Trail of Bits
- 103 skills
- 0 followers
- 7k repo stars
- 75 verified
- 2 weeks ago last updated
- ▌ Second Opinion 2 · trailofbits bundleGets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits. Use when the user requests an external review, a second opinion on code, a codex review, a gemini review, an antigravity review, or /second-opinion.
- ▌ Mutation Testing 2 · trailofbits bundleConfigures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
- ▌ Review Walkthrough · trailofbits bundleGenerates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.
- ▌ Post Patch Validation · trailofbits bundleValidates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation, regressions, and newly introduced security failures. Use after a patch exists and before accepting, merging, or reporting it as fixed; also use when an AI-generated patch, remediation commit, pull request, or proposed upstream fix needs adversarial post-patch validation across any language.
- ▌ Idac · trailofbits bundleUse for reverse-engineering work through the local `idac` CLI against a live IDA GUI session, an existing `.i64` / `.idb` database, or a binary that IDA can open. Trigger this skill when the task involves decompilation, disassembly, ctree or microcode inspection, functions, locals, types, xrefs, strings, imports, C++ class or vtable recovery, target or backend selection, prototype or local/type mutations, reanalysis, or IDAPython execution through IDA.
- ▌ Context Loader · trailofbits bundleSynchronizes startup context across Claude instances, runs at launch.
- ▌
- ▌ Teach · trailofbits bundleTeaches the user a new skill or concept over multiple sessions, using the current directory as a stateful teaching workspace with lessons, learning records, and reference materials.
- ▌ Handoff · trailofbitsCompacts the current conversation into a handoff document so a fresh agent can continue the work in a new session.
- ▌ Grilling · trailofbitsInterviews the user relentlessly about a plan, decision, or idea until every branch of the decision tree is resolved. Use when the user wants to stress-test their thinking, sharpen a plan or design before acting, or uses any 'grill' trigger phrase (e.g. "grill me on this").
- ▌ Ghidra Headless · trailofbits bundleReverse engineers binaries using Ghidra's headless analyzer. Use when decompiling executables, extracting functions, strings, symbols, or analyzing call graphs from compiled binaries without the Ghidra GUI.
- ▌ Openai Gh Fix CI · trailofbits bundleUse when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft a fix plan, and implement only after explicit approval. Treat external providers (for example Buildkite) as out of scope and report only the details URL. Originally from OpenAI's curated skills catalog.
- ▌ Writing Great Skills · trailofbits bundleReference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.
- ▌ Openai Gh Address Comments · trailofbits bundleHelp address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the user to authenticate if not logged in. Originally from OpenAI's curated skills catalog.
- ▌ Rust Review 2 · trailofbitsPerforms comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. Use when auditing Rust crates, services, or libraries — particularly those with `unsafe`, FFI, or concurrent code.
- ▌ Codeql 2 · trailofbits bundle>- Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.
- ▌
- ▌ Trailmark Variant Neighborhood · trailofbits bundleExpands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes. Use after one issue is found to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review with graph-derived candidate locations.
- ▌ Writing Lean Proofs · trailofbits bundleWrites and reviews structured Lean 4 proofs and designs Lean libraries following Mathlib conventions. Use when proving theorems in Lean, formalizing mathematics or specifications in Lean 4, defining new types or definitions in a Lean library, reviewing Lean proofs for readability and maintainability, refactoring long tactic proofs into lemmas, filling in sorry placeholders in a Lean development, setting up CI or linters for a Lean project, diagnosing slow proofs or maxHeartbeats timeouts, or writing custom tactics, macros, or linters.
- ▌ Trailmark Finding Triage · trailofbits bundlePerforms graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence. Use when deciding whether one candidate issue is reachable, prioritizing a finding before PoC work, preparing evidence for exploit validation, or checking whether a static-analysis result is actionable.
- ▌ Trailmark Review Gate · trailofbits bundleRuns a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge.
- ▌ Slicing Code Context · trailofbits bundleSelects bounded, graph-informed source slices with Trailmark and delegates focused code analysis or patch-proposal work to a smaller subagent. Use when offloading function-, class-, caller-, callee-, call-path-, entrypoint-, or line-focused code tasks to constrained or locally hosted models without exposing the full repository.
- ▌ Open Sourcing · trailofbits bundleThis skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public", "check open-source readiness", "choose a license for this project", or "set up release automation" ahead of a public launch. Provides a release-readiness workflow covering secrets hygiene, licensing, documentation, CI, and language-specific packaging.
- ▌ Github Triage · trailofbits bundleTriages a repository's open GitHub issues and pull requests via the gh CLI. Optionally reviews and merges ready PRs — incrementally merging passing automated/bot PRs and maintainer-approved ones, and spawning review subagents for never-reviewed ones — then closes already-resolved issues with comments citing the resolving PR or commit, cross-links issues with their pending fix PRs, and assigns local-only priority and change-size estimates for everything outstanding. Use when triaging, grooming, or reviewing a repository's open issues and PRs.
- ▌ Goal Prompt · trailofbits bundleDrafts copy-paste-ready /goal commands for goal mode in Claude Code and Codex. Use when the user asks to create, write, rewrite, improve, compress, clean up, or prepare a goal prompt, goal condition, /goal command, goal-mode objective, or copy-ready long-running task objective.
- ▌ Pr Improver · trailofbitsRuns an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. Reviews are performed by an installed PR-review skill (default: pr-review-toolkit's review-pr). Use to fix review findings on a branch before opening or updating a pull request ('clean up this branch', 'fix this PR until review passes', 'run review-and-fix on my changes'). NOT for a one-time review — run the PR-review skill directly.
- ▌ Code Improver · trailofbitsRuns an autonomous review-and-fix improvement loop over any code target — a skill, plugin, module, or directory — using a reviewer the user names: any installed skill or agent. Keeps a cross-round findings ledger, escalates when fixes stop converging, and guards scope mechanically. Use when asked to 'improve this code until review passes', 'run an improvement loop with <reviewer>', or to iterate review-and-fix with a specific reviewer. For skills prefer the skill-improver entry; for a branch prefer pr-improver.
- ▌ Modern Cpp · trailofbits bundleGuides C++ code toward modern idioms (C++20/23/26). Use when writing new C++ code, modernizing legacy patterns, or working on security-critical C++. Replaces raw pointers with smart pointers, SFINAE with concepts, printf with std::print, error codes with std::expected.
- ▌ Interpreting Culture Index · trailofbits bundleInterprets Culture Index survey data, behavioral profiles, and personality assessments from JSON or PDF. Supports individual profile interpretation, team composition analysis, burnout detection, hiring profiles, manager coaching, interview transcript analysis, and conflict mediation.
- ▌ Burpsuite Project Parser · trailofbits bundleSearches and extracts data from Burp Suite project files (.burp) using the burpsuite-project-file-parser extension, enabling regex searches on response headers and bodies, extraction of security audit findings, and analysis of proxy history and site map data.
- ▌ Testing Handbook Generator · trailofbits bundleGenerates Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.
- ▌ Ton Vulnerability Scanner · trailofbits bundleScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
- ▌ Supply Chain Risk Auditor · trailofbits bundleAudits project dependencies for supply chain risks including single maintainers, unmaintained packages, low popularity, high-risk features, past CVEs, and missing security contacts.
- ▌ Token Integration Analyzer · trailofbits bundleAnalyzes token implementations and integrations for ERC20/ERC721 conformity, weird token patterns, contract composition, owner privileges, and on-chain scarcity.
- ▌ Cairo Vulnerability Scanner · trailofbits bundleScans Cairo/StarkNet smart contracts for 6 critical vulnerability patterns including arithmetic overflow, L1-L2 messaging issues, and signature replay. Use when auditing StarkNet projects.
- ▌ Cosmos Vulnerability Scanner · trailofbits bundleScans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities such as chain halts, fund loss, and state divergence.
- ▌ Solana Vulnerability Scanner · trailofbits bundleScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
- ▌ Algorand Vulnerability Scanner · trailofbits bundleScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues.
- ▌ Substrate Vulnerability Scanner · trailofbits bundleScans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
- ▌ Semgrep Rule Variant Creator · trailofbits bundlePorts existing Semgrep rules to new target languages with applicability analysis and test-driven validation.
- ▌ Chrome MCP Troubleshooting · trailofbits bundleDiagnose and fix connectivity issues with the Claude in Chrome MCP extension, including native host conflicts between Claude.app and Claude Code CLI.
- ▌ Ask Questions If Underspecified · trailofbits bundleClarify requirements before implementing by asking targeted questions when a request has multiple plausible interpretations or key details are unclear.
- ▌ Dwarf Expert · trailofbits bundleProvides expertise for analyzing DWARF debug files and understanding the DWARF debug format (v3-v5). Triggers when understanding DWARF information, interacting with DWARF files, answering DWARF-related questions, or working with code that parses DWARF data.
- ▌ Modern Python · trailofbits bundleConfigures Python projects with modern tooling (uv, ruff, ty) for new projects, scripts, or migrations from legacy tools.
- ▌ Trailmark Summary · trailofbits bundleRuns a Trailmark summary analysis on a codebase to auto-detect languages, count entry points, and list dependencies.
- ▌ Zeroize Audit · trailofbits bundleDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
- ▌ Audit Augmentation · trailofbits bundleProjects external audit findings from SARIF static analysis results and weAudit annotation files onto Trailmark code graphs as annotations and subgraphs, enabling cross-referencing with pre-analysis data like blast radius and taint.
- ▌ Second Opinion · trailofbits bundleRuns external LLM code reviews (OpenAI Codex or Google Gemini CLI) on uncommitted changes, branch diffs, or specific commits.
- ▌ Skill Improver · trailofbits bundleIteratively reviews and fixes Claude Code skill quality issues by running automated fix-review cycles using the skill-reviewer agent until they meet standards.
- ▌ Sarif Parsing · trailofbits bundleParse, analyze, and process SARIF files from static analysis tools like CodeQL and Semgrep, including filtering, deduplication, aggregation, and CI/CD integration.
- ▌ Aflpp · trailofbits bundleFuzz C/C++ projects with multi-core support using AFL++, a fork of AFL with better performance and advanced features.
- ▌ Ruzzy · trailofbits bundleCoverage-guided fuzzing for Ruby code and C extensions using libFuzzer and sanitizers.
- ▌ Mermaid To Proverif · trailofbits bundleTranslates Mermaid sequence diagrams of cryptographic protocols into ProVerif formal verification models (.pv files) for proving security properties like secrecy, authentication, and forward secrecy.
- ▌ Libafl · trailofbits bundleBuild custom fuzzers with a modular Rust library, supporting advanced mutation strategies, custom feedback mechanisms, and non-standard target architectures.
- ▌ Trailmark Structural · trailofbits bundleRuns full Trailmark structural analysis by building a graph and computing pre-analysis passes for hotspots, taint, blast radius, privilege boundaries, and attack surface.
- ▌ Debug Buttercup · trailofbits bundleDiagnose pod crashes, restart loops, Redis failures, resource pressure, and other service misbehavior in the crs namespace on Kubernetes.
- ▌ Let Fate Decide · trailofbits bundleDraws a Tarot spread to inject randomness into decision-making when prompts are vague or multiple approaches are equally valid.
- ▌ Atheris · trailofbits bundleFuzz Python code and C extensions with coverage guidance and AddressSanitizer support using a libFuzzer-based fuzzer.
- ▌ Ossfuzz · trailofbits bundleSet up continuous fuzzing infrastructure for open-source projects using Google's OSS-Fuzz platform, including building and running fuzz harnesses locally and enrolling new projects.
- ▌ Mutation Testing · trailofbits bundleConfigures mewt or muton mutation testing campaigns — scopes targets, tunes timeouts, and optimizes long-running runs.
- ▌ Libfuzzer · trailofbits bundleCoverage-guided fuzzer built into LLVM for C/C++ projects. Use for fuzzing C/C++ code that can be compiled with Clang.
- ▌ Crypto Protocol Diagram · trailofbits bundleExtracts protocol message flow from source code, RFCs, academic papers, pseudocode, or formal models (ProVerif/Tamarin) and generates Mermaid sequence diagrams with cryptographic annotations.
- ▌ Variant Analysis · trailofbits bundleFind similar vulnerabilities and bugs across codebases using pattern-based analysis after identifying an initial issue.
- ▌ Cargo Fuzz · trailofbits bundleFuzz Rust projects with libFuzzer using cargo-fuzz, including harness writing, sanitizer integration, and coverage analysis.
- ▌ Wycheproof · trailofbits bundleValidate cryptographic implementations against known attacks and edge cases using Wycheproof test vectors.
- ▌ Yara Rule Authoring · trailofbits bundleWrite high-quality YARA-X detection rules for malware identification, covering naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction.
- ▌ Insecure Defaults · trailofbits bundleDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
- ▌ Devcontainer Setup · trailofbits bundleCreates pre-configured devcontainers with Claude Code, language-specific tooling (Python, Node, Rust, Go), and persistent volumes for isolated development environments.
- ▌ Seatbelt Sandboxer · trailofbits bundleGenerates minimal macOS Seatbelt sandbox configurations to isolate and restrict applications with allowlist-based profiles.
- ▌ Differential Review · trailofbits bundlePerforms security-focused differential review of code changes (PRs, commits, diffs), adapting analysis depth to codebase size and generating comprehensive markdown reports.
- ▌ Harness Writing · trailofbits bundleWrite effective fuzzing harnesses across languages to improve code coverage and find bugs in your system under test.
- ▌ Dimensional Analysis · trailofbits bundleOrchestrates a dimensional-analysis pipeline to annotate codebases with unit/dimension comments, discover dimensional vocabulary, and detect arithmetic bugs from unit mismatches or precision loss.
- ▌ Entry Point Analyzer · trailofbits bundleIdentifies state-changing entry points in smart contract codebases for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.
- ▌ Firebase Apk Scanner · trailofbits bundleScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
- ▌ Semgrep Rule Creator · trailofbits bundleCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns with proper testing and validation.
- ▌ Address Sanitizer · trailofbits bundleDetect memory errors like buffer overflows and use-after-free bugs in C/C++ code during fuzzing and testing using AddressSanitizer.
- ▌ Coverage Analysis · trailofbits bundleMeasures code coverage during fuzzing to assess harness effectiveness and identify fuzzing blockers.
- ▌ Fuzzing Obstacles · trailofbits bundlePatch code to bypass checksums, global state, and validation checks that block fuzzer progress, using conditional compilation for C/C++ and Rust.
- ▌ Fuzzing Dictionary · trailofbits bundleGuides fuzzers with domain-specific tokens to reach deeper code paths in parsers, protocol handlers, and file format processors.
- ▌ Guidelines Advisor · trailofbits bundleAnalyzes smart contract codebases against Trail of Bits' secure development guidelines, generating documentation, reviewing architecture and upgradeability patterns, assessing implementation quality, identifying pitfalls, and providing prioritized recommendations.
- ▌ Audit Context Building · trailofbits bundleEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
- ▌ Constant Time Analysis · trailofbits bundleAnalyzes cryptographic code to detect operations that leak secret data through execution timing variations, supporting multiple languages.
- ▌ Property Based Testing · trailofbits bundleProvides guidance for property-based testing across multiple languages and smart contracts, helping detect patterns where PBT offers stronger coverage than example-based tests.
- ▌ Constant Time Testing · trailofbits bundleDetect timing side channels in cryptographic code using formal, symbolic, dynamic, and statistical testing tools.
- ▌ Audit Prep Assistant · trailofbits bundlePrepares codebases for security review using Trail of Bits' checklist by setting review goals, running static analysis, increasing test coverage, removing dead code, and generating documentation.
- ▌ Agentic Actions Auditor · trailofbits bundleAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
- ▌ Secure Workflow Guide · trailofbits bundleGuides through a 5-step secure development workflow for smart contracts, including automated scanning with Slither, special feature validation, visual security diagrams, security property documentation, and manual review.
- ▌ Spec To Code Compliance · trailofbits bundleVerifies that blockchain code implements exactly what documentation specifies, identifying gaps between specs and implementation for audit engagements.
- ▌ Designing Workflow Skills · trailofbits bundleGuides the design and structuring of workflow-based Claude Code skills with multi-step phases, decision trees, subagent delegation, and progressive disclosure.
- ▌ Code Maturity Assessor · trailofbits bundleAssesses codebase maturity using Trail of Bits' 9-category framework, producing a professional scorecard with evidence-based ratings and actionable recommendations.
- ▌ Gh CLI · trailofbits bundleEnforces authenticated gh CLI workflows over unauthenticated curl/WebFetch patterns for GitHub operations.
- ▌ C Review · trailofbits bundlePerforms comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. Use when auditing native C/C++ applications, reviewing daemons or services for memory safety, or hunting integer overflow / use-after-free / race conditions in userspace code.
- ▌ Fp Check · trailofbits bundleVerifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.
- ▌ Genotoxic · trailofbits bundleTriage mutation testing results by combining survived mutants, unnecessary test statements, and code graph analysis to identify false positives, missing test coverage, and fuzzing targets.
- ▌ Trailmark · trailofbits bundleBuilds and queries multi-language source code graphs for security analysis, including blast radius, taint propagation, privilege boundaries, and entry point enumeration.
- ▌ Codeql · trailofbits bundleScans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis, with support for multiple languages, scan modes, and data extension models.
- ▌ Vector Forge · trailofbits bundleUses mutation testing to systematically identify gaps in test vector coverage for cryptographic algorithms, then generates new test vectors that close those gaps. Measures effectiveness by comparing mutation kill rates before and after.
- ▌ Git Cleanup · trailofbits bundleSafely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.
- ▌ Rust Review · trailofbitsAudits Rust codebases for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes.
- ▌ Sharp Edges · trailofbits bundleIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes in API designs, configuration schemas, and cryptographic library ergonomics.