Official agent skill

Trailmark Review Gate

by trailofbits in trailofbits/skills

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Trailmark Review Gate

skills CLI
$ npx skills add trailofbits/skills --skill trailmark-review-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills trailmark-review-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trailmark/skills/trailmark-review-gate .claude/skills/trailmark-review-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trailmark-review-gate
GitHub stars
7.4k
Token cost
~1.1k tokens
SKILL.md length
456 words
Files
6 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

  • Works in 5 steps: Resolve Inputs → Build Graph Evidence → Normalize Changes → …
  • Reviewing a pull request for graph-level security regressions before merge
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations to Reject and Workflow, plus 1 more section
  • Calls git

What it does

The agent resolves the two sides of a change from refs, a branch, a commit range or two directories, using git diff, git show and worktrees instead of checking out branches. Both snapshots go through Trailmark's pre-analysis so taint, privilege-boundary, blast-radius, complexity and entry point signals exist, and the differences are normalized into added, removed and modified nodes.

Fixed gate rules turn that evidence into a compact structural packet reviewers can cite while reading the code. It looks for new entry points, new tainted paths, removed validation or authorization calls, privilege-boundary drift, growth in blast radius or complexity and newly reachable sensitive sinks. If graph construction fails the result is UNKNOWN, never a pass, and a passing gate does not replace line-level review.

When your agent uses it

  • Reviewing a pull request for graph-level security regressions before merge
  • Checking whether a fix commit removed validation or authorization on a reachable path
  • Comparing a release diff for attack surface growth
  • Producing structural evidence to support a differential review

Example prompts

  • “Run the Trailmark review gate on the feature/payments branch against main.”
  • “Did the fix commit remove any auth checks on paths reachable from the API?”
  • “Compare the release branch with the last tag and tell me whether blast radius grew.”

Requirements

  • Trailmark
  • A Git repository with the refs to compare
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Write

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Resolve Inputs
  2. Build Graph Evidence
  3. Normalize Changes
  4. Apply Gate Rules
  5. Emit Packet

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trailmark Review Gate loads about 1.1k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 456 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 456 words, ~1,113 tokens.

Download SKILL.mdSave it as .claude/skills/trailmark-review-gate/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
trailmark-review-gate
description
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge.
allowed-tools
Bash, Read, Grep, Glob, Write

Trailmark Review Gate

Apply deterministic security gate rules to Trailmark structural diff evidence. This skill does not replace line-level review. It produces a compact structural packet reviewers can cite while they inspect the code.

When to Use

  • Reviewing a branch, pull request, release diff, or fix commit
  • Checking whether a change expands attack surface
  • Looking for removed validation or authorization on reachable paths
  • Comparing before/after taint, privilege-boundary, blast-radius, or complexity signals
  • Producing graph evidence for a differential review

When NOT to Use

  • Single-snapshot analysis. Use trailmark or trailmark-structural.
  • Text-diff review only. Use differential-review.
  • Full vulnerability discovery. Use an audit or bug-finding workflow.
  • One static finding. Use trailmark-finding-triage.
  • Tooling is unavailable and the user wants manual review only.

Rationalizations to Reject

RationalizationWhy It Is WrongRequired Action
"The line diff is small, so no graph gate is needed"Small changes can create new call pathsCompare before/after graphs
"Graph gate passed, so the PR is secure"The gate only checks structural regressionsStill perform line-level review
"Trailmark failed, so pass the gate"Tool failure is unknown risk, not successEmit UNKNOWN
"Tests pass, so removed validation is fine"Tests may miss affected entrypoint pathsReview the removed path manually
"Only new code matters"Removed auth, validation, and callers can be higher risk than additionsReview removals and path changes

Workflow

Review Gate Progress:
- [ ] Step 1: Resolve before/after inputs
- [ ] Step 2: Build graph-evolution evidence
- [ ] Step 3: Normalize structural changes
- [ ] Step 4: Apply gate rules
- [ ] Step 5: Emit review packet and actions
Step 1: Resolve Inputs

Accept two refs, a branch name, a commit range, or before/after directories. Do not check out branches unnecessarily. Prefer git diff, git show, and git worktrees, following the graph-evolution snapshot workflow.

Show full SKILL.md (201 more words)Show less
Step 2: Build Graph Evidence

Run graph-evolution or equivalent Trailmark before/after graph analysis. Both snapshots must run engine.preanalysis() so taint, privilege-boundary, blast-radius, complexity, and entrypoint signals are available.

Record Trailmark version and any feature probes. If graph construction fails, emit UNKNOWN.

Step 3: Normalize Changes

Normalize evidence into:

  • added, removed, and modified nodes
  • added and removed edges
  • entrypoint set changes
  • taint membership changes
  • privilege-boundary membership changes
  • blast-radius changes
  • complexity changes
  • newly reachable sensitive sinks
  • unresolved, proxy, or dynamic edge changes
Step 4: Apply Gate Rules

Apply the rules in references/gate-rules.md. Gate verdicts are:

VerdictMeaning
FAILA high-risk structural regression needs review before acceptance
WARNA meaningful graph change needs reviewer attention
PASSNo configured structural gate fired
UNKNOWNTrailmark failed or evidence is too incomplete
Step 5: Emit Packet

Write the packet using references/output-format.md, then hand it to the branch reviewer. Use references/review-integration.md when combining this packet with differential-review or another PR review process.

Requirements

  • Never mutate the user's working branch while comparing refs.
  • Never report PASS when Trailmark failed.
  • Separate graph evidence from manual security judgment.
  • Include exact changed nodes or paths for every FAIL and WARN.
  • Include limitations when parser, proxy, unresolved-call, or dynamic-dispatch uncertainty affects the verdict.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references, assets) in plugins/trailmark/skills/trailmark-review-gate of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/gate-rules.md
  • references/output-format.md
  • references/review-integration.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Trailmark Review Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trailmark Review Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trailmark Review Gate this skilltrailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence
Reviewsoftspark/ai-toolkit179—~3.1kAutomated safety check: NotesApache-2.0
Openqodexopenqodex/openqodex470—~2.4kAutomated safety check: PassApache-2.0
Claude Securityanthropics/claude-plugins-official38k—~1.4kAutomated safety check: PassApache-2.0
Remediating With AWS Security Agentaws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Review

    softspark/ai-toolkit

    Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Openqodex

    openqodex/openqodex

    Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

    470 GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Claude Security

    anthropics/claude-plugins-official

    Official

    Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

    38k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Remediating With AWS Security Agent

    aws/agent-toolkit-for-aws

    Official

    Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

    2.8k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated today
    DevelopmentAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Questions about Trailmark Review Gate

What does Trailmark Review Gate do?

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. The agent resolves the two sides of a change from refs, a branch, a commit range or two directories, using git diff, git show and worktrees instead of checking out branches. Both snapshots go through Trailmark's pre-analysis so taint, privilege-boundary, blast-radius, complexity and entry point signals exist, and the differences are normalized into added, removed and modified nodes.

When should I use Trailmark Review Gate?

Trailmark Review Gate fits situations like: reviewing a pull request for graph-level security regressions before merge; checking whether a fix commit removed validation or authorization on a reachable path; comparing a release diff for attack surface growth; producing structural evidence to support a differential review.

How do I install Trailmark Review Gate in Claude Code?

Run `npx skills add trailofbits/skills --skill trailmark-review-gate -a claude-code`. Or copy the skill folder (plugins/trailmark/skills/trailmark-review-gate in trailofbits/skills) into .claude/skills/trailmark-review-gate in your project. Claude Code loads it when a task matches its description.

How do I install Trailmark Review Gate in Codex?

Run `npx skills add trailofbits/skills --skill trailmark-review-gate -a codex`. Or copy the skill folder (plugins/trailmark/skills/trailmark-review-gate in trailofbits/skills) into .agents/skills/trailmark-review-gate in your project. Codex loads it when a task matches its description.

Can I use Trailmark Review Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill trailmark-review-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trailmark-review-gate, .gemini/skills/trailmark-review-gate, .github/skills/trailmark-review-gate and .opencode/skills/trailmark-review-gate in your project.

What does Trailmark Review Gate need to run?

Going by SKILL.md and its folder, Trailmark Review Gate needs the command-line tools its instructions call (git). Our summary lists: Trailmark; A Git repository with the refs to compare. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Write.

Does Trailmark Review Gate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Trailmark Review Gate safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Trailmark Review Gate use?

Trailmark Review Gate is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trailmark Review Gate use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Trailmark Review Gate?

Skills that share tags, products or a category with Trailmark Review Gate: Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Review (softspark/ai-toolkit, 179 stars), Openqodex (openqodex/openqodex, 470 stars) and Claude Security (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trailmark Review Gate?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.