Fodhol/skills

🚀 Enhance your AI-assisted security workflows with plugins from the Trail of Bits Skills Marketplace for smarter analysis and testing.

2Stars on the repository
60Mods indexed here, across every type
3d agoLast push, which is what freshness is scored on
CC-BY-SA-4.0Licence, which decides whether bodies are shown

trailofbits

01

Fodhol/skills

Plugin Claude Code

Plugin marketplace listing 20 plugins: ask-questions-if-underspecified, audit-context-building, building-secure-contracts, burpsuite-project-parser, constant-time-analysis.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Clarify requirements before implementing. Do not use automatically, only when invoked explicitly.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Build deep architectural context through ultra-granular code analysis before vulnerability hunting.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Search and extract data from Burp Suite project files (.burp) directly from the command line for use in Claude.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Detect compiler-induced timing side-channels in cryptographic code.

2 3d ago A tokens not measured CC-BY-SA-4.0

culture-index

08

Fodhol/skills

Plugin Claude Code

Interprets Culture Index survey results for individuals and teams.

2 3d ago A tokens not measured CC-BY-SA-4.0

differential-review

09

Fodhol/skills

Plugin Claude Code

Security-focused differential review of code changes with git history analysis and blast radius estimation.

2 3d ago A tokens not measured CC-BY-SA-4.0

dwarf-expert

10

Fodhol/skills

Plugin Claude Code

Interact with and understand the DWARF debugging format.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

2 3d ago A tokens not measured CC-BY-SA-4.0

fix-review

13

Fodhol/skills

Plugin Claude Code

Verifies that code changes address security audit findings without introducing bugs.

2 3d ago A tokens not measured CC-BY-SA-4.0

modern-python

14

Fodhol/skills

Plugin Claude Code

Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Property-based testing guidance for multiple languages and smart contracts.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Create custom Semgrep rules for detecting bug patterns and security vulnerabilities.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation.

2 3d ago A tokens not measured CC-BY-SA-4.0

sharp-edges

18

Fodhol/skills

Plugin Claude Code

Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Specification-to-code compliance checker for blockchain audits with evidence-based alignment analysis.

2 3d ago A tokens not measured CC-BY-SA-4.0

static-analysis

20

Fodhol/skills

Plugin Claude Code

Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection.

2 3d ago A tokens not measured CC-BY-SA-4.0

Fodhol/skills

Plugin Claude Code

Skills from the Trail of Bits Application Security Testing Handbook (appsec.guide).

2 3d ago A tokens not measured CC-BY-SA-4.0