Official agent skill

Trailmark Variant Neighborhood

by trailofbits in trailofbits/skills

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Trailmark Variant Neighborhood

skills CLI
$ npx skills add trailofbits/skills --skill trailmark-variant-neighborhood -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills trailmark-variant-neighborhood --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trailmark/skills/trailmark-variant-neighborhood .claude/skills/trailmark-variant-neighborhood && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trailmark-variant-neighborhood
GitHub stars
7.5k
Token cost
~1.1k tokens
SKILL.md length
431 words
Files
6 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

  • Works in 5 steps: Normalize And Bind The Seed → Expand Neighborhoods → Rank Candidates → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations to Reject and Workflow, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Trailmark Variant Neighborhood is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes. Use after one issue is found to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review with graph-derived candidate locations.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files and assets (for example `agents/openai.yaml`, `references/neighborhood-patterns.md` and `references/output-format.md`).

It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “Use the trailmark-variant-neighborhood skill to expand one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant…”
  • “/trailmark-variant-neighborhood”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Write

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Normalize And Bind The Seed
  2. Expand Neighborhoods
  3. Rank Candidates
  4. Extract Pattern Guidance
  5. Emit Handoff Packet

What it can do on your machine

Read from SKILL.md and the folder at commit 442fc9d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trailmark Variant Neighborhood loads about 1.1k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 442fc9d, republished under its CC-BY-SA-4.0 licence (© trailofbits). 431 words, ~1,073 tokens.

Download SKILL.mdSave it as .claude/skills/trailmark-variant-neighborhood/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
trailmark-variant-neighborhood
description
Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes. Use after one issue is found to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review with graph-derived candidate locations.
allowed-tools
Bash, Read, Grep, Glob, Write

Trailmark Variant Neighborhood

Expand one seed issue into graph-derived variant candidates. This skill generates review targets, not confirmed findings.

When to Use

  • A finding is confirmed or plausible and variants may exist
  • The vulnerable pattern depends on call context
  • The issue involves a shared sink, source, validator, interface, override, trait, hook, handler, adapter, or critical type
  • The next step is to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review

When NOT to Use

  • No seed issue exists. Use discovery or triage first.
  • The pattern is purely syntactic and already obvious. Use semgrep-rule-creator directly.
  • The question is exploit-chain composition across multiple findings. Use a composition workflow.
  • The goal is remediation verification. Use a remediation-review workflow.
  • The seed cannot be bound to a graph node.

Rationalizations to Reject

RationalizationWhy It Is WrongRequired Action
"Nearby code means variant"Proximity is only a candidate reasonRank it as a review target
"Only exact same names matter"Variants often share sinks or preconditions, not namesExpand across callers, callees, interfaces, and types
"Every candidate is a finding"This skill outputs candidates for reviewAvoid vulnerability claims
"Unreachable candidates can be ignored completely"They may become reachable after refactorsRank lower or list as deferred
"Graph candidates replace semantic pattern work"Graph structure finds locations, not root-cause semanticsHand off to variant-analysis, Semgrep, CodeQL, or manual review

Workflow

Variant Neighborhood Progress:
- [ ] Step 1: Normalize and bind the seed
- [ ] Step 2: Expand graph neighborhoods
- [ ] Step 3: Rank candidates
- [ ] Step 4: Extract variant pattern guidance
- [ ] Step 5: Emit handoff packet
Step 1: Normalize And Bind The Seed

Accept finding text, file/line, function name, or output from trailmark-finding-triage. Bind the seed to a Trailmark node and record the root cause in plain language.

If the seed has no concrete graph binding, stop before inventing variants.

Show full SKILL.md (164 more words)Show less
Step 2: Expand Neighborhoods

Use the dimensions in references/neighborhood-patterns.md:

  • shared callers
  • shared callees and sinks
  • entrypoint path neighbors
  • interface, override, trait, and implementation siblings
  • file or module cluster neighbors
  • taint or privilege-boundary peers
  • type and state-reference neighbors

Bound expansion to avoid candidate floods.

Step 3: Rank Candidates

Rank with references/ranking.md. Prioritize entrypoint-reachable, tainted, boundary-adjacent, high-blast-radius, shared sink, same-interface, and close-distance candidates. Penalize test, mock, generated, vendor, unreachable, and trusted-internal-only candidates.

Step 4: Extract Pattern Guidance

Summarize what should be searched for syntactically and what requires semantic review. Identify whether follow-up belongs in:

  • variant-analysis
  • semgrep-rule-creator
  • static-analysis with CodeQL or SARIF-producing tools
  • manual review
Step 5: Emit Handoff Packet

Use references/output-format.md. Include ranked candidates, inclusion reasons, exclusions, limitations, and the variant-analysis handoff.

Stop Conditions

  • No graph binding exists
  • Candidate count is too high and the root cause is underspecified
  • Trailmark cannot analyze the target language
  • The seed is only in test, generated, or vendor code and the user did not say that code is in scope

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references, assets) in plugins/trailmark/skills/trailmark-variant-neighborhood of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/neighborhood-patterns.md
  • references/output-format.md
  • references/ranking.md

Open the folder on GitHubat commit 442fc9d

Compare with similar skills

Trailmark Variant Neighborhood next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trailmark Variant Neighborhood compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trailmark Variant Neighborhood this skilltrailofbits/skills7.5k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence
Semgrepwaybarrios/opencode-power-pack534—~2.4kAutomated safety check: PassMIT
Semgrepsemgrep/skills324—~2.3kAutomated safety check: PassCustom licence
Code Auditzhaoxuya520/reverse-skill41k2 repos~374Automated safety check: WarnMIT

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    534 GitHub stars~2.4k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Semgrep

    semgrep/skills

    Official

    Run Semgrep static analysis scans and create custom detection rules.

    324 GitHub stars~2.3k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Code Audit

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

    41k GitHub starsUsed in 2 repos~374 tokens
    SecurityAuto-check: warnings
  • Sast Configuration

    davila7/claude-code-templates

    Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

    33k GitHub starsUsed in 11 repos~1.6k tokens
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.5k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.5k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.5k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Trailmark Variant Neighborhood

What does Trailmark Variant Neighborhood do?

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…. Trailmark Variant Neighborhood is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes.

When should I use Trailmark Variant Neighborhood?

Trailmark Variant Neighborhood fits situations like: tasks that involve Static analysis and SAST.

How do I install Trailmark Variant Neighborhood in Claude Code?

Run `npx skills add trailofbits/skills --skill trailmark-variant-neighborhood -a claude-code`. Or copy the skill folder (plugins/trailmark/skills/trailmark-variant-neighborhood in trailofbits/skills) into .claude/skills/trailmark-variant-neighborhood in your project. Claude Code loads it when a task matches its description.

How do I install Trailmark Variant Neighborhood in Codex?

Run `npx skills add trailofbits/skills --skill trailmark-variant-neighborhood -a codex`. Or copy the skill folder (plugins/trailmark/skills/trailmark-variant-neighborhood in trailofbits/skills) into .agents/skills/trailmark-variant-neighborhood in your project. Codex loads it when a task matches its description.

Can I use Trailmark Variant Neighborhood in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill trailmark-variant-neighborhood -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trailmark-variant-neighborhood, .gemini/skills/trailmark-variant-neighborhood, .github/skills/trailmark-variant-neighborhood and .opencode/skills/trailmark-variant-neighborhood in your project.

What does Trailmark Variant Neighborhood need to run?

SKILL.md names no scripts, command-line tools or credentials: Trailmark Variant Neighborhood is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Write.

Does Trailmark Variant Neighborhood access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Trailmark Variant Neighborhood safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Trailmark Variant Neighborhood use?

Trailmark Variant Neighborhood is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trailmark Variant Neighborhood use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Trailmark Variant Neighborhood?

Skills that share tags, products or a category with Trailmark Variant Neighborhood: Semgrep (vigolium/piolium, 140 stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 220 stars), Semgrep (waybarrios/opencode-power-pack, 534 stars) and Semgrep (semgrep/skills, 324 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trailmark Variant Neighborhood?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,455 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 9, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.