Secure Coding
-
trailofbits Bundle WycheproofValidate cryptographic implementations against known attacks and edge cases using Wycheproof test vectors.
7k -
trailofbits Bundle Seatbelt SandboxerGenerates minimal macOS Seatbelt sandbox configurations to isolate and restrict applications with allowlist-based profiles.
7k -
trailofbits Bundle Differential ReviewPerforms security-focused differential review of code changes (PRs, commits, diffs), adapting analysis depth to codebase size and generating comprehensive markdown reports.
Audited 7k -
trailofbits Bundle Harness WritingWrite effective fuzzing harnesses across languages to improve code coverage and find bugs in your system under test.
Audited 7k -
trailofbits Bundle Dimensional AnalysisOrchestrates a dimensional-analysis pipeline to annotate codebases with unit/dimension comments, discover dimensional vocabulary, and detect arithmetic bugs from unit mismatches or precision loss.
7k -
trailofbits Bundle Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns with proper testing and validation.
7k -
trailofbits Bundle Coverage AnalysisMeasures code coverage during fuzzing to assess harness effectiveness and identify fuzzing blockers.
7k -
trailofbits Bundle Fuzzing ObstaclesPatch code to bypass checksums, global state, and validation checks that block fuzzer progress, using conditional compilation for C/C++ and Rust.
7k -
trailofbits Bundle Fuzzing DictionaryGuides fuzzers with domain-specific tokens to reach deeper code paths in parsers, protocol handlers, and file format processors.
7k -
trailofbits Bundle Guidelines AdvisorAnalyzes smart contract codebases against Trail of Bits' secure development guidelines, generating documentation, reviewing architecture and upgradeability patterns, assessing implementation quality, identifying pitfalls, and providing prioritized recommendations.
Audited 7k -
trailofbits Bundle Constant Time AnalysisAnalyzes cryptographic code to detect operations that leak secret data through execution timing variations, supporting multiple languages.
7k -
trailofbits Bundle Constant Time TestingDetect timing side channels in cryptographic code using formal, symbolic, dynamic, and statistical testing tools.
Audited 7k -
trailofbits Bundle Audit Prep AssistantPrepares codebases for security review using Trail of Bits' checklist by setting review goals, running static analysis, increasing test coverage, removing dead code, and generating documentation.
7k -
trailofbits Bundle Secure Workflow GuideGuides through a 5-step secure development workflow for smart contracts, including automated scanning with Slither, special feature validation, visual security diagrams, security property documentation, and manual review.
7k -
trailofbits Bundle Spec To Code ComplianceVerifies that blockchain code implements exactly what documentation specifies, identifying gaps between specs and implementation for audit engagements.
Audited 7k -
trailofbits Bundle Code Maturity AssessorAssesses codebase maturity using Trail of Bits' 9-category framework, producing a professional scorecard with evidence-based ratings and actionable recommendations.
Audited 7k -
trailofbits Bundle Ton Vulnerability ScannerScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
7k -
trailofbits Bundle Token Integration AnalyzerAnalyzes token implementations and integrations for ERC20/ERC721 conformity, weird token patterns, contract composition, owner privileges, and on-chain scarcity.
7k -
trailofbits Bundle Cosmos Vulnerability ScannerScans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities such as chain halts, fund loss, and state divergence.
7k -
trailofbits Bundle Solana Vulnerability ScannerScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
7k -
trailofbits Bundle Algorand Vulnerability ScannerScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues.
7k -
trailofbits Bundle Substrate Vulnerability ScannerScans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
7k -
bankrbot Bundle 1clawStore and retrieve API keys, passwords, and credentials in an HSM-backed encrypted vault via MCP or REST API, with policy-based access control, secret rotation, multi-chain signing, and prompt injection scanning.
1.2k -
bankrbot Bundle Uniswap HooksBuild Uniswap v4 hooks with security-first guidance on threat modeling, permission flags, NoOp attack prevention, delta accounting, and pre-deployment audit checklists.
1.2k -
bankrbot Bundle Smart Contract AuditAudits EVM smart contracts across 19 domains using parallel specialist agents, synthesizes findings, and files GitHub issues.
1.2k -
bankrbot Bundle Aeon Vuln ScannerAudits trending open-source repos for exploitable vulnerabilities using Semgrep, TruffleHog, osv-scanner, and Slither, then routes findings to responsible disclosure channels (PVR for code flaws, public PRs for dependency CVEs).
1.2k -
bankrbot Bundle WalletsCreate and manage Ethereum wallets, including EOAs, smart contract wallets, Safe multisig, EIP-7702, and account abstraction, with AI agent key safety rules and transaction approval thresholds.
1.2k -
bankrbot Bundle SecurityAudit Solidity smart contracts for reentrancy, oracle manipulation, token decimals, SafeERC20, ERC-4626 inflation, infinite approvals, and MEV vulnerabilities with a pre-deployment checklist.
Audited 1.2k -
bankrbot Bundle Aeon Skill Security ScanAudit installed SKILL.md files and companion scripts for shell injection, secret exfiltration, path traversal, prompt-override payloads, destructive commands, and obfuscation. Integrates with Bankr Safety Scores and produces delta reports against prior scans.
Audited 1.2k -
dimillian Bundle Review SwarmLaunches four parallel read-only sub-agents to review a git diff or file scope for regressions, security risks, performance issues, and contract gaps, then aggregates findings into a prioritized fix path.
3.8k -
mcollina Bundle OAUTHImplements OAuth 2.0/2.1 authorization flows in Fastify applications, including authorization code with PKCE, client credentials, device flow, refresh token rotation, JWT validation, and token introspection/revocation endpoints.
Audited 1.9k -
mukul975 Bundle Securing Kubernetes On CloudHardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring.
24.6k -
mukul975 Bundle Securing Serverless FunctionsHardens serverless compute platforms (AWS Lambda, Azure Functions, Google Cloud Functions) by enforcing least privilege IAM roles, eliminating hardcoded secrets, scanning dependencies for vulnerabilities, validating input, securing function URLs, and enabling runtime monitoring.
24.6k -
mukul975 Bundle Defending Llms With GuardrailsDeploy Llama Guard, NeMo Guardrails, and LLM Guard as runtime input/output scanners to block jailbreaks, prompt injection, and toxic content in production LLM applications.
24.6k -
mukul975 Bundle Implementing Saml Sso With OktaConfigure Okta as a SAML 2.0 Identity Provider and implement SP-initiated and IdP-initiated SSO flows with attribute mapping, assertion encryption, and security hardening.
Audited 24.6k -
mukul975 Bundle Securing Helm Chart DeploymentsSecure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
24.6k