Official agent skill

Crypto Protocol Diagrams

by trailofbits in trailofbits/skills

Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Crypto Protocol Diagrams

skills CLI
$ npx skills add trailofbits/skills --skill crypto-protocol-diagram -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills crypto-protocol-diagram --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trailmark/skills/crypto-protocol-diagram .claude/skills/crypto-protocol-diagram && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-protocol-diagram
GitHub stars
7.4k
Token cost
~4.6k tokens
SKILL.md length
1,877 words
Files
11 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

  • Works in 8 steps: Determine Input Type → Locate Protocol Entry Points → Identify Parties and Roles → …
  • Diagramming a handshake or key exchange from its implementation
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations to Reject and Workflow, plus 4 more sections
  • Runs Python scripts from its folder; calls rg

What it does

Given source code or a specification, the agent works out who sends what to whom, which cryptographic transformations happen at each step and what phases the protocol has. It writes a Mermaid sequenceDiagram to a file and prints an ASCII version inline. Accepted specifications include RFCs, academic papers, pseudocode, informal prose and ProVerif or Tamarin models, and a URL can be fetched.

The skill sets firm habits: read the source or spec systematically instead of diagramming from memory, run the spec workflow first when both code and spec exist and then note where the code diverges, annotate every cryptographic operation, and show abort and error paths in alt blocks. Two worked examples, a simple handshake in Python and a small ProVerif model, set the expected output quality. Call graphs and class structure go to a different skill.

When your agent uses it

  • Diagramming a handshake or key exchange from its implementation
  • Extracting the message flow from an RFC or academic paper
  • Drawing a sequence diagram of a ProVerif or Tamarin model
  • Documenting a protocol such as TLS, Noise, Signal or X3DH before a security review

Example prompts

  • “Draw a sequence diagram of the Noise handshake implemented in src/handshake.go.”
  • “Extract the message flow from the X3DH specification and annotate the key derivations.”
  • “Diagram the ProVerif model in models/auth.pv, including the abort paths.”
  • “Show the Double Ratchet message exchange as a sequence diagram.”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Determine Input Type
  2. Locate Protocol Entry Points
  3. Identify Parties and Roles
  4. Trace Message Flow
  5. Annotate Cryptographic Operations
  6. Identify Protocol Phases
  7. Generate sequenceDiagram
  8. Verify and Deliver

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Protocol Diagrams loads about 4.6k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 128 tokens; SKILL.md has 1,877 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,877 words, ~4,627 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-protocol-diagram/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
crypto-protocol-diagram
description
Extracts protocol message flow from source code, RFCs, academic papers, pseudocode, informal prose, ProVerif (.pv), or Tamarin (.spthy) models and generates Mermaid sequenceDiagrams with cryptographic annotations. Use when diagramming a crypto protocol, visualizing a handshake or key exchange flow, extracting message flow from a spec or RFC, diagramming a ProVerif or Tamarin model, or drawing sequence diagrams for TLS, Noise, Signal, X3DH, Double Ratchet, FROST, DH, or ECDH protocols.

Crypto Protocol Diagram

Produces a Mermaid sequenceDiagram (written to file) and an ASCII sequence diagram (printed inline) from either:

  • Source code implementing a cryptographic protocol, or
  • A specification — RFC, academic paper, pseudocode, informal prose, ProVerif (.pv), or Tamarin (.spthy) model.

Tools used: Read, Write, Grep, Glob, Bash, WebFetch (for URL specs).

Unlike the diagramming-code skill (which visualizes code structure), this skill extracts protocol semantics: who sends what to whom, what cryptographic transformations occur at each step, and what protocol phases exist.

For call graphs, class hierarchies, or module dependency maps, use the diagramming-code skill instead.

When to Use

  • User asks to diagram, visualize, or extract a cryptographic protocol
  • Input is source code implementing a handshake, key exchange, or multi-party protocol
  • Input is an RFC, academic paper, pseudocode, or formal model (ProVerif/Tamarin)
  • User names a specific protocol (TLS, Noise, Signal, X3DH, FROST)

When NOT to Use

  • User wants a call graph, class hierarchy, or module dependency map — use diagramming-code
  • User wants to formally verify a protocol — use mermaid-to-proverif (after generating the diagram)
  • Input has no cryptographic protocol semantics (no parties, no message exchange)

Rationalizations to Reject

RationalizationWhy It's WrongRequired Action
"The protocol is simple, I can diagram from memory"Memory-based diagrams miss steps and invert arrowsRead the source or spec systematically
"I'll skip the spec path since code exists"Code may diverge from the spec — both paths catch different bugsWhen both exist, run spec workflow first, then annotate code divergences
"Crypto annotations are optional decoration"Without crypto annotations, the diagram is just a message flow — useless for security reviewAnnotate every cryptographic operation
"The abort path is obvious, no need for alt blocks"Implicit abort handling hides missing error checksShow every abort/error path with alt blocks
"I don't need to check the examples first"The examples define the expected output quality barStudy the relevant example before working on unfamiliar input
"ProVerif/Tamarin models are code, not specs"Formal models are specifications — they describe intended behavior, not implementationUse the spec workflow (S1–S5) for .pv and .spthy files

Workflow

Protocol Diagram Progress:
- [ ] Step 0: Determine input type (code / spec / both)
- [ ] Step 1 (code) or S1–S5 (spec): Extract protocol structure
- [ ] Step 6: Generate sequenceDiagram
- [ ] Step 7: Verify and deliver

Step 0: Determine Input Type

Before doing anything else, classify the input:

SignalInput type
Source file extensions (.py, .rs, .go, .ts, .js, .cpp, .c)Code
Function/class definitions, import statementsCode
RFC-style section headers (§, Section X.Y, MUST/SHALL keywords)Spec
Algorithm/Protocol/Figure labels, mathematical notationSpec
ProVerif file (.pv) with process, let, in/outSpec
Tamarin file (.spthy) with rule, --[...]->Spec
Plain prose or numbered steps describing a protocolSpec
Both source files and a spec documentBoth (annotate divergences with ⚠️)
  • Code only → skip to Step 1 below
  • Spec only → skip to Spec Workflow (S1–S5) below
  • Both → run Spec Workflow first, then use the code-reading steps to verify the implementation against the spec diagram and annotate any divergences with ⚠️
  • Ambiguous → ask the user: "Is this a source code file, a specification document, or both?"

Step 1: Locate Protocol Entry Points

Grep for function names, type names, and comments that reveal the protocol:

bash
# Find handshake, session, round, phase entry points
rg -l "handshake|session_init|round[_0-9]|setup|keygen|send_msg|recv_msg" {targetDir}

# Find crypto primitives in use
rg "sign|verify|encrypt|decrypt|dh|ecdh|kdf|hkdf|hmac|hash|commit|reveal|share" \
    {targetDir} --type-add 'src:*.{py,rs,go,ts,js,cpp,c}' -t src -l

Start reading from the highest-level orchestration function — the one that calls into handshake phases or the main protocol loop.

Step 2: Identify Parties and Roles

Extract participant names from:

  • Struct/class names: Client, Server, Initiator, Responder, Prover, Verifier, Dealer, Party, Coordinator
  • Function parameter names that carry state for a role
  • Comments declaring the protocol role
  • Test fixtures that set up two-party or N-party scenarios

Map these to Mermaid participant declarations. Use short, readable aliases:

participant I as Initiator
participant R as Responder
Step 3: Trace Message Flow

Follow state transitions and network sends/receives. Look for patterns like:

PatternMeaning
send(msg) / recv()Direct message exchange
serialize + transmitStructured message sent
Return value passed to other party's functionLogical message (in-process)
round1_output → round2_inputRound-based MPC step
Struct fields named ephemeral_key, ciphertext, mac, tagMessage contents

For in-process protocol implementations (where both parties run in the same process), treat function call boundaries as logical message sends when they represent what would be a network boundary in deployment.

Step 4: Annotate Cryptographic Operations

At each protocol step, identify and label:

OperationDiagram annotation
Key generationNote over A: keygen(params) → pk, sk
DH / ECDHNote over A,B: DH(sk_A, pk_B)
KDF / HKDFNote over A: HKDF(ikm, salt, info)
SigningNote over A: Sign(sk, msg) → σ
VerificationNote over B: Verify(pk, msg, σ)
EncryptionNote over A: Enc(key, plaintext) → ct
DecryptionNote over B: Dec(key, ct) → plaintext
CommitmentNote over A: Commit(value, rand) → C
HashNote over A: H(data) → digest
Secret sharingNote over D: Share(secret, t, n) → {s_i}
Threshold combineNote over C: Combine({s_i}) → secret

Keep annotations concise — use mathematical shorthand, not code.

Step 5: Identify Protocol Phases

Group message steps into named phases using rect or Note blocks:

Common phases to detect:

  • Setup / Key Generation: party key creation, trusted setup, parameter gen
  • Handshake / Init: ephemeral key exchange, nonce exchange, version negotiation
  • Authentication: identity proof, certificate exchange, signature verification
  • Key Derivation: session key derivation from shared secrets
  • Data Transfer / Main Protocol: encrypted application data exchange
  • Finalization / Teardown: session close, MAC verification, abort handling

Detect abort/error paths and show them with alt blocks.


Spec Workflow (S1–S5)

Use this path when the input is a specification document rather than source code. After completing S1–S5, continue with Step 6 (Generate sequenceDiagram) and Step 7 (Verify and deliver) from the code workflow above.

Step S1: Ingest the Spec

Obtain the full spec text:

  • File path provided → read with the Read tool
  • URL provided → fetch with WebFetch
  • Pasted inline → work directly from conversation context

Then identify the spec format and read references/spec-parsing-patterns.md for format-specific extraction guidance:

FormatSignals
RFCRFC XXXX, MUST/SHALL/SHOULD, ABNF grammars, section-numbered prose
Academic paper / pseudocodeAlgorithm X, Protocol X, Figure X, numbered steps, ←/→ in math mode
Informal proseNumbered lists, "A sends B ...", plain English descriptions
ProVerif (.pv)process, let, in(ch, x), out(ch, msg), ! (replication)
Tamarin (.spthy)rule, --[ ]->, Fr(~x), !Pk(A, pk), In(m), Out(m)

If the spec references a known named protocol (TLS, Noise, Signal, X3DH, Double Ratchet, FROST), also read references/protocol-patterns.md to use its canonical flow as a skeleton and fill in spec-specific details.

Step S2: Extract Parties and Roles

Identify all protocol participants. Look for:

  • Named roles in prose or pseudocode: Alice, Bob, Client, Server, Initiator, Responder, Prover, Verifier, Dealer, Party_i, Coordinator, Signer
  • Section headers: "Parties", "Roles", "Participants", "Setup", "Notation"
  • ProVerif: process names at top level (let ClientProc(...), let ServerProc(...))
  • Tamarin: rule names and fact arguments (e.g. !Pk($A, pk) — $A is a party)

Map each role to a Mermaid participant declaration. Use short IDs with descriptive aliases (see naming conventions in references/mermaid-sequence-syntax.md).

Show full SKILL.md (821 more words)Show less
Step S3: Extract Message Flow

Trace what each party sends to whom and in what order. Extraction patterns by format:

RFC / informal prose:

  • Arrow notation: A → B: msg, A -> B
  • Sentence patterns: "A sends B ...", "B responds with ...", "A transmits ...", "upon receiving X, B sends Y"
  • Numbered steps: extract in order, inferring sender/receiver from context

Pseudocode:

  • Function signatures with explicit sender/receiver parameters
  • send(party, msg) / receive(party) calls
  • Return values passed as inputs to the other party's function in the next step

ProVerif (.pv):

  • out(ch, msg) — send on channel ch
  • in(ch, x) — receive on channel ch, bind to x
  • Match out/in pairs on the same channel to identify message flows
  • ! (replication) signals a role that handles multiple sessions

Tamarin (.spthy):

  • In(m) premise — receive message m
  • Out(m) conclusion — send message m
  • Rule name and ordering of rules reveal protocol rounds
  • Fr(~x) — fresh random value generated by a party
  • --[ Label ]-> facts — security annotations, not messages

Preserve the ordering and round structure. Group concurrent sends (broadcast) using par blocks in the final diagram.

Step S4: Extract Cryptographic Operations

For each protocol step, identify the cryptographic operations performed and which party performs them:

Spec notationOperationDiagram annotation
keygen(), Gen(1^λ)Key generationNote over A: keygen() → pk, sk
DH(a, B), g^abDH / ECDHNote over A,B: DH(sk_A, pk_B)
KDF(ikm), HKDF(...)Key derivationNote over A: HKDF(ikm, salt, info) → k
Sign(sk, m), σ ← SignSigningNote over A: Sign(sk, msg) → σ
Verify(pk, m, σ)VerificationNote over B: Verify(pk, msg, σ)
Enc(k, m), {m}_kEncryptionNote over A: Enc(k, plaintext) → ct
Dec(k, c)DecryptionNote over B: Dec(k, ct) → plaintext
H(m), hash(m)HashNote over A: H(data) → digest
Commit(v, r), comCommitmentNote over A: Commit(value, rand) → C
ProVerif senc(m, k)Symmetric encryptionNote over A: Enc(k, m) → ct
ProVerif pk(sk)Public key derivationNote over A: pk = pk(sk)
ProVerif sign(m, sk)SigningNote over A: Sign(sk, m) → σ

Identify security conditions and abort paths:

  • Prose: "if verification fails, abort", "only if ...", "reject if ..."
  • Pseudocode: assert, require, if ... abort
  • ProVerif: if m = expected then ... else 0
  • Tamarin: contradicting facts or restriction lemmas

These become alt blocks in the final diagram.

Step S5: Flag Spec Ambiguities

Before moving to Step 6, check for gaps:

  • Unclear message ordering: infer from round structure or section order; annotate with ⚠️ ordering inferred from spec structure
  • Implied parties: if a party's role is implied but unnamed, give it a descriptive name and note the inference
  • Missing steps: if the spec omits a step that the canonical pattern for this protocol requires, annotate: ⚠️ spec omits [step] — canonical protocol requires it
  • Underspecified crypto: if the spec says "encrypt" without specifying the scheme, annotate: ⚠️ encryption scheme not specified
  • ProVerif/Tamarin: private channels (c declared with new c or as a private free name) represent out-of-band channels — note them

<!-- Both code path (Steps 1–5) and spec path (Steps S1–S5) continue here -->
Step 6: Generate sequenceDiagram

Produce Mermaid syntax following the rules in references/mermaid-sequence-syntax.md.

Completeness over brevity. Show every distinct message type. Omit repeated loop iterations (use loop blocks instead), but never omit a distinct protocol step.

Correctness over aesthetics. The diagram must match what the code actually does. If the code diverges from a known spec, annotate the divergence:

Note over A,B: ⚠️ spec requires MAC here — implementation omits it
Step 7: Verify and Deliver

Before delivering:

  • Every participant declared actually sends or receives at least one message
  • Arrows point in the correct direction (sender → receiver)
  • Cryptographic operations are on the correct party (the one computing them)
  • If protocol phases are used, no arrows appear outside a phase block
  • alt blocks cover known abort/error paths
  • Diagram renders without syntax errors (check references/mermaid-sequence-syntax.md for common pitfalls)
  • If spec divergence found, annotated with ⚠️

Write the diagram to a file. Choose a filename derived from the protocol name, e.g. noise-xx-handshake.md or x3dh-key-agreement.md. Write a Markdown file with this structure:

markdown
# <Protocol Name> Sequence Diagram

\`\`\`mermaid
sequenceDiagram
    ...
\`\`\`

## Protocol Summary

- **Parties:** ...
- **Round complexity:** ...
- **Key primitives:** ...
- **Authentication:** ...
- **Forward secrecy:** ...
- **Notable:** [spec deviations or security observations, or "none"]

After writing the file, print an ASCII sequence diagram inline in the response, followed by the Protocol Summary. State the output filename so the user knows where to find the Mermaid source.

Follow all drawing conventions in references/ascii-sequence-diagram.md, including the inline output format.


Decision Tree

── Input is a spec document (not code)?
│  └─ Step S1: identify format, read references/spec-parsing-patterns.md
│
── Input is source code (not a spec)?
│  └─ Step 1: grep for handshake/round/send/recv entry points
│
── Both spec and code provided?
│  └─ Run Spec Workflow (S1–S5) first to build canonical diagram,
│     then read code and annotate divergences with ⚠️
│
── Spec is a known protocol (TLS, Noise, Signal, X3DH, FROST)?
│  └─ Read references/protocol-patterns.md and use canonical flow as skeleton
│
── Spec is ProVerif (.pv) or Tamarin (.spthy)?
│  └─ Read references/spec-parsing-patterns.md → Formal Models section
│
── Spec message ordering is ambiguous?
│  └─ Infer from round/section structure, annotate with ⚠️
│
── Can't identify parties from spec?
│  └─ Check "Parties"/"Notation" sections; for ProVerif read process names;
│     for Tamarin read rule names and fact arguments
│
── Don't know which code files implement the protocol?
│  └─ Step 1: grep for handshake/round/send/recv entry points
│
── Can't identify parties from struct names?
│  └─ Read test files — test setup reveals roles
│
── Protocol runs in-process (no network calls)?
│  └─ Treat function argument passing at role boundaries as messages
│
── MPC / threshold protocol with N parties?
│  └─ Read references/protocol-patterns.md → MPC section
│
── Mermaid syntax error?
│  └─ Read references/mermaid-sequence-syntax.md → Common Pitfalls
│
└─ ASCII drawing conventions?
   └─ Read references/ascii-sequence-diagram.md

Examples

Code path — examples/simple-handshake/:

  • protocol.py — two-party authenticated key exchange (X25519 DH + Ed25519 signing + HKDF + ChaCha20-Poly1305)
  • expected-output.md — exact ASCII diagram and Mermaid file the skill should produce for that protocol

Spec path (ProVerif) — examples/simple-proverif/:

  • model.pv — HMAC challenge-response authentication modeled in ProVerif
  • expected-output.md — step-by-step extraction walkthrough (parties, message flow, crypto ops) and the exact ASCII diagram and Mermaid file the skill should produce

Study the relevant example before working on an unfamiliar input.


Supporting Documentation

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references, assets) in plugins/trailmark/skills/crypto-protocol-diagram of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • examples/simple-handshake/expected-output.md
  • examples/simple-handshake/protocol.py
  • examples/simple-proverif/expected-output.md
  • examples/simple-proverif/model.pv
  • references/ascii-sequence-diagram.md
  • references/mermaid-sequence-syntax.md
  • references/protocol-patterns.md
  • references/spec-parsing-patterns.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Crypto Protocol Diagrams next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Protocol Diagrams compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Protocol Diagrams this skilltrailofbits/skills7.4k—~4.6kAutomated safety check: PassCC-BY-SA-4.0
Audit Flowzebbern/claude-code-guide4.7k—~4.2kAutomated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Static SecurityVeryGoodOpenSource/vgv-ai-flutter-plugin169—~4.4kAutomated safety check: NotesMIT

Similar skills

  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.7k GitHub stars~4.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Static Security

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies.

    169 GitHub stars~4.4k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes

Works with

Questions about Crypto Protocol Diagrams

What does Crypto Protocol Diagrams do?

Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. Given source code or a specification, the agent works out who sends what to whom, which cryptographic transformations happen at each step and what phases the protocol has. It writes a Mermaid sequenceDiagram to a file and prints an ASCII version inline.

When should I use Crypto Protocol Diagrams?

Crypto Protocol Diagrams fits situations like: diagramming a handshake or key exchange from its implementation; extracting the message flow from an RFC or academic paper; drawing a sequence diagram of a ProVerif or Tamarin model; documenting a protocol such as TLS, Noise, Signal or X3DH before a security review.

How do I install Crypto Protocol Diagrams in Claude Code?

Run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a claude-code`. Or copy the skill folder (plugins/trailmark/skills/crypto-protocol-diagram in trailofbits/skills) into .claude/skills/crypto-protocol-diagram in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Protocol Diagrams in Codex?

Run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a codex`. Or copy the skill folder (plugins/trailmark/skills/crypto-protocol-diagram in trailofbits/skills) into .agents/skills/crypto-protocol-diagram in your project. Codex loads it when a task matches its description.

Can I use Crypto Protocol Diagrams in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill crypto-protocol-diagram -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-protocol-diagram, .gemini/skills/crypto-protocol-diagram, .github/skills/crypto-protocol-diagram and .opencode/skills/crypto-protocol-diagram in your project.

What does Crypto Protocol Diagrams need to run?

Going by SKILL.md and its folder, Crypto Protocol Diagrams needs Python for the scripts in its folder and the command-line tools its instructions call (rg).

Does Crypto Protocol Diagrams access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Crypto Protocol Diagrams safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crypto Protocol Diagrams use?

Crypto Protocol Diagrams is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Protocol Diagrams use?

About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.3k tokens, read only when the agent opens those files.

What are the alternatives to Crypto Protocol Diagrams?

Skills that share tags, products or a category with Crypto Protocol Diagrams: Audit Flow (zebbern/claude-code-guide, 4.7k stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Code Security (semgrep/skills, 322 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Protocol Diagrams?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.