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-prep-assistant
GitHub stars
7.4k
Token cost
~2.5k tokens
SKILL.md length
693 words
Files
3 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

  • Works in 4 steps: Set Review Goals → Resolve Easy Issues → Ensure Code Accessibility → …
  • Preparing a repository before an external security audit
  • SKILL.md covers Purpose, The Preparation Process, How I Work and Rationalizations (Do Not Skip), plus 3 more sections
  • Calls git; reaches github.com

What it does

Following a Trail of Bits checklist and meant for use a week or two before the audit, the skill works in four steps. It helps define the security level you want, your biggest concerns and the worst-case scenario, and records goals to share with assessors. Next it runs static analysis (Slither for Solidity, dylint for Rust, golangci-lint for Go, CodeQL and Semgrep for Go, Rust and C++), triages findings, fixes easy ones and documents accepted risks.

It also analyzes coverage and suggests tests, finds dead code, lists files in and out of scope, writes tested build instructions, freezes a stable commit, branch and tag, and marks boilerplate. The documentation step produces flowcharts, sequence diagrams, user stories, on-chain and off-chain assumptions and actor privileges. For learning unfamiliar code you are about to audit, audit-context-building is the better fit.

When your agent uses it

  • Preparing a repository before an external security audit
  • Deciding what to fix before auditors start
  • Writing build instructions and scope lists for assessors
  • Producing flowcharts and user stories for a review team

Example prompts

  • “Get this Solidity repo ready for an audit next month and run Slither first.”
  • “List what auditors need from this project and which parts are out of scope.”
  • “Create sequence diagrams and a user-story document for the protocol before the review.”

Requirements

  • Static analysis tools for your language, such as Slither, dylint or golangci-lint

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Set Review Goals
  2. Resolve Easy Issues
  3. Ensure Code Accessibility
  4. Generate Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Prep Assistant loads about 2.5k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 693 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 693 words, ~2,492 tokens.

Download SKILL.mdSave it as .claude/skills/audit-prep-assistant/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
audit-prep-assistant
description
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). Use when preparing your own codebase to be audited by someone else, getting a repository review-ready before an external security review, deciding what to fix before auditors start, or asking what assessors need from a project. For understanding unfamiliar code you are about to audit, use audit-context-building instead.

Audit Prep Assistant

Purpose

Helps prepare for a security review using Trail of Bits' checklist. A well-prepared codebase makes the review process smoother and more effective.

Use this: 1-2 weeks before your security audit


The Preparation Process

Step 1: Set Review Goals

Helps define what you want from the review:

Key Questions:

  • What's the overall security level you're aiming for?
  • What areas concern you most?
    • Previous audit issues?
    • Complex components?
    • Fragile parts?
  • What's the worst-case scenario for your project?

Documents goals to share with the assessment team.


Step 2: Resolve Easy Issues

Runs static analysis and helps fix low-hanging fruit:

Run Static Analysis:

For Solidity:

bash
slither . --exclude-dependencies

For Rust:

bash
dylint --all

For Go:

bash
golangci-lint run

For Go/Rust/C++:

bash
# CodeQL and Semgrep checks

Then I'll:

  • Triage all findings
  • Help fix easy issues
  • Document accepted risks

Increase Test Coverage:

  • Analyze current coverage
  • Identify untested code
  • Suggest new tests
  • Run full test suite

Remove Dead Code:

  • Find unused functions/variables
  • Identify unused libraries
  • Locate stale features
  • Suggest cleanup

Goal: Clean static analysis report, high test coverage, minimal dead code


Step 3: Ensure Code Accessibility

Helps make code clear and accessible:

Provide Detailed File List:

  • List all files in scope
  • Mark out-of-scope files
  • Explain folder structure
  • Document dependencies

Create Build Instructions:

  • Write step-by-step setup guide
  • Test on fresh environment
  • Document dependencies and versions
  • Verify build succeeds

Freeze Stable Version:

  • Identify commit hash for review
  • Create dedicated branch
  • Tag release version
  • Lock dependencies

Identify Boilerplate:

  • Mark copied/forked code
  • Highlight your modifications
  • Document third-party code
  • Focus review on your code

Step 4: Generate Documentation

Helps create documentation:

Flowcharts and Sequence Diagrams:

  • Map primary workflows
  • Show component relationships
  • Visualize data flow
  • Identify critical paths

User Stories:

  • Define user roles
  • Document use cases
  • Explain interactions
  • Clarify expectations

On-chain/Off-chain Assumptions:

  • Data validation procedures
  • Oracle information
  • Bridge assumptions
  • Trust boundaries

Actors and Privileges:

  • List all actors
  • Document roles
  • Define privileges
  • Map access controls

External Developer Docs:

  • Link docs to code
  • Keep synchronized
  • Explain architecture
  • Document APIs

Function Documentation:

  • System and function invariants
  • Parameter ranges (min/max values)
  • Arithmetic formulas and precision loss
  • Complex logic explanations
  • NatSpec for Solidity

Glossary:

  • Define domain terms
  • Explain acronyms
  • Consistent terminology
  • Business logic concepts

Video Walkthroughs (optional):

  • Complex workflows
  • Areas of concern
  • Architecture overview

How I Work

When invoked, I will:

  1. Help set review goals - Ask about concerns and document them
  2. Run static analysis - Execute appropriate tools for your platform
  3. Analyze test coverage - Identify gaps and suggest improvements
  4. Find dead code - Search for unused code and libraries
  5. Review accessibility - Check build instructions and scope clarity
  6. Generate documentation - Create flowcharts, user stories, glossaries
  7. Create prep checklist - Track what's done and what's remaining

Adapts based on:

  • Your platform (Solidity, Rust, Go, etc.)
  • Available tools
  • Existing documentation
  • Review timeline

Show full SKILL.md (248 more words)Show less

Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"README covers setup, no need for detailed build instructions"READMEs assume context auditors don't haveTest build on fresh environment, document every dependency version
"Static analysis already ran, no need to run again"Codebase changed since last runExecute static analysis tools, generate fresh report
"Test coverage looks decent""Looks decent" isn't measured coverageRun coverage tools, identify specific untested code paths
"Not much dead code to worry about"Dead code hides during manual reviewUse automated detection tools to find unused functions/variables
"Architecture is straightforward, no diagrams needed"Text descriptions miss visual patternsGenerate actual flowcharts and sequence diagrams
"Can freeze version right before audit"Last-minute freezing creates rushed handoffIdentify and document commit hash now, create dedicated branch
"Terms are self-explanatory"Domain knowledge isn't universalCreate comprehensive glossary with all domain-specific terms
"I'll do this step later"Steps build on each other - skipping creates gapsComplete all 4 steps sequentially, track progress with checklist

Example Output

When I finish helping you prepare, you'll have concrete deliverables like:

=== AUDIT PREP PACKAGE ===

Project: DeFi DEX Protocol
Audit Date: March 15, 2024
Preparation Status: Complete

---

## REVIEW GOALS DOCUMENT

Security Objectives:
- Verify economic security of liquidity pool swaps
- Validate oracle manipulation resistance
- Assess flash loan attack vectors

Areas of Concern:
1. Complex AMM pricing calculation (src/SwapRouter.sol:89-156)
2. Multi-hop swap routing logic (src/Router.sol)
3. Oracle price aggregation (src/PriceOracle.sol:45-78)

Worst-Case Scenario:
- Flash loan attack drains liquidity pools via oracle manipulation

Questions for Auditors:
- Can the AMM pricing model produce negative slippage under edge cases?
- Is the slippage protection sufficient to prevent sandwich attacks?
- How resilient is the system to temporary oracle failures?

---

## STATIC ANALYSIS REPORT

Slither Scan Results:
✓ High: 0 issues
✓ Medium: 0 issues
⚠ Low: 2 issues (triaged - documented in TRIAGE.md)
ℹ Info: 5 issues (code style, acceptable)

Tool: slither . --exclude-dependencies
Date: March 1, 2024
Status: CLEAN (all critical issues resolved)

---

## TEST COVERAGE REPORT

Overall Coverage: 94%
- Statements: 1,245 / 1,321 (94%)
- Branches: 456 / 498 (92%)
- Functions: 89 / 92 (97%)

Uncovered Areas:
- Emergency pause admin functions (tested manually)
- Governance migration path (one-time use)

Command: forge coverage
Status: EXCELLENT

---

## CODE SCOPE

In-Scope Files (8):
✓ src/SwapRouter.sol (456 lines)
✓ src/LiquidityPool.sol (234 lines)
✓ src/PairFactory.sol (389 lines)
✓ src/PriceOracle.sol (167 lines)
✓ src/LiquidityManager.sol (298 lines)
✓ src/Governance.sol (201 lines)
✓ src/FlashLoan.sol (145 lines)
✓ src/RewardsDistributor.sol (178 lines)

Out-of-Scope:
- lib/ (OpenZeppelin, external dependencies)
- test/ (test contracts)
- scripts/ (deployment scripts)

Total In-Scope: 2,068 lines of Solidity

---

## BUILD INSTRUCTIONS

Prerequisites:
- Foundry 0.2.0+
- Node.js 18+
- Git

Setup:
```bash
git clone https://github.com/project/repo.git
cd repo
git checkout audit-march-2024  # Frozen branch
forge install
forge build
forge test

Verification: ✓ Build succeeds without errors ✓ All 127 tests pass ✓ No warnings from compiler


DOCUMENTATION

Generated Artifacts: ✓ ARCHITECTURE.md - System overview with diagrams ✓ USER_STORIES.md - 12 user interaction flows ✓ GLOSSARY.md - 34 domain terms defined ✓ docs/diagrams/contract-interactions.png ✓ docs/diagrams/swap-flow.png ✓ docs/diagrams/state-machine.png

NatSpec Coverage: 100% of public functions


DEPLOYMENT INFO

Network: Ethereum Mainnet Commit: abc123def456 (audit-march-2024 branch) Deployed Contracts:

  • SwapRouter: 0x1234...
  • PriceOracle: 0x5678... [... etc]

PACKAGE READY FOR AUDIT ✓ Next Step: Share with Trail of Bits assessment team


---

## What You'll Get

**Review Goals Document**:
- Security objectives
- Areas of concern
- Worst-case scenarios
- Questions for auditors

**Clean Codebase**:
- Triaged static analysis (or clean report)
- High test coverage
- No dead code
- Clear scope

**Accessibility Package**:
- File list with scope
- Build instructions
- Frozen commit/branch
- Boilerplate identified

**Documentation Suite**:
- Flowcharts and diagrams
- User stories
- Architecture docs
- Actor/privilege map
- Inline code comments
- Glossary
- Video walkthroughs (if created)

**Audit Prep Checklist**:
- [ ] Review goals documented
- [ ] Static analysis clean/triaged
- [ ] Test coverage >80%
- [ ] Dead code removed
- [ ] Build instructions verified
- [ ] Stable version frozen
- [ ] Flowcharts created
- [ ] User stories documented
- [ ] Assumptions documented
- [ ] Actors/privileges listed
- [ ] Function docs complete
- [ ] Glossary created

---

## Timeline

**2 weeks before audit**:
- Set review goals
- Run static analysis
- Start fixing issues

**1 week before audit**:
- Increase test coverage
- Remove dead code
- Freeze stable version
- Start documentation

**Few days before audit**:
- Complete documentation
- Verify build instructions
- Create final checklist
- Send package to auditors

---

## Ready to Prep

Let me know when you're ready and I'll help you prepare for your security review!

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/building-secure-contracts/skills/audit-prep-assistant of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Audit Prep Assistant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Prep Assistant compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Prep Assistant this skilltrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0
Audit PrepPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Evm Audit Flowmtarcure/claude-vibe-squad162—~1.5kAutomated safety check: PassMIT
Find Untested Sourcesdotnet/skills5.6k1 repos~3.3kAutomated safety check: PassMIT
Reviewwebern/cargo-readme385—~2kAutomated safety check: NotesApache-2.0
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT

Similar skills

  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Evm Audit Flow

    mtarcure/claude-vibe-squad

    A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

    162 GitHub stars~1.5k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Testing & QAAuto-check passed
  • Review

    webern/cargo-readme

    Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

    385 GitHub stars~2k tokensUpdated 11 days ago
    Testing & QAAuto-check: notes
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Questions about Audit Prep Assistant

What does Audit Prep Assistant do?

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. Following a Trail of Bits checklist and meant for use a week or two before the audit, the skill works in four steps. It helps define the security level you want, your biggest concerns and the worst-case scenario, and records goals to share with assessors.

When should I use Audit Prep Assistant?

Audit Prep Assistant fits situations like: preparing a repository before an external security audit; deciding what to fix before auditors start; writing build instructions and scope lists for assessors; producing flowcharts and user stories for a review team.

How do I install Audit Prep Assistant in Claude Code?

Run `npx skills add trailofbits/skills --skill audit-prep-assistant -a claude-code`. Or copy the skill folder (plugins/building-secure-contracts/skills/audit-prep-assistant in trailofbits/skills) into .claude/skills/audit-prep-assistant in your project. Claude Code loads it when a task matches its description.

How do I install Audit Prep Assistant in Codex?

Run `npx skills add trailofbits/skills --skill audit-prep-assistant -a codex`. Or copy the skill folder (plugins/building-secure-contracts/skills/audit-prep-assistant in trailofbits/skills) into .agents/skills/audit-prep-assistant in your project. Codex loads it when a task matches its description.

Can I use Audit Prep Assistant in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill audit-prep-assistant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-prep-assistant, .gemini/skills/audit-prep-assistant, .github/skills/audit-prep-assistant and .opencode/skills/audit-prep-assistant in your project.

What does Audit Prep Assistant need to run?

Going by SKILL.md and its folder, Audit Prep Assistant needs the command-line tools its instructions call (git). Our summary lists: Static analysis tools for your language, such as Slither, dylint or golangci-lint.

Does Audit Prep Assistant access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Prep Assistant safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Prep Assistant use?

Audit Prep Assistant is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Prep Assistant use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Prep Assistant?

Skills that share tags, products or a category with Audit Prep Assistant: Audit Prep (PlamenTSV/plamen, 303 stars), Evm Audit Flow (mtarcure/claude-vibe-squad, 162 stars), Find Untested Sources (dotnet/skills, 5.6k stars) and Review (webern/cargo-readme, 385 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Prep Assistant?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.