Builds and deploys an MCP server from an OpenAPI or Swagger spec with the mcp-use TypeScript SDK.
Category · 471 skills
Development skills
The skills in the directory filed under Development, in the editor's order.
Development skills
Guides building with shadcn/ui components: discovery, installation, customisation and best practices.
Audits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
Audit Context Building
Trail of BitsBuilds an understanding of a codebase before an audit: what each function assumes, guarantees and depends on.
Detects timing side-channel vulnerabilities in cryptographic code written in C, C++, Go and other languages.
Devcontainer Setup
Trail of BitsCreates devcontainers with Claude Code, language tooling for Python, Node, Rust or Go, and persistent volumes.
Differential Review
Trail of BitsReviews code changes for security: adapts depth to codebase size, estimates blast radius and checks test coverage.
Entry Point Analyzer
Trail of BitsIdentifies the state-changing entry points of a smart contract codebase and groups them by access level.
FP Check
Trail of BitsVerifies suspected security bugs one by one and gives a true or false positive verdict with evidence.
GH CLI
Trail of BitsMakes the agent use the authenticated gh CLI for GitHub URLs, pull requests and issues instead of unauthenticated fetches.
Modern Python
Trail of BitsConfigures Python projects with uv, ruff and ty, including migration from pip, Poetry, mypy and black.
Mutation Testing
Trail of BitsConfigures mutation testing campaigns with mewt or muton and analyses the surviving mutants.
Property-Based Testing
Trail of BitsWrites, reviews and debugs property-based tests with Hypothesis, fast-check, proptest and similar tools.
Second Opinion
Trail of BitsGets an independent code review of your changes from Codex or Antigravity.
Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.
Sharp Edges
Trail of BitsIdentifies error-prone APIs, dangerous configurations and designs that invite security mistakes.
Spec to Code Compliance
Trail of BitsChecks code against its specification: which requirements hold, which are contradicted and which are missing.
Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
SARIF Parsing
Trail of BitsParses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.
Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.
Supply Chain Risk Auditor
Trail of BitsAudits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Designs and improves fuzzing harnesses for C, C++ and Rust targets.
Variant Analysis
Trail of BitsHunts for other instances of a bug that has already been found, across the whole codebase.
YARA Rule Authoring
Trail of BitsGuides the authoring of YARA-X detection rules for malware identification.