Official Agent Skills
Skills published by verified organisations. Every one is reviewed before listing, and the publisher's identity is checked, not just claimed.
-
trailofbits Bundle Trailmark StructuralRuns full Trailmark structural analysis by building a graph and computing pre-analysis passes for hotspots, taint, blast radius, privilege boundaries, and attack surface.
7k -
trailofbits Bundle Debug ButtercupDiagnose pod crashes, restart loops, Redis failures, resource pressure, and other service misbehavior in the crs namespace on Kubernetes.
7k -
trailofbits Bundle AtherisFuzz Python code and C extensions with coverage guidance and AddressSanitizer support using a libFuzzer-based fuzzer.
7k -
trailofbits Bundle OssfuzzSet up continuous fuzzing infrastructure for open-source projects using Google's OSS-Fuzz platform, including building and running fuzz harnesses locally and enrolling new projects.
7k -
trailofbits Bundle Mutation TestingConfigures mewt or muton mutation testing campaigns — scopes targets, tunes timeouts, and optimizes long-running runs.
Audited 7k -
trailofbits Bundle LibfuzzerCoverage-guided fuzzer built into LLVM for C/C++ projects. Use for fuzzing C/C++ code that can be compiled with Clang.
Audited 7k -
trailofbits Bundle Variant AnalysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis after identifying an initial issue.
Audited 7k -
trailofbits Bundle Cargo FuzzFuzz Rust projects with libFuzzer using cargo-fuzz, including harness writing, sanitizer integration, and coverage analysis.
7k -
trailofbits Bundle WycheproofValidate cryptographic implementations against known attacks and edge cases using Wycheproof test vectors.
7k -
trailofbits Bundle Yara Rule AuthoringWrite high-quality YARA-X detection rules for malware identification, covering naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction.
7k -
trailofbits Bundle Devcontainer SetupCreates pre-configured devcontainers with Claude Code, language-specific tooling (Python, Node, Rust, Go), and persistent volumes for isolated development environments.
7k -
trailofbits Bundle Seatbelt SandboxerGenerates minimal macOS Seatbelt sandbox configurations to isolate and restrict applications with allowlist-based profiles.
7k -
trailofbits Bundle Differential ReviewPerforms security-focused differential review of code changes (PRs, commits, diffs), adapting analysis depth to codebase size and generating comprehensive markdown reports.
Audited 7k -
trailofbits Bundle Harness WritingWrite effective fuzzing harnesses across languages to improve code coverage and find bugs in your system under test.
Audited 7k -
trailofbits Bundle Dimensional AnalysisOrchestrates a dimensional-analysis pipeline to annotate codebases with unit/dimension comments, discover dimensional vocabulary, and detect arithmetic bugs from unit mismatches or precision loss.
7k -
trailofbits Bundle Entry Point AnalyzerIdentifies state-changing entry points in smart contract codebases for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.
7k -
trailofbits Bundle Firebase Apk ScannerScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
7k -
trailofbits Bundle Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns with proper testing and validation.
7k -
trailofbits Bundle Coverage AnalysisMeasures code coverage during fuzzing to assess harness effectiveness and identify fuzzing blockers.
7k -
trailofbits Bundle Fuzzing ObstaclesPatch code to bypass checksums, global state, and validation checks that block fuzzer progress, using conditional compilation for C/C++ and Rust.
7k -
trailofbits Bundle Fuzzing DictionaryGuides fuzzers with domain-specific tokens to reach deeper code paths in parsers, protocol handlers, and file format processors.
7k -
trailofbits Bundle Guidelines AdvisorAnalyzes smart contract codebases against Trail of Bits' secure development guidelines, generating documentation, reviewing architecture and upgradeability patterns, assessing implementation quality, identifying pitfalls, and providing prioritized recommendations.
Audited 7k -
trailofbits Bundle Constant Time AnalysisAnalyzes cryptographic code to detect operations that leak secret data through execution timing variations, supporting multiple languages.
7k -
trailofbits Bundle Property Based TestingProvides guidance for property-based testing across multiple languages and smart contracts, helping detect patterns where PBT offers stronger coverage than example-based tests.
Audited 7k -
trailofbits Bundle Constant Time TestingDetect timing side channels in cryptographic code using formal, symbolic, dynamic, and statistical testing tools.
Audited 7k -
trailofbits Bundle Audit Prep AssistantPrepares codebases for security review using Trail of Bits' checklist by setting review goals, running static analysis, increasing test coverage, removing dead code, and generating documentation.
7k -
trailofbits Bundle Secure Workflow GuideGuides through a 5-step secure development workflow for smart contracts, including automated scanning with Slither, special feature validation, visual security diagrams, security property documentation, and manual review.
7k -
trailofbits Bundle Spec To Code ComplianceVerifies that blockchain code implements exactly what documentation specifies, identifying gaps between specs and implementation for audit engagements.
Audited 7k -
trailofbits Bundle Designing Workflow SkillsGuides the design and structuring of workflow-based Claude Code skills with multi-step phases, decision trees, subagent delegation, and progressive disclosure.
Audited 7k -
trailofbits Bundle Code Maturity AssessorAssesses codebase maturity using Trail of Bits' 9-category framework, producing a professional scorecard with evidence-based ratings and actionable recommendations.
Audited 7k -
trailofbits Bundle Testing Handbook GeneratorGenerates Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.
7k -
trailofbits Bundle Ton Vulnerability ScannerScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
7k -
trailofbits Bundle Supply Chain Risk AuditorAudits project dependencies for supply chain risks including single maintainers, unmaintained packages, low popularity, high-risk features, past CVEs, and missing security contacts.
7k -
trailofbits Bundle Token Integration AnalyzerAnalyzes token implementations and integrations for ERC20/ERC721 conformity, weird token patterns, contract composition, owner privileges, and on-chain scarcity.
7k -
trailofbits Bundle Cosmos Vulnerability ScannerScans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities such as chain halts, fund loss, and state divergence.
7k -
trailofbits Bundle Solana Vulnerability ScannerScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
7k