
More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
Most Used Tags
Diagnose and fix connectivity issues for the Claude in Chrome MCP extension.
Evaluates project dependencies for risk of exploitation or takeover.
Learn techniques for writing effective fuzzing harnesses across multiple programming languages.
Scans Algorand smart contracts for 11 common vulnerabilities to enhance security.
Configures mutation testing campaigns with mewt or muton, optimizing performance and scope.
Detects timing side-channel vulnerabilities in cryptographic code.
Configures Python projects with modern tooling for streamlined development.
Verifies code compliance with documentation for blockchain audits.
OSS-Fuzz offers free continuous fuzzing for open source projects, streamlining the testing process.
Coverage analysis measures code exercised during fuzzing to enhance harness effectiveness and identify blockers.
Generates minimal macOS Seatbelt sandbox configurations for application isolation.
Injects randomness into decision-making by drawing Tarot cards for vague prompts.
Generates mutation-driven test vectors for cryptographic algorithms to improve coverage.
Constant-time testing identifies timing side channels in cryptographic code to enhance security.
Conducts security-focused differential reviews of code changes to prevent vulnerabilities.
Expertise for analyzing DWARF debug files and understanding the DWARF standard (v3-v5).
Annotates codebases with dimensional analysis to prevent formula bugs and dimensional mismatches.
Systematically verifies suspected security bugs to eliminate false positives with documented evidence.
Safely analyze and clean up local git branches and worktrees by categorizing them.
Detects insecure defaults that allow applications to run with weak security configurations.
Runs external LLM code reviews on code changes using OpenAI Codex or Google Gemini.
AddressSanitizer detects memory errors during fuzzing C/C++ code.
Analyzes codebases to provide a quick structural overview with language detection and entry point count.
Generates sequence diagrams for cryptographic protocols from source code or specifications.
Scans codebases for security vulnerabilities using CodeQL's advanced analysis techniques.
Prepares codebases for security reviews using Trail of Bits' checklist, enhancing code quality and documentation.
Enhance smart contract security with a structured 5-step workflow.
Techniques for patching code to overcome fuzzing obstacles like checksums and global state.
AFL++ enhances fuzzing performance with multi-core support for C/C++ projects.
Smart contract development advisor that analyzes codebases and provides actionable recommendations based on best practices.
Scan Substrate/Polkadot pallets for critical vulnerabilities to enhance security.
Command-line tool for searching and analyzing Burp Suite project files (.burp).
Creates devcontainers with Claude Code and language-specific tooling for isolated development.
Interprets Culture Index surveys and behavioral profiles for team and individual insights.
Run Semgrep static analysis scans on codebases with parallel execution for enhanced performance.
Atheris is a coverage-guided fuzzer for Python code and C extensions, leveraging libFuzzer.
Fuzzing dictionaries enhance fuzzers with domain-specific tokens for effective testing.
Conducts comprehensive structural analysis for codebases using Trailmark.
Augments Trailmark code graphs with external audit findings for enhanced analysis.
Graph-informed mutation testing triage for identifying test gaps and fuzzing targets.
Translates Mermaid sequence diagrams of cryptographic protocols into ProVerif models for formal verification.
Identify and analyze similar vulnerabilities across codebases using pattern-based techniques.
Create custom Semgrep rules to detect security vulnerabilities and code patterns.
Create language variants of existing Semgrep rules for targeted applications.
Builds and queries multi-language source code graphs for security analysis.
Guidance for implementing property-based testing across multiple languages and smart contracts.
Audits C/C++/Rust code for missing zeroization of sensitive data, ensuring secure handling of secrets.
Scans TON smart contracts for critical vulnerabilities in FunC code.
Enables ultra-granular, line-by-line code analysis for deep architectural context before vulnerability discovery.
Scan Solana programs for critical vulnerabilities to enhance security.
Systematic assessment of code maturity using a 9-category framework.
Create high-quality YARA-X detection rules for effective malware identification.
LibAFL is a modular fuzzing library for building custom fuzzers with advanced features.
Identifies error-prone APIs and configurations to prevent security mistakes.
Scan Android APKs for Firebase security misconfigurations and vulnerabilities.
Scans Cairo/StarkNet smart contracts for critical vulnerabilities.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations.
Parses and processes SARIF files from static analysis tools for actionable insights.
Coverage-guided fuzzer for C/C++ projects integrated with LLVM.
Generates Mermaid diagrams from Trailmark code graphs for visualizing code architecture.
cargo-fuzz is the leading fuzzing tool for Rust projects using Cargo, leveraging libFuzzer for effective testing.
Iteratively improves Claude Code skills by fixing quality issues through automated review cycles.
Design and structure multi-step workflow skills for Claude Code effectively.
Clarify requirements before implementation to avoid miscommunication and errors.
Analyzes token implementations and integrations for security and conformity using a comprehensive checklist.
Debugs the Buttercup CRS on Kubernetes to diagnose service failures and resource issues.
Analyzes smart contract codebases to identify state-changing entry points for security audits.
Scans Cosmos SDK modules and CosmWasm contracts for critical vulnerabilities that can halt chains or cause fund loss.
Generate Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.
A marketplace of skills from Trail of Bits enhancing AI-assisted security analysis and development workflows.
Compares code graphs across snapshots to identify security-relevant changes.
Wycheproof provides test vectors for validating cryptographic implementations against known attacks.
Ruzzy is a coverage-guided fuzzer for Ruby, enabling effective testing of Ruby code and C extensions.