跳过主要内容

By author · 23 skills

Trail of Bits Skills

Every skill by Trail of Bits in the directory. Each page has a summary, the install command and a link to the source.

Skills by Trail of Bits

Audits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.

DevelopmentGitHub stars: 7.3kInstalls: 6.2k

Builds an understanding of a codebase before an audit: what each function assumes, guarantees and depends on.

DevelopmentGitHub stars: 7.3kInstalls: 6.1k

Detects timing side-channel vulnerabilities in cryptographic code written in C, C++, Go and other languages.

DevelopmentGitHub stars: 7.3kInstalls: 5k

Devcontainer Setup

Trail of Bits

Creates devcontainers with Claude Code, language tooling for Python, Node, Rust or Go, and persistent volumes.

DevelopmentGitHub stars: 7.3kInstalls: 4.8k

Differential Review

Trail of Bits

Reviews code changes for security: adapts depth to codebase size, estimates blast radius and checks test coverage.

DevelopmentGitHub stars: 7.3kInstalls: 7.2k

Identifies the state-changing entry points of a smart contract codebase and groups them by access level.

DevelopmentGitHub stars: 7.3kInstalls: 5.2k

FP Check

Trail of Bits

Verifies suspected security bugs one by one and gives a true or false positive verdict with evidence.

DevelopmentGitHub stars: 7.3kInstalls: 6.4k

GH CLI

Trail of Bits

Makes the agent use the authenticated gh CLI for GitHub URLs, pull requests and issues instead of unauthenticated fetches.

DevelopmentGitHub stars: 7.3kInstalls: 6.1k

Modern Python

Trail of Bits

Configures Python projects with uv, ruff and ty, including migration from pip, Poetry, mypy and black.

DevelopmentGitHub stars: 7.3kInstalls: 8k

Mutation Testing

Trail of Bits

Configures mutation testing campaigns with mewt or muton and analyses the surviving mutants.

DevelopmentGitHub stars: 7.3kInstalls: 3.8k

Writes, reviews and debugs property-based tests with Hypothesis, fast-check, proptest and similar tools.

DevelopmentGitHub stars: 7.3kInstalls: 6.1k

Second Opinion

Trail of Bits

Gets an independent code review of your changes from Codex or Antigravity.

DevelopmentGitHub stars: 7.3kInstalls: 4.8k

Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.

DevelopmentGitHub stars: 7.3kInstalls: 5.2k

Sharp Edges

Trail of Bits

Identifies error-prone APIs, dangerous configurations and designs that invite security mistakes.

DevelopmentGitHub stars: 7.3kInstalls: 6k

Checks code against its specification: which requirements hold, which are contradicted and which are missing.

DevelopmentGitHub stars: 7.3kInstalls: 5.3k

CodeQL

Trail of Bits

Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.

DevelopmentGitHub stars: 7.3kInstalls: 7.7k

SARIF Parsing

Trail of Bits

Parses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.

DevelopmentGitHub stars: 7.3kInstalls: 5.4k

Semgrep

Trail of Bits

Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.

DevelopmentGitHub stars: 7.3kInstalls: 8.6k

Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.

DevelopmentGitHub stars: 7.3kInstalls: 7.2k

Designs and improves fuzzing harnesses for C, C++ and Rust targets.

DevelopmentGitHub stars: 7.3kInstalls: 5k

Variant Analysis

Trail of Bits

Hunts for other instances of a bug that has already been found, across the whole codebase.

DevelopmentGitHub stars: 7.3kInstalls: 5.7k

YARA Rule Authoring

Trail of Bits

Guides the authoring of YARA-X detection rules for malware identification.

DevelopmentGitHub stars: 7.3kInstalls: 4.7k

Zeroize Audit

Trail of Bits

Detects missing zeroisation of sensitive data in C, C++ and Rust code, including cases removed by the compiler.

DevelopmentGitHub stars: 7.3kInstalls: 4.3k