Explain Tests
meain/dotfiles
Explain test code changes as a side-by-side HTML page — real test code on the left, a short note on the right saying which case that code covers.
Generates an interactive HTML walkthrough for reviewing code changes.
$ npx skills add trailofbits/skills --skill review-walkthrough -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills review-walkthrough --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .claude/skills/review-walkthrough && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .claude/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthroughType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill review-walkthrough -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills review-walkthrough --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .agents/skills/review-walkthrough && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .agents/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill review-walkthrough -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills review-walkthrough --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .cursor/skills/review-walkthrough && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .cursor/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/review-walkthrough/skills/review-walkthrough--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill review-walkthrough -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills review-walkthrough --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .gemini/skills/review-walkthrough && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .gemini/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills review-walkthroughInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill review-walkthrough -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .github/skills/review-walkthrough && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .github/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill review-walkthrough -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills review-walkthrough --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/review-walkthrough/skills/review-walkthrough .opencode/skills/review-walkthrough && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-walkthrough" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/review-walkthrough/skills/review-walkthrough into .opencode/skills/review-walkthrough/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-walkthrough", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-walkthroughGenerates an interactive HTML walkthrough for reviewing code changes.
Review Walkthrough is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `agents/openai.yaml` and `scripts/render_walkthrough.py`).
It sits in Frontend & Design, covering HTML artifacts. It works with Git. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gituvghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, uv and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Walkthrough loads about 1.7k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 968 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 968 words, ~1,687 tokens.
.claude/skills/review-walkthrough/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Generate a self-contained HTML walkthrough of the current branch, with the final
diff split into logical steps, explanations, and critical review findings. Choose
the grouping and reading order for comprehension; commit order need not dictate
either. Invoke as /review-walkthrough:review-walkthrough in Claude Code or
$review-walkthrough in Codex.
Respect a user-specified base. Otherwise, use the current open PR's base when PR
metadata is available. Without a PR, discover the repository's default branch
from git symbolic-ref --quiet --short refs/remotes/origin/HEAD or the configured
remote's equivalent. Do not assume it is main. If the selected base is missing
or ambiguous, ask for it rather than silently choosing another branch.
Resolve the base and HEAD to commit IDs with
git rev-parse --verify --end-of-options "${ref}^{commit}", then compute their
merge base with git merge-base. Capture the complete patch using
git diff --no-ext-diff --no-textconv --no-color --src-prefix=a/ --dst-prefix=b/ "$merge_base" "$head_sha" --.
Initialize variables and run the commands that consume them in the same shell
invocation; shell variables do not persist between tool calls. Save the patch to
a temporary file outside the checkout and retain its actual path. Stop on a Git
error or an empty patch and explain the result.
This scope includes committed changes through the captured HEAD. Mention any
uncommitted work that is excluded. Do not change branches, reset the checkout,
or alter source files to prepare the review. Keep generated data and HTML outside
the checkout unless the user requests a particular output location; generated
review artifacts never belong in the captured patch.
For a GitHub PR, collect owner, repo, pr_number, and head_sha from its
metadata. Include them only when the PR head matches the captured HEAD and the
chosen base matches the PR base. Otherwise use null and explain why comment
export is unavailable. A failed authentication or network request is not evidence
that no PR exists; report the failure and ask for the base if it cannot be
determined. GitHub access is optional when the user supplies the base or confirms
there is no PR.
Read the changed files and the surrounding source, tests, configuration, and dependency metadata needed to judge them. Keep the review read-only; do not run the project's tests or install its dependencies merely to build the walkthrough.
Group related files into steps covering one concept each. Put definitions before their consumers, wiring after the components it connects, and tests after or beside their subjects. Copy each complete per-file diff from the captured patch verbatim into exactly one step. Reordering files between steps is allowed; splitting, rewriting, omitting, or inventing their patches is not. Preserve rename, binary, and mode-change entries even when they have no text hunks. Binary summaries identify changed files; their payloads are outside this review.
Write one explanation per step, usually 50–150 words, covering the change's purpose, design choices, trade-offs, and connections to other steps. Refer to actual identifiers. Write one review list per step covering bugs, security, validation, API design, or performance issues supported by the code. Report findings with severity rather than suppressing minor issues. Use an empty list for a step with no findings.
Explanations and review bodies are HTML fragments. Use <p>, <strong>, <em>,
<code>, <pre>, and <ul>/<li> for structure. Write literal < and > in
prose or snippets as < and >. Backticks and Markdown fences are literal
text here. Supported inline tags also include <sup>, <sub>, <kbd>, <del>,
and <a href="https://…">. The page sanitizes fragments and converts them to
Markdown when preparing a PR comment. Only safe link targets survive; arbitrary
attributes, scripts, and images do not. Tables export as text rows with cell
separators; captions and row order are preserved. Prefer prose, lists, and code
blocks when their structure is sufficient.
Anchor findings to a file in the same step and a line in that file's displayed
diff. Use side: "RIGHT" for additions or new-file context and side: "LEFT"
for deletions or old-file context. For a range, line and end_line use that
same side within one hunk. A finding spanning multiple steps belongs with the
file it addresses, or remains unanchored. An unanchored finding is still
displayed but cannot become an inline PR comment.
Use a file-writing tool to create a JSON object with the fields below. Preserve the literal patch as JSON string data, with no shell expansion.
| Field | Value |
|---|---|
title | Feature or review title |
steps | Array of objects with sha (step ID such as step-1), message (step title), files (paths in patch order), and diff (complete per-file patches) |
explanations | HTML strings, one per step |
reviews | Arrays of findings, one per step; each finding has severity (high, medium, or low), title, and HTML body |
pr_meta | Object with owner, repo, pr_number, and head_sha, or null |
An anchored finding also has file, line, and side, plus optional end_line.
The three arrays have equal lengths and corresponding entries. File paths match
the diff headers without their a/ or b/ prefix; a renamed file uses its new
path. Set side explicitly so lines that occur on both sides are unambiguous.
Run the bundled renderer with the actual paths created for this review:
uv run --no-project {baseDir}/scripts/render_walkthrough.py \
--input /tmp/data.json \
--diff /tmp/captured.patch \
--output /tmp/walkthrough.htmlThe renderer validates the data, compares every step's patches with the complete captured diff, checks anchors, and safely embeds the result in the bundled template. Fix reported input errors rather than bypassing the renderer or generating an alternative page.
Open the output with open on macOS or xdg-open on Linux when a browser is
available, and tell the user its path. In a headless run, report the file without
opening it. When PR metadata is present, the page lets the user copy a gh api
command for their selected comments. It does not execute the command or post
anything to GitHub. Comment and Request Changes require a review summary before
the command can be copied; the summary is optional for Approve.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in plugins/review-walkthrough/skills/review-walkthrough of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Review Walkthrough next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Walkthrough this skilltrailofbits/skills | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Explain Testsmeain/dotfiles | 285 | — | ~1.5k | Automated safety check: Pass | MIT | |
| LobeHub Interactive Prototypelobehub/lobehub | 83k | — | ~1.6k | Automated safety check: Pass | Custom licence | |
| Paperclip Pagepaperclipai/paperclip | 99k | — | ~1k | Automated safety check: Pass | MIT | |
| Openkb Deck NeonVectifyAI/OpenKB | 4.7k | 1 repos | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Webhome Homepage Builderwebhtv/webhtv | 1.7k | — | ~3.8k | Automated safety check: Pass | GPL-3.0 |
meain/dotfiles
Explain test code changes as a side-by-side HTML page — real test code on the left, a short note on the right saying which case that code covers.
lobehub/lobehub
Builds single-file interactive HTML prototypes rendered with the real LobeHub UI components and written as production-style React, so they can later be split into files.
paperclipai/paperclip
Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.
VectifyAI/OpenKB
A skill your agent uses when the user asks the openkb chat to make a deck / slide presentation / PPT / slides / 演示稿 / 幻灯片 from their compiled KB content AND wants a dark, high-tech, neon / glow /…
webhtv/webhtv
Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML.
solo-agent/solo
A skill your agent uses when a Solo task or thread should become an interactive, reviewable, self-contained HTML artifact for progress/status, review/decision, or comparison/leaderboard work inside…
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Works with
Categories
Generates an interactive HTML walkthrough for reviewing code changes. Review Walkthrough is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Generates an interactive HTML walkthrough for reviewing code changes.
Review Walkthrough fits situations like: tasks that involve HTML artifacts.
Run `npx skills add trailofbits/skills --skill review-walkthrough -a claude-code`. Or copy the skill folder (plugins/review-walkthrough/skills/review-walkthrough in trailofbits/skills) into .claude/skills/review-walkthrough in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill review-walkthrough -a codex`. Or copy the skill folder (plugins/review-walkthrough/skills/review-walkthrough in trailofbits/skills) into .agents/skills/review-walkthrough in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill review-walkthrough -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-walkthrough, .gemini/skills/review-walkthrough, .github/skills/review-walkthrough and .opencode/skills/review-walkthrough in your project.
Going by SKILL.md and its folder, Review Walkthrough needs Python for the scripts in its folder and the command-line tools its instructions call (git, uv and gh). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, uv and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Review Walkthrough is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Walkthrough: Explain Tests (meain/dotfiles, 285 stars), LobeHub Interactive Prototype (lobehub/lobehub, 83k stars), Paperclip Page (paperclipai/paperclip, 99k stars) and Openkb Deck Neon (VectifyAI/OpenKB, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.