all publishers

Trail of Bits

@trailofbits source repo

103 published skills · page 1 of 2

  1. ▌
    Second Opinion 2 · trailofbits bundle
    Gets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits. Use when the user requests an external review, a second opinion on code, a codex review, a gemini review, an antigravity review, or /second-opinion.
    7k repo stars
  2. ▌
    Mutation Testing 2 · trailofbits bundle
    Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
    7k repo stars
  3. ▌
    Review Walkthrough · trailofbits bundle
    Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.
    7k repo stars
  4. ▌
    Post Patch Validation · trailofbits bundle
    Validates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation, regressions, and newly introduced security failures. Use after a patch exists and before accepting, merging, or reporting it as fixed; also use when an AI-generated patch, remediation commit, pull request, or proposed upstream fix needs adversarial post-patch validation across any language.
    7k repo stars
  5. ▌
    Idac · trailofbits bundle
    Use for reverse-engineering work through the local `idac` CLI against a live IDA GUI session, an existing `.i64` / `.idb` database, or a binary that IDA can open. Trigger this skill when the task involves decompilation, disassembly, ctree or microcode inspection, functions, locals, types, xrefs, strings, imports, C++ class or vtable recovery, target or backend selection, prototype or local/type mutations, reanalysis, or IDAPython execution through IDA.
    7k repo stars
  6. ▌
    Context Loader · trailofbits bundle
    Synchronizes startup context across Claude instances, runs at launch.
    7k repo stars
  7. ▌
    CSV Summarizer · trailofbits bundle
    Print row and column counts for a CSV file
    7k repo stars
  8. ▌
    Teach · trailofbits bundle
    Teaches the user a new skill or concept over multiple sessions, using the current directory as a stateful teaching workspace with lessons, learning records, and reference materials.
    7k repo stars
  9. ▌
    Handoff · trailofbits
    Compacts the current conversation into a handoff document so a fresh agent can continue the work in a new session.
    7k repo stars
  10. ▌
    Grilling · trailofbits
    Interviews the user relentlessly about a plan, decision, or idea until every branch of the decision tree is resolved. Use when the user wants to stress-test their thinking, sharpen a plan or design before acting, or uses any 'grill' trigger phrase (e.g. "grill me on this").
    7k repo stars
  11. ▌
    Ghidra Headless · trailofbits bundle
    Reverse engineers binaries using Ghidra's headless analyzer. Use when decompiling executables, extracting functions, strings, symbols, or analyzing call graphs from compiled binaries without the Ghidra GUI.
    7k repo stars
  12. ▌
    Openai Gh Fix CI · trailofbits bundle
    Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft a fix plan, and implement only after explicit approval. Treat external providers (for example Buildkite) as out of scope and report only the details URL. Originally from OpenAI's curated skills catalog.
    7k repo stars
  13. ▌
    Writing Great Skills · trailofbits bundle
    Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.
    7k repo stars
  14. ▌
    Openai Gh Address Comments · trailofbits bundle
    Help address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the user to authenticate if not logged in. Originally from OpenAI's curated skills catalog.
    7k repo stars
  15. ▌
    Rust Review 2 · trailofbits
    Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. Use when auditing Rust crates, services, or libraries — particularly those with `unsafe`, FFI, or concurrent code.
    7k repo stars
  16. ▌
    Codeql 2 · trailofbits bundle
    >- Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.
    7k repo stars
  17. ▌
    Fix Review · trailofbits
    Verify fix commits address audit findings without new bugs
    7k repo stars
  18. ▌
    Trailmark Variant Neighborhood · trailofbits bundle
    Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes. Use after one issue is found to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review with graph-derived candidate locations.
    7k repo stars
  19. ▌
    Writing Lean Proofs · trailofbits bundle
    Writes and reviews structured Lean 4 proofs and designs Lean libraries following Mathlib conventions. Use when proving theorems in Lean, formalizing mathematics or specifications in Lean 4, defining new types or definitions in a Lean library, reviewing Lean proofs for readability and maintainability, refactoring long tactic proofs into lemmas, filling in sorry placeholders in a Lean development, setting up CI or linters for a Lean project, diagnosing slow proofs or maxHeartbeats timeouts, or writing custom tactics, macros, or linters.
    7k repo stars
  20. ▌
    Trailmark Finding Triage · trailofbits bundle
    Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence. Use when deciding whether one candidate issue is reachable, prioritizing a finding before PoC work, preparing evidence for exploit validation, or checking whether a static-analysis result is actionable.
    7k repo stars
  21. ▌
    Trailmark Review Gate · trailofbits bundle
    Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge.
    7k repo stars
  22. ▌
    Slicing Code Context · trailofbits bundle
    Selects bounded, graph-informed source slices with Trailmark and delegates focused code analysis or patch-proposal work to a smaller subagent. Use when offloading function-, class-, caller-, callee-, call-path-, entrypoint-, or line-focused code tasks to constrained or locally hosted models without exposing the full repository.
    7k repo stars
  23. ▌
    Open Sourcing · trailofbits bundle
    This skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public", "check open-source readiness", "choose a license for this project", or "set up release automation" ahead of a public launch. Provides a release-readiness workflow covering secrets hygiene, licensing, documentation, CI, and language-specific packaging.
    7k repo stars
  24. ▌
    Github Triage · trailofbits bundle
    Triages a repository's open GitHub issues and pull requests via the gh CLI. Optionally reviews and merges ready PRs — incrementally merging passing automated/bot PRs and maintainer-approved ones, and spawning review subagents for never-reviewed ones — then closes already-resolved issues with comments citing the resolving PR or commit, cross-links issues with their pending fix PRs, and assigns local-only priority and change-size estimates for everything outstanding. Use when triaging, grooming, or reviewing a repository's open issues and PRs.
    7k repo stars
  25. ▌
    Goal Prompt · trailofbits bundle
    Drafts copy-paste-ready /goal commands for goal mode in Claude Code and Codex. Use when the user asks to create, write, rewrite, improve, compress, clean up, or prepare a goal prompt, goal condition, /goal command, goal-mode objective, or copy-ready long-running task objective.
    7k repo stars
  26. ▌
    Pr Improver · trailofbits
    Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. Reviews are performed by an installed PR-review skill (default: pr-review-toolkit's review-pr). Use to fix review findings on a branch before opening or updating a pull request ('clean up this branch', 'fix this PR until review passes', 'run review-and-fix on my changes'). NOT for a one-time review — run the PR-review skill directly.
    7k repo stars
  27. ▌
    Code Improver · trailofbits
    Runs an autonomous review-and-fix improvement loop over any code target — a skill, plugin, module, or directory — using a reviewer the user names: any installed skill or agent. Keeps a cross-round findings ledger, escalates when fixes stop converging, and guards scope mechanically. Use when asked to 'improve this code until review passes', 'run an improvement loop with <reviewer>', or to iterate review-and-fix with a specific reviewer. For skills prefer the skill-improver entry; for a branch prefer pr-improver.
    7k repo stars
  28. ▌
    Modern Cpp · trailofbits bundle
    Guides C++ code toward modern idioms (C++20/23/26). Use when writing new C++ code, modernizing legacy patterns, or working on security-critical C++. Replaces raw pointers with smart pointers, SFINAE with concepts, printf with std::print, error codes with std::expected.
    7k repo stars
  29. ▌
    Interpreting Culture Index · trailofbits bundle
    Interprets Culture Index survey data, behavioral profiles, and personality assessments from JSON or PDF. Supports individual profile interpretation, team composition analysis, burnout detection, hiring profiles, manager coaching, interview transcript analysis, and conflict mediation.
    7k repo stars
  30. ▌
    Burpsuite Project Parser · trailofbits bundle
    Searches and extracts data from Burp Suite project files (.burp) using the burpsuite-project-file-parser extension, enabling regex searches on response headers and bodies, extraction of security audit findings, and analysis of proxy history and site map data.
    7k repo stars
  31. ▌
    Testing Handbook Generator · trailofbits bundle
    Generates Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.
    7k repo stars
  32. ▌
    Ton Vulnerability Scanner · trailofbits bundle
    Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
    7k repo stars
  33. ▌
    Supply Chain Risk Auditor · trailofbits bundle
    Audits project dependencies for supply chain risks including single maintainers, unmaintained packages, low popularity, high-risk features, past CVEs, and missing security contacts.
    7k repo stars
  34. ▌
    Token Integration Analyzer · trailofbits bundle
    Analyzes token implementations and integrations for ERC20/ERC721 conformity, weird token patterns, contract composition, owner privileges, and on-chain scarcity.
    7k repo stars
  35. ▌
    Cairo Vulnerability Scanner · trailofbits bundle
    Scans Cairo/StarkNet smart contracts for 6 critical vulnerability patterns including arithmetic overflow, L1-L2 messaging issues, and signature replay. Use when auditing StarkNet projects.
    7k repo stars
  36. ▌
    Cosmos Vulnerability Scanner · trailofbits bundle
    Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities such as chain halts, fund loss, and state divergence.
    7k repo stars
  37. ▌
    Solana Vulnerability Scanner · trailofbits bundle
    Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
    7k repo stars
  38. ▌
    Algorand Vulnerability Scanner · trailofbits bundle
    Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues.
    7k repo stars
  39. ▌
    Substrate Vulnerability Scanner · trailofbits bundle
    Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
    7k repo stars
  40. ▌
    Semgrep Rule Variant Creator · trailofbits bundle
    Ports existing Semgrep rules to new target languages with applicability analysis and test-driven validation.
    7k repo stars
  41. ▌
    Chrome MCP Troubleshooting · trailofbits bundle
    Diagnose and fix connectivity issues with the Claude in Chrome MCP extension, including native host conflicts between Claude.app and Claude Code CLI.
    7k repo stars
  42. ▌
    Ask Questions If Underspecified · trailofbits bundle
    Clarify requirements before implementing by asking targeted questions when a request has multiple plausible interpretations or key details are unclear.
    7k repo stars
  43. ▌
    Dwarf Expert · trailofbits bundle
    Provides expertise for analyzing DWARF debug files and understanding the DWARF debug format (v3-v5). Triggers when understanding DWARF information, interacting with DWARF files, answering DWARF-related questions, or working with code that parses DWARF data.
    7k repo stars
  44. ▌
    Modern Python · trailofbits bundle
    Configures Python projects with modern tooling (uv, ruff, ty) for new projects, scripts, or migrations from legacy tools.
    7k repo stars
  45. ▌
    Trailmark Summary · trailofbits bundle
    Runs a Trailmark summary analysis on a codebase to auto-detect languages, count entry points, and list dependencies.
    7k repo stars
  46. ▌
    Zeroize Audit · trailofbits bundle
    Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
    7k repo stars
  47. ▌
    Audit Augmentation · trailofbits bundle
    Projects external audit findings from SARIF static analysis results and weAudit annotation files onto Trailmark code graphs as annotations and subgraphs, enabling cross-referencing with pre-analysis data like blast radius and taint.
    7k repo stars
  48. ▌
    Second Opinion · trailofbits bundle
    Runs external LLM code reviews (OpenAI Codex or Google Gemini CLI) on uncommitted changes, branch diffs, or specific commits.
    7k repo stars
  49. ▌
    Skill Improver · trailofbits bundle
    Iteratively reviews and fixes Claude Code skill quality issues by running automated fix-review cycles using the skill-reviewer agent until they meet standards.
    7k repo stars
  50. ▌
    Sarif Parsing · trailofbits bundle
    Parse, analyze, and process SARIF files from static analysis tools like CodeQL and Semgrep, including filtering, deduplication, aggregation, and CI/CD integration.
    7k repo stars
  51. ▌
    Aflpp · trailofbits bundle
    Fuzz C/C++ projects with multi-core support using AFL++, a fork of AFL with better performance and advanced features.
    7k repo stars
  52. ▌
    Ruzzy · trailofbits bundle
    Coverage-guided fuzzing for Ruby code and C extensions using libFuzzer and sanitizers.
    7k repo stars
  53. ▌
    Mermaid To Proverif · trailofbits bundle
    Translates Mermaid sequence diagrams of cryptographic protocols into ProVerif formal verification models (.pv files) for proving security properties like secrecy, authentication, and forward secrecy.
    7k repo stars
  54. ▌
    Libafl · trailofbits bundle
    Build custom fuzzers with a modular Rust library, supporting advanced mutation strategies, custom feedback mechanisms, and non-standard target architectures.
    7k repo stars
  55. ▌
    Trailmark Structural · trailofbits bundle
    Runs full Trailmark structural analysis by building a graph and computing pre-analysis passes for hotspots, taint, blast radius, privilege boundaries, and attack surface.
    7k repo stars
  56. ▌
    Debug Buttercup · trailofbits bundle
    Diagnose pod crashes, restart loops, Redis failures, resource pressure, and other service misbehavior in the crs namespace on Kubernetes.
    7k repo stars
  57. ▌
    Let Fate Decide · trailofbits bundle
    Draws a Tarot spread to inject randomness into decision-making when prompts are vague or multiple approaches are equally valid.
    7k repo stars
  58. ▌
    Atheris · trailofbits bundle
    Fuzz Python code and C extensions with coverage guidance and AddressSanitizer support using a libFuzzer-based fuzzer.
    7k repo stars
  59. ▌
    Ossfuzz · trailofbits bundle
    Set up continuous fuzzing infrastructure for open-source projects using Google's OSS-Fuzz platform, including building and running fuzz harnesses locally and enrolling new projects.
    7k repo stars
  60. ▌
    Mutation Testing · trailofbits bundle
    Configures mewt or muton mutation testing campaigns — scopes targets, tunes timeouts, and optimizes long-running runs.
    7k repo stars
  61. ▌
    Libfuzzer · trailofbits bundle
    Coverage-guided fuzzer built into LLVM for C/C++ projects. Use for fuzzing C/C++ code that can be compiled with Clang.
    7k repo stars
  62. ▌
    Crypto Protocol Diagram · trailofbits bundle
    Extracts protocol message flow from source code, RFCs, academic papers, pseudocode, or formal models (ProVerif/Tamarin) and generates Mermaid sequence diagrams with cryptographic annotations.
    7k repo stars
  63. ▌
    Variant Analysis · trailofbits bundle
    Find similar vulnerabilities and bugs across codebases using pattern-based analysis after identifying an initial issue.
    7k repo stars
  64. ▌
    Cargo Fuzz · trailofbits bundle
    Fuzz Rust projects with libFuzzer using cargo-fuzz, including harness writing, sanitizer integration, and coverage analysis.
    7k repo stars
  65. ▌
    Wycheproof · trailofbits bundle
    Validate cryptographic implementations against known attacks and edge cases using Wycheproof test vectors.
    7k repo stars
  66. ▌
    Yara Rule Authoring · trailofbits bundle
    Write high-quality YARA-X detection rules for malware identification, covering naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction.
    7k repo stars
  67. ▌
    Insecure Defaults · trailofbits bundle
    Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
    7k repo stars
  68. ▌
    Devcontainer Setup · trailofbits bundle
    Creates pre-configured devcontainers with Claude Code, language-specific tooling (Python, Node, Rust, Go), and persistent volumes for isolated development environments.
    7k repo stars
  69. ▌
    Seatbelt Sandboxer · trailofbits bundle
    Generates minimal macOS Seatbelt sandbox configurations to isolate and restrict applications with allowlist-based profiles.
    7k repo stars
  70. ▌
    Differential Review · trailofbits bundle
    Performs security-focused differential review of code changes (PRs, commits, diffs), adapting analysis depth to codebase size and generating comprehensive markdown reports.
    7k repo stars
  71. ▌
    Harness Writing · trailofbits bundle
    Write effective fuzzing harnesses across languages to improve code coverage and find bugs in your system under test.
    7k repo stars
  72. ▌
    Dimensional Analysis · trailofbits bundle
    Orchestrates a dimensional-analysis pipeline to annotate codebases with unit/dimension comments, discover dimensional vocabulary, and detect arithmetic bugs from unit mismatches or precision loss.
    7k repo stars
  73. ▌
    Entry Point Analyzer · trailofbits bundle
    Identifies state-changing entry points in smart contract codebases for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.
    7k repo stars
  74. ▌
    Firebase Apk Scanner · trailofbits bundle
    Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
    7k repo stars
  75. ▌
    Semgrep Rule Creator · trailofbits bundle
    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns with proper testing and validation.
    7k repo stars
  76. ▌
    Address Sanitizer · trailofbits bundle
    Detect memory errors like buffer overflows and use-after-free bugs in C/C++ code during fuzzing and testing using AddressSanitizer.
    7k repo stars
  77. ▌
    Coverage Analysis · trailofbits bundle
    Measures code coverage during fuzzing to assess harness effectiveness and identify fuzzing blockers.
    7k repo stars
  78. ▌
    Fuzzing Obstacles · trailofbits bundle
    Patch code to bypass checksums, global state, and validation checks that block fuzzer progress, using conditional compilation for C/C++ and Rust.
    7k repo stars
  79. ▌
    Fuzzing Dictionary · trailofbits bundle
    Guides fuzzers with domain-specific tokens to reach deeper code paths in parsers, protocol handlers, and file format processors.
    7k repo stars
  80. ▌
    Guidelines Advisor · trailofbits bundle
    Analyzes smart contract codebases against Trail of Bits' secure development guidelines, generating documentation, reviewing architecture and upgradeability patterns, assessing implementation quality, identifying pitfalls, and providing prioritized recommendations.
    7k repo stars
  81. ▌
    Audit Context Building · trailofbits bundle
    Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
    7k repo stars
  82. ▌
    Constant Time Analysis · trailofbits bundle
    Analyzes cryptographic code to detect operations that leak secret data through execution timing variations, supporting multiple languages.
    7k repo stars
  83. ▌
    Property Based Testing · trailofbits bundle
    Provides guidance for property-based testing across multiple languages and smart contracts, helping detect patterns where PBT offers stronger coverage than example-based tests.
    7k repo stars
  84. ▌
    Constant Time Testing · trailofbits bundle
    Detect timing side channels in cryptographic code using formal, symbolic, dynamic, and statistical testing tools.
    7k repo stars
  85. ▌
    Audit Prep Assistant · trailofbits bundle
    Prepares codebases for security review using Trail of Bits' checklist by setting review goals, running static analysis, increasing test coverage, removing dead code, and generating documentation.
    7k repo stars
  86. ▌
    Agentic Actions Auditor · trailofbits bundle
    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
    7k repo stars
  87. ▌
    Secure Workflow Guide · trailofbits bundle
    Guides through a 5-step secure development workflow for smart contracts, including automated scanning with Slither, special feature validation, visual security diagrams, security property documentation, and manual review.
    7k repo stars
  88. ▌
    Spec To Code Compliance · trailofbits bundle
    Verifies that blockchain code implements exactly what documentation specifies, identifying gaps between specs and implementation for audit engagements.
    7k repo stars
  89. ▌
    Designing Workflow Skills · trailofbits bundle
    Guides the design and structuring of workflow-based Claude Code skills with multi-step phases, decision trees, subagent delegation, and progressive disclosure.
    7k repo stars
  90. ▌
    Code Maturity Assessor · trailofbits bundle
    Assesses codebase maturity using Trail of Bits' 9-category framework, producing a professional scorecard with evidence-based ratings and actionable recommendations.
    7k repo stars
  91. ▌
    Gh CLI · trailofbits bundle
    Enforces authenticated gh CLI workflows over unauthenticated curl/WebFetch patterns for GitHub operations.
    7k repo stars
  92. ▌
    C Review · trailofbits bundle
    Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. Use when auditing native C/C++ applications, reviewing daemons or services for memory safety, or hunting integer overflow / use-after-free / race conditions in userspace code.
    7k repo stars
  93. ▌
    Fp Check · trailofbits bundle
    Verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.
    7k repo stars
  94. ▌
    Genotoxic · trailofbits bundle
    Triage mutation testing results by combining survived mutants, unnecessary test statements, and code graph analysis to identify false positives, missing test coverage, and fuzzing targets.
    7k repo stars
  95. ▌
    Trailmark · trailofbits bundle
    Builds and queries multi-language source code graphs for security analysis, including blast radius, taint propagation, privilege boundaries, and entry point enumeration.
    7k repo stars
  96. ▌
    Codeql · trailofbits bundle
    Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis, with support for multiple languages, scan modes, and data extension models.
    7k repo stars
  97. ▌
    Vector Forge · trailofbits bundle
    Uses mutation testing to systematically identify gaps in test vector coverage for cryptographic algorithms, then generates new test vectors that close those gaps. Measures effectiveness by comparing mutation kill rates before and after.
    7k repo stars
  98. ▌
    Git Cleanup · trailofbits bundle
    Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.
    7k repo stars
  99. ▌
    Rust Review · trailofbits
    Audits Rust codebases for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes.
    7k repo stars
  100. ▌
    Sharp Edges · trailofbits bundle
    Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes in API designs, configuration schemas, and cryptographic library ergonomics.
    7k repo stars