SkillPass
Official

trailofbits

75 skills

Published skills (75)

01AD
AddressSanitizer
Detects memory errors like buffer overflows and use-after-free bugs in C/C++ code during fuzzing.
2mo ago
Fuzzing
by trailofbits
02AF
AFL++
Multi-core fuzzing tool for C/C++ projects with enhanced performance and advanced features.
2mo ago
Fuzzing
by trailofbits
03AA
Agentic Actions Auditor
Scans GitHub Actions workflows for security vulnerabilities in AI agent integrations and detects prompt injection attack vectors in CI/CD pipelines.
2mo ago
Security Review
by trailofbits
04AS
Algorand Vulnerability Scanner
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks and access control issues.
2mo ago
Security Review
by trailofbits
05AU
Ask Questions If Underspecified
Prompts clarification of ambiguous requirements before proceeding with implementation.
2mo ago
Agent Workflow
by trailofbits
06AT
Atheris
Coverage-guided fuzzer for testing Python code and C extensions through automated input generation.
2mo ago
Fuzzing
by trailofbits
07AA
Audit Augmentation
Maps SARIF and weAudit security findings onto code graphs, linked by file and line location.
2mo ago
Code Analysis
by trailofbits
08AB
Audit Context Building
Performs line-by-line code analysis to establish detailed architectural context for vulnerability and bug detection.
2mo ago
Code Analysis
by trailofbits
09AA
Audit Prep Assistant
Prepares codebases for security review by running analysis tools, improving test coverage, and generating documentation.
2mo ago
Security Review
by trailofbits
10BP
Burp Suite Project Parser
Search and extract data from Burp Suite project files using regex patterns and command-line queries.
2mo ago
Security Review
by trailofbits
11CR
C/C++ Security Review
Analyzes C/C++ code for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities.
2mo ago
Security Review
by trailofbits
12CS
Cairo Vulnerability Scanner
Scans Cairo and StarkNet smart contracts for critical vulnerabilities including arithmetic overflow and messaging issues.
2mo ago
Blockchain
by trailofbits
13CF
Cargo Fuzz
Fuzz test Rust projects with libFuzzer integration through Cargo.
2mo ago
Fuzzing
by trailofbits
14CT
Chrome MCP Troubleshooting
Diagnoses and resolves connectivity issues with the Claude in Chrome MCP extension.
2mo ago
Dev Tooling
by trailofbits
15CA
Code Maturity Assessor
Evaluates codebase against nine security and quality dimensions with evidence-based ratings and recommendations.
2mo ago
Code Analysis
by trailofbits
16CS
CodeQL Security Scanner
Scans codebases for security vulnerabilities using interprocedural data flow and taint tracking analysis.
2mo ago
Code Analysis
by trailofbits
17CA
Constant-Time Analysis
Detects timing side-channel vulnerabilities in cryptographic code across multiple programming languages.
2mo ago
Cryptography
by trailofbits
18CT
Constant-Time Testing
Detects timing side channels in cryptographic code to prevent timing-based attacks.
2mo ago
Cryptography
by trailofbits
19CS
Cosmos Vulnerability Scanner
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical vulnerabilities including chain halts, fund loss, and state divergence.
2mo ago
Blockchain
by trailofbits
20CA
Coverage Analysis
Measures code exercised during fuzzing to assess harness effectiveness and identify blockers.
2mo ago
Fuzzing
by trailofbits
21CD
Crypto Protocol Diagram
Extracts protocol message flows from specifications, code, or formal models and generates annotated sequence diagrams.
2mo ago
Cryptography
by trailofbits
22CI
Culture Index Interpreter
Analyzes Culture Index behavioral profiles and assessments for team dynamics, hiring, and conflict resolution.
2mo ago
Notes & Knowledge
by trailofbits
23DC
Debug Buttercup CRS
Diagnoses and troubleshoots Buttercup Cyber Reasoning System pods and services running on Kubernetes.
2mo ago
Dev Tooling
by trailofbits
24DS
Dev Container Setup
Creates isolated development containers with Claude Code and language-specific tooling for Python, Node, Rust, and Go.
2mo ago
Dev Tooling
by trailofbits
25DC
Diagramming Code
Generates Mermaid diagrams visualizing code architecture, call graphs, dependencies, class hierarchies, and data flows.
2mo ago
Code Analysis
by trailofbits
26DR
Differential Review
Analyzes code changes for security risks with context-aware depth and blast radius assessment.
2mo ago
Security Review
by trailofbits
27DA
Dimensional Analysis
Annotates code with dimensional analysis comments to document units, dimensions, and catch arithmetic vulnerabilities.
2mo ago
Code Analysis
by trailofbits
28DE
DWARF Expert
Analyzes DWARF debug files and explains the DWARF debug format standard across versions 3-5.
2mo ago
Code Analysis
by trailofbits
29EA
Entry Point Analyzer
Identifies state-changing functions in smart contracts and categorizes them by access level for security auditing.
2mo ago
Blockchain
by trailofbits
30FS
Firebase APK Scanner
Scans Android APKs for Firebase security misconfigurations, exposed databases, storage buckets, and authentication issues.
2mo ago
Security Review
by trailofbits
31FC
FP Check
Systematically verifies suspected security bugs to determine if they are true positives or false positives with documented evidence.
2mo ago
Security Review
by trailofbits
32FD
Fuzzing Dictionary
Guides fuzzers with domain-specific tokens for testing parsers, protocols, and format-specific code.
2mo ago
Fuzzing
by trailofbits
33FW
Fuzzing Harness Writing
Learn techniques for writing effective fuzzing harnesses across multiple programming languages.
2mo ago
Fuzzing
by trailofbits
34FO
Fuzzing Obstacles
Patch code barriers like checksums and global state that block fuzzer progress.
2mo ago
Fuzzing
by trailofbits
35GE
Genotoxic
Analyzes mutation testing results using call graphs to identify test gaps and weak coverage areas.
2mo ago
Testing & QA
by trailofbits
36GC
Git Cleanup
Analyzes and safely removes local git branches and worktrees by detecting merged, squash-merged, superseded, or abandoned work.
2mo ago
Dev Practices
by trailofbits
37GC
GitHub CLI
Execute authenticated GitHub operations using the gh CLI instead of direct API calls.
2mo ago
Dev Tooling
by trailofbits
38GE
Graph Evolution
Compares code structure between snapshots to detect security-relevant changes like new attack paths and taint propagation shifts.
2mo ago
Code Analysis
by trailofbits
39GA
Guidelines Advisor
Analyzes smart contract code against Trail of Bits best practices and generates documentation, security assessments, and actionable recommendations.
2mo ago
Blockchain
by trailofbits
40ID
Insecure Defaults Detection
Detects hardcoded secrets, weak authentication, and permissive security configurations that enable insecure production deployments.
2mo ago
Security Review
by trailofbits
41LD
Let Fate Decide
Uses a 12-house Tarot spread to resolve ambiguous requests and inject guided randomness into planning.
2mo ago
Agent Workflow
by trailofbits
42LI
LibAFL
Build custom fuzzers with modular components for advanced fuzzing, mutations, and specialized targets.
2mo ago
Fuzzing
by trailofbits
43LI
libFuzzer
Coverage-guided fuzzing for C/C++ code compiled with Clang.
2mo ago
Fuzzing
by trailofbits
44MP
Mermaid to ProVerif
Converts Mermaid sequence diagrams of cryptographic protocols into ProVerif formal verification models.
2mo ago
Cryptography
by trailofbits
45MP
Modern Python
Configures Python projects with modern tooling including uv, ruff, and type checking.
2mo ago
Dev Tooling
by trailofbits
46MS
Mutation Testing Setup
Configures mutation testing campaigns with mewt or muton, optimizing targets and timeouts for your test runs.
2mo ago
Testing & QA
by trailofbits
47OS
OSS-Fuzz
Sets up continuous fuzzing infrastructure and enrolls open source projects in free automated fuzz testing.
2mo ago
Fuzzing
by trailofbits
48PT
Property-Based Testing
Guides you through property-based testing for code and smart contracts across multiple languages.
2mo ago
Testing & QA
by trailofbits
49RR
Rust Security Review
Analyzes Rust code for unsafe blocks, memory safety issues, concurrency hazards, and FFI vulnerabilities.
2mo ago
Security Review
by trailofbits
50RU
Ruzzy
Coverage-guided fuzzer for Ruby code and C extensions by Trail of Bits.
2mo ago
Fuzzing
by trailofbits
51SP
SARIF Parsing
Parses and processes SARIF files from static analysis tools, handling filtering, deduplication, and format conversion.
2mo ago
Code Analysis
by trailofbits
52SS
Seatbelt Sandboxer
Generates minimal macOS Seatbelt sandbox configurations with allowlist-based profiles.
2mo ago
Dev Tooling
by trailofbits
53SO
Second Opinion
Runs external LLM code reviews on uncommitted changes, diffs, or commits using OpenAI or Google models.
2mo ago
Security Review
by trailofbits
54SG
Secure Workflow Guide
Guides smart contract security through automated scanning, conformance checks, visual diagrams, and property documentation.
2mo ago
Security Review
by trailofbits
55SE
Semgrep
Run static analysis scans on codebases to detect vulnerabilities, bugs, and security issues across multiple languages.
2mo ago
Code Analysis
by trailofbits
56SC
Semgrep Rule Creator
Generates custom Semgrep rules to detect security vulnerabilities, bugs, and specific code patterns in static analysis.
2mo ago
Code Analysis
by trailofbits
57SC
Semgrep Rule Variant Creator
Generates language-specific variants of Semgrep rules with test directories for target languages.
2mo ago
Code Analysis
by trailofbits
58SE
Sharp Edges
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes.
2mo ago
Security Review
by trailofbits
59SI
Skill Improver
Iteratively reviews and refixes Claude Code skills until they meet quality standards.
2mo ago
Agent Workflow
by trailofbits
60SS
Solana Vulnerability Scanner
Detects critical security vulnerabilities in Solana programs including CPI exploits, PDA validation flaws, and signer checks.
2mo ago
Blockchain
by trailofbits
61SC
Spec to Code Compliance
Verifies that code implementations match their technical specifications and documentation requirements.
2mo ago
Security Review
by trailofbits
62SS
Substrate Vulnerability Scanner
Scans Substrate pallets for critical vulnerabilities including overflow, panic DoS, incorrect weights, and origin checks.
2mo ago
Security Review
by trailofbits
63SA
Supply Chain Risk Auditor
Identifies dependencies at heightened risk of exploitation or takeover to assess supply chain vulnerabilities.
2mo ago
Security Review
by trailofbits
64TG
Testing Handbook Generator
Generates Claude Code skills for security testing tools by analyzing the Trail of Bits Testing Handbook.
2mo ago
Agent Workflow
by trailofbits
65TA
Token Integration Analyzer
Analyzes token implementations and integrations for ERC20/ERC721 conformity, detects non-standard patterns, and assesses contract risks.
2mo ago
Blockchain
by trailofbits
66TS
TON Vulnerability Scanner
Scans TON smart contracts for critical vulnerabilities including integer-as-boolean misuse, fake Jettons, and unsafe forward operations.
2mo ago
Security Review
by trailofbits
67TR
Trailmark
Builds and queries source code graphs with security analysis for attack surface mapping and taint propagation tracking.
2mo ago
Code Analysis
by trailofbits
68TA
Trailmark Structural Analysis
Analyzes Trailmark code structure to identify hotspots, taint paths, blast radius, and privilege boundaries.
2mo ago
Code Analysis
by trailofbits
69TS
Trailmark Summary
Analyzes a codebase to detect languages, count entry points, and list dependencies.
2mo ago
Code Analysis
by trailofbits
70VA
Variant Analysis
Find similar vulnerabilities and bugs across codebases using pattern-based analysis.
2mo ago
Code Analysis
by trailofbits
71VF
Vector Forge
Generates cryptographic test vectors by identifying uncovered code paths through mutation testing.
2mo ago
Cryptography
by trailofbits
72WD
Workflow Skill Design
Guides structuring multi-step Claude Code skills with phases, routing, delegation, and safety gates.
2mo ago
Agent Workflow
by trailofbits
73WY
Wycheproof
Test cryptographic implementations against known attacks and edge cases with comprehensive test vectors.
2mo ago
Cryptography
by trailofbits
74YA
YARA Rule Authoring
Guides creation and optimization of YARA-X malware detection rules with best practices for performance and accuracy.
2mo ago
Security Review
by trailofbits
75ZA
Zeroization Audit
Detects missing zeroization of sensitive data in source code and identifies compiler optimization removals.
2mo ago
Security Review
by trailofbits