EasyGlobe EasyGlobe
Back to Skills Hub

GitHub Repository Detail

trailofbits/skills

trailofbits/skills · generated-local-file

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows — a GitHub Skill repository verified at commit 7be90d6 with 79 SKILL.md files for skill collections workflows.

Skill Overview

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows — a GitHub Skill repository verified at commit 7be90d6 with 79 SKILL.md files for skill collections workflows.

What task this skill solves

This is a repository-level resource. The directory does not split its multiple Skills into duplicate entries. Review the representative paths and sampled commit, then use the upstream README for installation and runtime requirements.

  • Check the default branch, sampled commit, and last push.
  • Use representative SKILL.md paths to judge task coverage.
  • Independently review upstream code, scripts, license, and permissions before installation.

Resource Type

GitHub Hot Skill Repositories

Categories

Meta & Tools

Tags

Skill Collections, agent-skills, GitHub Skills

The download is an EasyGlobe-authored bilingual repository brief with verification evidence, not a redistributed repository or directly installable single Skill.

Detailed Skill Introduction

What trailofbits/skills is for

trailofbits/skills is an AI agent skill resource for Meta & Tools workflows. Based on the archived project material, its core value is: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows — a GitHub Skill repository verified at commit 7be90d6 with 79 SKILL.md files for skill collections workflows.. This detail page focuses on the practical questions to answer before adopting the skill: what task it solves, how setup works, which README notes matter, where the local Markdown copy is available, and whether the workflow can be adapted for Claude, Codex, Gemini, Kimi, GLM, ChatGPT, or an internal AI agent.

README summary

> This is an EasyGlobe-authored bilingual repository brief, not a redistributed third-party Skill and not an installable copy of the repository. Review the upstream repository before use.

README capability notes

| Path | Frontmatter name | Frontmatter description | SHA-256 |

| --- | --- | --- | --- |

| plugins/agentic-actions-auditor/skills/agentic-actions-auditor/SKILL.md | agentic-actions-auditor | Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations....

Workflow fit and practical value

The current taxonomy places trailofbits/skills under Meta & Tools, with tags such as Skill Collections, agent-skills, GitHub Skills. That means the skill should be evaluated through the lens of repeatable work: what task it helps an AI agent perform, what context the agent needs, what output a user should expect, and whether the workflow can be reused as a team SOP. The archived README is used as the first source of truth whenever it includes feature lists, examples, setup notes, or usage guidance. The local Markdown download is useful for review, internal documentation, and adapting the instructions into your own agent skills repository.

Installation, usage, and platform notes

No explicit installation section was found in the archived README. Open the original source for the official setup path; the download button provides the local Markdown copy saved by EasyGlobe. Use this skill when the task involves Skill Collections, agent-skills, GitHub Skills. It can be adapted into Claude Skills, Codex Skills, Gemini Skills, Kimi Skills, GLM Skills, or a team SOP. If the README does not include a complete command-by-command setup path, the Skill URL remains the official source for the latest installation instructions. Platform support should be confirmed from the original project, but the information on this page is organized so it can be reused as a reference for Claude, Codex, Gemini, Kimi, GLM, ChatGPT, or internal AI agent workflows.

Capabilities

| Path | Frontmatter name | Frontmatter description | SHA-256 |

| --- | --- | --- | --- |

| plugins/agentic-actions-auditor/skills/agentic-actions-auditor/SKILL.md | agentic-actions-auditor | Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations. | 80e36ab06e3ee667ac45bab036ed395fc425c4d54fa72c4b4981a5b982a389aa |

| plugins/audit-context-building/skills/audit-context-building/SKILL.md | audit-context-building | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass. | 222efa73743565a8fdb42e9bd08e9649c739fa0abc11129b35d267c9814b5916 |

| plugins/building-secure-contracts/skills/algorand-vulnerability-scanner/SKILL.md | algorand-vulnerability-scanner | Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal). | 55e5336040e0f24ac5b3d6258ac458cd7cbd9ae0f7db5541fe4ed95c10b58c58 |

| plugins/building-secure-contracts/skills/audit-prep-assistant/SKILL.md | audit-prep-assistant | Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). | ea7db549ff26a57ebd101140dd8ed44434d5c91f3d91efc8927541bea8dd23e8 |...

Supported Platforms

Use this skill as a reference template for these AI agents, model workflows, or team SOPs.

Claude SkillsCodex SkillsGemini SkillsKimi SkillsGLM SkillsChatGPT Skills

Configuration & Updates

No standalone configuration section was detected in the archive. If the source project requires API keys, account auth, CLI setup, or plugin config, follow the Skill URL.

README Command Examples

No displayable command code block was detected in the README.

Tags

Skill Collectionsagent-skillsGitHub Skills

FAQ

Is trailofbits/skills a single Skill?

No. This page represents one GitHub repository. It may contain multiple Skills, and at least one sampled SKILL.md passed the name and description frontmatter gate.

What is in the repository brief download?

It contains an EasyGlobe-authored bilingual summary, repository metadata, representative paths, and frontmatter content hashes. It does not contain the third-party repository or original Skill text.

How is the hot rank calculated?

The score combines weekly/monthly GitHub trend signals, log-normalized stars, age-adjusted stars per day, recent push/release activity, and Skill packaging, documentation, license, and static safety clarity.

Is verification a security audit?

No. Verification confirms repository eligibility, valid frontmatter, and a limited set of static risk patterns. Independently review upstream code, scripts, and permissions before installation.