trailofbits

trailofbits/skills

105 resources in this repository

GitHub
🎯76πŸ”Œ28πŸͺ1
4,343

🎯Skills76

🎯ask-questions-if-underspecified🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

ask-questions-if-underspecified
🎯semgrep🎯Skill

Runs Semgrep static analysis for security vulnerability detection and code quality enforcement, from the Trail of Bits Skills Marketplace for AI-assisted security workflows.

semgrep
🎯modern-python🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

modern-python
🎯codeql🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

codeql
🎯secure-workflow-guide🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

secure-workflow-guide
🎯insecure-defaults🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

insecure-defaults
🎯code-maturity-assessor🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

code-maturity-assessor
🎯differential-review🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

differential-review
🎯sharp-edges🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

sharp-edges
🎯audit-context-building🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

audit-context-building
🎯supply-chain-risk-auditor🎯Skill

Supply chain risk auditor skill from Trail of Bits for analyzing dependency trees, detecting vulnerable packages, and auditing software supply chain security.

supply-chain-risk-auditor
🎯property-based-testing🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

property-based-testing
🎯variant-analysis🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

variant-analysis
🎯solana-vulnerability-scanner🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

solana-vulnerability-scanner
🎯fp-check🎯Skill

A Trail of Bits plugin that performs systematic false positive verification for security bug analysis, using mandatory gate reviews to ensure only valid security findings are reported.

fp-check
🎯spec-to-code-compliance🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

spec-to-code-compliance
🎯agentic-actions-auditor🎯Skill

Agentic actions auditor skill from Trail of Bits for auditing AI agent actions, ensuring safety and detecting potentially harmful behaviors.

agentic-actions-auditor
🎯sarif-parsing🎯Skill

Parses SARIF (Static Analysis Results Interchange Format) files to process outputs from security scanners like CodeQL, Semgrep, and other static analysis tools

sarif-parsing
🎯token-integration-analyzer🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

token-integration-analyzer
🎯entry-point-analyzer🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

entry-point-analyzer
🎯guidelines-advisor🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

guidelines-advisor
🎯audit-prep-assistant🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

audit-prep-assistant
🎯fuzzing-obstacles🎯Skill

Identifies and resolves common obstacles in software fuzzing campaigns, improving coverage and vulnerability detection with advanced strategies

fuzzing-obstacles
🎯semgrep-rule-creator🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

semgrep-rule-creator
🎯coverage-analysis🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

coverage-analysis
🎯harness-writing🎯Skill

Generates fuzzing test harnesses for security testing, from the Trail of Bits Skills Marketplace for AI-assisted security analysis and development workflows.

harness-writing
🎯firebase-apk-scanner🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

firebase-apk-scanner
🎯constant-time-analysis🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

constant-time-analysis
🎯cargo-fuzz🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

cargo-fuzz
🎯address-sanitizer🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

address-sanitizer
🎯testing-handbook-generator🎯Skill

Generates comprehensive software testing handbooks covering test cases, scenarios, and best practices for development and QA teams

testing-handbook-generator
🎯cosmos-vulnerability-scanner🎯Skill

Scans Cosmos blockchain smart contracts for security vulnerabilities using static analysis and security best practice checks

cosmos-vulnerability-scanner
🎯fuzzing-dictionary🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

fuzzing-dictionary
🎯constant-time-testing🎯Skill

Tests cryptographic code for timing vulnerabilities that could expose sensitive data through execution time variations

constant-time-testing
🎯algorand-vulnerability-scanner🎯Skill

Scans Algorand blockchain smart contracts for security vulnerabilities and provides detailed remediation insights

algorand-vulnerability-scanner
🎯interpreting-culture-index🎯Skill

Interprets Culture Index assessment results to provide insights on team dynamics, work patterns, and leadership style compatibility

interpreting-culture-index
🎯dwarf-expert🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

dwarf-expert
🎯libfuzzer🎯Skill

Provides LibFuzzer patterns for coverage-guided fuzzing of C/C++ libraries, including harness writing, corpus management, and crash analysis

libfuzzer
🎯ossfuzz🎯Skill

Integrates projects with Google OSS-Fuzz for continuous fuzzing of open source software, covering configuration and integration best practices

ossfuzz
🎯substrate-vulnerability-scanner🎯Skill

Scans Substrate blockchain runtime code for security vulnerabilities with static analysis and detailed security reporting

substrate-vulnerability-scanner
🎯wycheproof🎯Skill

Tests cryptographic implementations against Google Wycheproof test vectors to identify weaknesses in crypto libraries and protocols

wycheproof
🎯semgrep-rule-variant-creator🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

semgrep-rule-variant-creator
🎯ton-vulnerability-scanner🎯Skill

Scans TON blockchain smart contracts for security vulnerabilities using static analysis techniques

ton-vulnerability-scanner
🎯atheris🎯Skill

Provides Atheris patterns for Python fuzzing using LibFuzzer-based coverage-guided testing to discover bugs and vulnerabilities

atheris
🎯cairo-vulnerability-scanner🎯Skill

Scans Cairo smart contracts on Starknet for security vulnerabilities with automated static analysis and detailed reporting

cairo-vulnerability-scanner
🎯aflpp🎯Skill

Provides AFL++ patterns for advanced coverage-guided fuzzing including custom mutators, persistent mode, and crash deduplication

aflpp
🎯libafl🎯Skill

Provides LibAFL patterns for building custom fuzzers in Rust with coverage-guided feedback, hybrid fuzzing, and multi-architecture support

libafl
🎯ruzzy🎯Skill

Provides Ruzzy patterns for Ruby fuzzing with coverage-guided testing to discover vulnerabilities in Ruby C extensions

ruzzy
🎯gh-cli🎯Skill

A Trail of Bits Claude Code plugin that intercepts GitHub URL fetches and redirects them to the authenticated gh CLI for seamless, credential-aware GitHub access.

gh-cli
🎯yara-rule-authoring🎯Skill

Assists security researchers in creating, refining, and validating YARA rules for malware detection and threat hunting.

yara-rule-authoring
🎯claude-in-chrome-troubleshooting🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

claude-in-chrome-troubleshooting
🎯burpsuite-project-parser🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

burpsuite-project-parser
🎯devcontainer-setup🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

devcontainer-setup
🎯second-opinion🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

second-opinion
🎯git-cleanup🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

git-cleanup
🎯debug-buttercup🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

debug-buttercup
🎯skill-improver🎯Skill

Skill improver from Trail of Bits for analyzing and enhancing existing Claude Code skills with better structure and coverage.

skill-improver
🎯designing-workflow-skills🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

designing-workflow-skills
🎯let-fate-decide🎯Skill

Let-fate-decide skill from Trail of Bits for randomized decision-making in testing and fuzzing workflows.

let-fate-decide
🎯zeroize-audit🎯Skill

Security audit skill from Trail of Bits for detecting improper or missing zeroization of sensitive data in memory, focusing on cryptographic key cleanup and secure memory handling.

zeroize-audit
🎯seatbelt-sandboxer🎯Skill

Seatbelt sandboxer skill from Trail of Bits for implementing macOS Seatbelt sandbox profiles to contain application behavior.

seatbelt-sandboxer
🎯dimensional-analysis🎯Skill

Security skill from Trail of Bits that annotates codebases with dimensional analysis comments to detect unit mismatches and formula bugs.

dimensional-analysis
🎯diagramming-code🎯Skill

Generate Mermaid diagrams from Trailmark code graphs β€” call graphs, class hierarchies, module dependency maps, containment diagrams, complexity heatmaps, and attack-surface data-flow visualizations.

diagramming-code
🎯mutation-testing🎯Skill

Configure mewt or muton mutation-testing campaigns β€” scope targets, tune timeouts, and optimize long-running runs. mewt targets general-purpose languages (Rust, Solidity, Go, TS, JS) while muton targets TON smart contracts (Tact, Tolk, FunC).

mutation-testing
🎯audit-augmentation🎯Skill

Project SARIF static-analysis findings and weAudit annotations onto Trailmark code graphs β€” map findings to nodes by file/line overlap and create severity-based subgraphs for context-aware review.

audit-augmentation
🎯graph-evolution🎯Skill

Compares Trailmark code graphs at two source snapshots (commits, tags, or directories) and surfaces security-relevant structural changes β€” new attack paths, blast radius growth, taint propagation shifts, and privilege boundary changes that text diffs miss. Designed for pre-release audits and differential security review over a range of commits.

graph-evolution
🎯trailmark🎯Skill

Build and query multi-language source-code graphs for security analysis β€” covers blast radius, taint propagation, privilege boundaries, and entry-point enumeration. Supports 16 languages including Solidity, Cairo, Circom, Rust, Go, Python, C/C++, TypeScript.

trailmark
🎯trailmark-summary🎯Skill

Run a quick `trailmark analyze --summary` pass on a codebase β€” returns language detection, entry-point counts, and dependency graph shape for fast structural orientation before deeper analysis.

trailmark-summary
🎯crypto-protocol-diagram🎯Skill

Extract protocol message flow from source code, RFCs, papers, pseudocode, informal prose, or ProVerif/Tamarin models and produce Mermaid sequenceDiagrams with cryptographic annotations β€” TLS, Noise, Signal, X3DH, Double Ratchet, FROST, DH, ECDH.

crypto-protocol-diagram
🎯trailmark-structural🎯Skill

Runs full trailmark structural analysis with all four pre-analysis passes β€” blast radius, taint propagation, privilege boundaries, and complexity hotspots β€” for detailed audit prioritization data. Meant for when vivisect Phase 1 needs cross-referenced structural context, not quick summaries.

trailmark-structural
🎯mermaid-to-proverif🎯Skill

Translates Mermaid sequenceDiagrams of cryptographic protocols into ProVerif (.pv) formal verification models to check properties like secrecy, authentication, forward secrecy, and replay resistance. Takes annotated message flows (Sign, Verify, DH, HKDF, Enc, Dec) and emits a model ready to pass to the ProVerif verifier.

mermaid-to-proverif
🎯vector-forge🎯Skill

Uses mutation testing to find gaps in cryptographic test vector coverage, then generates new vectors that specifically exercise the escaped mutants. Compares before/after mutation kill rates to prove the new vectors actually improve coverage β€” useful for building Wycheproof-style cross-implementation test suites.

vector-forge
🎯genotoxic🎯Skill

Graph-informed triage for mutation testing and necessist runs β€” combines survived mutants and unnecessary test statements with Trailmark call graph data to separate false positives, missing unit test targets, and fuzzing targets. Supports mutation frameworks including circomvent and cairo-mutants.

genotoxic
🎯fix-review🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

fix-review
🎯using-gh-cli🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

using-gh-cli
🎯burp-suite🎯Skill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

burp-suite

πŸ”ŒPlugins28

πŸ”Œinsecure-defaultsπŸ”ŒPlugin

Trail of Bits code-auditing plugin that detects insecure default configurations, hardcoded credentials, and fail-open security patterns during AI-assisted security review.

πŸ”Œburpsuite-project-parserπŸ”ŒPlugin

Trail of Bits code-auditing plugin that searches and extracts data from Burp Suite project files for AI-assisted security analysis.

πŸ”Œsemgrep-rule-creatorπŸ”ŒPlugin

Trail of Bits code-auditing plugin that creates and refines Semgrep rules for custom vulnerability detection.

πŸ”Œconstant-time-analysisπŸ”ŒPlugin

Trail of Bits verification plugin that detects compiler-induced timing side-channels in cryptographic code β€” credited with finding a timing side-channel in ML-DSA signing (RustCrypto).

πŸ”Œgh-cliπŸ”ŒPlugin

Intercepts GitHub URL fetches and curl/wget commands, redirecting to the authenticated gh CLI. Includes gh CLI usage guidance.

πŸ”Œworkflow-skill-designπŸ”ŒPlugin

Teaches design patterns for workflow-based Claude Code skills and provides a review agent for auditing existing skills

πŸ”Œyara-authoringπŸ”ŒPlugin

YARA-X detection rule authoring with linting and quality analysis

πŸ”Œculture-indexπŸ”ŒPlugin

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

πŸ”Œdifferential-reviewπŸ”ŒPlugin

Security-focused differential review of code changes with git history analysis and blast radius estimation

πŸ”Œsharp-edgesπŸ”ŒPlugin

Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes

πŸ”Œstatic-analysisπŸ”ŒPlugin

Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection

πŸ”Œsemgrep-rule-variant-creatorπŸ”ŒPlugin

Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation

πŸ”Œspec-to-code-complianceπŸ”ŒPlugin

Specification-to-code compliance checker for blockchain audits with evidence-based alignment analysis

πŸ”Œdebug-buttercupπŸ”ŒPlugin

Debug Buttercup Kubernetes deployments

πŸ”Œbuilding-secure-contractsπŸ”ŒPlugin

Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.

πŸ”Œfirebase-apk-scannerπŸ”ŒPlugin

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

πŸ”Œproperty-based-testingπŸ”ŒPlugin

Property-based testing guidance for multiple languages and smart contracts

πŸ”Œaudit-context-buildingπŸ”ŒPlugin

Build deep architectural context through ultra-granular code analysis before vulnerability hunting

πŸ”Œtesting-handbook-skillsπŸ”ŒPlugin

Plugin

πŸ”Œsecond-opinionπŸ”ŒPlugin

Runs code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits. Bundles codex-mcp-server for direct MCP tool access to Codex.

πŸ”Œmodern-pythonπŸ”ŒPlugin

Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.

πŸ”Œclaude-in-chrome-troubleshootingπŸ”ŒPlugin

Diagnose and fix Claude in Chrome MCP extension connectivity issues

πŸ”Œask-questions-if-underspecifiedπŸ”ŒPlugin

Clarify ambiguous requirements by asking questions before implementing. Only when invoked explicitly.

πŸ”Œentry-point-analyzerπŸ”ŒPlugin

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.

πŸ”Œdwarf-expertπŸ”ŒPlugin

Interact with and understand the DWARF debugging format

πŸ”Œvariant-analysisπŸ”ŒPlugin

Find similar vulnerabilities and bugs across codebases using pattern-based analysis

πŸ”Œdevcontainer-setupπŸ”ŒPlugin

Create pre-configured devcontainers with Claude Code and language-specific tooling

πŸ”Œgit-cleanupπŸ”ŒPlugin

Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.

πŸͺMarketplaces1