π―Skills55
ask-questions-if-underspecified skill from trailofbits/skills
semgrep skill from trailofbits/skills
differential-review skill from trailofbits/skills
secure-workflow-guide skill from trailofbits/skills
sharp-edges skill from trailofbits/skills
property-based-testing skill from trailofbits/skills
codeql skill from trailofbits/skills
variant-analysis skill from trailofbits/skills
guidelines-advisor skill from trailofbits/skills
token-integration-analyzer skill from trailofbits/skills
Parses SARIF (Static Analysis Results Interchange Format) files to process outputs from security scanners like CodeQL, Semgrep, and other static analysis tools
audit-context-building skill from trailofbits/skills
Identifies and resolves common obstacles in software fuzzing campaigns, improving coverage and vulnerability detection with advanced strategies
spec-to-code-compliance skill from trailofbits/skills
solana-vulnerability-scanner skill from trailofbits/skills
audit-prep-assistant skill from trailofbits/skills
code-maturity-assessor skill from trailofbits/skills
coverage-analysis skill from trailofbits/skills
entry-point-analyzer skill from trailofbits/skills
semgrep-rule-creator skill from trailofbits/skills
constant-time-analysis skill from trailofbits/skills
cargo-fuzz skill from trailofbits/skills
address-sanitizer skill from trailofbits/skills
fuzzing-dictionary skill from trailofbits/skills
harness-writing skill from trailofbits/skills
Generates comprehensive software testing handbooks covering test cases, scenarios, and best practices for development and QA teams
Scans Cosmos blockchain smart contracts for security vulnerabilities using static analysis and security best practice checks
Tests cryptographic code for timing vulnerabilities that could expose sensitive data through execution time variations
Scans Algorand blockchain smart contracts for security vulnerabilities and provides detailed remediation insights
fix-review skill from trailofbits/skills
Provides LibFuzzer patterns for coverage-guided fuzzing of C/C++ libraries, including harness writing, corpus management, and crash analysis
Integrates projects with Google OSS-Fuzz for continuous fuzzing of open source software, covering configuration and integration best practices
Provides Atheris patterns for Python fuzzing using LibFuzzer-based coverage-guided testing to discover bugs and vulnerabilities
Interprets Culture Index assessment results to provide insights on team dynamics, work patterns, and leadership style compatibility
Scans Substrate blockchain runtime code for security vulnerabilities with static analysis and detailed security reporting
Provides AFL++ patterns for advanced coverage-guided fuzzing including custom mutators, persistent mode, and crash deduplication
Provides LibAFL patterns for building custom fuzzers in Rust with coverage-guided feedback, hybrid fuzzing, and multi-architecture support
dwarf-expert skill from trailofbits/skills
Tests cryptographic implementations against Google Wycheproof test vectors to identify weaknesses in crypto libraries and protocols
Scans TON blockchain smart contracts for security vulnerabilities using static analysis techniques
Scans Cairo smart contracts on Starknet for security vulnerabilities with automated static analysis and detailed reporting
Provides Ruzzy patterns for Ruby fuzzing with coverage-guided testing to discover vulnerabilities in Ruby C extensions
firebase-apk-scanner skill from trailofbits/skills
semgrep-rule-variant-creator skill from trailofbits/skills
modern-python skill from trailofbits/skills
insecure-defaults skill from trailofbits/skills
burpsuite-project-parser skill from trailofbits/skills
Assists security researchers in creating, refining, and validating YARA rules for malware detection and threat hunting.
claude-in-chrome-troubleshooting skill from trailofbits/skills
Provides expert code review and alternative implementation suggestions to improve code quality, performance, and maintainability
Sets up reproducible development environments using Visual Studio Code Dev Containers with pre-configured toolchains and dependencies
Automates systematic debugging of Python code by identifying potential errors, performance bottlenecks, and memory leaks with intelligent analysis.
burp-suite skill from trailofbits/skills
Automates Git repository maintenance by removing stale branches, cleaning up local refs, and optimizing repository size and performance
Streamline GitHub workflow automation, repository management, and CLI-based interactions with powerful GitHub CLI commands and scripting techniques
πPlugins3
Interprets Culture Index survey results for individuals and teams
Create custom Semgrep rules for detecting bug patterns and security vulnerabilities
Skills from the Trail of Bits Application Security Testing Handbook (appsec.guide)
