# Trail of Bits Skills Marketplace

> Source: <https://github.com/trailofbits/skills>
> Published: 2026-08-11 19:18:56+00:00

Trail of Bits Skills Marketplace
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.

Also see: claude-code-config · skills-curated · claude-code-devcontainer · dropkit

Browse and Install Plugins
Codex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata.

Install the marketplace with:

To add the marketplace locally (e.g., for testing or development), navigate to the parent directory of this repository:

Plugin
Description
agentic-actions-auditor
Audit GitHub Actions workflows for AI agent security vulnerabilities
audit-context-building
Understand a codebase before looking for bugs in it, one function at a time
burpsuite-project-parser
Search and extract data from Burp Suite project files
c-review
Comprehensive C/C++ security review with clustered parallel workers and SARIF output
differential-review
Security-focused differential review of code changes with git history analysis
dimensional-analysis
Annotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs
fp-check
Systematic false positive verification for security bug analysis with mandatory gate reviews
insecure-defaults
Parallel audit workflow for fail-open insecure defaults, with a refuting verifier per candidate file
rust-review
Comprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and async runtime with SARIF output
semgrep-rule-creator
Create and refine Semgrep rules for custom vulnerability detection
semgrep-rule-variant-creator
Port existing Semgrep rules to new target languages with test-driven validation
sharp-edges
Identify error-prone APIs, dangerous configurations, and footgun designs
static-analysis
Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing
supply-chain-risk-auditor
Audit npm, PyPI, and Go dependencies for version-matched advisories, abandoned upstreams, publisher concentration, and install scripts
testing-handbook-skills
Skills from the Testing Handbook : fuzzers, static analysis, sanitizers, coverage
trailmark
Code graph analysis, bounded subagent context slicing, Mermaid diagrams, mutation testing triage, and protocol verification
variant-analysis
Find similar vulnerabilities across codebases using pattern-based analysis
vulnerability-triage-brocards
Triage vulnerability reports using 7 brocards to accept, dismiss, or request more info before deeper analysis

Plugin
Description
yara-authoring
YARA detection rule authoring with linting, atom analysis, and best practices

Plugin
Description
constant-time-analysis
Detect compiler-induced timing side-channels in cryptographic code
mutation-testing
Configure mewt/muton mutation testing campaigns — scope targets, tune timeouts, optimize long runs
property-based-testing
Property-based testing guidance for multiple languages and smart contracts
spec-to-code-compliance
Check code against the documentation that specifies it, across contracts, C/C++, services, and firmware
writing-lean-proofs
Write structured Lean 4 proofs and design Lean libraries following Mathlib conventions
zeroize-audit
Detect missing or compiler-eliminated zeroization of secrets in C/C++ and Rust

Plugin
Description
dwarf-expert
Analyze DWARF debug info: parse and search DIEs, verify integrity, write DWARF parsing code

Plugin
Description
devcontainer-setup
Create pre-configured devcontainers with Claude Code and language-specific tooling
gh-cli
Intercept GitHub URL fetches and redirect to the authenticated `gh`

CLI
git-cleanup
Safely clean up git worktrees and local branches with gated confirmation workflow
github-triage
Triage open GitHub issues and PRs: merge ready bot/approved PRs, review unreviewed ones via subagents, close resolved issues with cited comments, cross-link pending fixes, and score the rest with local-only priority and change-size estimates
let-fate-decide
Draw Tarot cards using cryptographic randomness to add entropy to vague planning
modern-python
Modern Python tooling and best practices with uv, ruff, and pytest
open-sourcing
Prepare a repository for public release: secrets hygiene, licensing, CI readiness, and release automation
second-opinion
Run code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on changes, diffs, or commits. Bundles Codex's built-in MCP server.
skill-improver
Iterative skill refinement loop using automated fix-review cycles

Plugin
Description
culture-index
Interpret Culture Index survey results for individuals and teams

Bugs discovered using Trail of Bits Skills. Found something? Let us know!

When reporting bugs you've found, feel free to mention:

Found using Trail of Bits Skills

We welcome contributions! See AGENTS.md for skill authoring guidelines, and
run `make check`

before you push — it runs most of CI locally (see AGENTS.md for
what it does not cover).

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License . Made by Trail of Bits .
