trailofbits/skills
trailofbits/skills · 44 plugins
Marketplace Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Install
/plugin marketplace add trailofbits/skillsRun inside Claude Code, then install plugins from it. Check the repo's README before you run it.
Plugins 44
After adding the marketplace, install one with /plugin install <name>@trailofbits.
- 1audit-context-buildingUnderstand a codebase before looking for bugs in it. Reads it function by function, records what each one assumes and depends on, and saves the write-ups to files instead of filling up the conversation.
/plugin install audit-context-building@trailofbits - 2building-secure-contractsComprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.
/plugin install building-secure-contracts@trailofbits - 3burpsuite-project-parserSearch and extract data from Burp Suite project files (.burp) for security analysis
/plugin install burpsuite-project-parser@trailofbits - 4chrome-mcp-troubleshootingDiagnose and fix Claude in Chrome MCP extension connectivity issues
/plugin install chrome-mcp-troubleshooting@trailofbits - 5constant-time-analysisDetect compiler-induced timing side-channels in cryptographic code
/plugin install constant-time-analysis@trailofbits - 6culture-indexInterprets Culture Index survey results for individuals and teams
/plugin install culture-index@trailofbits - 7devcontainer-setupCreate pre-configured devcontainers with Claude Code and language-specific tooling
/plugin install devcontainer-setup@trailofbits - 8differential-reviewSecurity-focused differential review of code changes with git history analysis and blast radius estimation
/plugin install differential-review@trailofbits - 9firebase-apk-scannerScan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
/plugin install firebase-apk-scanner@trailofbits - 10gh-cliIntercepts GitHub URL fetches (WebFetch and MCP fetch tools) and curl/wget commands, redirecting to the authenticated gh CLI.
/plugin install gh-cli@trailofbits - 11dwarf-expertAnalyze DWARF debug information: parse and search DIEs with dwarfdump and readelf, verify debug info integrity, and write DWARF parsing code
/plugin install dwarf-expert@trailofbits - 12entry-point-analyzerAnalyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.
/plugin install entry-point-analyzer@trailofbits - 13mutation-testingConfigures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
/plugin install mutation-testing@trailofbits - 14post-patch-validationValidates security patches against the reported bug, root-cause variants, and surrounding behavior. Returns reproducible failures to repair and validation gaps, with pinned inputs and saved evidence. Bundles a validate-patch dynamic workflow for Claude Code.
/plugin install post-patch-validation@trailofbits - 15property-based-testingWrite, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants
/plugin install property-based-testing@trailofbits - 16semgrep-rule-creatorCreate custom Semgrep rules for detecting bug patterns and security vulnerabilities
/plugin install semgrep-rule-creator@trailofbits - 17semgrep-rule-variant-creatorCreates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation
/plugin install semgrep-rule-variant-creator@trailofbits - 18sharp-edgesIdentify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes
/plugin install sharp-edges@trailofbits - 19static-analysisStatic analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection
/plugin install static-analysis@trailofbits - 20spec-to-code-complianceCheck code against the documentation that specifies it: one agent per requirement, divergences refuted before they are reported, evidence cited to the line
/plugin install spec-to-code-compliance@trailofbits - 21testing-handbook-skillsSkills from the Trail of Bits Application Security Testing Handbook (appsec.guide)
/plugin install testing-handbook-skills@trailofbits - 22trailmarkBuilds source and binary code graphs for security analysis, context slicing, mutation testing, cryptographic protocol modeling, finding triage, and variant analysis.
/plugin install trailmark@trailofbits - 23variant-analysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis
/plugin install variant-analysis@trailofbits - 24c-reviewComprehensive C/C++ security code review, with coverage verified against a parse of the source
/plugin install c-review@trailofbits - 25rust-reviewComprehensive Rust security code review with specialized bug-finding agents covering the safe/unsafe boundary, memory safety in unsafe blocks, concurrency, panic-induced DoS, recursion-induced stack overflow, FFI, and async runtime hazards
/plugin install rust-review@trailofbits - 26modern-pythonModern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.
/plugin install modern-python@trailofbits - 27insecure-defaultsDetects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production
/plugin install insecure-defaults@trailofbits - 28review-walkthroughGenerates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.
/plugin install review-walkthrough@trailofbits - 29second-opinionGets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits.
/plugin install second-opinion@trailofbits - 30yara-authoringYARA-X detection rule authoring with linting and quality analysis
/plugin install yara-authoring@trailofbits - 31git-cleanupSafely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.
/plugin install git-cleanup@trailofbits - 32goal-promptDrafts copy-ready /goal commands for goal mode in Claude Code and Codex: verifiable completion conditions with stop bounds, normalized to a single line under the 4,000-character cap.
/plugin install goal-prompt@trailofbits - 33supply-chain-risk-auditorAudit a project's npm, PyPI, and Go dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned upstreams, npm publisher concentration, and install scripts
/plugin install supply-chain-risk-auditor@trailofbits - 34zeroize-auditDetects missing or compiler-optimized zeroization of sensitive data with assembly and control-flow analysis
/plugin install zeroize-audit@trailofbits - 35let-fate-decideDraws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous.
/plugin install let-fate-decide@trailofbits - 36agentic-actions-auditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference)
/plugin install agentic-actions-auditor@trailofbits - 37code-improverImproves code targets — skills, plugins, or a branch's changes — through an autonomous review-and-fix workflow with a pluggable reviewer (any installed skill or agent), a cross-round findings ledger, oscillation escalation, and a mechanical scope guard.
/plugin install code-improver@trailofbits - 38fp-checkSystematic false positive verification for security bug analysis with mandatory gate reviews
/plugin install fp-check@trailofbits - 39dimensional-analysisAnnotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol. Prevents dimensional mismatches and catches formula bugs early.
/plugin install dimensional-analysis@trailofbits - 40vulnerability-triage-brocardsPrincipled framework for triaging vulnerability reports using 7 brocards (rules of thumb). Evaluates incoming CVEs, bug bounty submissions, and security findings against structured dismissal/acceptance criteria before escalating to deeper analysis.
/plugin install vulnerability-triage-brocards@trailofbits - 41github-triageTriages a repository's open GitHub issues and pull requests via the gh CLI: optionally merges ready bot and maintainer-approved PRs and spawns review subagents for unreviewed ones, closes already-resolved issues with referenced explanations, cross-links issues with pending fix PRs, and assigns local-only priority and change-size estimates.
/plugin install github-triage@trailofbits - 42open-sourcingPrepares a repository for public open-source release: secrets-history hygiene, license selection, documentation and CI readiness checks, and language-specific packaging and release guidance.
/plugin install open-sourcing@trailofbits - 43writing-lean-proofsStructured Lean 4 proof writing and library design following Mathlib conventions
/plugin install writing-lean-proofs@trailofbits - 44modern-cppModern C++ best practices (C++20/23/26). Use when writing C++ code, creating new C++ projects, or modernizing legacy C++ patterns.
/plugin install modern-cpp@trailofbits
Files
Trail of Bits Skills Marketplace
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Also see: claude-code-config · codex-config · skills-curated · claude-code-devcontainer · dropkit · coop
Installation
Claude Code Marketplace
/plugin marketplace add trailofbits/skills
Browse and Install Plugins
/plugin menu
Codex
Codex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata.
Install the marketplace with:
codex plugin marketplace add trailofbits/skills
codex plugin list
codex plugin add <plugin-name>@trailofbitsChatGPT Workspace Marketplace
Use this repository's .claude-plugin/marketplace.json for workspace imports.
Skills that include agents/openai.yaml also need interface.display_name and
interface.short_description in that YAML file; plugin metadata does not supply them.
After a metadata fix is published, sync the repository again in your workspace
marketplace to retry failed imports.
Local Development
To add the marketplace locally (e.g., for testing or development), navigate to the parent directory of this repository:
cd /path/to/parent # e.g., if repo is at ~/projects/skills, be in ~/projects
/plugins marketplace add ./skills
Available Plugins
Smart Contract Security
| Plugin | Description |
|---|---|
| building-secure-contracts | Smart contract security toolkit with vulnerability scanners for 6 blockchains and 5 development guideline assistants |
| entry-point-analyzer | Identify state-changing entry points in smart contracts for security auditing |
Code Auditing
| Plugin | Description |
|---|---|
| agentic-actions-auditor | Audit GitHub Actions workflows for AI agent security vulnerabilities |
| audit-context-building | Understand a codebase before looking for bugs in it, one function at a time |
| burpsuite-project-parser | Search and extract data from Burp Suite project files |
| c-review | Comprehensive C/C++ security code review, with coverage verified against a parse of the source |
| differential-review | Security-focused differential review of code changes with git history analysis |
| dimensional-analysis | Annotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs |
| fp-check | Systematic false positive verification for security bug analysis with mandatory gate reviews |
| insecure-defaults | Parallel audit workflow for fail-open insecure defaults, with a refuting verifier per candidate file |
| rust-review | Comprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and async runtime with SARIF output |
| semgrep-rule-creator | Create and refine Semgrep rules for custom vulnerability detection |
| semgrep-rule-variant-creator | Port existing Semgrep rules to new target languages with test-driven validation |
| sharp-edges | Identify error-prone APIs, dangerous configurations, and footgun designs |
| static-analysis | Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing |
| supply-chain-risk-auditor | Audit npm, PyPI, and Go dependencies for version-matched advisories, abandoned upstreams, publisher concentration, and install scripts |
| testing-handbook-skills | Skills from the Testing Handbook: fuzzers, static analysis, sanitizers, coverage |
| trailmark | Code graph analysis, bounded subagent context slicing, Mermaid diagrams, mutation testing triage, and protocol verification |
| variant-analysis | Find similar vulnerabilities across codebases using pattern-based analysis |
| vulnerability-triage-brocards | Triage vulnerability reports using 7 brocards to accept, dismiss, or request more info before deeper analysis |
Malware Analysis
| Plugin | Description |
|---|---|
| yara-authoring | YARA detection rule authoring with linting, atom analysis, and best practices |
Verification
| Plugin | Description |
|---|---|
| constant-time-analysis | Detect compiler-induced timing side-channels in cryptographic code |
| mutation-testing | Configure mutation testing, analyze surviving mutants, and investigate bugs in weakly tested code |
| post-patch-validation | Help patch authors find missed variants and regressions, with reproducible failures and explicit validation gaps |
| property-based-testing | Write, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants |
| spec-to-code-compliance | Check code against the documentation that specifies it, across contracts, C/C++, services, and firmware |
| writing-lean-proofs | Write structured Lean 4 proofs and design Lean libraries following Mathlib conventions |
| zeroize-audit | Detect missing or compiler-eliminated zeroization of secrets in C/C++ and Rust |
Reverse Engineering
| Plugin | Description |
|---|---|
| dwarf-expert | Analyze DWARF debug info: parse and search DIEs, verify integrity, write DWARF parsing code |
Mobile Security
| Plugin | Description |
|---|---|
| firebase-apk-scanner | Scan Android APKs for Firebase security misconfigurations |
Development
| Plugin | Description |
|---|---|
| code-improver | Autonomous review-and-fix workflow over skills, plugins, or a branch, with a pluggable reviewer, findings ledger, escalation, and scope guard |
| devcontainer-setup | Create pre-configured devcontainers with Claude Code and language-specific tooling |
| gh-cli | Intercept GitHub URL fetches — WebFetch, MCP fetch tools, and curl/wget — and redirect to the authenticated gh CLI |
| git-cleanup | Safely clean up git worktrees and local branches: a dynamic workflow gathers merge evidence and tries to refute its own delete recommendations, behind gated confirmation |
| goal-prompt | Draft /goal commands for goal mode in Claude Code and Codex — verifiable completion conditions formatted to a copy-ready single line |
| github-triage | Triage open GitHub issues and PRs: merge ready bot/approved PRs, review unreviewed ones via subagents, close resolved issues with cited comments, cross-link pending fixes, and score the rest with local-only priority and change-size estimates |
| let-fate-decide | Draw Tarot cards using cryptographic randomness to add entropy to vague planning |
| modern-cpp | Modern C++ best practices (C++20/23/26) with compiler hardening and safe idioms |
| modern-python | Modern Python tooling and best practices with uv, ruff, and pytest |
| open-sourcing | Prepare a repository for public release: secrets hygiene, licensing, CI readiness, and release automation |
| review-walkthrough | Generate an interactive walkthrough of branch changes with ordered diffs, explanations, and anchored review findings |
| second-opinion | Get independent reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits |
Team Management
| Plugin | Description |
|---|---|
| culture-index | Interpret Culture Index survey results for individuals and teams |
Tooling
| Plugin | Description |
|---|---|
| chrome-mcp-troubleshooting | Diagnose and fix Claude in Chrome MCP extension connectivity issues |
Trophy Case
Bugs discovered using Trail of Bits Skills. Found something? Let us know!
When reporting bugs you've found, feel free to mention:
Found using Trail of Bits Skills
| Skill | Bug |
|---|---|
| constant-time-analysis | Timing side-channel in ML-DSA signing |
Contributing
We welcome contributions! See AGENTS.md for skill authoring guidelines, and
run make check before you push — it runs most of CI locally (see AGENTS.md for
what it does not cover).
Codex provides advisory fast reviews for eligible PRs from this repository. Maintainers
with write access can request another fast review by commenting @codex review, or a
deeper review by applying the deep-review label. Fork PRs are excluded.
License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. Made by Trail of Bits.
{
"name": "trailofbits",
"owner": {
"name": "Trail of Bits",
"email": "opensource@trailofbits.com"
},
"metadata": {
"version": "1.0.0",
"description": "Claude Code plugins from Trail of Bits for enhanced AI-assisted security analysis and development"
},
"plugins": [
{
"name": "audit-context-building",
"description": "Understand a codebase before looking for bugs in it. Reads it function by function, records what each one assumes and depends on, and saves the write-ups to files instead of filling up the conversation.",
"version": "2.0.2",
"author": {
"name": "Omar Inuwa"
},
"source": "./plugins/audit-context-building"
},
{
"name": "building-secure-contracts",
"version": "1.2.2",
"description": "Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.",
"author": {
"name": "Omar Inuwa && Paweł Płatek"
},
"source": "./plugins/building-secure-contracts"
},
{
"name": "burpsuite-project-parser",
"version": "1.1.2",
"description": "Search and extract data from Burp Suite project files (.burp) for security analysis",
"author": {
"name": "Will Vandevanter"
},
"source": "./plugins/burpsuite-project-parser"
},
{
"name": "chrome-mcp-troubleshooting",
"version": "1.1.5",
"description": "Diagnose and fix Claude in Chrome MCP extension connectivity issues",
"author": {
"name": "Dan Guido"
},
"source": "./plugins/chrome-mcp-troubleshooting"
},
{
"name": "constant-time-analysis",
"version": "0.2.6",
"description": "Detect compiler-induced timing side-channels in cryptographic code",
"author": {
"name": "Scott Arciszewski",
"email": "opensource@trailofbits.com"
},
"source": "./plugins/constant-time-analysis"
},
{
"name": "culture-index",
"version": "1.1.6",
"description": "Interprets Culture Index survey results for individuals and teams",
"author": {
"name": "Dan Guido"
},
"source": "./plugins/culture-index"
},
{
"name": "devcontainer-setup",
"version": "0.2.4",
"description": "Create pre-configured devcontainers with Claude Code and language-specific tooling",
"author": {
"name": "Alexis Challande",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/devcontainer-setup"
},
{
"name": "differential-review",
"description": "Security-focused differential review of code changes with git history analysis and blast radius estimation",
"version": "1.1.4",
"author": {
"name": "Omar Inuwa"
},
"source": "./plugins/differential-review"
},
{
"name": "firebase-apk-scanner",
"version": "2.2.2",
"description": "Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.",
"author": {
"name": "Nick Sellier"
},
"source": "./plugins/firebase-apk-scanner"
},
{
"name": "gh-cli",
"version": "1.6.2",
"description": "Intercepts GitHub URL fetches (WebFetch and MCP fetch tools) and curl/wget commands, redirecting to the authenticated gh CLI.",
"author": {
"name": "William Tan",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/gh-cli"
},
{
"name": "dwarf-expert",
"description": "Analyze DWARF debug information: parse and search DIEs with dwarfdump and readelf, verify debug info integrity, and write DWARF parsing code",
"version": "1.1.2",
"author": {
"name": "Evan Hellman",
"email": "opensource@trailofbits.com"
},
"source": "./plugins/dwarf-expert"
},
{
"name": "entry-point-analyzer",
"version": "1.0.4",
"description": "Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.",
"author": {
"name": "Nicolas Donboly",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/entry-point-analyzer"
},
{
"name": "mutation-testing",
"version": "1.9.2",
"description": "Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.",
"author": {
"name": "Trail of Bits",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/mutation-testing"
},
{
"name": "post-patch-validation",
"version": "0.2.2",
"description": "Validates security patches against the reported bug, root-cause variants, and surrounding behavior. Returns reproducible failures to repair and validation gaps, with pinned inputs and saved evidence. Bundles a validate-patch dynamic workflow for Claude Code.",
"author": {
"name": "Scott Arciszewski",
"email": "opensource@trailofbits.com",
"url": "https://github.com/tob-scott-a"
},
"source": "./plugins/post-patch-validation"
},
{
"name": "property-based-testing",
"description": "Write, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants",
"version": "1.2.2",
"author": {
"name": "Henrik Brodin",
"email": "opensource@trailofbits.com"
},
"source": "./plugins/property-based-testing"
},
{
"name": "semgrep-rule-creator",
"version": "1.2.6",
"description": "Create custom Semgrep rules for detecting bug patterns and security vulnerabilities",
"author": {
"name": "Maciej Domanski"
},
"source": "./plugins/semgrep-rule-creator"
},
{
"name": "semgrep-rule-variant-creator",
"version": "1.1.3",
"description": "Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation",
"author": {
"name": "Maciej Domanski",
"email": "opensource@trailofbits.com"
},
"source": "./plugins/semgrep-rule-variant-creator"
},
{
"name": "sharp-edges",
"version": "1.1.3",
"description": "Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes",
"author": {
"name": "Scott Arciszewski",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/sharp-edges"
},
{
"name": "static-analysis",
"version": "1.5.0",
"description": "Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection",
"author": {
"name": "Axel Mierczuk & Paweł Płatek"
},
"source": "./plugins/static-analysis"
},
{
"name": "spec-to-code-compliance",
"description": "Check code against the documentation that specifies it: one agent per requirement, divergences refuted before they are reported, evidence cited to the line",
"version": "2.0.2",
"author": {
"name": "Omar Inuwa"
},
"source": "./plugins/spec-to-code-compliance"
},
{
"name": "testing-handbook-skills",
"version": "1.2.2",
"description": "Skills from the Trail of Bits Application Security Testing Handbook (appsec.guide)",
"author": {
"name": "Paweł Płatek"
},
"source": "./plugins/testing-handbook-skills"
},
{
"name": "trailmark",
"version": "0.11.4",
"description": "Builds source and binary code graphs for security analysis, context slicing, mutation testing, cryptographic protocol modeling, finding triage, and variant analysis.",
"author": {
"name": "Scott Arciszewski",
"url": "https://github.com/tob-scott-a"
},
"source": "./plugins/trailmark"
},
{
"name": "variant-analysis",
"version": "2.0.4",
"description": "Find similar vulnerabilities and bugs across codebases using pattern-based analysis",
"author": {
"name": "Axel Mierczuk"
},
"source": "./plugins/variant-analysis"
},
{
"name": "c-review",
"version": "2.0.3",
"description": "Comprehensive C/C++ security code review, with coverage verified against a parse of the source",
"author": {
"name": "Paweł Płatek"
},
"source": "./plugins/c-review"
},
{
"name": "rust-review",
"version": "1.1.2",
"description": "Comprehensive Rust security code review with specialized bug-finding agents covering the safe/unsafe boundary, memory safety in unsafe blocks, concurrency, panic-induced DoS, recursion-induced stack overflow, FFI, and async runtime hazards",
"author": {
"name": "Andrea Cappa (Aptos Labs) & Paweł Płatek (Trail of Bits)"
},
"source": "./plugins/rust-review"
},
{
"name": "modern-python",
"version": "1.6.2",
"description": "Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.",
"author": {
"name": "William Tan",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/modern-python"
},
{
"name": "insecure-defaults",
"version": "2.0.3",
"description": "Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production",
"author": {
"name": "Trail of Bits",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/insecure-defaults"
},
{
"name": "review-walkthrough",
"version": "1.2.3",
"description": "Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.",
"author": {
"name": "Facundo Tuesca",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/review-walkthrough"
},
{
"name": "second-opinion",
"version": "1.8.3",
"description": "Gets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits.",
"author": {
"name": "Dan Guido"
},
"source": "./plugins/second-opinion"
},
{
"name": "yara-authoring",
"version": "2.1.3",
"description": "YARA-X detection rule authoring with linting and quality analysis",
"author": {
"name": "Trail of Bits",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/yara-authoring"
},
{
"name": "git-cleanup",
"version": "2.3.3",
"description": "Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work.",
"author": {
"name": "Henrik Brodin",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/git-cleanup"
},
{
"name": "goal-prompt",
"version": "0.1.2",
"description": "Drafts copy-ready /goal commands for goal mode in Claude Code and Codex: verifiable completion conditions with stop bounds, normalized to a single line under the 4,000-character cap.",
"author": {
"name": "Paweł Płatek"
},
"source": "./plugins/goal-prompt"
},
{
"name": "supply-chain-risk-auditor",
"version": "2.0.4",
"description": "Audit a project's npm, PyPI, and Go dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned upstreams, npm publisher concentration, and install scripts",
"author": {
"name": "Eric Quintero"
},
"source": "./plugins/supply-chain-risk-auditor"
},
{
"name": "zeroize-audit",
"version": "0.3.3",
"description": "Detects missing or compiler-optimized zeroization of sensitive data with assembly and control-flow analysis",
"author": {
"name": "Trail of Bits",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/zeroize-audit"
},
{
"name": "let-fate-decide",
"version": "1.2.5",
"description": "Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous.",
"author": {
"name": "Scott Arciszewski",
"url": "https://github.com/tob-scott-a"
},
"source": "./plugins/let-fate-decide"
},
{
"name": "agentic-actions-auditor",
"version": "1.3.2",
"description": "Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference)",
"author": {
"name": "Emilio López & Will Vandevanter"
},
"source": "./plugins/agentic-actions-auditor"
},
{
"name": "code-improver",
"version": "1.0.2",
"description": "Improves code targets — skills, plugins, or a branch's changes — through an autonomous review-and-fix workflow with a pluggable reviewer (any installed skill or agent), a cross-round findings ledger, oscillation escalation, and a mechanical scope guard.",
"author": {
"name": "Paweł Płatek",
"url": "https://github.com/GrosQuildu"
},
"source": "./plugins/code-improver"
},
{
"name": "fp-check",
"version": "1.0.5",
"description": "Systematic false positive verification for security bug analysis with mandatory gate reviews",
"author": {
"name": "Maciej Domanski"
},
"source": "./plugins/fp-check"
},
{
"name": "dimensional-analysis",
"version": "3.0.3",
"description": "Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol. Prevents dimensional mismatches and catches formula bugs early.",
"author": {
"name": "Coriolan Pinhas & Benjamin Samuels",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/dimensional-analysis"
},
{
"name": "vulnerability-triage-brocards",
"version": "0.1.3",
"description": "Principled framework for triaging vulnerability reports using 7 brocards (rules of thumb). Evaluates incoming CVEs, bug bounty submissions, and security findings against structured dismissal/acceptance criteria before escalating to deeper analysis.",
"author": {
"name": "Alexis Challande",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/vulnerability-triage-brocards"
},
{
"name": "github-triage",
"version": "0.1.2",
"description": "Triages a repository's open GitHub issues and pull requests via the gh CLI: optionally merges ready bot and maintainer-approved PRs and spawns review subagents for unreviewed ones, closes already-resolved issues with referenced explanations, cross-links issues with pending fix PRs, and assigns local-only priority and change-size estimates.",
"author": {
"name": "Evan Sultanik",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/github-triage"
},
{
"name": "open-sourcing",
"version": "0.1.2",
"description": "Prepares a repository for public open-source release: secrets-history hygiene, license selection, documentation and CI readiness checks, and language-specific packaging and release guidance.",
"author": {
"name": "Evan Sultanik",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/open-sourcing"
},
{
"name": "writing-lean-proofs",
"version": "0.1.2",
"description": "Structured Lean 4 proof writing and library design following Mathlib conventions",
"author": {
"name": "Fredrik Dahlgren",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/writing-lean-proofs"
},
{
"name": "modern-cpp",
"version": "1.0.2",
"description": "Modern C++ best practices (C++20/23/26). Use when writing C++ code, creating new C++ projects, or modernizing legacy C++ patterns.",
"author": {
"name": "Julius Alexandre",
"email": "opensource@trailofbits.com",
"url": "https://github.com/trailofbits"
},
"source": "./plugins/modern-cpp"
}
]
}Facts
- Kind
- Marketplace
- Repo
- trailofbits/skills
- Group
- Uncategorized
- Marketplace name
- trailofbits
- Owner
- Trail of Bits
- License
- CC-BY-SA-4.0
- Language
- Python
- Created
- 2026-01-14
- Forks
- 634
- Topics
- agent-skills
- Plugins
- 28
- 1f/prompts.chatf/prompts.chatf.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
- 2affaan-m/everything-claude-codeaffaan-m/everything-claude-codeThe agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
- 3obra/superpowersobra/superpowersAn agentic skills framework & software development methodology that works.
- 4anthropics/skillsanthropics/skillsPublic repository for Agent Skills
- 5anthropics/claude-codeanthropics/claude-codeClaude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
- 6nextlevelbuilder/ui-ux-pro-max-skillnextlevelbuilder/ui-ux-pro-max-skillAn AI skill that provides design intelligence for building professional UI/UX across multiple platforms.