Security Analysis
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .claude/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .claude/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocardsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .agents/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .agents/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .cursor/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .cursor/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .gemini/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .gemini/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills vulnerability-triage-brocardsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .github/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .github/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .opencode/skills/vulnerability-triage-brocards && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vulnerability-triage-brocards" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards into .opencode/skills/vulnerability-triage-brocards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-triage-brocards", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulnerability-triage-brocardsScreens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.
This skill puts incoming vulnerability reports through seven falsifiable tests, called brocards, adapted from William Woodruff's Brocards for vulnerability triage. Each report is checked in order and gets one of three verdicts per test: PASS, DISMISS with the reason written down, or NEEDS-MORE-INFO with what is missing. By default evaluation stops at the first DISMISS, though you can ask for a full run through all seven.
Its main use is as a quality gate between automated vulnerability discovery and human review, where most raw findings fail at least one test and can be dropped without auditor time. It also covers triaging findings during an audit, judging third-party CVEs against a codebase, reviewing bug bounty submissions and writing a defensible case for dismissing a CVE. The first brocard dismisses any report without a coherent threat model. It does not hunt for new bugs, prove exploitability or triage fuzzer crashes, and references/brocards-detail.md holds the longer explanations.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are mermaid).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
vulnbrocards.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vulnerability Triage Brocards loads about 2.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 156 tokens; SKILL.md has 984 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 984 words, ~2,181 tokens.
.claude/skills/vulnerability-triage-brocards/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Systematically evaluate incoming vulnerability reports against 7 principled criteria before committing resources to deeper analysis. Each brocard is a falsifiable test: if a report fails any brocard, document the reason and dismiss or request clarification. If a report survives all 7, escalate it.
The 7 brocards are adapted from William Woodruff's "Brocards for vulnerability triage" (2026).
This skill is the quality gate between automated discovery and human review. Findings that survive triage proceed to PoC development and formal writeup.
flowchart TD
A([agentic vulnerability discovery]) -->|raw findings| B[vulnerability-triage-brocards]
B -->|DISMISS| C([Document brocard # and reasoning])
B -->|NEEDS-MORE-INFO| D([Request specific evidence])
B -->|ACCEPT| E[PoC / exploitability proof]
E --> F[vulnerability report writeup]For each incoming vulnerability report, evaluate it against all 7 brocards sequentially. By default, stop at the first DISMISS verdict and report it. If the user requests a full evaluation, continue through all 7 brocards regardless of intermediate failures. For each brocard, record one of three verdicts:
Dismiss any report that lacks a coherent threat model. The report must articulate: (a) who the attacker is, (b) what capability the attacker has, (c) how the attacker exploits the behavior, and (d) what harm results.
Reports that describe a code behavior without connecting it to attacker- reachable harm fail this brocard.
Quick test: Can the report answer "an attacker with [capability] can [action] to achieve [impact]"? If not, dismiss or request clarification.
Dismiss any report where the attacker capabilities required to trigger the vulnerability equal or exceed the impact of the vulnerability itself. If the attacker must already possess the power the exploit would grant, the vulnerability is redundant.
Quick test: Does triggering the exploit require capabilities that already subsume its impact? If yes, dismiss.
Dismiss any report describing behavior that is theoretically possible but does not occur in actual software usage. Check whether the vulnerable code path is reachable in practice.
Quick test: Is the vulnerable code path exercised by any real caller? If not, dismiss. If the report targets a library, ask if we should check downstream usage.
Dismiss any report where the behavior results from correct implementation of a specification. The vulnerability, if any, exists in the standard -- not the implementation.
Nuance: If an implementation voluntarily adopts a stricter posture than the standard requires, and that strictness fails, the implementation is vulnerable even though the standard permits the behavior.
Quick test: Does the specification require or permit this behavior? If yes, the report targets the standard, not the code.
Dismiss any report describing behavior that is explicitly documented, especially when the documentation includes security implications or usage caveats.
Nuance: Downstream usage that violates documented guidelines may constitute a valid vulnerability in the downstream project, not the documented component.
Quick test: Does the project's documentation describe this behavior and warn against misuse? If yes, dismiss the report against the project itself.
Dismiss any report whose remediation would cause more harm than the vulnerability itself. Evaluate: (a) severity of the vulnerability in practice, (b) cost and disruption of the proposed fix, (c) blast radius of the remediation (dependency graph, ecosystem impact).
Quick test: Would fixing this cause more disruption than the vulnerability itself? If yes, dismiss or downgrade severity.
A CVE identifier or formal report does not prove a vulnerability exists. Conversely, absence of a report does not prove safety. Evaluate the technical merits independently of report metadata.
Quick test: Strip the CVE number and CVSS score. Does the technical description alone justify action? Judge on evidence, not authority.
After evaluating all 7 brocards, produce a structured triage summary:
## Triage Summary: [Report ID or Title]
| # | Brocard | Verdict | Rationale |
|---|---------|---------|-----------|
| 1 | Threat Model | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 2 | Exploit from the Heavens | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 3 | Outside of Usage | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 4 | Standard Behavior | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 5 | Documented Behavior | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 6 | Cure Worse Than Disease | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 7 | Report Sufficiency | PASS/DISMISS/NEEDS-MORE-INFO | ... |
**Overall Verdict:** ACCEPT / DISMISS / NEEDS-MORE-INFO
**Reasoning:** [1-3 sentence justification]
**Next Step:** [escalate to PoC development / request info / close]Guard against these reasoning failures in both directions:
For expanded explanations, examples, and edge cases for each brocard, consult
references/brocards-detail.md.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Vulnerability Triage Brocards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vulnerability Triage Brocards this skilltrailofbits/skills | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Security Analysismicrosoft/haste | 107 | — | ~1k | Automated safety check: Pass | MIT | |
| Find Cybersecurity Firmjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Deepsec Vulnerability Scannervercel-labs/deepsec | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None |
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
vercel-labs/deepsec
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
Categories
Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. This skill puts incoming vulnerability reports through seven falsifiable tests, called brocards, adapted from William Woodruff's Brocards for vulnerability triage. Each report is checked in order and gets one of three verdicts per test: PASS, DISMISS with the reason written down, or NEEDS-MORE-INFO with what is missing.
Vulnerability Triage Brocards fits situations like: filtering raw findings from an agentic vulnerability discovery pipeline; deciding whether a bug bounty submission deserves investigation; assessing whether a third-party CVE affects the code under audit; writing a documented justification for dismissing or deprioritizing a CVE.
Run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a claude-code`. Or copy the skill folder (plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards in trailofbits/skills) into .claude/skills/vulnerability-triage-brocards in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a codex`. Or copy the skill folder (plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards in trailofbits/skills) into .agents/skills/vulnerability-triage-brocards in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-triage-brocards, .gemini/skills/vulnerability-triage-brocards, .github/skills/vulnerability-triage-brocards and .opencode/skills/vulnerability-triage-brocards in your project.
SKILL.md names no scripts, command-line tools or credentials: Vulnerability Triage Brocards is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: vulnbrocards.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vulnerability Triage Brocards is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vulnerability Triage Brocards: Security Analysis (microsoft/haste, 107 stars), Find Cybersecurity Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Auditor (eigent-ai/eigent, 15k stars) and Deepsec Vulnerability Scanner (vercel-labs/deepsec, 8.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.