{"slug": "trail-of-bits-skills-marketplace", "title": "Trail of Bits Skills Marketplace", "summary": "Trail of Bits released a Claude Code plugin marketplace with 26 security-focused skills for AI-assisted code analysis, including auditors for GitHub Actions, C/C++, Rust, and supply chains, plus tools for static analysis, mutation testing, and YARA rule authoring. The marketplace is compatible with Codex via Claude marketplace support and can be installed locally for testing.", "body_md": "Trail of Bits Skills Marketplace\nA Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.\n\nAlso see: claude-code-config · skills-curated · claude-code-devcontainer · dropkit\n\nBrowse and Install Plugins\nCodex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata.\n\nInstall the marketplace with:\n\nTo add the marketplace locally (e.g., for testing or development), navigate to the parent directory of this repository:\n\nPlugin\nDescription\nagentic-actions-auditor\nAudit GitHub Actions workflows for AI agent security vulnerabilities\naudit-context-building\nUnderstand a codebase before looking for bugs in it, one function at a time\nburpsuite-project-parser\nSearch and extract data from Burp Suite project files\nc-review\nComprehensive C/C++ security review with clustered parallel workers and SARIF output\ndifferential-review\nSecurity-focused differential review of code changes with git history analysis\ndimensional-analysis\nAnnotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs\nfp-check\nSystematic false positive verification for security bug analysis with mandatory gate reviews\ninsecure-defaults\nParallel audit workflow for fail-open insecure defaults, with a refuting verifier per candidate file\nrust-review\nComprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and async runtime with SARIF output\nsemgrep-rule-creator\nCreate and refine Semgrep rules for custom vulnerability detection\nsemgrep-rule-variant-creator\nPort existing Semgrep rules to new target languages with test-driven validation\nsharp-edges\nIdentify error-prone APIs, dangerous configurations, and footgun designs\nstatic-analysis\nStatic analysis toolkit with CodeQL, Semgrep, and SARIF parsing\nsupply-chain-risk-auditor\nAudit npm, PyPI, and Go dependencies for version-matched advisories, abandoned upstreams, publisher concentration, and install scripts\ntesting-handbook-skills\nSkills from the Testing Handbook : fuzzers, static analysis, sanitizers, coverage\ntrailmark\nCode graph analysis, bounded subagent context slicing, Mermaid diagrams, mutation testing triage, and protocol verification\nvariant-analysis\nFind similar vulnerabilities across codebases using pattern-based analysis\nvulnerability-triage-brocards\nTriage vulnerability reports using 7 brocards to accept, dismiss, or request more info before deeper analysis\n\nPlugin\nDescription\nyara-authoring\nYARA detection rule authoring with linting, atom analysis, and best practices\n\nPlugin\nDescription\nconstant-time-analysis\nDetect compiler-induced timing side-channels in cryptographic code\nmutation-testing\nConfigure mewt/muton mutation testing campaigns — scope targets, tune timeouts, optimize long runs\nproperty-based-testing\nProperty-based testing guidance for multiple languages and smart contracts\nspec-to-code-compliance\nCheck code against the documentation that specifies it, across contracts, C/C++, services, and firmware\nwriting-lean-proofs\nWrite structured Lean 4 proofs and design Lean libraries following Mathlib conventions\nzeroize-audit\nDetect missing or compiler-eliminated zeroization of secrets in C/C++ and Rust\n\nPlugin\nDescription\ndwarf-expert\nAnalyze DWARF debug info: parse and search DIEs, verify integrity, write DWARF parsing code\n\nPlugin\nDescription\ndevcontainer-setup\nCreate pre-configured devcontainers with Claude Code and language-specific tooling\ngh-cli\nIntercept GitHub URL fetches and redirect to the authenticated `gh`\n\nCLI\ngit-cleanup\nSafely clean up git worktrees and local branches with gated confirmation workflow\ngithub-triage\nTriage open GitHub issues and PRs: merge ready bot/approved PRs, review unreviewed ones via subagents, close resolved issues with cited comments, cross-link pending fixes, and score the rest with local-only priority and change-size estimates\nlet-fate-decide\nDraw Tarot cards using cryptographic randomness to add entropy to vague planning\nmodern-python\nModern Python tooling and best practices with uv, ruff, and pytest\nopen-sourcing\nPrepare a repository for public release: secrets hygiene, licensing, CI readiness, and release automation\nsecond-opinion\nRun code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on changes, diffs, or commits. Bundles Codex's built-in MCP server.\nskill-improver\nIterative skill refinement loop using automated fix-review cycles\n\nPlugin\nDescription\nculture-index\nInterpret Culture Index survey results for individuals and teams\n\nBugs discovered using Trail of Bits Skills. Found something? Let us know!\n\nWhen reporting bugs you've found, feel free to mention:\n\nFound using Trail of Bits Skills\n\nWe welcome contributions! See AGENTS.md for skill authoring guidelines, and\nrun `make check`\n\nbefore you push — it runs most of CI locally (see AGENTS.md for\nwhat it does not cover).\n\nThis work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License . Made by Trail of Bits .", "url": "https://wpnews.pro/news/trail-of-bits-skills-marketplace", "canonical_source": "https://github.com/trailofbits/skills", "published_at": "2026-08-11 19:18:56+00:00", "updated_at": "2026-08-11 19:43:18.826612+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools", "ai-products"], "entities": ["Trail of Bits", "Claude Code", "Codex", "GitHub Actions", "Burp Suite", "Semgrep", "CodeQL", "YARA"], "alternates": {"html": "https://wpnews.pro/news/trail-of-bits-skills-marketplace", "markdown": "https://wpnews.pro/news/trail-of-bits-skills-marketplace.md", "text": "https://wpnews.pro/news/trail-of-bits-skills-marketplace.txt", "jsonld": "https://wpnews.pro/news/trail-of-bits-skills-marketplace.jsonld"}}