Trailofbits
Applied security engineering
Security skills for audits, fuzzing, sanitizers, and code review.
Featured skills
property-based-testing
Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or...
github-triage
Triages a repository's open GitHub issues and pull requests via the gh CLI.
diagramming-code
Generates Mermaid diagrams from Trailmark code graphs.
aflpp
AFL++ is a fork of AFL with better fuzzing performance and advanced features.
agentic-actions-auditor
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action,...
algorand-vulnerability-scanner
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees,...
ask-questions-if-underspecified
Clarify requirements before implementing.
atheris
Atheris is a coverage-guided Python fuzzer based on libFuzzer.
audit-augmentation
Augments Trailmark code graphs with external audit findings from SARIF static analysis results, weAudit annotation...
audit-context-building
Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug...
audit-prep-assistant
Prepares codebases for security review using Trail of Bits' checklist.
burpsuite-project-parser
Searches and explores Burp Suite project files (.burp) from the command line.
Twostraws
Swift development education
Practical guidance for SwiftUI, concurrency, testing, and SwiftData.
Vercel
Web application infrastructure
Skills for Vercel, Next.js, AI SDK, Turborepo, and deployment.
Vercel Labs
Experimental agent tools
Experimental tools for agent browsers, deployment, and application development.