4 min read

Trail of Bits Skills: Security Auditing Skills for Claude Code (GitHub, Scanned)

A security firm's Claude Code plugins for code audits, static analysis, fuzzing and YARA rules.

Trail of Bits Skills logo
✅
Scan: safe. Nothing malicious; the notes are a share-alike licence and two plugins whose hooks change how the agent calls curl, gh, pip and python. Scanned Oct 8, 2026; the full report is below.

Trail of Bits is a security research and auditing firm, and this is its marketplace of 44 Claude Code plugins built from how its own auditors work. Most are for finding bugs: static analysis with CodeQL, Semgrep and SARIF, writing and porting Semgrep rules, variant analysis, differential review of changes, C, C++ and Rust security reviews, insecure-defaults and sharp-edges hunts, supply-chain risk audits, smart contract scanners for six blockchains, constant-time analysis for crypto code, and skills taken from the firm's Testing Handbook on fuzzing and sanitizers. Others cover YARA rule authoring, property-based and mutation testing, false-positive checking and vulnerability triage.

A few plugins are general development helpers, such as modern-python (steers the agent to uv), gh-cli (steers GitHub access through the authenticated gh CLI), devcontainer-setup and git-cleanup. Codex can load the same marketplace through its Claude plugin compatibility.

It has about 7,400 stars and 59 contributors. The licence is CC-BY-SA-4.0 rather than a software licence: you can use and adapt the skills, but anything you derive from them and share must credit Trail of Bits and carry the same licence.

  • Repository: github.com/trailofbits/skills
  • Licence: CC-BY-SA-4.0 (Creative Commons Attribution Share Alike 4.0 International)
  • Language: Python. Stars: 7,428. Forks: 633. Last push: Oct 7, 2026.
  • Scan: safe, Oct 8, 2026, commit 82fe822

Who it is for

Security engineers, auditors and developers who want Claude Code to review code the way a professional audit team would, and teams that write Semgrep, CodeQL or YARA rules.

Getting started

1. In Claude Code, add the marketplace

/plugin marketplace add trailofbits/skills

2. Browse and install the plugins you want

/plugin menu

3. Codex: add the marketplace

codex plugin marketplace add trailofbits/skills

4. Codex: install a plugin

codex plugin add <plugin-name>@trailofbits

The /plugin commands are typed inside Claude Code, not a shell; the codex commands run in a terminal. Several skills drive external tools such as Semgrep, CodeQL or fuzzers, which you install separately.

Safety scan

We cloned trailofbits/skills at commit 82fe822 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • The 3 secret hits are example Firebase API keys in a reference document about finding leaked keys in Android APKs: two AIzaXX placeholders and one public example key. No committed binaries and no bare-IP URLs across 1,441 files and about 206,000 lines.
  • A second, skill-specific pass looked for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell commands, long base64 and plugin hooks. The security-themed text it found (exfiltration, credential paths, YARA rules) is detection content, which is what a security firm's skills should contain.
  • The two curl piped to bash lines are in a devcontainer Dockerfile template (Claude Code's own installer and fnm). They run only if you build that container.
  • The gh-cli plugin's hooks intercept the agent's curl and fetch calls to GitHub and steer them to the authenticated gh CLI, and modern-python adds PATH shims that answer pip and python calls with uv alternatives. Both act locally only, but they do change how your agent behaves once installed.
  • 7 lockfiles with no known advisories. 3 workflows; the one pull_request_target workflow (claude-review) does not check out PR code, the one third-party action is pinned, and Dependabot is on. Licence present; no security policy in the repository.

What the scanner counted

CheckResult
Secrets3 candidates found and read; see the notes above.
Suspicious code2 pattern hits found and read; every one is listed under the raw findings.
Install-time code9 installer scripts (one edits your shell profile)
Committed binariesNone.
CI workflows3 workflows. 1 uses pull_request_target, none check out the pull request head. 0 of 1 third-party action pinned to a tag rather than a commit.
Network hosts23 distinct hosts referenced from source; most often github.com, api.github.com, registry.npmjs.org, identitytoolkit.googleapis.com. No URLs to bare IP addresses.
Known vulnerabilities0 advisories across 28 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. plugins/c-review/scripts/uv.lock: 1 packages, 0 advisories; plugins/constant-time-analysis/uv.lock: 1 packages, 0 advisories; plugins/culture-index/skills/interpreting-culture-index/scripts/uv.lock: 8 packages, 0 advisories; plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/scripts/uv.lock: 1 packages, 0 advisories; plugins/testing-handbook-skills/scripts/uv.lock: 2 packages, 0 advisories; plugins/trailmark/skills/slicing-code-context/scripts/uv.lock: 14 packages, 0 advisories; plugins/yara-authoring/skills/yara-rule-authoring/scripts/uv.lock: 2 packages, 0 advisories.
Project hygieneHas automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (3, redacted)
WhereRuleMatch
plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:22google-api-keyAIzaXX…XXX (39 chars)
plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:596google-api-keyAIzaXX…XXX (39 chars)
plugins/firebase-apk-scanner/skills/firebase-apk-scanner/references/vulnerabilities.md:742google-api-keyAIzaSy…P6Q (39 chars)
Pattern hits (2)
WhereRuleMatch
plugins/devcontainer-setup/skills/devcontainer-setup/resources/Dockerfile:76download-piped-to-shellRUN curl -fsSL https://claude.ai/install.sh | bash && \
plugins/devcontainer-setup/skills/devcontainer-setup/resources/Dockerfile:90download-piped-to-shellRUN curl -fsSL https://fnm.vercel.app/install | bash -s -- --install-dir "$FNM_DIR" --skip-shell && \
Installer scripts (9)
Workflows worth a look

By the numbers

Stars7,428
Forks633
Contributors59
Commits206
Open issues29
Open pull requests9
Releases0
Latest releasenone tagged
LicenceCC-BY-SA-4.0
Main languagePython
Project age8 months
Last pushOct 7, 2026
Tracked files1,441
Lines of code206K
Checkout size9 MB

Lines by language: Markdown 104.5K, Python 62.3K, JavaScript 15.1K, Shell 12.1K, JSON 3,736, YAML 2,973.

Questions

Is Trail of Bits Skills free?

Yes. The skills are free under CC-BY-SA-4.0, which lets you use and adapt them but requires credit and the same licence on anything you share that is derived from them. You still need Claude Code or Codex under their own pricing, and long audits use a lot of tokens.

Can these skills replace a security audit?

No. They make an agent follow an auditor's methods and use the right tools, which helps it find real bugs and filter false positives, but the results still need a person who understands the code and the threat model to check them.

Do I need Semgrep, CodeQL or other tools installed?

For the skills that drive them, yes. Static analysis, fuzzing and smart contract skills call those tools and tell the agent how to read their output. Review-style skills such as differential-review, sharp-edges or audit-context-building need only the agent.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.