Baike.dev
All toolsTrendingOpen sourceNewsSubmit
Log in
< 返回工具列表
S

skills

> AI 编程
开源

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

220.5K stars0 点赞0 次浏览
访问官网GitHub

工具介绍

Trail of Bits Skills Marketplace A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility. > Also see: claude-code-config · skills-curated · claude-code-devcontainer · dropkit Installation Claude Code Marketplace Browse and Install Plugins Codex Codex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata. Install the marketplace with: Local Development To add the marketplace locally (e.g., for testing or development), navigate to the **parent directory** of this repository: Available Plugins Smart Contract Security | Plugin | Description | |--------|-------------| | building-secure-contracts | Smart contract security toolkit with vulnerability scanners for 6 blockchains | | entry-point-analyzer | Identify state-changing entry points in smart contracts for security auditing | Code Auditing | Plugin | Description | |--------|-------------| | agentic-actions-auditor | Audit GitHub Actions workflows for AI agent security vulnerabilities | | audit-context-building | Understand a codebase before looking for bugs in it, one function at a time | | burpsuite-project-parser | Search and extract data from Burp Suite project files | | c-review | Comprehensive C/C++ security review with clustered parallel workers and SARIF output | | differential-review | Security-focused differential review of code changes with git history analysis | | dimensional-analysis | Annotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs | | fp-check | Systematic false positive verification for security bug analysis with mandatory gate reviews | | insecure-defaults | Parallel audit workflow for fail-open insecure defaults, with a refuting verifier per candidate file | | rust-review | Comprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and async runtime with SARIF output | | semgrep-rule-creator | Create and refine Semgrep rules for custom vulnerability detection | | semgrep-rule-variant-creator | Port existing Semgrep rules to new target languages with test-driven validation | | sharp-edges | Identify error-prone APIs, dangerous configurations, and footgun designs | | static-analysis | Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing | | supply-chain-risk-auditor | Audit npm, PyPI, and Go dependencies for version-matched advisories, abandoned upstreams, publisher concentration, and install scripts | | testing-handbook-skills | Skills from the Testing Handbook: fuzzers, static analysis, sanitizers, coverage | | trailmark | Code graph analysis, bounded subagent context slicing, Mermaid diagrams, mutation testing triage, and protocol verification | | variant-analysis | Find similar vulnerabilities across codebases using pattern-based analysis | | vulnerability-triage-brocards | Triage vulnerability reports using 7 brocards to accept, dismiss, or request more info before deeper analysis | Malware Analysis | Plugin | Description | |--------|-------------| | yara-authoring | YARA detection rule authoring with linting, atom analysis, and best practices | Verification | Plugin | Description | |--------|-------------| | constant-time-analysis | Detect compiler-induced timing side-channels in cryptographic code | | mutation-testing | Configure mewt/muton mutation testing campaigns — scope targets, tune timeouts, optimize long runs | | property-based-testing | Write, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants | | spec-to-code-compliance | Check code against the documentation that specifies it, across contracts, C/C++, services, and firmware | | writing-lean-proofs | Write structured Lean 4 proofs and design Lean libraries following Mathlib conventions | | zeroize-audit | Detect missing or compiler-eliminated zeroization of secrets in C/C++ and Rust | Reverse Engineering | Plugin | Description | |--------|-------------| | dwarf-expert | Analyze DWARF debug info: parse and search DIEs, verify integrity, write DWARF parsing code | Mobile Security | Plugin | Description | |--------|-------------| | firebase-apk-scanner | Scan Android APKs for Firebase security misconfigurations | Development | Plugin | Description | |--------|-------------| | devc

核心特点

  • •Trail of Bits Skills Marketplace
  • •> Also see: claude-code-config · skills-curated · claude-code-devcontainer · dropkit
  • •Installation
  • •Claude Code Marketplace
  • •Browse and Install Plugins
  • •Codex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata.
  • •Install the marketplace with:
  • •Local Development

> 标签

Pythonagent-skills

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年8月18日
分类AI 编程
定价开源

> 相关工具

G
GitHub Copilot
AI 编程助手,上下文感知代码补全
C
Cursor
面向 AI 结对编程的代码编辑器
S
skills
Skills for Real Engineers. Straight from my .agents directory.
Baike.dev

baike.dev helps you discover great languages, frameworks, databases, DevOps and cloud-native tools.

Quick links

  • Home
  • All tools
  • Trending
  • Open source

About

  • About us
  • Community
  • News

Contribute

Found a great developer tool? Share it with the community.

Submit a tool
© 2026 baike.dev Developer EncyclopediaUpdated daily · Discover great developer tools