πŸͺ

trailofbits-skills

πŸͺMarketplace

trailofbits/skills

VibeIndex|
What it does
|

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

Overview

Trail of Bits Skills Marketplace is a Claude Code plugin marketplace providing security-focused skills for AI-assisted security analysis, testing, and development workflows. Built by Trail of Bits, a leading security research firm, it offers specialized plugins spanning smart contract security, code auditing, and development best practices.

Key Features

  • Smart contract security: Includes vulnerability scanners for 6 blockchains and entry point analyzers for security auditing of state-changing contract functions
  • Code auditing tools: Deep architectural context building through ultra-granular code analysis, with Burp Suite project integration
  • Easy marketplace integration: Install with /plugin marketplace add trailofbits/skills and browse plugins via /plugin menu
  • Local development support: Add the marketplace locally for testing and development with simple directory-based setup
  • Curated security expertise: Companion repositories for claude-code-config, skills-curated, claude-code-devcontainer, and dropkit

Who is this for?

This marketplace is designed for security researchers, smart contract auditors, and developers who want to enhance their Claude Code workflows with professional security analysis tools. It is particularly valuable for teams conducting blockchain security audits or code reviews that require structured, thorough vulnerability assessment.

communityaccessacrossactiveagentalignmentambiguousanalysisanalyzeranalyzes

Add this Marketplace

Add marketplace in Claude Code:
/plugin marketplace add trailofbits/skills
25Plugins
2,885
Last UpdatedFeb 24, 2026

Plugins in this Marketplace

πŸ”Œ

ask-questions-if-underspecified

Clarify ambiguous requirements by asking questions before implementing. Only when invoked explicitly.

0
πŸ”Œ

audit-context-building

Build deep architectural context through ultra-granular code analysis before vulnerability hunting

0
πŸ”Œ

building-secure-contracts

Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.

0
πŸ”Œ

burpsuite-project-parser

Search and extract data from Burp Suite project files (.burp) for security analysis

0
πŸ”Œ

claude-in-chrome-troubleshooting

Diagnose and fix Claude in Chrome MCP extension connectivity issues

0
πŸ”Œ

constant-time-analysis

Detect compiler-induced timing side-channels in cryptographic code

0
πŸ”Œ

debug-buttercup

Debug Buttercup Kubernetes deployments

0
πŸ”Œ

devcontainer-setup

Create pre-configured devcontainers with Claude Code and language-specific tooling

0
πŸ”Œ

differential-review

Security-focused differential review of code changes with git history analysis and blast radius estimation

0
πŸ”Œ

dwarf-expert

Interact with and understand the DWARF debugging format

0
πŸ”Œ

entry-point-analyzer

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.

0
πŸ”Œ

firebase-apk-scanner

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

0
πŸ”Œ

gh-cli

Intercepts GitHub URL fetches and curl/wget commands, redirecting to the authenticated gh CLI. Includes gh CLI usage guidance.

3,263
πŸ”Œ

git-cleanup

Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.

0
πŸ”Œ

insecure-defaults

Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production

0
πŸ”Œ

modern-python

Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.

0
πŸ”Œ

property-based-testing

Property-based testing guidance for multiple languages and smart contracts

0
πŸ”Œ

second-opinion

Runs code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits. Bundles codex-mcp-server for direct MCP tool access to Codex.

0
πŸ”Œ

semgrep-rule-variant-creator

Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation

0
πŸ”Œ

sharp-edges

Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes

0
πŸ”Œ

spec-to-code-compliance

Specification-to-code compliance checker for blockchain audits with evidence-based alignment analysis

0
πŸ”Œ

static-analysis

Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection

0
πŸ”Œ

variant-analysis

Find similar vulnerabilities and bugs across codebases using pattern-based analysis

0
πŸ”Œ

workflow-skill-design

Teaches design patterns for workflow-based Claude Code skills and provides a review agent for auditing existing skills

3,419
πŸ”Œ

yara-authoring

YARA-X detection rule authoring with linting and quality analysis

3,419