token-integration-analyzer

Systematically analyzes the codebase for token-related security concerns using Trail of Bits' token integration checklis...

github

substrate-vulnerability-scanner

Systematically scan Substrate runtime modules (pallets) for platform-specific security vulnerabilities that can cause no...

github

solana-vulnerability-scanner

Systematically scan Solana programs (native and Anchor framework) for platform-specific security vulnerabilities related...

github

secure-workflow-guide

Guides through Trail of Bits' secure development workflow - a 5-step process to enhance smart contract security througho...

github

guidelines-advisor

Systematically analyzes the codebase and provides guidance based on Trail of Bits' development guidelines: Generate docu...

github

cosmos-vulnerability-scanner

Scan Cosmos SDK modules and CosmWasm contracts for vulnerabilities that cause chain halts, consensus failures, or fund l...

github

code-maturity-assessor

Systematically assesses codebase maturity using Trail of Bits' 9-category framework. Provides evidence-based ratings and...

github

cairo-vulnerability-scanner

Systematically scan Cairo smart contracts on StarkNet for platform-specific security vulnerabilities related to arithmet...

github

audit-prep-assistant

Helps prepare for a security review using Trail of Bits' checklist. A well-prepared codebase makes the review process sm...

github

algorand-vulnerability-scanner

Systematically scan Algorand smart contracts (TEAL and PyTeal) for platform-specific security vulnerabilities documented...

github

audit-augmentation

Projects findings from external tools (SARIF) and human auditors (weAudit) onto Trailmark code graphs as annotations and...

github

dimensional-analysis

This skill orchestrates a dimensional-analysis pipeline for codebases that perform numeric computations with mixed units...

github

variant-analysis

You are a variant analysis expert. Your role is to help find similar vulnerabilities and bugs across a codebase after id...

github

let-fate-decide

When the path forward is unclear, let the cards speak. Run the drawing script: uv run --no-config {baseDir}/scripts/draw...

github

libafl

LibAFL is a modular fuzzing library that implements features from AFL-based fuzzers like AFL++. Unlike traditional fuzze...

github

differential-review

Security-focused code review for PRs, commits, and diffs. Risk-First: Focus on auth, crypto, value transfer, external ca...

github

modern-python

Guide for modern Python tooling and best practices, based on trailofbits/cookiecutter-python. Creating a new Python proj...

github

entry-point-analyzer

Systematically identify all state-changing entry points in a smart contract codebase to guide security audits. Use this ...

github

insecure-defaults

Finds fail-open vulnerabilities where apps run insecurely with missing configuration. Distinguishes exploitable defaults...

github

devcontainer-setup

Creates a pre-configured devcontainer with Claude Code and language-specific tooling. User asks to "set up a devcontaine...

github

c-review

Runs in the main conversation (invoke via /c-review:c-review). Orchestrator owns the Task ledger as bookkeeping for retr...

github

crypto-protocol-diagram

Produces a Mermaid sequenceDiagram (written to file) and an ASCII sequence diagram (printed inline) from either: Source ...

github

agentic-actions-auditor

Static security analysis guidance for GitHub Actions workflows that invoke AI coding agents. This skill teaches you how ...

github

fp-check

"Is this bug real?" or "is this a true positive?" "Is this a false positive?" or "verify this finding" "Check if this vu...

github