๐Ÿช

trailofbits-skills

๐ŸชMarketplace

trailofbits/skills

Add this Marketplace

Add marketplace in Claude Code:
$/plugin marketplace add trailofbits/skills
VibeIndex|
What it does
|

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Overview

Trail of Bits Skills Marketplace is a Claude Code plugin marketplace providing security-focused skills for AI-assisted security analysis, testing, and development workflows. Built by Trail of Bits, a leading security research firm, it offers specialized plugins spanning smart contract security, code auditing, and development best practices.

Key Features

  • Smart contract security: Includes vulnerability scanners for 6 blockchains and entry point analyzers for security auditing of state-changing contract functions
  • Code auditing tools: Deep architectural context building through ultra-granular code analysis, with Burp Suite project integration
  • Easy marketplace integration: Install with /plugin marketplace add trailofbits/skills and browse plugins via /plugin menu
  • Local development support: Add the marketplace locally for testing and development with simple directory-based setup
  • Curated security expertise: Companion repositories for claude-code-config, skills-curated, claude-code-devcontainer, and dropkit

Who is this for?

This marketplace is designed for security researchers, smart contract auditors, and developers who want to enhance their Claude Code workflows with professional security analysis tools. It is particularly valuable for teams conducting blockchain security audits or code reviews that require structured, thorough vulnerability assessment.

communityaccessacrossactiveagentalignmentambiguousanalysisanalyzeranalyzes
25Plugins
4,329
Last UpdatedJul 6, 2026

Plugins in this Marketplace

๐Ÿ”Œ

ask-questions-if-underspecified

Clarify ambiguous requirements by asking questions before implementing. Only when invoked explicitly.

5,950
๐Ÿ”Œ

audit-context-building

Build deep architectural context through ultra-granular code analysis before vulnerability hunting

5,950
๐Ÿ”Œ

building-secure-contracts

Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.

0
๐Ÿ”Œ

burpsuite-project-parser

Trail of Bits code-auditing plugin that searches and extracts data from Burp Suite project files for AI-assisted security analysis.

5,955
๐Ÿ”Œ

claude-in-chrome-troubleshooting

Diagnose and fix Claude in Chrome MCP extension connectivity issues

0
๐Ÿ”Œ

constant-time-analysis

Trail of Bits verification plugin that detects compiler-induced timing side-channels in cryptographic code โ€” credited with finding a timing side-channel in ML-DSA signing (RustCrypto).

5,950
๐Ÿ”Œ

debug-buttercup

Debug Buttercup Kubernetes deployments

5,951
๐Ÿ”Œ

devcontainer-setup

Create pre-configured devcontainers with Claude Code and language-specific tooling

0
๐Ÿ”Œ

differential-review

Security-focused differential review of code changes with git history analysis and blast radius estimation

5,951
๐Ÿ”Œ

dwarf-expert

Interact with and understand the DWARF debugging format

5,951
๐Ÿ”Œ

entry-point-analyzer

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.

0
๐Ÿ”Œ

firebase-apk-scanner

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

5,951
๐Ÿ”Œ

gh-cli

Intercepts GitHub URL fetches and curl/wget commands, redirecting to the authenticated gh CLI. Includes gh CLI usage guidance.

5,950
๐Ÿ”Œ

git-cleanup

Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.

5,955
๐Ÿ”Œ

insecure-defaults

Trail of Bits code-auditing plugin that detects insecure default configurations, hardcoded credentials, and fail-open security patterns during AI-assisted security review.

5,955
๐Ÿ”Œ

modern-python

Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.

0
๐Ÿ”Œ

property-based-testing

Property-based testing guidance for multiple languages and smart contracts

5,955
๐Ÿ”Œ

second-opinion

Runs code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits. Bundles codex-mcp-server for direct MCP tool access to Codex.

0
๐Ÿ”Œ

semgrep-rule-variant-creator

Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation

5,955
๐Ÿ”Œ

sharp-edges

Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes

0
๐Ÿ”Œ

spec-to-code-compliance

Specification-to-code compliance checker for blockchain audits with evidence-based alignment analysis

0
๐Ÿ”Œ

static-analysis

Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection

5,951
๐Ÿ”Œ

variant-analysis

Find similar vulnerabilities and bugs across codebases using pattern-based analysis

0
๐Ÿ”Œ

workflow-skill-design

Teaches design patterns for workflow-based Claude Code skills and provides a review agent for auditing existing skills

5,957
๐Ÿ”Œ

yara-authoring

YARA-X detection rule authoring with linting and quality analysis

5,955

More from this repository10

๐ŸŽฏ
ask-questions-if-underspecified๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
semgrep๐ŸŽฏSkill

Runs Semgrep static analysis for security vulnerability detection and code quality enforcement, from the Trail of Bits Skills Marketplace for AI-assisted security workflows.

๐ŸŽฏ
modern-python๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
insecure-defaults๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
codeql๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
secure-workflow-guide๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
code-maturity-assessor๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
supply-chain-risk-auditor๐ŸŽฏSkill

Supply chain risk auditor skill from Trail of Bits for analyzing dependency trees, detecting vulnerable packages, and auditing software supply chain security.

๐ŸŽฏ
differential-review๐ŸŽฏSkill

A Claude Code plugin marketplace from Trail of Bits providing skills for AI-assisted security analysis, testing, and development workflows.

๐ŸŽฏ
fp-check๐ŸŽฏSkill

A Trail of Bits plugin that performs systematic false positive verification for security bug analysis, using mandatory gate reviews to ensure only valid security findings are reported.