Skip to main content
Source repository

trailofbits/skills

These skills were imported into SkillJury from the public skills ecosystem.

62 linked skillsVisit source
Source listing

62 imported skills

fix-review

by trailofbits/skills

400

Differential analysis to verify commits address security findings without introducing bugs.

Software EngineeringFrontend and DesignFirst seen Jan 18, 2026

debug-buttercup

by trailofbits/skills

388

All pods run in namespace crs . Key services:

Software EngineeringFrontend and DesignFirst seen Feb 10, 2026

designing-workflow-skills

by trailofbits/skills

297

Build workflow-based skills that execute reliably by following structural patterns, not prose.

Software EngineeringFrontend and DesignFirst seen Feb 18, 2026

supply-chain-risk-auditor

by trailofbits/skills

279

Activates when the user says "audit this project's dependencies".

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

skill-improver

by trailofbits/skills

248

Iteratively improve a Claude Code skill using the skill-reviewer agent until it meets quality standards.

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

agentic-actions-auditor

by trailofbits/skills

240

Static security analysis guidance for GitHub Actions workflows that invoke AI coding agents. This skill teaches you how to discover workflow files locally or from remote GitHub repositories, identify AI action steps, follow cross-file references to composite actions and reusable workflows that may contain hidden AI...

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

let-fate-decide

by trailofbits/skills

231

When the path forward is unclear, let the cards speak.

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

seatbelt-sandboxer

by trailofbits/skills

231

Generate minimally-permissioned allowlist-based Seatbelt sandbox configurations for applications.

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

zeroize-audit

by trailofbits/skills

231

Detect missing zeroization of sensitive data in source code and identify zeroization that is removed or weakened by compiler optimizations (e.g., dead-store elimination), with mandatory LLVM IR/asm evidence. Capabilities include:

Software EngineeringFrontend and DesignFirst seen Feb 25, 2026

using-gh-cli

by trailofbits/skills

212

Always use gh instead of curl , wget , or WebFetch for GitHub URLs. The gh CLI uses the user's authenticated token automatically, so it:

Software EngineeringFrontend and DesignFirst seen Feb 11, 2026

fp-check

by trailofbits/skills

203

If you catch yourself thinking any of these, STOP.

Software EngineeringFrontend and Design

ask-questions-if-underspecified

by trailofbits/skills

1

Use this skill when a request has multiple plausible interpretations or key details (objective, scope, constraints, environment, or safety) are unclear.

Software EngineeringFrontend and DesignFirst seen Jan 18, 2026

differential-review

by trailofbits/skills

1

Security-focused code review for PRs, commits, and diffs.

Software EngineeringFrontend and DesignFirst seen Jan 18, 2026

semgrep

by trailofbits/skills

1

Run a Semgrep scan with automatic language detection, parallel execution via Task subagents, and merged SARIF output.

Software EngineeringFrontend and DesignFirst seen Jan 18, 2026
Page 3 of 3