Second Opinion
Trail of BitsGets an independent code review of your changes from Codex or Antigravity.
By agent · Claude Code
Skills in the open SKILL.md format that Claude Code reads. Each one has a plain-language summary and the command to install it.
$ npx skills add <author>/<skill>Replace the placeholder with the author and skill name from the skill's page. Start a new Claude Code session afterwards so the skill is picked up.
Gets an independent code review of your changes from Codex or Antigravity.
Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.
Identifies error-prone APIs, dangerous configurations and designs that invite security mistakes.
Checks code against its specification: which requirements hold, which are contradicted and which are missing.
Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
Parses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.
Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Designs and improves fuzzing harnesses for C, C++ and Rust targets.
Hunts for other instances of a bug that has already been found, across the whole codebase.
Guides the authoring of YARA-X detection rules for malware identification.
Detects missing zeroisation of sensitive data in C, C++ and Rust code, including cases removed by the compiler.
Guides the design of n8n AI agents and LLM chains built from the LangChain AI nodes.
Writes JavaScript for n8n Code nodes, covering $input, $json and $node syntax, HTTP helpers and date handling.
Writes native Python for n8n Code nodes and migrates older Pyodide-based code.
Wires error handling into n8n workflows so that failures are visible, structured and recoverable.
Validates n8n expression syntax and fixes common errors when mapping data between nodes.
Guides use of the n8n-mcp tools: searching nodes, validating configurations, using templates and managing workflows and credentials.
Guides node configuration in n8n: property dependencies, required fields and common patterns by node type.
Interprets n8n validation errors and warnings, and guides the fix.
Supplies workflow architecture patterns drawn from real n8n workflows, such as webhook processing and HTTP API integration.
Applies Anthony Fu's tooling and conventions to JavaScript and TypeScript projects: linting, monorepos and library publishing.
Reference for Nitro, the server toolkit behind Nuxt: server routes, route rules, caching, storage, tasks and websockets.
Reference for Nuxt: SSR, auto-imports, file-based routing, server routes, useFetch, middleware and hybrid rendering.
Questions
A folder with a SKILL.md file: instructions, and sometimes scripts and reference files, that Claude Code loads when a task calls for them.
Each skill page has an install command. Run it in a terminal, then start a new Claude Code session so the skill is picked up.
An instructions file is loaded in every session and describes the project. A skill is loaded only when a task calls for it, so it can be long and specific without costing context on every turn.