Official agent skill

Dimensional Analysis Annotator

by trailofbits in trailofbits/skills

Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Dimensional Analysis Annotator

skills CLI
$ npx skills add trailofbits/skills --skill dimensional-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills dimensional-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .claude/skills/dimensional-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dimensional-analysis
GitHub stars
7.4k
Token cost
~4.5k tokens
SKILL.md length
2,069 words
Files
7 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.

  • Works in 4 steps: Vocabulary and Scope Discovery → Anchor Annotation → Dimension Propagation → …
  • Annotating a DeFi or financial codebase with unit and decimal comments
  • SKILL.md covers When to Use, When NOT to Use, Execution Mode and Scope and Coverage Guarantees, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

A controller workflow hands the real work to subagents in a fixed sequence of steps: scanning for arithmetic files, discovering the dimension vocabulary, annotating, propagating annotations and validating for bugs. The main context only routes work, builds prompts, saves state, retries and checks coverage. Annotations are short comments recording the unit and decimal scaling next to each value.

It always runs in full-auto mode and ignores any mode argument. Every file the scanner marks in scope is processed across all priority tiers, from critical down to low, and results arrive in one summary at the end. Reference notes cover annotation rules, common dimensions, dimension algebra and bug patterns. It is not meant for code without unit conversions, pure integer counting or a quick check of one formula.

When your agent uses it

  • Annotating a DeFi or financial codebase with unit and decimal comments
  • Hunting arithmetic bugs from unit mismatches, missing scaling or precision loss
  • Auditing code that mixes decimal precisions or fixed-point arithmetic
  • Performing dimensional analysis on a scientific computation codebase

Example prompts

  • “Annotate the units and decimal scaling across the lending protocol in ./contracts.”
  • “Run a dimensional analysis on our pricing code and list any formulas that mix mismatched units.”
  • “Check the offchain oracle adapter for precision loss between token decimals.”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Grep, List, Glob, Task, TodoRead, TodoWrite

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Vocabulary and Scope Discovery
  2. Anchor Annotation
  3. Dimension Propagation
  4. Bug Detection

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep
    • List
    • Glob
    • Task
    • TodoRead
    • TodoWrite

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dimensional Analysis Annotator loads about 4.5k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 2,069 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 2,069 words, ~4,465 tokens.

Download SKILL.mdSave it as .claude/skills/dimensional-analysis/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
dimensional-analysis
description
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol, offchain code, or other blockchain-related codebase with arithmetic. Prevents dimensional mismatches and catches formula bugs early.
allowed-tools
Read, Write, Grep, List, Glob, Task, TodoRead, TodoWrite

Dimensional Analysis Skill

This skill orchestrates a dimensional-analysis pipeline for codebases that perform numeric computations with mixed units, precisions, or scaling factors. The main skill context is a workflow controller only: it delegates scanning, vocabulary discovery, annotation, propagation, and validation to specialized subagents, then manages batching, persistence, retries, coverage gates, and final reporting.

When to Use

  • Annotating a codebase with unit/dimension comments (e.g., D18{tok}, D27{UoA/tok})
  • Performing dimensional analysis on DeFi protocols, financial code, or scientific computations
  • Hunting for arithmetic bugs caused by unit mismatches, missing scaling, or precision loss
  • Auditing codebases with mixed decimal precisions or fixed-point arithmetic

When NOT to Use

  • Codebases with no numeric arithmetic or unit conversions — there is nothing to annotate
  • Pure integer counting logic (loop indices, array lengths) with no physical or financial dimensions
  • When you only need a quick spot-check of a single formula — read the code directly instead of running the full pipeline

Execution Mode

This skill runs in one mode only: full-auto. This is a workflow-based skill that delegates step-specific work to specialized agents via the Task tool. You orchestrate the overall process, manage coverage and state persistence, and ensure that every in-scope file is processed through each step of the pipeline.

  • Always run the full pipeline in this order: Step 1 -> Step 2 -> Step 3 -> Step 4.
  • The main skill context must not perform repository-wide dimensional analysis, annotation, propagation, or bug validation itself when a dedicated subagent exists for that step.
  • The main skill context may inspect artifacts, manifests, and subagent outputs only as needed to route work, build prompts, persist state, and determine completion.
  • Any mode argument provided by the caller is ignored.
  • Report all results at the end in a single summary.

When you start a step, report it:

text
Starting Step: Step {n}

Scope and Coverage Guarantees

This skill must audit all in-scope arithmetic files, including large repositories.

  • In-scope files are defined by Step 1 scanner output (files array), across all priority tiers (CRITICAL, HIGH, MEDIUM, LOW).
  • If Step 1 narrows inputs for vocabulary discovery (for example, CRITICAL/HIGH only), that narrowing applies to discovery only. It never reduces annotation or validation scope.
  • arithmetic-scanner persists the in-scope file manifest to DIMENSIONAL_SCOPE.json in the project root, and that manifest is the source of truth for Steps 2-4.
  • A file is considered fully covered only when all three statuses are present:
    • step2: anchor annotation completed (or explicit no-anchor result)
    • step3: propagation completed (or explicit no-propagation result)
    • step4: validation completed
  • dimension-discoverer persists the discovered dimensional vocabulary to DIMENSIONAL_UNITS.md in the project root for reuse by later steps and future runs.
  • When a file ends in a terminal BLOCKED state, persist the blocking reason and retry count in DIMENSIONAL_SCOPE.json and reflect the same file in coverage.unprocessed_files.
  • Do not finish while any in-scope file remains unprocessed in any step.

Delegation Contract

  • arithmetic-scanner owns repository scanning, arithmetic-file prioritization, and writing DIMENSIONAL_SCOPE.json.
  • dimension-discoverer owns dimensional vocabulary discovery, unit inference, and writing DIMENSIONAL_UNITS.md.
  • dimension-annotator owns annotation format decisions, anchor-point edits, and comment-writing behavior.
  • dimension-propagator owns propagation logic, inferred annotations, and mismatch reporting during tracing.
  • dimension-validator owns bug detection, red-flag evaluation, rationalization rejection, and confirmation or refutation of propagated mismatches.
  • The main skill context must not substitute its own dimensional reasoning for skipped or unlaunched subagents. If a step requires specialized reasoning, launch the corresponding subagent.
  • Use reference files as subagent support material. Pass them to the relevant step in prompts instead of treating them as instructions for the main skill context.

Workflow

Follow these sections in order. Do not advance until the current step satisfies its completion gate.

Shared Orchestration Rules
  • DIMENSIONAL_SCOPE.json and DIMENSIONAL_UNITS.md live in the project root.
  • The main skill context verifies Step 1 artifacts but does not write either Step 1 artifact itself.
  • DIMENSIONAL_SCOPE.json.in_scope_files is the source of truth for Steps 2-4. Never derive later scope from discovery-only inputs.
  • When a later step reaches terminal BLOCKED, persist the matching step*_reason and step*_retry_count fields on the file entry in DIMENSIONAL_SCOPE.json.
  • coverage.unprocessed_files must be derived from terminal BLOCKED entries in DIMENSIONAL_SCOPE.json using { "path": "...", "blocked_step": "step2|step3|step4", "reason": "...", "retry_count": 1 }.
  • A step may retry a BLOCKED file once with a focused prompt. If it is still BLOCKED, keep the documented reason and continue. Do not finalize while any file remains PENDING.
Step 1: Vocabulary and Scope Discovery

If cached artifacts cannot be reused, delegate repository scanning to arithmetic-scanner and vocabulary discovery to dimension-discoverer. Do not do that step-specific analysis directly in the main skill context.

  1. Check whether DIMENSIONAL_UNITS.md and DIMENSIONAL_SCOPE.json already exist in the project root.
  2. If both exist, read them and confirm:
    • DIMENSIONAL_SCOPE.json.project_root matches the current repo root
    • DIMENSIONAL_SCOPE.json contains in_scope_files, discoverer_focus_files, recommended_discovery_order, and per-file step2, step3, step4 fields
    • DIMENSIONAL_UNITS.md is a usable dimensional vocabulary for this repo
  3. If either artifact is stale, malformed, missing required structure, or clearly for another repo, discard reuse and rerun the rest of Step 1.
  4. If both artifacts are valid, reuse them directly. If in_scope_files is empty, skip Steps 2-4 and produce final output with zero findings.
  5. Otherwise use the Task tool to spawn the arithmetic-scanner agent. Its prompt must include:
    • project root path
    • absolute output path for DIMENSIONAL_SCOPE.json
    • instruction to write the Step 1 scope manifest to disk and return the same scope data in its report
  6. The scanner owns Step 1 scope persistence. It must:
    • identify dimensional-arithmetic files and prioritize them as usual
    • write DIMENSIONAL_SCOPE.json with project_root, in_scope_files, discoverer_focus_files, and recommended_discovery_order
    • initialize every in-scope file with step2: "PENDING", step3: "PENDING", and step4: "PENDING"
    • still write an empty manifest when no arithmetic files are found
    • still narrow discoverer_focus_files to CRITICAL/HIGH when more than 50 arithmetic files are found, while keeping all priorities in in_scope_files
  7. After the scanner completes, read DIMENSIONAL_SCOPE.json from disk and confirm it exists and contains the required Step 1 fields before continuing.
  8. Use the Task tool to spawn the dimension-discoverer agent. Its prompt must include:
    • project root path
    • absolute path to DIMENSIONAL_SCOPE.json
    • absolute output path for DIMENSIONAL_UNITS.md
    • prioritized discoverer_focus_files with each file's path, priority, score, and category
    • recommended_discovery_order
  9. The discoverer owns Step 1 vocabulary persistence. It must read DIMENSIONAL_SCOPE.json as the Step 1 source of truth and write DIMENSIONAL_UNITS.md with Base Units, Derived Units, and Precision Prefixes sections. If in_scope_files is empty, it must still write the same headings with empty sections.
  10. Step 1 is complete only when both artifacts exist on disk, pass the reuse checks above, and correctly represent the zero-file case. If in_scope_files is empty after the discoverer writes DIMENSIONAL_UNITS.md, skip Steps 2-4 and produce final output with zero findings.
Step 2: Anchor Annotation

The main skill context must not add annotations itself. Use the Task tool to spawn dimension-annotator agents for all anchor-point annotation work. For full examples and annotation format details, see [{baseDir}/references/annotate.md]({baseDir}/references/annotate.md).

  • Read DIMENSIONAL_SCOPE.json and build batches from in_scope_files. Every in-scope file, including MEDIUM and LOW priority files, must receive a Step 2 outcome.
  • Batch files instead of spawning one agent per file:
    • <= 10 files: one batch
    • 11-30 files: one batch per category
    • > 30 files: one batch per category, splitting categories larger than 10 files into sub-batches of about 8 files
  • Launch categories in Step 1 recommended discovery order: math libraries, then oracles, then core logic, then peripheral. Batches inside the same category may run in parallel.
  • Before launching annotators, set step2 = "PENDING" for every in-scope file and persist the updated DIMENSIONAL_SCOPE.json.
  • Each annotator prompt must include:
    • absolute path to DIMENSIONAL_UNITS.md
    • absolute path to DIMENSIONAL_SCOPE.json
    • assigned file paths in order
    • each file's category and matched patterns from scanner output
    • summary of previously annotated interfaces or types from earlier batches, when applicable
    • required per-file status output: ANNOTATED, REVIEWED_NO_ANCHOR_CHANGES, or BLOCKED plus a one-line justification
  • After each batch, immediately persist each assigned file to exactly one Step 2 status:
    • ANNOTATED
    • REVIEWED_NO_ANCHOR_CHANGES
    • BLOCKED
  • If a file is BLOCKED, also persist step2_reason and step2_retry_count. Retry each BLOCKED file once with a focused prompt.
  • Do not continue to Step 3 while any file remains PENDING in on-disk manifest state.
Show full SKILL.md (751 more words)Show less
Step 3: Dimension Propagation

The main skill context must not perform propagation reasoning itself. Use the Task tool to spawn dimension-propagator agents to extend annotations through arithmetic, function calls, and assignments. For algebra details, see [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md).

  • Read DIMENSIONAL_SCOPE.json and build propagation batches from in_scope_files. Every in-scope file must receive a Step 3 outcome.
  • Use the same batching rules and category ordering as Step 2.
  • Before launching propagators, confirm every file already has a non-pending Step 2 status.
  • Then set step3 = "PENDING" for every in-scope file and persist the updated manifest.
  • Each propagator prompt must include:
    • absolute path to DIMENSIONAL_UNITS.md
    • absolute path to DIMENSIONAL_SCOPE.json
    • assigned file paths in order
    • each file's category and matched patterns
    • summary of Step 2 anchor annotations for the assigned files and any upstream interfaces they depend on
    • required per-file status output: PROPAGATED, REVIEWED_NO_PROPAGATION_CHANGES, or BLOCKED plus a one-line justification
  • After each batch, immediately persist each assigned file to exactly one Step 3 status:
    • PROPAGATED
    • REVIEWED_NO_PROPAGATION_CHANGES
    • BLOCKED
  • If a file is BLOCKED, also persist step3_reason and step3_retry_count. Retry each BLOCKED file once with a focused prompt.
  • After all propagators complete, aggregate:
    • annotations added by confidence level (CERTAIN, INFERRED, UNCERTAIN)
    • mismatches found, with severities for validator deduplication
    • coverage gaps that could not be inferred
  • Do not continue to Step 4 while any file remains PENDING in on-disk manifest state.
Step 4: Bug Detection

The main skill context must not perform bug detection itself. Use the Task tool to spawn dimension-validator agents to detect dimensional bugs in annotated code. For examples, red flags, rationalization checks, and standard vocabulary, see [{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md), [{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md), and [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md). DO NOT DETECT BUGS IN ANY OTHER STEP.

  • Validate every file in DIMENSIONAL_SCOPE.json.in_scope_files.
  • Use this priority order without skipping lower tiers:
    1. files with CRITICAL or HIGH Step 3 mismatches
    2. remaining CRITICAL and HIGH scanner-priority files
    3. remaining MEDIUM and LOW files
  • Before launching validators, confirm every file already has a non-pending Step 3 status.
  • Then set step4 = "PENDING" for every in-scope file and persist the updated manifest.
  • Spawn one dimension-validator agent per file. For large repos, run them in waves of roughly 10-30 files to keep orchestration stable.
  • Each validator prompt must include:
    • absolute path to DIMENSIONAL_UNITS.md
    • absolute path to DIMENSIONAL_SCOPE.json
    • the single file path to validate
    • a summary of anchor and propagated annotations in the file
    • Step 3 mismatch summaries for the file, including mismatch IDs
    • cross-file function signatures or return dimensions needed for call-boundary checks
    • required per-file status output: VALIDATED or BLOCKED
  • After each wave, immediately persist each file to exactly one Step 4 status:
    • VALIDATED
    • BLOCKED
  • If a file is BLOCKED, also persist step4_reason and step4_retry_count. Retry each BLOCKED file once with a focused prompt.
  • Deduplicate findings:
    • confirmed Step 3 mismatches keep their original IDs and severities
    • refuted Step 3 mismatches are noted as false positives and excluded from final counts
    • genuinely new findings receive new DIM-XXX IDs
  • Aggregate confirmed findings, new findings, refuted findings, coverage summary, and final coverage.unprocessed_files.
  • Step 4 is complete only when DIMENSIONAL_SCOPE.json.in_scope_files contains no step4: "PENDING" entries.

Reference Documentation

Pass these references to the relevant subagent when a step needs them:

  • [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md) - Propagator and validator algebra rules
  • [{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md) - Validator vocabulary reference
  • [{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md) - Validator bug-pattern and red-flag reference
  • [{baseDir}/references/annotate.md]({baseDir}/references/annotate.md) - Annotator format and example reference

Final Output

At the end of the analysis, provide a structured summary unless some other output format has been specified:

json
{
  "mode": "full-auto",
  "project_root": "<path>",
  "vocabulary": {
    "base_units": ["..."],
    "derived_units": ["..."],
    "precision_prefixes": ["..."]
  },
  "annotations": {
    "total_added": 0,
    "by_file": {}
  },
  "findings": {
    "critical": 0,
    "high": 0,
    "medium": 0,
    "details": []
  },
  "uncertainties_resolved": 0,
  "coverage": {
    "in_scope_files": 0,
    "anchor_reviewed_files": "0/0",
    "propagation_reviewed_files": "0/0",
    "validation_reviewed_files": "0/0",
    "annotated_functions": "0/0",
    "annotated_variables": "0/0",
    "unprocessed_files": [
      {
        "path": "/path/to/repo/contracts/LegacyMath.sol",
        "blocked_step": "step3",
        "reason": "Parser could not process generated source",
        "retry_count": 1
      }
    ]
  }
}

Completion Checklist

You are NOT done until all of these are true:

File Coverage Gates
  • DIMENSIONAL_UNITS.md exists in the project root
  • DIMENSIONAL_SCOPE.json exists in the project root and is the source of truth for downstream coverage
  • Every in-scope arithmetic file discovered in Step 1 appears in DIMENSIONAL_SCOPE.json.in_scope_files
  • Every in-scope file has a non-PENDING Step 2 status (ANNOTATED, REVIEWED_NO_ANCHOR_CHANGES, or BLOCKED)
  • Every in-scope file has a non-PENDING Step 3 status (PROPAGATED, REVIEWED_NO_PROPAGATION_CHANGES, or BLOCKED)
  • Every in-scope file has a non-PENDING Step 4 status (VALIDATED or BLOCKED)
  • No in-scope file remains PENDING in any step
  • Any BLOCKED file has a documented reason in the final output
  • coverage.unprocessed_files exactly matches the final set of terminal BLOCKED files after retries, using path, blocked_step, reason, and retry_count
Summary Report
  • Final summary JSON/report provided
  • Final coverage counters match DIMENSIONAL_SCOPE.json
  • List of modified files provided when edits occurred
  • Any dimensional mismatches or bugs found are summarized
  • Any remaining blocked or unprocessed files are called out with reasons

If DIMENSIONAL_SCOPE.json and the final report disagree, reconcile the report or continue processing until they match. Do not claim completion from agent intent alone; completion is determined by manifest coverage and final reported statuses.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references, assets) in plugins/dimensional-analysis/skills/dimensional-analysis of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/annotate.md
  • references/bug-patterns.md
  • references/common-dimensions.md
  • references/dimension-algebra.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Dimensional Analysis Annotator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dimensional Analysis Annotator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dimensional Analysis Annotator this skilltrailofbits/skills7.4k—~4.5kAutomated safety check: PassCC-BY-SA-4.0
Secure Codingtechygarg/lattice198—~1.5kAutomated safety check: PassMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Best Practicesmidudev/100cosas.dev1143 repos~3kAutomated safety check: PassMIT
Read-Only Code AuditHarnessMD/munder-difflin8.5k—~350Automated safety check: NotesMIT
Codebase Review SwarmZaxbyHub/opencode-swarm488—~2.8kAutomated safety check: PassMIT

Similar skills

  • Secure Coding

    techygarg/lattice

    Apply security-conscious thinking when generating or modifying code.

    198 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Best Practices

    midudev/100cosas.dev

    Apply modern web development best practices for security, compatibility, and code quality.

    114 GitHub starsUsed in 3 repos~3k tokens
    DevelopmentAuto-check passed
  • Read-Only Code Audit

    HarnessMD/munder-difflin

    Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.

    8.5k GitHub stars~350 tokensUpdated today
    DevelopmentAuto-check: notes
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    488 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Find Bugs

    getsentry/skills

    Official

    Find bugs, security vulnerabilities, and code quality issues in local branch changes.

    1k GitHub starsUsed in 9 repos~708 tokens
    DevelopmentAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Questions about Dimensional Analysis Annotator

What does Dimensional Analysis Annotator do?

Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. A controller workflow hands the real work to subagents in a fixed sequence of steps: scanning for arithmetic files, discovering the dimension vocabulary, annotating, propagating annotations and validating for bugs. The main context only routes work, builds prompts, saves state, retries and checks coverage.

When should I use Dimensional Analysis Annotator?

Dimensional Analysis Annotator fits situations like: annotating a DeFi or financial codebase with unit and decimal comments; hunting arithmetic bugs from unit mismatches, missing scaling or precision loss; auditing code that mixes decimal precisions or fixed-point arithmetic; performing dimensional analysis on a scientific computation codebase.

How do I install Dimensional Analysis Annotator in Claude Code?

Run `npx skills add trailofbits/skills --skill dimensional-analysis -a claude-code`. Or copy the skill folder (plugins/dimensional-analysis/skills/dimensional-analysis in trailofbits/skills) into .claude/skills/dimensional-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Dimensional Analysis Annotator in Codex?

Run `npx skills add trailofbits/skills --skill dimensional-analysis -a codex`. Or copy the skill folder (plugins/dimensional-analysis/skills/dimensional-analysis in trailofbits/skills) into .agents/skills/dimensional-analysis in your project. Codex loads it when a task matches its description.

Can I use Dimensional Analysis Annotator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill dimensional-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dimensional-analysis, .gemini/skills/dimensional-analysis, .github/skills/dimensional-analysis and .opencode/skills/dimensional-analysis in your project.

What does Dimensional Analysis Annotator need to run?

SKILL.md names no scripts, command-line tools or credentials: Dimensional Analysis Annotator is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Grep, List, Glob, Task, TodoRead, TodoWrite.

Does Dimensional Analysis Annotator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dimensional Analysis Annotator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dimensional Analysis Annotator use?

Dimensional Analysis Annotator is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dimensional Analysis Annotator use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.

What are the alternatives to Dimensional Analysis Annotator?

Skills that share tags, products or a category with Dimensional Analysis Annotator: Secure Coding (techygarg/lattice, 198 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars), Best Practices (midudev/100cosas.dev, 114 stars) and Read-Only Code Audit (HarnessMD/munder-difflin, 8.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dimensional Analysis Annotator?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.