Official agent skill

Trailmark Graph Evolution

by trailofbits in trailofbits/skills

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Trailmark Graph Evolution

skills CLI
$ npx skills add trailofbits/skills --skill graph-evolution -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills graph-evolution --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trailmark/skills/graph-evolution .claude/skills/graph-evolution && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
graph-evolution
GitHub stars
7.4k
Token cost
~3.4k tokens
SKILL.md length
1,286 words
Files
6 (incl. scripts, references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

  • Works in 5 steps: Create Snapshots → Build Graphs and Run Pre-Analysis → Compute Structural Diff → …
  • Comparing two git refs to see what changed structurally
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations to Reject and Prerequisites, plus 7 more sections
  • Runs Python scripts from its folder; calls uv and git

What it does

Two snapshots of a codebase (git commits, tags or plain directories) are each turned into a Trailmark code graph, and the skill computes a structural diff between them. The result flags new attack paths, complexity shifts, blast radius growth, taint propagation changes and privilege boundary modifications, the kinds of change a line-by-line diff does not show.

A table of rejected shortcuts keeps the analysis honest: run pre-analysis on both snapshots, use the structural diff alongside the text diff, review removals as well as additions, classify every change including low-severity ones, build both graphs, and install the tool rather than compare by hand. One warning is explicit: `trailmark diff` assumes Python unless told otherwise and returns an empty result for other languages, so `--language` must always be passed. Line-level review, single-snapshot analysis, diagrams and mutation testing triage belong to other skills.

When your agent uses it

  • Comparing two git refs to see what changed structurally
  • Auditing a range of commits for security-relevant evolution
  • Doing a structural comparison between two release tags before shipping
  • Finding functions whose blast radius or complexity grew without notice

Example prompts

  • “Compare the code graphs at the last two release tags and list any new attack paths.”
  • “Audit the commits between the audit snapshot and main for taint propagation changes.”
  • “Check whether the refactor on this branch grew the blast radius of any authentication functions.”

Requirements

  • The Trailmark tool
  • Python, for `scripts/graph_diff.py`

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create Snapshots
  2. Build Graphs and Run Pre-Analysis
  3. Compute Structural Diff
  4. Interpret Diff and Generate Report
  5. Clean Up

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trailmark Graph Evolution loads about 3.4k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 1,286 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,286 words, ~3,360 tokens.

Download SKILL.mdSave it as .claude/skills/graph-evolution/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
graph-evolution
description
Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes. Detects new attack paths, complexity shifts, blast radius growth, taint propagation changes, and privilege boundary modifications that text diffs miss. Use when comparing code between commits or tags, analyzing structural evolution, detecting attack surface growth, reviewing what changed between audit snapshots, or finding security-relevant changes that text diffs miss.

Graph Evolution

Builds Trailmark code graphs at two source snapshots and computes a structural diff. Surfaces security-relevant changes that text-level diffs miss: new attack paths, complexity shifts, blast radius growth, taint propagation changes, and privilege boundary modifications.

When to Use

  • Comparing two git refs to understand what structurally changed
  • Auditing a range of commits for security-relevant evolution
  • Detecting new attack paths created by code changes
  • Finding functions whose blast radius or complexity grew silently
  • Identifying taint propagation changes across refactors
  • Pre-release structural comparison (tag-to-tag or branch-to-branch)

When NOT to Use

  • Line-level code review (use differential-review for text-diff analysis)
  • Single-snapshot analysis (use the trailmark skill directly)
  • Diagram generation from a single snapshot (use the diagramming-code skill)
  • Mutation testing triage (use the genotoxic skill)

Rationalizations to Reject

RationalizationWhy It's WrongRequired Action
"We just need the structural diff, skip pre-analysis"Without pre-analysis, you miss taint changes, blast radius growth, and privilege boundary shiftsRun engine.preanalysis() on both snapshots
"Text diff covers what changed"Text diffs miss new attack paths, transitive complexity shifts, and subgraph membership changesUse structural diff to complement text diff
"Only added nodes matter"Removed security functions and shifted privilege boundaries are equally dangerousReview removals and modifications, not just additions
"Low-severity structural changes can be ignored"INFO-level changes (dead code removal) can mask removed security checksClassify every change, review removals for replaced functionality
"One snapshot's graph is enough for comparison"Single-snapshot analysis can't detect evolution — you need both before and afterAlways build and export both graphs
"Tool isn't installed, I'll compare manually"Manual comparison misses what graph analysis catchesInstall trailmark first
"The diff came back empty, so nothing changed structurally"trailmark diff defaults --language to python and exits 0 with empty arrays on any other target, so an empty diff reads identically whether the code is unchanged or the language was wrongPass --language explicitly and re-run before concluding no change

Prerequisites

trailmark must be installed. If uv run trailmark fails, run:

bash
uv tool install trailmark
# Python snippets: uv run --with trailmark python -   (a tool env is not importable)

DO NOT fall back to "manual comparison" or reading source files as a substitute for running trailmark. The tool must be installed and used programmatically. If installation fails, report the error.


Quick Start

bash
# Compare two git refs (e.g., tags, branches, commits)
# 1. Build graphs at each snapshot
# 2. Run pre-analysis on both
# 3. Compute structural diff
# 4. Generate report

# Step-by-step: see Workflow below

Decision Tree

├─ Need to understand what each metric means?
│  └─ Read: references/evolution-metrics.md
│
├─ Need the report output format?
│  └─ Read: references/report-format.md
│
├─ Already have two graph JSON exports?
│  └─ Jump to Phase 3 (run native diff + graph_diff.py)
│
└─ Starting from two git refs?
   └─ Start at Phase 1

Workflow

Graph Evolution Progress:
- [ ] Phase 1: Create snapshots (git worktrees)
- [ ] Phase 2: Build graphs + pre-analysis on both snapshots
- [ ] Phase 3: Compute structural diff
- [ ] Phase 4: Interpret diff and generate report
- [ ] Phase 5: Clean up worktrees
Phase 1: Create Snapshots

Use git worktrees to get clean copies of each ref without disturbing the working tree.

bash
# Create temp directories for worktrees
BEFORE_DIR=$(mktemp -d)
AFTER_DIR=$(mktemp -d)

# Create worktrees (run from repo root)
git worktree add "$BEFORE_DIR" {before_ref}
git worktree add "$AFTER_DIR" {after_ref}

If comparing two directories instead of git refs, skip this phase and use the directory paths directly in Phase 2.

Phase 2: Build Graphs and Run Pre-Analysis

Build Trailmark graphs for both snapshots and run pre-analysis on each. Pre-analysis computes blast radius, taint propagation, privilege boundaries, and entrypoint enumeration.

python
from trailmark.query.api import QueryEngine

def build_and_export(target_dir, output_path, language="auto"):
    """Build graph, run pre-analysis, export JSON."""
    engine = QueryEngine.from_directory(target_dir, language=language)
    engine.preanalysis()
    json_str = engine.to_json()
    with open(output_path, "w") as f:
        f.write(json_str)
    return engine.summary()

import tempfile, os
work_dir = tempfile.mkdtemp(prefix="trailmark_evolution_")
before_json = os.path.join(work_dir, "before_graph.json")
after_json = os.path.join(work_dir, "after_graph.json")

before_summary = build_and_export(
    "{before_dir}", before_json
)
after_summary = build_and_export(
    "{after_dir}", after_json
)

Verify both graphs built successfully by checking the summary output. If either fails, rerun with an explicit language or comma-separated list instead of auto.

Phase 3: Compute Structural Diff

Run both:

  1. Trailmark's native structural diff for nodes, edges, and entrypoints
  2. The plugin's graph_diff.py helper for subgraph membership changes

Use the same work_dir from Phase 2, and pass the same --language value Phase 2 built with. trailmark diff defaults that flag to python, so on any other target the default exits 0 and writes empty arrays rather than reporting a mismatch.

bash
trailmark diff --json --language auto "{before_dir}" "{after_dir}" > "{work_dir}/trailmark_diff.json" || \
  uv run trailmark diff --json --language auto "{before_dir}" "{after_dir}" > "{work_dir}/trailmark_diff.json"

uv run {baseDir}/scripts/graph_diff.py \
    --before "{before_json}" \
    --after "{after_json}" > "{work_dir}/subgraph_diff.json"

If Phase 2 needed an explicit language or a comma-separated list instead of auto, use that same value here.

If either diff command fails or writes an empty JSON file, stop and report the error instead of continuing to Phase 4.

A trailmark_diff.json whose nodes, edges, and entrypoints arrays are all empty means either nothing changed structurally or both snapshots parsed to (near-)empty graphs. Decide which using Phase 2's graph summaries: if either snapshot's node count is zero or implausibly small for the target, the parse missed the code — name the language set explicitly (rust, solidity, python,rust) and re-run. Healthy node counts on both snapshots plus an empty diff is genuine structural stability.

The native Trailmark diff contains:

KeyContents
summary_deltaChanges in node/edge/entrypoint counts
nodes.addedNew functions, classes, methods
nodes.removedDeleted functions, classes, methods
nodes.modifiedFunctions with changed CC, params, line span
edges.addedNew call/inheritance/import relationships
edges.removedDeleted relationships
entrypointsAdded, removed, and modified entrypoints

The subgraph diff contains:

KeyContents
subgraphsPer-subgraph membership changes (tainted, high_blast_radius, etc.)
Show full SKILL.md (593 more words)Show less
Phase 4: Interpret Diff and Generate Report

Read both diff JSON files and generate a security-focused markdown report. See references/report-format.md for the full template.

Interpretation priorities (highest to lowest):

  1. New tainted paths — nodes entering the tainted subgraph, especially if they also appear in added edges targeting sensitive functions
  2. Privilege boundary changes — new or removed trust transitions from the native entrypoint/edge diff plus the subgraph diff
  3. Attack surface growth — new entrypoints, especially untrusted_external, from trailmark_diff.json
  4. Blast radius increases — nodes entering high_blast_radius
  5. Complexity spikes — CC increases > 3 on tainted or entrypoint-reachable nodes
  6. Structural additions — new nodes and edges (review needed)
  7. Structural removals — verify removed security functions were replaced

Cross-reference structural changes with git diff {before_ref}..{after_ref} to add source-level context to findings.

Severity classification:

SeverityStructural Signal
CRITICALNew tainted path to sensitive function, removed auth boundary
HIGHNew entrypoint + high blast radius, large CC increase on tainted node
MEDIUMNew trust-boundary-crossing edges, moderate CC increase
LOWAdded nodes without entrypoint reachability
INFODead code removal, complexity reductions

For detailed metric definitions, see references/evolution-metrics.md.

Phase 5: Clean Up

Remove git worktrees after the report is written:

bash
git worktree remove "{before_dir}"
git worktree remove "{after_dir}"

Diff Reference

trailmark diff --json --language auto BEFORE AFTER
uv run {baseDir}/scripts/graph_diff.py [OPTIONS]

trailmark diff --language defaults to python. On a target in any other language that default still exits 0, emitting well-formed JSON with empty nodes, edges, and entrypoints arrays, so always pass the flag: auto detects and merges every supported language found under the target, and a single name (rust, solidity) or comma-separated list (python,rust) pins an explicit set. auto fails loudly with No supported languages detected under <path> when a snapshot holds nothing it can parse, which is the outcome you want. Confirm the language first; only then can an empty diff count as evidence that nothing changed.

Use trailmark diff for:

  • Node/edge changes
  • Added/removed/modified entrypoints
  • Human-readable structural diff reports

Use graph_diff.py for:

  • Subgraph membership changes derived from engine.preanalysis()
  • tainted, high_blast_radius, privilege_boundary, and related sets
ArgumentDefaultDescription
--beforerequiredPath to the "before" graph JSON
--afterrequiredPath to the "after" graph JSON
--indent2JSON output indentation

graph_diff.py input format: Trailmark JSON exports from engine.to_json(). graph_diff.py output: JSON structural diff for nodes, edges, and subgraphs.


Quality Checklist

Before delivering the report:

  • Both graphs built successfully (check summaries)
  • Pre-analysis ran on both snapshots
  • Native Trailmark diff computed (trailmark_diff.json); if it is empty, both snapshots' Phase 2 node counts were non-zero, so empty means stable
  • Subgraph diff computed and non-empty (subgraph_diff.json)
  • All subgraph changes interpreted (tainted, blast radius, etc.)
  • Critical findings include evidence (node IDs, edge diffs)
  • Severity levels assigned to all findings
  • Source-level context added via git diff cross-reference
  • Worktrees cleaned up (or temp dirs removed)
  • Report written to GRAPH_EVOLUTION_*.md

Integration

trailmark skill: Phase 2 uses the trailmark API for graph building and pre-analysis. All trailmark query patterns work on either snapshot's engine.

differential-review skill: Use graph-evolution for structural analysis, differential-review for line-level code review. The two are complementary — graph-evolution finds attack paths that text diffs miss, while differential-review provides git blame context and micro-adversarial analysis.

trailmark-review-gate skill: Use trailmark-review-gate after graph-evolution when a branch, pull request, fix commit, or release diff needs a PASS/WARN/FAIL/UNKNOWN structural review packet. The gate applies deterministic review rules to graph-evolution output; it does not replace human review.

genotoxic skill: If graph-evolution reveals new high-CC tainted nodes, feed them to genotoxic for mutation testing triage.

diagramming-code skill: Generate before/after diagrams to visualize structural changes. Use call-graph or data-flow diagrams focused on changed nodes.


Supporting Documentation

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in plugins/trailmark/skills/graph-evolution of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/evolution-metrics.md
  • references/report-format.md
  • scripts/graph_diff.py

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Trailmark Graph Evolution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trailmark Graph Evolution compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trailmark Graph Evolution this skilltrailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Openqodexopenqodex/openqodex303—~1.9kAutomated safety check: PassApache-2.0
Remediating With AWS Security Agentaws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0
Codexqa Rootcause Analyzeropenqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.0
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence

Similar skills

  • Openqodex

    openqodex/openqodex

    Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

    303 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Remediating With AWS Security Agent

    aws/agent-toolkit-for-aws

    Official

    Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

    2.8k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

    152 GitHub stars~2.6k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • Code Context Slicing

    trailofbits/skills

    Official

    Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.

    7.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Trailmark Graph Evolution

What does Trailmark Graph Evolution do?

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. Two snapshots of a codebase (git commits, tags or plain directories) are each turned into a Trailmark code graph, and the skill computes a structural diff between them. The result flags new attack paths, complexity shifts, blast radius growth, taint propagation changes and privilege boundary modifications, the kinds of change a line-by-line diff does not show.

When should I use Trailmark Graph Evolution?

Trailmark Graph Evolution fits situations like: comparing two git refs to see what changed structurally; auditing a range of commits for security-relevant evolution; doing a structural comparison between two release tags before shipping; finding functions whose blast radius or complexity grew without notice.

How do I install Trailmark Graph Evolution in Claude Code?

Run `npx skills add trailofbits/skills --skill graph-evolution -a claude-code`. Or copy the skill folder (plugins/trailmark/skills/graph-evolution in trailofbits/skills) into .claude/skills/graph-evolution in your project. Claude Code loads it when a task matches its description.

How do I install Trailmark Graph Evolution in Codex?

Run `npx skills add trailofbits/skills --skill graph-evolution -a codex`. Or copy the skill folder (plugins/trailmark/skills/graph-evolution in trailofbits/skills) into .agents/skills/graph-evolution in your project. Codex loads it when a task matches its description.

Can I use Trailmark Graph Evolution in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill graph-evolution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/graph-evolution, .gemini/skills/graph-evolution, .github/skills/graph-evolution and .opencode/skills/graph-evolution in your project.

What does Trailmark Graph Evolution need to run?

Going by SKILL.md and its folder, Trailmark Graph Evolution needs Python for the scripts in its folder and the command-line tools its instructions call (uv and git). Our summary lists: The Trailmark tool; Python, for `scripts/graph_diff.py`.

Does Trailmark Graph Evolution access the network?

SKILL.md contains no URLs. Its commands use uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Trailmark Graph Evolution safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Trailmark Graph Evolution use?

Trailmark Graph Evolution is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trailmark Graph Evolution use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Trailmark Graph Evolution?

Skills that share tags, products or a category with Trailmark Graph Evolution: Openqodex (openqodex/openqodex, 303 stars), Remediating With AWS Security Agent (aws/agent-toolkit-for-aws, 2.8k stars), Skeptic (RaoFoundation/subtensor, 389 stars) and Codexqa Rootcause Analyzer (openqa-cn/codexqa, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trailmark Graph Evolution?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.