Trail of Bits is a security research and auditing firm, and this is its marketplace of 44 Claude Code plugins built from how its own auditors work. Most are for finding bugs: static analysis with CodeQL, Semgrep and SARIF, writing and porting Semgrep rules, variant analysis, differential review of changes, C, C++ and Rust security reviews, insecure-defaults and sharp-edges hunts, supply-chain risk audits, smart contract scanners for six blockchains, constant-time analysis for crypto code, and skills taken from the firm's Testing Handbook on fuzzing and sanitizers. Others cover YARA rule authoring, property-based and mutation testing, false-positive checking and vulnerability triage.
A few plugins are general development helpers, such as modern-python (steers the agent to uv), gh-cli (steers GitHub access through the authenticated gh CLI), devcontainer-setup and git-cleanup. Codex can load the same marketplace through its Claude plugin compatibility.
It has about 7,400 stars and 59 contributors. The licence is CC-BY-SA-4.0 rather than a software licence: you can use and adapt the skills, but anything you derive from them and share must credit Trail of Bits and carry the same licence.
- Repository: github.com/trailofbits/skills
- Licence: CC-BY-SA-4.0 (Creative Commons Attribution Share Alike 4.0 International)
- Language: Python. Stars: 7,428. Forks: 633. Last push: Oct 7, 2026.
- Scan: safe, Oct 8, 2026, commit 82fe822
Who it is for
Security engineers, auditors and developers who want Claude Code to review code the way a professional audit team would, and teams that write Semgrep, CodeQL or YARA rules.
Getting started
1. In Claude Code, add the marketplace
/plugin marketplace add trailofbits/skills2. Browse and install the plugins you want
/plugin menu3. Codex: add the marketplace
codex plugin marketplace add trailofbits/skills4. Codex: install a plugin
codex plugin add <plugin-name>@trailofbitsThe /plugin commands are typed inside Claude Code, not a shell; the codex commands run in a terminal. Several skills drive external tools such as Semgrep, CodeQL or fuzzers, which you install separately.
Safety scan
We cloned trailofbits/skills at commit 82fe822 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- The 3 secret hits are example Firebase API keys in a reference document about finding leaked keys in Android APKs: two AIzaXX placeholders and one public example key. No committed binaries and no bare-IP URLs across 1,441 files and about 206,000 lines.
- A second, skill-specific pass looked for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell commands, long base64 and plugin hooks. The security-themed text it found (exfiltration, credential paths, YARA rules) is detection content, which is what a security firm's skills should contain.
- The two curl piped to bash lines are in a devcontainer Dockerfile template (Claude Code's own installer and fnm). They run only if you build that container.
- The gh-cli plugin's hooks intercept the agent's curl and fetch calls to GitHub and steer them to the authenticated gh CLI, and modern-python adds PATH shims that answer pip and python calls with uv alternatives. Both act locally only, but they do change how your agent behaves once installed.
- 7 lockfiles with no known advisories. 3 workflows; the one pull_request_target workflow (claude-review) does not check out PR code, the one third-party action is pinned, and Dependabot is on. Licence present; no security policy in the repository.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 3 candidates found and read; see the notes above. |
| Suspicious code | 2 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 9 installer scripts (one edits your shell profile) |
| Committed binaries | None. |
| CI workflows | 3 workflows. 1 uses pull_request_target, none check out the pull request head. 0 of 1 third-party action pinned to a tag rather than a commit. |
| Network hosts | 23 distinct hosts referenced from source; most often github.com, api.github.com, registry.npmjs.org, identitytoolkit.googleapis.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 0 advisories across 28 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. plugins/c-review/scripts/uv.lock: 1 packages, 0 advisories; plugins/constant-time-analysis/uv.lock: 1 packages, 0 advisories; plugins/culture-index/skills/interpreting-culture-index/scripts/uv.lock: 8 packages, 0 advisories; plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/scripts/uv.lock: 1 packages, 0 advisories; plugins/testing-handbook-skills/scripts/uv.lock: 2 packages, 0 advisories; plugins/trailmark/skills/slicing-code-context/scripts/uv.lock: 14 packages, 0 advisories; plugins/yara-authoring/skills/yara-rule-authoring/scripts/uv.lock: 2 packages, 0 advisories. |
| Project hygiene | Has automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (3, redacted)
| Where | Rule | Match |
|---|---|---|
| plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:22 | google-api-key | AIzaXX…XXX (39 chars) |
| plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:596 | google-api-key | AIzaXX…XXX (39 chars) |
| plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:742 | google-api-key | AIzaSy…P6Q (39 chars) |
Pattern hits (2)
| Where | Rule | Match |
|---|---|---|
| plugins/devcontainer-setup/skills/devcontainer-setup/resources/Dockerfile:76 | download-piped-to-shell | RUN curl -fsSL https://claude.ai/install.sh | bash && \ |
| plugins/devcontainer-setup/skills/devcontainer-setup/resources/Dockerfile:90 | download-piped-to-shell | RUN curl -fsSL https://fnm.vercel.app/install | bash -s -- --install-dir "$FNM_DIR" --skip-shell && \ |
Installer scripts (9)
- plugins/code-improver/evals/ablation/run.sh, 122 lines
- plugins/devcontainer-setup/skills/devcontainer-setup/resources/install.sh, 864 lines, edits your shell profile; talks to github.com
- plugins/gh-cli/hooks/setup-shims.sh, 33 lines
- plugins/git-cleanup/evals/run-evals.sh, 300 lines
- plugins/git-cleanup/evals/selftest/run-selftest.sh, 259 lines
- plugins/modern-python/hooks/setup-shims.sh, 25 lines
- plugins/property-based-testing/evals-extra/run.sh, 687 lines
- plugins/static-analysis/skills/semgrep/scripts/run-scans.sh, 787 lines
- plugins/writing-lean-proofs/evals/run.sh, 617 lines
Workflows worth a look
- .github/workflows/claude-review.yml: pull_request_target
By the numbers
| Stars | 7,428 |
|---|---|
| Forks | 633 |
| Contributors | 59 |
| Commits | 206 |
| Open issues | 29 |
| Open pull requests | 9 |
| Releases | 0 |
| Latest release | none tagged |
| Licence | CC-BY-SA-4.0 |
| Main language | Python |
| Project age | 8 months |
| Last push | Oct 7, 2026 |
| Tracked files | 1,441 |
| Lines of code | 206K |
| Checkout size | 9 MB |
Lines by language: Markdown 104.5K, Python 62.3K, JavaScript 15.1K, Shell 12.1K, JSON 3,736, YAML 2,973.
Questions
Is Trail of Bits Skills free?
Yes. The skills are free under CC-BY-SA-4.0, which lets you use and adapt them but requires credit and the same licence on anything you share that is derived from them. You still need Claude Code or Codex under their own pricing, and long audits use a lot of tokens.
Can these skills replace a security audit?
No. They make an agent follow an auditor's methods and use the right tools, which helps it find real bugs and filter false positives, but the results still need a person who understands the code and the threat model to check them.
Do I need Semgrep, CodeQL or other tools installed?
For the skills that drive them, yes. Static analysis, fuzzing and smart contract skills call those tools and tell the agent how to read their output. Review-style skills such as differential-review, sharp-edges or audit-context-building need only the agent.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
