Official agent skill

Variant Analysis

by trailofbits in trailofbits/skills

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Variant Analysis

skills CLI
$ npx skills add trailofbits/skills --skill variant-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills variant-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/variant-analysis/skills/variant-analysis .claude/skills/variant-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
variant-analysis
GitHub stars
7.4k
Token cost
~967 tokens
SKILL.md length
448 words
Files
18 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

  • Works in 5 steps: Narrow scope — searching only the module… → Pattern too specific — searching one… → One vulnerability class — chasing a… → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers When to Use, When NOT to Use, The Five Steps and Running it as a Workflow, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Variant Analysis is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. Use immediately after a vulnerability, logic bug, or bad pattern turns up in a specific file and the question becomes where else it occurs, including the bare conversational form ("are there others like this?", "is this the same bug?"). Also for generalizing one known instance into a CodeQL or Semgrep query for its whole pattern family, and for triaging a set of look-alike candidates against a known root…

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including reference files and assets (for example `agents/openai.yaml`, `references/reporting.md` and `references/root-cause.md`).

It sits in Security, covering Static analysis and SAST and Root cause analysis. It works with Semgrep. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Root cause analysis

Example prompts

  • “are there others like this?”
  • “is this the same bug?”
  • “Use the variant-analysis skill to hunt for the other instances of a bug already found — the variants of one root cause across a codebase”
  • “/variant-analysis”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Narrow scope — searching only the module the original bug was in
  2. Pattern too specific — searching one attribute and missing the family around it
  3. One vulnerability class — chasing a single manifestation of the root cause
  4. Happy-path testing — never trying the null, empty, and boundary cases
  5. Generalizing too fast — abstracting several elements at once, so noise cannot be

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Variant Analysis loads about 967 tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~146
When it runs · the whole SKILL.md, loaded when a task matches
~967
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 448 words, ~967 tokens.

Download SKILL.mdSave it as .claude/skills/variant-analysis/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
variant-analysis
description
Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. Use immediately after a vulnerability, logic bug, or bad pattern turns up in a specific file and the question becomes where else it occurs, including the bare conversational form ("are there others like this?", "is this the same bug?"). Also for generalizing one known instance into a CodeQL or Semgrep query for its whole pattern family, and for triaging a set of look-alike candidates against a known root cause. Not for initial discovery with no bug in hand.

Variant Analysis

Find the other instances of a bug you have already found. One root cause usually has several manifestations, and they are rarely in the module where you found the first one.

When to Use

  • A vulnerability has been found and you need to search for similar instances
  • Building or refining CodeQL/Semgrep queries for security patterns
  • Performing systematic code audits after an initial issue discovery
  • Analyzing how a single root cause manifests in different code paths

When NOT to Use

  • Initial vulnerability discovery — use audit-context-building or a domain-specific audit
  • General code review with no known pattern to search for
  • Writing fix recommendations — use issue-writer
  • Understanding unfamiliar code — use audit-context-building first

The Five Steps

Read the reference for a step when you reach it.

1. Understand the original issue. Extract the root cause — why the code is wrong, not what it does — and enumerate the directions a variant could hide in: related identifiers, other manifestations of the same mistake, data-type edge cases. → references/root-cause.md

2. Create an exact match. Write a pattern matching ONLY the known instance and confirm it hits. A pattern that matches nothing means you have misunderstood the bug, and every search built on it is calibrated against the wrong code.

3–4. Generalize one element at a time. Climb from the exact match toward the pattern family, running and reading all matches after each single change. Stop when more than half the matches are noise. → references/searching.md — abstraction ladder, tool selection, false-positive filters

5. Triage. Decide which candidates are real, and say so with a severity attached. → references/triage.md

Then write it up, including the patterns that failed and a CI rule to prevent regression. → references/reporting.md

Show full SKILL.md (172 more words)Show less

Running it as a Workflow

This plugin ships /variant-analysis:variants, which runs the five steps across parallel subagents — one per expansion axis, looping until the sweep stops finding anything new. Each stage reads the reference above that matches its job.

Use the workflow when the codebase is large or the root cause has many manifestations. Work the steps directly when the search is narrow or you want a say in each generalization.

What Makes Hunts Fail

  1. Narrow scope — searching only the module the original bug was in
  2. Pattern too specific — searching one attribute and missing the family around it
  3. One vulnerability class — chasing a single manifestation of the root cause
  4. Happy-path testing — never trying the null, empty, and boundary cases
  5. Generalizing too fast — abstracting several elements at once, so noise cannot be attributed to any one of them

The first three are covered in root-cause.md and searching.md, the fourth in triage.md.

Resources

CodeQL (resources/codeql/): python.ql, javascript.ql, java.ql, go.ql, cpp.ql

Semgrep (resources/semgrep/): python.yaml, javascript.yaml, java.yaml, go.yaml, cpp.yaml

Report: resources/variant-report-template.md

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (references, assets) in plugins/variant-analysis/skills/variant-analysis of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/reporting.md
  • references/root-cause.md
  • references/searching.md
  • references/triage.md
  • resources/codeql/cpp.ql
  • resources/codeql/go.ql
  • resources/codeql/java.ql
  • resources/codeql/javascript.ql
  • resources/codeql/python.ql
  • resources/semgrep/cpp.yaml
  • resources/semgrep/go.yaml
  • resources/semgrep/java.yaml
  • … and 3 more

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Variant Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Variant Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Variant Analysis this skilltrailofbits/skills7.4k—~967Automated safety check: PassCC-BY-SA-4.0
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
Sast SemgrepAgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassCustom licence
Semgrepwaybarrios/opencode-power-pack533—~2.4kAutomated safety check: PassMIT
Semgrepsemgrep/skills322—~2.3kAutomated safety check: PassCustom licence
Code Auditzhaoxuya520/reverse-skill40k2 repos~374Automated safety check: WarnMIT

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    533 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep

    semgrep/skills

    Official

    Run Semgrep static analysis scans and create custom detection rules.

    322 GitHub stars~2.3k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Code Audit

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

    40k GitHub starsUsed in 2 repos~374 tokens
    SecurityAuto-check: warnings
  • Sast Configuration

    davila7/claude-code-templates

    Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

    32k GitHub starsUsed in 10 repos~1.6k tokens
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Variant Analysis

What does Variant Analysis do?

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. Variant Analysis is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

When should I use Variant Analysis?

Variant Analysis fits situations like: tasks that involve Static analysis and SAST; tasks that involve Root cause analysis.

How do I install Variant Analysis in Claude Code?

Run `npx skills add trailofbits/skills --skill variant-analysis -a claude-code`. Or copy the skill folder (plugins/variant-analysis/skills/variant-analysis in trailofbits/skills) into .claude/skills/variant-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Variant Analysis in Codex?

Run `npx skills add trailofbits/skills --skill variant-analysis -a codex`. Or copy the skill folder (plugins/variant-analysis/skills/variant-analysis in trailofbits/skills) into .agents/skills/variant-analysis in your project. Codex loads it when a task matches its description.

Can I use Variant Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill variant-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/variant-analysis, .gemini/skills/variant-analysis, .github/skills/variant-analysis and .opencode/skills/variant-analysis in your project.

What does Variant Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Variant Analysis is instructions for the agent only.

Does Variant Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Variant Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Variant Analysis use?

Variant Analysis is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Variant Analysis use?

About 967 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Variant Analysis?

Skills that share tags, products or a category with Variant Analysis: Semgrep (vigolium/piolium, 138 stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 219 stars), Semgrep (waybarrios/opencode-power-pack, 533 stars) and Semgrep (semgrep/skills, 322 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Variant Analysis?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.