
More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
Most Used Tags
Systematically verifies suspected security bugs to eliminate false positives with documented evidence.
cargo-fuzz is the leading fuzzing tool for Rust projects using Cargo, leveraging libFuzzer for effective testing.
Run Semgrep static analysis scans on codebases with parallel execution for enhanced performance.
Evaluates project dependencies for risk of exploitation or takeover.
AFL++ enhances fuzzing performance with multi-core support for C/C++ projects.
OSS-Fuzz offers free continuous fuzzing for open source projects, streamlining the testing process.
Create high-quality YARA-X detection rules for effective malware identification.
Analyzes smart contract codebases to identify state-changing entry points for security audits.
A marketplace of skills from Trail of Bits enhancing AI-assisted security analysis and development workflows.
Scan Android APKs for Firebase security misconfigurations and vulnerabilities.
Analyzes codebases to provide a quick structural overview with language detection and entry point count.
Prepares codebases for security reviews using Trail of Bits' checklist, enhancing code quality and documentation.
LibAFL is a modular fuzzing library for building custom fuzzers with advanced features.
Fuzzing dictionaries enhance fuzzers with domain-specific tokens for effective testing.
Scans codebases for security vulnerabilities using CodeQL's advanced analysis techniques.
Conducts comprehensive structural analysis for codebases using Trailmark.
Systematic assessment of code maturity using a 9-category framework.
Graph-informed mutation testing triage for identifying test gaps and fuzzing targets.
Debugs the Buttercup CRS on Kubernetes to diagnose service failures and resource issues.
Conducts security-focused differential reviews of code changes to prevent vulnerabilities.
Constant-time testing identifies timing side channels in cryptographic code to enhance security.
Interprets Culture Index surveys and behavioral profiles for team and individual insights.
Safely analyze and clean up local git branches and worktrees by categorizing them.
Injects randomness into decision-making by drawing Tarot cards for vague prompts.
Scan Substrate/Polkadot pallets for critical vulnerabilities to enhance security.
Generates minimal macOS Seatbelt sandbox configurations for application isolation.
Enables ultra-granular, line-by-line code analysis for deep architectural context before vulnerability discovery.
Expertise for analyzing DWARF debug files and understanding the DWARF standard (v3-v5).
Augments Trailmark code graphs with external audit findings for enhanced analysis.
Create language variants of existing Semgrep rules for targeted applications.
Parses and processes SARIF files from static analysis tools for actionable insights.
Builds and queries multi-language source code graphs for security analysis.
Configures mutation testing campaigns with mewt or muton, optimizing performance and scope.
Scans Cosmos SDK modules and CosmWasm contracts for critical vulnerabilities that can halt chains or cause fund loss.
Techniques for patching code to overcome fuzzing obstacles like checksums and global state.
Generates mutation-driven test vectors for cryptographic algorithms to improve coverage.
Command-line tool for searching and analyzing Burp Suite project files (.burp).
Detects insecure defaults that allow applications to run with weak security configurations.
Atheris is a coverage-guided fuzzer for Python code and C extensions, leveraging libFuzzer.
Create custom Semgrep rules to detect security vulnerabilities and code patterns.
Translates Mermaid sequence diagrams of cryptographic protocols into ProVerif models for formal verification.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations.
Generates Mermaid diagrams from Trailmark code graphs for visualizing code architecture.
Enhance smart contract security with a structured 5-step workflow.
AddressSanitizer detects memory errors during fuzzing C/C++ code.
Diagnose and fix connectivity issues for the Claude in Chrome MCP extension.
Smart contract development advisor that analyzes codebases and provides actionable recommendations based on best practices.
Runs external LLM code reviews on code changes using OpenAI Codex or Google Gemini.
Verifies code compliance with documentation for blockchain audits.
Wycheproof provides test vectors for validating cryptographic implementations against known attacks.
Analyzes token implementations and integrations for security and conformity using a comprehensive checklist.
Scan Solana programs for critical vulnerabilities to enhance security.
Scans Cairo/StarkNet smart contracts for critical vulnerabilities.
Identifies error-prone APIs and configurations to prevent security mistakes.
Learn techniques for writing effective fuzzing harnesses across multiple programming languages.
Detects timing side-channel vulnerabilities in cryptographic code.
Scans TON smart contracts for critical vulnerabilities in FunC code.
Audits C/C++/Rust code for missing zeroization of sensitive data, ensuring secure handling of secrets.
Design and structure multi-step workflow skills for Claude Code effectively.
Creates devcontainers with Claude Code and language-specific tooling for isolated development.
Coverage-guided fuzzer for C/C++ projects integrated with LLVM.
Iteratively improves Claude Code skills by fixing quality issues through automated review cycles.
Guidance for implementing property-based testing across multiple languages and smart contracts.
Coverage analysis measures code exercised during fuzzing to enhance harness effectiveness and identify blockers.
Annotates codebases with dimensional analysis to prevent formula bugs and dimensional mismatches.
Configures Python projects with modern tooling for streamlined development.
Compares code graphs across snapshots to identify security-relevant changes.
Ruzzy is a coverage-guided fuzzer for Ruby, enabling effective testing of Ruby code and C extensions.
Scans Algorand smart contracts for 11 common vulnerabilities to enhance security.
Clarify requirements before implementation to avoid miscommunication and errors.
Identify and analyze similar vulnerabilities across codebases using pattern-based techniques.
Generates sequence diagrams for cryptographic protocols from source code or specifications.
Generate Claude Code skills from the Trail of Bits Testing Handbook for security testing tools and techniques.