
More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
Most Used Tags
Scan Solana programs for critical vulnerabilities to enhance security.
Learn techniques for writing effective fuzzing harnesses across multiple programming languages.
Translates Mermaid sequence diagrams of cryptographic protocols into ProVerif models for formal verification.
Smart contract development advisor that analyzes codebases and provides actionable recommendations based on best practices.
Analyzes codebases to provide a quick structural overview with language detection and entry point count.
Enhance smart contract security with a structured 5-step workflow.
Systematic assessment of code maturity using a 9-category framework.
Identifies error-prone APIs and configurations to prevent security mistakes.
Ruzzy is a coverage-guided fuzzer for Ruby, enabling effective testing of Ruby code and C extensions.
Generate Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.
Generates sequence diagrams for cryptographic protocols from source code or specifications.
Scans Cairo/StarkNet smart contracts for critical vulnerabilities.
Expertise for analyzing DWARF debug files and understanding the DWARF standard (v3-v5).
Generates Mermaid diagrams from Trailmark code graphs for visualizing code architecture.
Configures mutation testing campaigns with mewt or muton, optimizing performance and scope.
Identify and analyze similar vulnerabilities across codebases using pattern-based techniques.
Diagnose and fix connectivity issues for the Claude in Chrome MCP extension.
Constant-time testing identifies timing side channels in cryptographic code to enhance security.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations.
OSS-Fuzz offers free continuous fuzzing for open source projects, streamlining the testing process.
Command-line tool for searching and analyzing Burp Suite project files (.burp).
A marketplace of skills from Trail of Bits enhancing AI-assisted security analysis and development workflows.
Configures Python projects with modern tooling for streamlined development.
Create high-quality YARA-X detection rules for effective malware identification.
Prepares codebases for security reviews using Trail of Bits' checklist, enhancing code quality and documentation.
LibAFL is a modular fuzzing library for building custom fuzzers with advanced features.
Clarify requirements before implementation to avoid miscommunication and errors.
Scans Algorand smart contracts for 11 common vulnerabilities to enhance security.
Scans Cosmos SDK modules and CosmWasm contracts for critical vulnerabilities that can halt chains or cause fund loss.
Parses and processes SARIF files from static analysis tools for actionable insights.
Analyzes token implementations and integrations for security and conformity using a comprehensive checklist.
Creates devcontainers with Claude Code and language-specific tooling for isolated development.
Systematically verifies suspected security bugs to eliminate false positives with documented evidence.
Safely analyze and clean up local git branches and worktrees by categorizing them.
Guidance for implementing property-based testing across multiple languages and smart contracts.
Runs external LLM code reviews on code changes using OpenAI Codex or Google Gemini.
Create custom Semgrep rules to detect security vulnerabilities and code patterns.
Create language variants of existing Semgrep rules for targeted applications.
Run Semgrep static analysis scans on codebases with parallel execution for enhanced performance.
AddressSanitizer detects memory errors during fuzzing C/C++ code.
Coverage-guided fuzzer for C/C++ projects integrated with LLVM.
Augments Trailmark code graphs with external audit findings for enhanced analysis.
Graph-informed mutation testing triage for identifying test gaps and fuzzing targets.
Wycheproof provides test vectors for validating cryptographic implementations against known attacks.
Audits C/C++/Rust code for missing zeroization of sensitive data, ensuring secure handling of secrets.
Scans codebases for security vulnerabilities using CodeQL's advanced analysis techniques.
cargo-fuzz is the leading fuzzing tool for Rust projects using Cargo, leveraging libFuzzer for effective testing.
Conducts comprehensive structural analysis for codebases using Trailmark.
Generates mutation-driven test vectors for cryptographic algorithms to improve coverage.
Detects timing side-channel vulnerabilities in cryptographic code.
Coverage analysis measures code exercised during fuzzing to enhance harness effectiveness and identify blockers.
Scan Substrate/Polkadot pallets for critical vulnerabilities to enhance security.
Analyzes smart contract codebases to identify state-changing entry points for security audits.
Builds and queries multi-language source code graphs for security analysis.
Interprets Culture Index surveys and behavioral profiles for team and individual insights.
Iteratively improves Claude Code skills by fixing quality issues through automated review cycles.
Evaluates project dependencies for risk of exploitation or takeover.
Detects insecure defaults that allow applications to run with weak security configurations.
Techniques for patching code to overcome fuzzing obstacles like checksums and global state.
Enables ultra-granular, line-by-line code analysis for deep architectural context before vulnerability discovery.
Scan Android APKs for Firebase security misconfigurations and vulnerabilities.
Injects randomness into decision-making by drawing Tarot cards for vague prompts.
AFL++ enhances fuzzing performance with multi-core support for C/C++ projects.
Debugs the Buttercup CRS on Kubernetes to diagnose service failures and resource issues.
Scans TON smart contracts for critical vulnerabilities in FunC code.
Fuzzing dictionaries enhance fuzzers with domain-specific tokens for effective testing.
Design and structure multi-step workflow skills for Claude Code effectively.
Annotates codebases with dimensional analysis to prevent formula bugs and dimensional mismatches.
Atheris is a coverage-guided fuzzer for Python code and C extensions, leveraging libFuzzer.
Verifies code compliance with documentation for blockchain audits.
Generates minimal macOS Seatbelt sandbox configurations for application isolation.
Conducts security-focused differential reviews of code changes to prevent vulnerabilities.
Compares code graphs across snapshots to identify security-relevant changes.