Secure Coding
techygarg/lattice
Apply security-conscious thinking when generating or modifying code.
Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.
$ npx skills add trailofbits/skills --skill dimensional-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills dimensional-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .claude/skills/dimensional-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .claude/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill dimensional-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills dimensional-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .agents/skills/dimensional-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .agents/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill dimensional-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills dimensional-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .cursor/skills/dimensional-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .cursor/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/dimensional-analysis/skills/dimensional-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill dimensional-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills dimensional-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .gemini/skills/dimensional-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .gemini/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills dimensional-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill dimensional-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .github/skills/dimensional-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .github/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill dimensional-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills dimensional-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dimensional-analysis/skills/dimensional-analysis .opencode/skills/dimensional-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dimensional-analysis" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/dimensional-analysis/skills/dimensional-analysis into .opencode/skills/dimensional-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dimensional-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dimensional-analysisAnnotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic.
A controller workflow hands the real work to subagents in a fixed sequence of steps: scanning for arithmetic files, discovering the dimension vocabulary, annotating, propagating annotations and validating for bugs. The main context only routes work, builds prompts, saves state, retries and checks coverage. Annotations are short comments recording the unit and decimal scaling next to each value.
It always runs in full-auto mode and ignores any mode argument. Every file the scanner marks in scope is processed across all priority tiers, from critical down to low, and results arrive in one summary at the end. Reference notes cover annotation rules, common dimensions, dimension algebra and bug patterns. It is not meant for code without unit conversions, pure integer counting or a quick check of one formula.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGrepListGlobTaskTodoReadTodoWriteFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dimensional Analysis Annotator loads about 4.5k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 2,069 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 2,069 words, ~4,465 tokens.
.claude/skills/dimensional-analysis/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.This skill orchestrates a dimensional-analysis pipeline for codebases that perform numeric computations with mixed units, precisions, or scaling factors. The main skill context is a workflow controller only: it delegates scanning, vocabulary discovery, annotation, propagation, and validation to specialized subagents, then manages batching, persistence, retries, coverage gates, and final reporting.
D18{tok}, D27{UoA/tok})This skill runs in one mode only: full-auto.
This is a workflow-based skill that delegates step-specific work to specialized agents via the Task tool. You orchestrate the overall process, manage coverage and state persistence, and ensure that every in-scope file is processed through each step of the pipeline.
When you start a step, report it:
Starting Step: Step {n}This skill must audit all in-scope arithmetic files, including large repositories.
files array), across all priority tiers (CRITICAL, HIGH, MEDIUM, LOW).arithmetic-scanner persists the in-scope file manifest to DIMENSIONAL_SCOPE.json in the project root, and that manifest is the source of truth for Steps 2-4.step2: anchor annotation completed (or explicit no-anchor result)step3: propagation completed (or explicit no-propagation result)step4: validation completeddimension-discoverer persists the discovered dimensional vocabulary to DIMENSIONAL_UNITS.md in the project root for reuse by later steps and future runs.BLOCKED state, persist the blocking reason and retry count in DIMENSIONAL_SCOPE.json and reflect the same file in coverage.unprocessed_files.arithmetic-scanner owns repository scanning, arithmetic-file prioritization, and writing DIMENSIONAL_SCOPE.json.dimension-discoverer owns dimensional vocabulary discovery, unit inference, and writing DIMENSIONAL_UNITS.md.dimension-annotator owns annotation format decisions, anchor-point edits, and comment-writing behavior.dimension-propagator owns propagation logic, inferred annotations, and mismatch reporting during tracing.dimension-validator owns bug detection, red-flag evaluation, rationalization rejection, and confirmation or refutation of propagated mismatches.Follow these sections in order. Do not advance until the current step satisfies its completion gate.
DIMENSIONAL_SCOPE.json and DIMENSIONAL_UNITS.md live in the project root.DIMENSIONAL_SCOPE.json.in_scope_files is the source of truth for Steps 2-4. Never derive later scope from discovery-only inputs.BLOCKED, persist the matching step*_reason and step*_retry_count fields on the file entry in DIMENSIONAL_SCOPE.json.coverage.unprocessed_files must be derived from terminal BLOCKED entries in DIMENSIONAL_SCOPE.json using { "path": "...", "blocked_step": "step2|step3|step4", "reason": "...", "retry_count": 1 }.BLOCKED file once with a focused prompt. If it is still BLOCKED, keep the documented reason and continue. Do not finalize while any file remains PENDING.If cached artifacts cannot be reused, delegate repository scanning to arithmetic-scanner and vocabulary discovery to dimension-discoverer. Do not do that step-specific analysis directly in the main skill context.
DIMENSIONAL_UNITS.md and DIMENSIONAL_SCOPE.json already exist in the project root.DIMENSIONAL_SCOPE.json.project_root matches the current repo rootDIMENSIONAL_SCOPE.json contains in_scope_files, discoverer_focus_files, recommended_discovery_order, and per-file step2, step3, step4 fieldsDIMENSIONAL_UNITS.md is a usable dimensional vocabulary for this repoin_scope_files is empty, skip Steps 2-4 and produce final output with zero findings.Task tool to spawn the arithmetic-scanner agent. Its prompt must include:DIMENSIONAL_SCOPE.jsonDIMENSIONAL_SCOPE.json with project_root, in_scope_files, discoverer_focus_files, and recommended_discovery_orderstep2: "PENDING", step3: "PENDING", and step4: "PENDING"discoverer_focus_files to CRITICAL/HIGH when more than 50 arithmetic files are found, while keeping all priorities in in_scope_filesDIMENSIONAL_SCOPE.json from disk and confirm it exists and contains the required Step 1 fields before continuing.Task tool to spawn the dimension-discoverer agent. Its prompt must include:DIMENSIONAL_SCOPE.jsonDIMENSIONAL_UNITS.mddiscoverer_focus_files with each file's path, priority, score, and categoryrecommended_discovery_orderDIMENSIONAL_SCOPE.json as the Step 1 source of truth and write DIMENSIONAL_UNITS.md with Base Units, Derived Units, and Precision Prefixes sections. If in_scope_files is empty, it must still write the same headings with empty sections.in_scope_files is empty after the discoverer writes DIMENSIONAL_UNITS.md, skip Steps 2-4 and produce final output with zero findings.The main skill context must not add annotations itself. Use the Task tool to spawn dimension-annotator agents for all anchor-point annotation work. For full examples and annotation format details, see [{baseDir}/references/annotate.md]({baseDir}/references/annotate.md).
DIMENSIONAL_SCOPE.json and build batches from in_scope_files. Every in-scope file, including MEDIUM and LOW priority files, must receive a Step 2 outcome.<= 10 files: one batch11-30 files: one batch per category> 30 files: one batch per category, splitting categories larger than 10 files into sub-batches of about 8 filesstep2 = "PENDING" for every in-scope file and persist the updated DIMENSIONAL_SCOPE.json.DIMENSIONAL_UNITS.mdDIMENSIONAL_SCOPE.jsonANNOTATED, REVIEWED_NO_ANCHOR_CHANGES, or BLOCKED plus a one-line justificationANNOTATEDREVIEWED_NO_ANCHOR_CHANGESBLOCKEDBLOCKED, also persist step2_reason and step2_retry_count. Retry each BLOCKED file once with a focused prompt.PENDING in on-disk manifest state.The main skill context must not perform propagation reasoning itself. Use the Task tool to spawn dimension-propagator agents to extend annotations through arithmetic, function calls, and assignments. For algebra details, see [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md).
DIMENSIONAL_SCOPE.json and build propagation batches from in_scope_files. Every in-scope file must receive a Step 3 outcome.step3 = "PENDING" for every in-scope file and persist the updated manifest.DIMENSIONAL_UNITS.mdDIMENSIONAL_SCOPE.jsonPROPAGATED, REVIEWED_NO_PROPAGATION_CHANGES, or BLOCKED plus a one-line justificationPROPAGATEDREVIEWED_NO_PROPAGATION_CHANGESBLOCKEDBLOCKED, also persist step3_reason and step3_retry_count. Retry each BLOCKED file once with a focused prompt.CERTAIN, INFERRED, UNCERTAIN)PENDING in on-disk manifest state.The main skill context must not perform bug detection itself. Use the Task tool to spawn dimension-validator agents to detect dimensional bugs in annotated code. For examples, red flags, rationalization checks, and standard vocabulary, see [{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md), [{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md), and [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md). DO NOT DETECT BUGS IN ANY OTHER STEP.
DIMENSIONAL_SCOPE.json.in_scope_files.step4 = "PENDING" for every in-scope file and persist the updated manifest.dimension-validator agent per file. For large repos, run them in waves of roughly 10-30 files to keep orchestration stable.DIMENSIONAL_UNITS.mdDIMENSIONAL_SCOPE.jsonVALIDATED or BLOCKEDVALIDATEDBLOCKEDBLOCKED, also persist step4_reason and step4_retry_count. Retry each BLOCKED file once with a focused prompt.DIM-XXX IDscoverage.unprocessed_files.DIMENSIONAL_SCOPE.json.in_scope_files contains no step4: "PENDING" entries.Pass these references to the relevant subagent when a step needs them:
[{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md) - Propagator and validator algebra rules[{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md) - Validator vocabulary reference[{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md) - Validator bug-pattern and red-flag reference[{baseDir}/references/annotate.md]({baseDir}/references/annotate.md) - Annotator format and example referenceAt the end of the analysis, provide a structured summary unless some other output format has been specified:
{
"mode": "full-auto",
"project_root": "<path>",
"vocabulary": {
"base_units": ["..."],
"derived_units": ["..."],
"precision_prefixes": ["..."]
},
"annotations": {
"total_added": 0,
"by_file": {}
},
"findings": {
"critical": 0,
"high": 0,
"medium": 0,
"details": []
},
"uncertainties_resolved": 0,
"coverage": {
"in_scope_files": 0,
"anchor_reviewed_files": "0/0",
"propagation_reviewed_files": "0/0",
"validation_reviewed_files": "0/0",
"annotated_functions": "0/0",
"annotated_variables": "0/0",
"unprocessed_files": [
{
"path": "/path/to/repo/contracts/LegacyMath.sol",
"blocked_step": "step3",
"reason": "Parser could not process generated source",
"retry_count": 1
}
]
}
}You are NOT done until all of these are true:
DIMENSIONAL_UNITS.md exists in the project rootDIMENSIONAL_SCOPE.json exists in the project root and is the source of truth for downstream coverageDIMENSIONAL_SCOPE.json.in_scope_filesPENDING Step 2 status (ANNOTATED, REVIEWED_NO_ANCHOR_CHANGES, or BLOCKED)PENDING Step 3 status (PROPAGATED, REVIEWED_NO_PROPAGATION_CHANGES, or BLOCKED)PENDING Step 4 status (VALIDATED or BLOCKED)PENDING in any stepBLOCKED file has a documented reason in the final outputcoverage.unprocessed_files exactly matches the final set of terminal BLOCKED files after retries, using path, blocked_step, reason, and retry_countDIMENSIONAL_SCOPE.jsonIf DIMENSIONAL_SCOPE.json and the final report disagree, reconcile the report or continue processing until they match.
Do not claim completion from agent intent alone; completion is determined by manifest coverage and final reported statuses.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references, assets) in plugins/dimensional-analysis/skills/dimensional-analysis of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Dimensional Analysis Annotator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dimensional Analysis Annotator this skilltrailofbits/skills | 7.4k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Secure Codingtechygarg/lattice | 198 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Code Review Specialistluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT | |
| Best Practicesmidudev/100cosas.dev | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | |
| Read-Only Code AuditHarnessMD/munder-difflin | 8.5k | — | ~350 | Automated safety check: Notes | MIT | |
| Codebase Review SwarmZaxbyHub/opencode-swarm | 488 | — | ~2.8k | Automated safety check: Pass | MIT |
techygarg/lattice
Apply security-conscious thinking when generating or modifying code.
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
midudev/100cosas.dev
Apply modern web development best practices for security, compatibility, and code quality.
HarnessMD/munder-difflin
Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.
ZaxbyHub/opencode-swarm
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
getsentry/skills
Find bugs, security vulnerabilities, and code quality issues in local branch changes.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
Categories
Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. A controller workflow hands the real work to subagents in a fixed sequence of steps: scanning for arithmetic files, discovering the dimension vocabulary, annotating, propagating annotations and validating for bugs. The main context only routes work, builds prompts, saves state, retries and checks coverage.
Dimensional Analysis Annotator fits situations like: annotating a DeFi or financial codebase with unit and decimal comments; hunting arithmetic bugs from unit mismatches, missing scaling or precision loss; auditing code that mixes decimal precisions or fixed-point arithmetic; performing dimensional analysis on a scientific computation codebase.
Run `npx skills add trailofbits/skills --skill dimensional-analysis -a claude-code`. Or copy the skill folder (plugins/dimensional-analysis/skills/dimensional-analysis in trailofbits/skills) into .claude/skills/dimensional-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill dimensional-analysis -a codex`. Or copy the skill folder (plugins/dimensional-analysis/skills/dimensional-analysis in trailofbits/skills) into .agents/skills/dimensional-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill dimensional-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dimensional-analysis, .gemini/skills/dimensional-analysis, .github/skills/dimensional-analysis and .opencode/skills/dimensional-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Dimensional Analysis Annotator is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Grep, List, Glob, Task, TodoRead, TodoWrite.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dimensional Analysis Annotator is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dimensional Analysis Annotator: Secure Coding (techygarg/lattice, 198 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars), Best Practices (midudev/100cosas.dev, 114 stars) and Read-Only Code Audit (HarnessMD/munder-difflin, 8.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.