Agentic Actions Auditor
Trail of BitsAudits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
By author · 23 skills
Every skill by Trail of Bits in the directory. Each page has a summary, the install command and a link to the source.
Audits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
Builds an understanding of a codebase before an audit: what each function assumes, guarantees and depends on.
Detects timing side-channel vulnerabilities in cryptographic code written in C, C++, Go and other languages.
Creates devcontainers with Claude Code, language tooling for Python, Node, Rust or Go, and persistent volumes.
Reviews code changes for security: adapts depth to codebase size, estimates blast radius and checks test coverage.
Identifies the state-changing entry points of a smart contract codebase and groups them by access level.
Verifies suspected security bugs one by one and gives a true or false positive verdict with evidence.
Makes the agent use the authenticated gh CLI for GitHub URLs, pull requests and issues instead of unauthenticated fetches.
Configures Python projects with uv, ruff and ty, including migration from pip, Poetry, mypy and black.
Configures mutation testing campaigns with mewt or muton and analyses the surviving mutants.
Writes, reviews and debugs property-based tests with Hypothesis, fast-check, proptest and similar tools.
Gets an independent code review of your changes from Codex or Antigravity.
Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.
Identifies error-prone APIs, dangerous configurations and designs that invite security mistakes.
Checks code against its specification: which requirements hold, which are contradicted and which are missing.
Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
Parses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.
Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Designs and improves fuzzing harnesses for C, C++ and Rust targets.
Hunts for other instances of a bug that has already been found, across the whole codebase.
Guides the authoring of YARA-X detection rules for malware identification.
Detects missing zeroisation of sensitive data in C, C++ and Rust code, including cases removed by the compiler.