Official agent skill

Necessist Audit

by trailofbits in trailofbits/necessist

A skill your agent uses to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let…

OfficialAGPL-3.0Auto-check passed

Install Necessist Audit

skills CLI
$ npx skills add trailofbits/necessist --skill necessist-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/necessist necessist-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/necessist.git skills-src && mkdir -p .claude/skills && cp -r skills-src/core/skills/necessist-audit .claude/skills/necessist-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
necessist-audit
GitHub stars
156
Token cost
~988 tokens
SKILL.md length
511 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let…

  • Works in 5 steps: Inspect the removal and the complete… → Infer the intended behavior from tests,… → Seek supporting or refuting evidence in… → …
  • Audit Necessist results
  • SKILL.md covers Scope, Locate results, Investigate removals and Classify results, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Necessist Audit is an agent skill from trailofbits/necessist, published by the product's own GitHub organization. Use to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let tests pass without checking intended behavior.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A mutation-based tool for finding bugs in tests. The licence is AGPL-3.0.

When your agent uses it

  • Audit Necessist results
  • Running Necessist first if needed
  • Investigate whether passing removals reveal bugs in code
  • Including test-harness bugs that let tests pass without checking intended behavior

Example prompts

  • “/necessist-audit”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the removal and the complete affected test.
  2. Infer the intended behavior from tests, documentation, comments, related tests, and implementation. Determine why the test passes without…
  3. Seek supporting or refuting evidence in the affected test, implementation, callers, and focused non-mutating diagnostics.
  4. Consider benign explanations, including idempotence, duplicate setup, unreachable conditions, equivalent operations, nondeterminism, and…
  5. Before reporting a finding or lead, confirm that its recorded source location and removed text match the current checkout. If they do not…

What it can do on your machine

Read from SKILL.md and the folder at commit e00dca6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Necessist Audit loads about 988 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 511 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~988

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/necessist at commit e00dca6, republished under its AGPL-3.0 licence (© trailofbits). 511 words, ~988 tokens.

Download SKILL.mdSave it as .claude/skills/necessist-audit/SKILL.md (or your agent's skills folder).
name
necessist-audit
description
Use to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let tests pass without checking intended behavior.
metadata.version
4.1.0
metadata.license
AGPL-3.0-only

Audit Necessist results

Use passing removals as leads for finding bugs in the code or tests being audited.

Do not modify project source unless the user explicitly requests changes. Running Necessist and allowing it to create necessist.db is permitted.

Scope

Analyze only removals whose outcome is passed.

  • Do not report failed, timed-out, or nonbuildable removals as findings.
  • Treat tests both as evidence about intended behavior and as possible subjects of findings.
  • Report defects in project-owned code, tests, test helpers, fixtures, mocks, and test configuration.
  • In tests, look for harness bugs such as missing synchronization, ineffective assertions, swallowed errors, unchecked setup, and mocks or timing assumptions that stop exercising intended behavior.
  • Do not report defects confined to generated code, vendored code, or third-party dependencies.

Locate results

Use the directory specified by the user; otherwise use the current working directory. The active editor file does not limit scope. Audit every passing removal in that directory’s database unless the user explicitly limits the scope.

Look for necessist.db in that directory. If it does not exist, run necessist there and use the resulting database. If Necessist is unavailable or the run fails, report the error and ask the user how to proceed.

Read passing removals with necessist --dump. Use read-only SQLite queries only if needed.

Investigate removals

For each passing removal:

  1. Inspect the removal and the complete affected test.
  2. Infer the intended behavior from tests, documentation, comments, related tests, and implementation. Determine why the test passes without the removed operation, and form a concrete bug hypothesis when the removal appears meaningful.
  3. Seek supporting or refuting evidence in the affected test, implementation, callers, and focused non-mutating diagnostics.
  4. Consider benign explanations, including idempotence, duplicate setup, unreachable conditions, equivalent operations, nondeterminism, and persistent state. Do not treat a single rerun as proof that a flaky result is stable.
  5. Before reporting a finding or lead, confirm that its recorded source location and removed text match the current checkout. If they do not, mark the result as stale and recommend rerunning Necessist. Otherwise, cite repository-relative locations and the evidence supporting the conclusion.

Do not infer that a passing removal is a bug merely because Necessist reports it.

Show full SKILL.md (148 more words)Show less

Classify results

Classify a result as a finding only when all of the following are established:

  • a specific intended contract, invariant, or behavior and its source;
  • the affected code or test location and the mechanism that violates it;
  • evidence connecting the Necessist removal to the behavior; and
  • consideration and rejection of reasonable benign explanations.

If any required element is missing, classify the result as a lead and state what evidence is missing. When uncertain, classify the result as a lead.

Report

Order findings by likely impact. For each finding, report:

  • removed code and source location;
  • affected code or test location;
  • intended behavior and its source;
  • why the test still passes;
  • potential impact;
  • supporting evidence;
  • suggested fix.

List leads separately. End with counts of passing removals examined, findings, results for which no bug was established, and stale results.

Use concise Markdown. Do not implement recommendations unless the user asks.

© trailofbits, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in core/skills/necessist-audit of trailofbits/necessist.

Open the folder on GitHubat commit e00dca6

Compare with similar skills

Necessist Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Necessist Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Necessist Audit this skilltrailofbits/necessist156—~988Automated safety check: PassAGPL-3.0
Root Cause Investigationgarrytan/gstack136k—~12kAutomated safety check: NotesMIT
Investigate CIClickHouse/ClickHouse50k—~11kAutomated safety check: NotesApache-2.0
What Context Neededgithub/awesome-copilot40k1 repos~219Automated safety check: PassMIT
Investigate Issuevideojs/video.js40k—~318Automated safety check: PassCustom licence
Investigating ReplayPostHog/posthog40k—~2.5kAutomated safety check: PassCustom licence

Similar skills

  • Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.

    136k GitHub stars~12k tokensUpdated today
    DevelopmentAuto-check: notes
  • Investigate CI

    ClickHouse/ClickHouse

    Investigate a ClickHouse CI failure end-to-end from a PR or S3 report URL.

    50k GitHub stars~11k tokensUpdated today
    DatabasesAuto-check: notes
  • What Context Needed

    github/awesome-copilot

    Official

    Ask Copilot what files it needs to see before answering a question

    40k GitHub starsUsed in 1 repo~219 tokens
    Auto-check passed
  • Investigate Issue

    videojs/video.js

    Investigate GitHub issues without changing code. An agent skill from videojs/video.js.

    40k GitHub stars~318 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Investigating Replay

    PostHog/posthog

    Official

    Investigates a session recording by gathering metadata, person profile, same-session events, and linked error tracking issues in one pass.

    40k GitHub stars~2.5k tokensUpdated today
    DatabasesAuto-check passed
  • Investigating Logs

    PostHog/posthog

    Official

    Investigate logs in a PostHog project: verify a service or deployment is healthy, explain an error spike, triage an incident, or understand what a log stream is saying.

    40k GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed

Questions about Necessist Audit

What does Necessist Audit do?

A skill your agent uses to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let…. Necessist Audit is an agent skill from trailofbits/necessist, published by the product's own GitHub organization. Use to audit Necessist results, running Necessist first if needed, and investigate whether passing removals reveal bugs in code or tests, including test-harness bugs that let tests pass without checking intended behavior.

When should I use Necessist Audit?

Necessist Audit fits situations like: audit Necessist results; running Necessist first if needed; investigate whether passing removals reveal bugs in code; including test-harness bugs that let tests pass without checking intended behavior.

How do I install Necessist Audit in Claude Code?

Run `npx skills add trailofbits/necessist --skill necessist-audit -a claude-code`. Or copy the skill folder (core/skills/necessist-audit in trailofbits/necessist) into .claude/skills/necessist-audit in your project. Claude Code loads it when a task matches its description.

How do I install Necessist Audit in Codex?

Run `npx skills add trailofbits/necessist --skill necessist-audit -a codex`. Or copy the skill folder (core/skills/necessist-audit in trailofbits/necessist) into .agents/skills/necessist-audit in your project. Codex loads it when a task matches its description.

Can I use Necessist Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/necessist --skill necessist-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/necessist-audit, .gemini/skills/necessist-audit, .github/skills/necessist-audit and .opencode/skills/necessist-audit in your project.

What does Necessist Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Necessist Audit is instructions for the agent only.

Does Necessist Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Necessist Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Necessist Audit use?

Necessist Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Necessist Audit use?

About 988 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Necessist Audit?

Skills that share tags, products or a category with Necessist Audit: Root Cause Investigation (garrytan/gstack, 136k stars), Investigate CI (ClickHouse/ClickHouse, 50k stars), What Context Needed (github/awesome-copilot, 40k stars) and Investigate Issue (videojs/video.js, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Necessist Audit?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/necessist, which has 156 GitHub stars. The repository was last updated on October 8, 2026.

Source: trailofbits/necessist on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.