Audit Flow
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .claude/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .claude/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagramType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .agents/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .agents/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .cursor/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .cursor/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/trailmark/skills/crypto-protocol-diagram--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .gemini/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .gemini/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills crypto-protocol-diagramInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .github/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .github/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .opencode/skills/crypto-protocol-diagram && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "crypto-protocol-diagram" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/trailmark/skills/crypto-protocol-diagram into .opencode/skills/crypto-protocol-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "crypto-protocol-diagram", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
crypto-protocol-diagramTurns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.
Given source code or a specification, the agent works out who sends what to whom, which cryptographic transformations happen at each step and what phases the protocol has. It writes a Mermaid sequenceDiagram to a file and prints an ASCII version inline. Accepted specifications include RFCs, academic papers, pseudocode, informal prose and ProVerif or Tamarin models, and a URL can be fetched.
The skill sets firm habits: read the source or spec systematically instead of diagramming from memory, run the spec workflow first when both code and spec exist and then note where the code diverges, annotate every cryptographic operation, and show abort and error paths in alt blocks. Two worked examples, a simple handshake in Python and a small ProVerif model, set the expected output quality. Call graphs and class structure go to a different skill.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Crypto Protocol Diagrams loads about 4.6k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 128 tokens; SKILL.md has 1,877 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,877 words, ~4,627 tokens.
.claude/skills/crypto-protocol-diagram/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Produces a Mermaid sequenceDiagram (written to file) and an ASCII sequence
diagram (printed inline) from either:
.pv), or Tamarin (.spthy) model.Tools used: Read, Write, Grep, Glob, Bash, WebFetch (for URL specs).
Unlike the diagramming-code skill (which visualizes code structure), this skill
extracts protocol semantics: who sends what to whom, what cryptographic
transformations occur at each step, and what protocol phases exist.
For call graphs, class hierarchies, or module dependency maps, use the
diagramming-code skill instead.
diagramming-codemermaid-to-proverif (after generating the diagram)| Rationalization | Why It's Wrong | Required Action |
|---|---|---|
| "The protocol is simple, I can diagram from memory" | Memory-based diagrams miss steps and invert arrows | Read the source or spec systematically |
| "I'll skip the spec path since code exists" | Code may diverge from the spec — both paths catch different bugs | When both exist, run spec workflow first, then annotate code divergences |
| "Crypto annotations are optional decoration" | Without crypto annotations, the diagram is just a message flow — useless for security review | Annotate every cryptographic operation |
| "The abort path is obvious, no need for alt blocks" | Implicit abort handling hides missing error checks | Show every abort/error path with alt blocks |
| "I don't need to check the examples first" | The examples define the expected output quality bar | Study the relevant example before working on unfamiliar input |
| "ProVerif/Tamarin models are code, not specs" | Formal models are specifications — they describe intended behavior, not implementation | Use the spec workflow (S1–S5) for .pv and .spthy files |
Protocol Diagram Progress:
- [ ] Step 0: Determine input type (code / spec / both)
- [ ] Step 1 (code) or S1–S5 (spec): Extract protocol structure
- [ ] Step 6: Generate sequenceDiagram
- [ ] Step 7: Verify and deliverBefore doing anything else, classify the input:
| Signal | Input type |
|---|---|
Source file extensions (.py, .rs, .go, .ts, .js, .cpp, .c) | Code |
| Function/class definitions, import statements | Code |
RFC-style section headers (§, Section X.Y, MUST/SHALL keywords) | Spec |
Algorithm/Protocol/Figure labels, mathematical notation | Spec |
ProVerif file (.pv) with process, let, in/out | Spec |
Tamarin file (.spthy) with rule, --[...]-> | Spec |
| Plain prose or numbered steps describing a protocol | Spec |
| Both source files and a spec document | Both (annotate divergences with ⚠️) |
⚠️Grep for function names, type names, and comments that reveal the protocol:
# Find handshake, session, round, phase entry points
rg -l "handshake|session_init|round[_0-9]|setup|keygen|send_msg|recv_msg" {targetDir}
# Find crypto primitives in use
rg "sign|verify|encrypt|decrypt|dh|ecdh|kdf|hkdf|hmac|hash|commit|reveal|share" \
{targetDir} --type-add 'src:*.{py,rs,go,ts,js,cpp,c}' -t src -lStart reading from the highest-level orchestration function — the one that calls into handshake phases or the main protocol loop.
Extract participant names from:
Client, Server, Initiator, Responder, Prover,
Verifier, Dealer, Party, CoordinatorMap these to Mermaid participant declarations. Use short, readable aliases:
participant I as Initiator
participant R as ResponderFollow state transitions and network sends/receives. Look for patterns like:
| Pattern | Meaning |
|---|---|
send(msg) / recv() | Direct message exchange |
serialize + transmit | Structured message sent |
| Return value passed to other party's function | Logical message (in-process) |
round1_output → round2_input | Round-based MPC step |
Struct fields named ephemeral_key, ciphertext, mac, tag | Message contents |
For in-process protocol implementations (where both parties run in the same process), treat function call boundaries as logical message sends when they represent what would be a network boundary in deployment.
At each protocol step, identify and label:
| Operation | Diagram annotation |
|---|---|
| Key generation | Note over A: keygen(params) → pk, sk |
| DH / ECDH | Note over A,B: DH(sk_A, pk_B) |
| KDF / HKDF | Note over A: HKDF(ikm, salt, info) |
| Signing | Note over A: Sign(sk, msg) → σ |
| Verification | Note over B: Verify(pk, msg, σ) |
| Encryption | Note over A: Enc(key, plaintext) → ct |
| Decryption | Note over B: Dec(key, ct) → plaintext |
| Commitment | Note over A: Commit(value, rand) → C |
| Hash | Note over A: H(data) → digest |
| Secret sharing | Note over D: Share(secret, t, n) → {s_i} |
| Threshold combine | Note over C: Combine({s_i}) → secret |
Keep annotations concise — use mathematical shorthand, not code.
Group message steps into named phases using rect or Note blocks:
Common phases to detect:
Detect abort/error paths and show them with alt blocks.
Use this path when the input is a specification document rather than source code. After completing S1–S5, continue with Step 6 (Generate sequenceDiagram) and Step 7 (Verify and deliver) from the code workflow above.
Obtain the full spec text:
Then identify the spec format and read references/spec-parsing-patterns.md for format-specific extraction guidance:
| Format | Signals |
|---|---|
| RFC | RFC XXXX, MUST/SHALL/SHOULD, ABNF grammars, section-numbered prose |
| Academic paper / pseudocode | Algorithm X, Protocol X, Figure X, numbered steps, ←/→ in math mode |
| Informal prose | Numbered lists, "A sends B ...", plain English descriptions |
ProVerif (.pv) | process, let, in(ch, x), out(ch, msg), ! (replication) |
Tamarin (.spthy) | rule, --[ ]->, Fr(~x), !Pk(A, pk), In(m), Out(m) |
If the spec references a known named protocol (TLS, Noise, Signal, X3DH, Double Ratchet, FROST), also read references/protocol-patterns.md to use its canonical flow as a skeleton and fill in spec-specific details.
Identify all protocol participants. Look for:
Alice, Bob, Client, Server,
Initiator, Responder, Prover, Verifier, Dealer, Party_i,
Coordinator, Signerlet ClientProc(...), let ServerProc(...))!Pk($A, pk) — $A is a party)Map each role to a Mermaid participant declaration. Use short IDs with
descriptive aliases (see naming conventions in
references/mermaid-sequence-syntax.md).
Trace what each party sends to whom and in what order. Extraction patterns by format:
RFC / informal prose:
A → B: msg, A -> BPseudocode:
sender/receiver parameterssend(party, msg) / receive(party) callsProVerif (.pv):
out(ch, msg) — send on channel chin(ch, x) — receive on channel ch, bind to xout/in pairs on the same channel to identify message flows! (replication) signals a role that handles multiple sessionsTamarin (.spthy):
In(m) premise — receive message mOut(m) conclusion — send message mFr(~x) — fresh random value generated by a party--[ Label ]-> facts — security annotations, not messagesPreserve the ordering and round structure. Group concurrent sends (broadcast)
using par blocks in the final diagram.
For each protocol step, identify the cryptographic operations performed and which party performs them:
| Spec notation | Operation | Diagram annotation |
|---|---|---|
keygen(), Gen(1^λ) | Key generation | Note over A: keygen() → pk, sk |
DH(a, B), g^ab | DH / ECDH | Note over A,B: DH(sk_A, pk_B) |
KDF(ikm), HKDF(...) | Key derivation | Note over A: HKDF(ikm, salt, info) → k |
Sign(sk, m), σ ← Sign | Signing | Note over A: Sign(sk, msg) → σ |
Verify(pk, m, σ) | Verification | Note over B: Verify(pk, msg, σ) |
Enc(k, m), {m}_k | Encryption | Note over A: Enc(k, plaintext) → ct |
Dec(k, c) | Decryption | Note over B: Dec(k, ct) → plaintext |
H(m), hash(m) | Hash | Note over A: H(data) → digest |
Commit(v, r), com | Commitment | Note over A: Commit(value, rand) → C |
ProVerif senc(m, k) | Symmetric encryption | Note over A: Enc(k, m) → ct |
ProVerif pk(sk) | Public key derivation | Note over A: pk = pk(sk) |
ProVerif sign(m, sk) | Signing | Note over A: Sign(sk, m) → σ |
Identify security conditions and abort paths:
assert, require, if ... abortif m = expected then ... else 0These become alt blocks in the final diagram.
Before moving to Step 6, check for gaps:
⚠️ ordering inferred from spec structure⚠️ spec omits [step] — canonical protocol requires it⚠️ encryption scheme not specifiedc declared with new c or as a
private free name) represent out-of-band channels — note them<!-- Both code path (Steps 1–5) and spec path (Steps S1–S5) continue here -->
Produce Mermaid syntax following the rules in references/mermaid-sequence-syntax.md.
Completeness over brevity. Show every distinct message type. Omit repeated
loop iterations (use loop blocks instead), but never omit a distinct protocol
step.
Correctness over aesthetics. The diagram must match what the code actually does. If the code diverges from a known spec, annotate the divergence:
Note over A,B: ⚠️ spec requires MAC here — implementation omits itBefore delivering:
alt blocks cover known abort/error paths⚠️Write the diagram to a file. Choose a filename derived from the protocol
name, e.g. noise-xx-handshake.md or x3dh-key-agreement.md. Write a
Markdown file with this structure:
# <Protocol Name> Sequence Diagram
\`\`\`mermaid
sequenceDiagram
...
\`\`\`
## Protocol Summary
- **Parties:** ...
- **Round complexity:** ...
- **Key primitives:** ...
- **Authentication:** ...
- **Forward secrecy:** ...
- **Notable:** [spec deviations or security observations, or "none"]After writing the file, print an ASCII sequence diagram inline in the response, followed by the Protocol Summary. State the output filename so the user knows where to find the Mermaid source.
Follow all drawing conventions in references/ascii-sequence-diagram.md, including the inline output format.
── Input is a spec document (not code)?
│ └─ Step S1: identify format, read references/spec-parsing-patterns.md
│
── Input is source code (not a spec)?
│ └─ Step 1: grep for handshake/round/send/recv entry points
│
── Both spec and code provided?
│ └─ Run Spec Workflow (S1–S5) first to build canonical diagram,
│ then read code and annotate divergences with ⚠️
│
── Spec is a known protocol (TLS, Noise, Signal, X3DH, FROST)?
│ └─ Read references/protocol-patterns.md and use canonical flow as skeleton
│
── Spec is ProVerif (.pv) or Tamarin (.spthy)?
│ └─ Read references/spec-parsing-patterns.md → Formal Models section
│
── Spec message ordering is ambiguous?
│ └─ Infer from round/section structure, annotate with ⚠️
│
── Can't identify parties from spec?
│ └─ Check "Parties"/"Notation" sections; for ProVerif read process names;
│ for Tamarin read rule names and fact arguments
│
── Don't know which code files implement the protocol?
│ └─ Step 1: grep for handshake/round/send/recv entry points
│
── Can't identify parties from struct names?
│ └─ Read test files — test setup reveals roles
│
── Protocol runs in-process (no network calls)?
│ └─ Treat function argument passing at role boundaries as messages
│
── MPC / threshold protocol with N parties?
│ └─ Read references/protocol-patterns.md → MPC section
│
── Mermaid syntax error?
│ └─ Read references/mermaid-sequence-syntax.md → Common Pitfalls
│
└─ ASCII drawing conventions?
└─ Read references/ascii-sequence-diagram.mdCode path — examples/simple-handshake/:
protocol.py — two-party authenticated key exchange (X25519 DH +
Ed25519 signing + HKDF + ChaCha20-Poly1305)expected-output.md — exact ASCII diagram and Mermaid file the skill
should produce for that protocolSpec path (ProVerif) — examples/simple-proverif/:
model.pv — HMAC challenge-response authentication modeled in ProVerifexpected-output.md — step-by-step extraction walkthrough (parties,
message flow, crypto ops) and the exact ASCII diagram and Mermaid file the
skill should produceStudy the relevant example before working on an unfamiliar input.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (references, assets) in plugins/trailmark/skills/crypto-protocol-diagram of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Crypto Protocol Diagrams next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Crypto Protocol Diagrams this skilltrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Audit Flowzebbern/claude-code-guide | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | |
| Xray Pre Auditccashwell/evm-cortex | 131 | — | ~25k | Automated safety check: Pass | MIT | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Security Auditjellydn/my-ai-tools | 123 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Static SecurityVeryGoodOpenSource/vgv-ai-flutter-plugin | 169 | — | ~4.4k | Automated safety check: Notes | MIT |
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
jellydn/my-ai-tools
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
VeryGoodOpenSource/vgv-ai-flutter-plugin
Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Works with
Categories
Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. Given source code or a specification, the agent works out who sends what to whom, which cryptographic transformations happen at each step and what phases the protocol has. It writes a Mermaid sequenceDiagram to a file and prints an ASCII version inline.
Crypto Protocol Diagrams fits situations like: diagramming a handshake or key exchange from its implementation; extracting the message flow from an RFC or academic paper; drawing a sequence diagram of a ProVerif or Tamarin model; documenting a protocol such as TLS, Noise, Signal or X3DH before a security review.
Run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a claude-code`. Or copy the skill folder (plugins/trailmark/skills/crypto-protocol-diagram in trailofbits/skills) into .claude/skills/crypto-protocol-diagram in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a codex`. Or copy the skill folder (plugins/trailmark/skills/crypto-protocol-diagram in trailofbits/skills) into .agents/skills/crypto-protocol-diagram in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-protocol-diagram, .gemini/skills/crypto-protocol-diagram, .github/skills/crypto-protocol-diagram and .opencode/skills/crypto-protocol-diagram in your project.
Going by SKILL.md and its folder, Crypto Protocol Diagrams needs Python for the scripts in its folder and the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Crypto Protocol Diagrams is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Crypto Protocol Diagrams: Audit Flow (zebbern/claude-code-guide, 4.7k stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Code Security (semgrep/skills, 322 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.