Official agent skill

Sharp Edges Analysis

by trailofbits in trailofbits/skills

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Sharp Edges Analysis

skills CLI
$ npx skills add trailofbits/skills --skill sharp-edges -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills sharp-edges --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/sharp-edges/skills/sharp-edges .claude/skills/sharp-edges && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sharp-edges
GitHub stars
7.4k
Used in
3 other repos
Token cost
~3k tokens
SKILL.md length
1,009 words
Files
19 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

  • Works in 10 steps: Algorithm/Mode Selection Footguns → Dangerous Defaults → Primitive vs. Semantic APIs → …
  • Reviewing a library or API design for easy-to-misuse options
  • SKILL.md covers When to Use, When NOT to Use, Agent and Core Principle, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Built on the pit-of-success idea that secure use should be the path of least resistance, the skill checks whether an API, configuration format or cryptographic interface can be misused by an ordinary developer under deadline pressure. A dedicated sharp-edges-analyzer agent can run the whole workflow on its own: identify the surface, probe edge cases, model threats, then validate findings.

Sharp edge categories start with algorithm and mode selection, where letting callers choose invites wrong choices, with a JWT header that accepts an alg of none as the canonical case. Reference notes cover authentication patterns, configuration patterns, cryptographic APIs, case studies and per-language guides for C, C#, Go, Java, JavaScript, Kotlin, PHP, Python, Ruby, Rust and Swift, loaded on demand. Implementation bugs, business logic flaws and performance work are out of scope.

When your agent uses it

  • Reviewing a library or API design for easy-to-misuse options
  • Auditing a configuration schema for dangerous settings
  • Evaluating the ergonomics of a cryptographic API
  • Assessing whether authentication or authorization interfaces are secure by default

Example prompts

  • “Review the public API of our token library for footguns.”
  • “Does config/settings.schema.json allow any dangerous option combinations?”
  • “Is our encryption helper secure by default, or does it depend on developers reading the docs?”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Algorithm/Mode Selection Footguns
  2. Dangerous Defaults
  3. Primitive vs. Semantic APIs
  4. Configuration Cliffs
  5. Silent Failures
  6. Stringly-Typed Security
  7. Surface Identification
  8. Edge Case Probing
  9. Threat Modeling
  10. Validate Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are php, python, go and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sharp Edges Analysis loads about 3k tokens when it runs, and up to ~32k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 1,009 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~32k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,009 words, ~2,953 tokens.

Download SKILL.mdSave it as .claude/skills/sharp-edges/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
sharp-edges
description
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.
allowed-tools
Read, Grep, Glob

Sharp Edges Analysis

Evaluates whether APIs, configurations, and interfaces are resistant to developer misuse. Identifies designs where the "easy path" leads to insecurity.

When to Use

  • Reviewing API or library design decisions
  • Auditing configuration schemas for dangerous options
  • Evaluating cryptographic API ergonomics
  • Assessing authentication/authorization interfaces
  • Reviewing any code that exposes security-relevant choices to developers

When NOT to Use

  • Implementation bugs (use standard code review)
  • Business logic flaws (use domain-specific analysis)
  • Performance optimization (different concern)

Agent

The sharp-edges-analyzer agent runs the full sharp edges analysis workflow autonomously. Use it when you want a dedicated analysis of APIs, configurations, or interfaces for misuse resistance and footgun potential. The agent follows the four-phase workflow (Surface Identification, Edge Case Probing, Threat Modeling, Validate Findings) and reads language-specific references on demand.

Core Principle

The pit of success: Secure usage should be the path of least resistance. If developers must understand cryptography, read documentation carefully, or remember special rules to avoid vulnerabilities, the API has failed.

Rationalizations to Reject

RationalizationWhy It's WrongRequired Action
"It's documented"Developers don't read docs under deadline pressureMake the secure choice the default or only option
"Advanced users need flexibility"Flexibility creates footguns; most "advanced" usage is copy-pasteProvide safe high-level APIs; hide primitives
"It's the developer's responsibility"Blame-shifting; you designed the footgunRemove the footgun or make it impossible to misuse
"Nobody would actually do that"Developers do everything imaginable under pressureAssume maximum developer confusion
"It's just a configuration option"Config is code; wrong configs ship to productionValidate configs; reject dangerous combinations
"We need backwards compatibility"Insecure defaults can't be grandfather-clausedDeprecate loudly; force migration

Sharp Edge Categories

1. Algorithm/Mode Selection Footguns

APIs that let developers choose algorithms invite choosing wrong ones.

The JWT Pattern (canonical example):

  • Header specifies algorithm: attacker can set "alg": "none" to bypass signatures
  • Algorithm confusion: RSA public key used as HMAC secret when switching RS256→HS256
  • Root cause: Letting untrusted input control security-critical decisions

Detection patterns:

  • Function parameters like algorithm, mode, cipher, hash_type
  • Enums/strings selecting cryptographic primitives
  • Configuration options for security mechanisms

Example - PHP password_hash allowing weak algorithms:

php
// DANGEROUS: allows crc32, md5, sha1
password_hash($password, PASSWORD_DEFAULT); // Good - no choice
hash($algorithm, $password); // BAD: accepts "crc32"
2. Dangerous Defaults

Defaults that are insecure, or zero/empty values that disable security.

The OTP Lifetime Pattern:

python
# What happens when lifetime=0?
def verify_otp(code, lifetime=300):  # 300 seconds default
    if lifetime == 0:
        return True  # OOPS: 0 means "accept all"?
        # Or does it mean "expired immediately"?

Detection patterns:

  • Timeouts/lifetimes that accept 0 (infinite? immediate expiry?)
  • Empty strings that bypass checks
  • Null values that skip validation
  • Boolean defaults that disable security features
  • Negative values with undefined semantics

Questions to ask:

  • What happens with timeout=0? max_attempts=0? key=""?
  • Is the default the most secure option?
  • Can any default value disable security entirely?
3. Primitive vs. Semantic APIs

APIs that expose raw bytes instead of meaningful types invite type confusion.

The Libsodium vs. Halite Pattern:

php
// Libsodium (primitives): bytes are bytes
sodium_crypto_box($message, $nonce, $keypair);
// Easy to: swap nonce/keypair, reuse nonces, use wrong key type

// Halite (semantic): types enforce correct usage
Crypto::seal($message, new EncryptionPublicKey($key));
// Wrong key type = type error, not silent failure

Detection patterns:

  • Functions taking bytes, string, []byte for distinct security concepts
  • Parameters that could be swapped without type errors
  • Same type used for keys, nonces, ciphertexts, signatures

The comparison footgun:

go
// Timing-safe comparison looks identical to unsafe
if hmac == expected { }           // BAD: timing attack
if hmac.Equal(mac, expected) { }  // Good: constant-time
// Same types, different security properties
4. Configuration Cliffs

One wrong setting creates catastrophic failure, with no warning.

Detection patterns:

  • Boolean flags that disable security entirely
  • String configs that aren't validated
  • Combinations of settings that interact dangerously
  • Environment variables that override security settings
  • Constructor parameters with sensible defaults but no validation (callers can override with insecure values)

Examples:

yaml
# One typo = disaster
verify_ssl: fasle  # Typo silently accepted as truthy?

# Magic values
session_timeout: -1  # Does this mean "never expire"?

# Dangerous combinations accepted silently
auth_required: true
bypass_auth_for_health_checks: true
health_check_path: "/"  # Oops
php
// Sensible default doesn't protect against bad callers
public function __construct(
    public string $hashAlgo = 'sha256',  // Good default...
    public int $otpLifetime = 120,       // ...but accepts md5, 0, etc.
) {}

See config-patterns.md for detailed patterns.

5. Silent Failures

Errors that don't surface, or success that masks failure.

Detection patterns:

  • Functions returning booleans instead of throwing on security failures
  • Empty catch blocks around security operations
  • Default values substituted on parse errors
  • Verification functions that "succeed" on malformed input

Examples:

python
# Silent bypass
def verify_signature(sig, data, key):
    if not key:
        return True  # No key = skip verification?!

# Return value ignored
signature.verify(data, sig)  # Throws on failure
crypto.verify(data, sig)     # Returns False on failure
# Developer forgets to check return value
6. Stringly-Typed Security

Security-critical values as plain strings enable injection and confusion.

Detection patterns:

  • SQL/commands built from string concatenation
  • Permissions as comma-separated strings
  • Roles/scopes as arbitrary strings instead of enums
  • URLs constructed by joining strings

The permission accumulation footgun:

python
permissions = "read,write"
permissions += ",admin"  # Too easy to escalate

# vs. type-safe
permissions = {Permission.READ, Permission.WRITE}
permissions.add(Permission.ADMIN)  # At least it's explicit
Show full SKILL.md (402 more words)Show less

Analysis Workflow

Phase 1: Surface Identification
  1. Map security-relevant APIs: authentication, authorization, cryptography, session management, input validation
  2. Identify developer choice points: Where can developers select algorithms, configure timeouts, choose modes?
  3. Find configuration schemas: Environment variables, config files, constructor parameters
Phase 2: Edge Case Probing

For each choice point, ask:

  • Zero/empty/null: What happens with 0, "", null, []?
  • Negative values: What does -1 mean? Infinite? Error?
  • Type confusion: Can different security concepts be swapped?
  • Default values: Is the default secure? Is it documented?
  • Error paths: What happens on invalid input? Silent acceptance?
Phase 3: Threat Modeling

Consider three adversaries:

  1. The Scoundrel: Actively malicious developer or attacker controlling config

    • Can they disable security via configuration?
    • Can they downgrade algorithms?
    • Can they inject malicious values?
  2. The Lazy Developer: Copy-pastes examples, skips documentation

    • Will the first example they find be secure?
    • Is the path of least resistance secure?
    • Do error messages guide toward secure usage?
  3. The Confused Developer: Misunderstands the API

    • Can they swap parameters without type errors?
    • Can they use the wrong key/algorithm/mode by accident?
    • Are failure modes obvious or silent?
Phase 4: Validate Findings

For each identified sharp edge:

  1. Reproduce the misuse: Write minimal code demonstrating the footgun
  2. Verify exploitability: Does the misuse create a real vulnerability?
  3. Check documentation: Is the danger documented? (Documentation doesn't excuse bad design, but affects severity)
  4. Test mitigations: Can the API be used safely with reasonable effort?

If a finding seems questionable, return to Phase 2 and probe more edge cases.

Severity Classification

SeverityCriteriaExamples
CriticalDefault or obvious usage is insecureverify: false default; empty password allowed
HighEasy misconfiguration breaks securityAlgorithm parameter accepts "none"
MediumUnusual but possible misconfigurationNegative timeout has unexpected meaning
LowRequires deliberate misuseObscure parameter combination

References

By category:

By language (general footguns, not crypto-specific):

See also references/language-specific.md for a combined quick reference.

Quality Checklist

Before concluding analysis:

  • Probed all zero/empty/null edge cases
  • Verified defaults are secure
  • Checked for algorithm/mode selection footguns
  • Tested type confusion between security concepts
  • Considered all three adversary types
  • Verified error paths don't bypass security
  • Checked configuration validation
  • Constructor params validated (not just defaulted) - see config-patterns.md

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (references, assets) in plugins/sharp-edges/skills/sharp-edges of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/auth-patterns.md
  • references/case-studies.md
  • references/config-patterns.md
  • references/crypto-apis.md
  • references/lang-c.md
  • references/lang-csharp.md
  • references/lang-go.md
  • references/lang-java.md
  • references/lang-javascript.md
  • references/lang-kotlin.md
  • references/lang-php.md
  • references/lang-python.md
  • references/lang-ruby.md
  • references/lang-rust.md
  • references/lang-swift.md
  • … and 1 more

Open the folder on GitHubat commit 82fe822

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in trailofbits/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sharp Edges Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sharp Edges Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sharp Edges Analysis this skilltrailofbits/skills7.4k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Pump Securitynirholas/pump-fun-sdk133—~892Automated safety check: PassCustom licence
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT

Similar skills

  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Pump Security

    nirholas/pump-fun-sdk

    Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

    133 GitHub stars~892 tokensUpdated 19 days ago
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    442 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes

Questions about Sharp Edges Analysis

What does Sharp Edges Analysis do?

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. Built on the pit-of-success idea that secure use should be the path of least resistance, the skill checks whether an API, configuration format or cryptographic interface can be misused by an ordinary developer under deadline pressure. A dedicated sharp-edges-analyzer agent can run the whole workflow on its own: identify the surface, probe edge cases, model threats, then validate findings.

When should I use Sharp Edges Analysis?

Sharp Edges Analysis fits situations like: reviewing a library or API design for easy-to-misuse options; auditing a configuration schema for dangerous settings; evaluating the ergonomics of a cryptographic API; assessing whether authentication or authorization interfaces are secure by default.

How do I install Sharp Edges Analysis in Claude Code?

Run `npx skills add trailofbits/skills --skill sharp-edges -a claude-code`. Or copy the skill folder (plugins/sharp-edges/skills/sharp-edges in trailofbits/skills) into .claude/skills/sharp-edges in your project. Claude Code loads it when a task matches its description.

How do I install Sharp Edges Analysis in Codex?

Run `npx skills add trailofbits/skills --skill sharp-edges -a codex`. Or copy the skill folder (plugins/sharp-edges/skills/sharp-edges in trailofbits/skills) into .agents/skills/sharp-edges in your project. Codex loads it when a task matches its description.

Can I use Sharp Edges Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill sharp-edges -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sharp-edges, .gemini/skills/sharp-edges, .github/skills/sharp-edges and .opencode/skills/sharp-edges in your project.

What does Sharp Edges Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Sharp Edges Analysis is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob.

Does Sharp Edges Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sharp Edges Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sharp Edges Analysis use?

Sharp Edges Analysis is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sharp Edges Analysis use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.

What are the alternatives to Sharp Edges Analysis?

Skills that share tags, products or a category with Sharp Edges Analysis: Code Security (semgrep/skills, 322 stars), Security Audit (jellydn/my-ai-tools, 123 stars), Pump Security (nirholas/pump-fun-sdk, 133 stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sharp Edges Analysis?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.