* Add adversarial-modeler agent to differential-review plugin
Introduces a formal agent definition for adversarial threat modeling
on high-risk code changes. Updates SKILL.md to reference agent and
bumps version to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix {baseDir} paths and bump marketplace.json version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #84
- Fix decision tree formatting: use correct tree syntax (first
child uses branch connector, last child uses end connector)
- Add "When NOT to Use" section to adversarial-modeler agent per
contributing guidelines
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add sharp-edges-analyzer agent to sharp-edges plugin
Introduces a formal agent definition for the sharp edges analysis
workflow. Updates SKILL.md to reference agent and bumps version
to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Bump sharp-edges version to 1.1.0 in marketplace.json
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #81
- Add examples column to agent severity classification table
- Add language-specific.md combined quick reference to agent
- Document agent in plugin README.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add 17 archetype deep profile references to culture-index skill
Convert Culture Index archetype PDFs into structured markdown reference
files with consistent format: core traits, strengths, challenges,
management approach, risk profile, FlashPoints, variations, and summary.
Add Influencer to the archetype summary table in patterns-archetypes.md
and register all archetype files in the SKILL.md reference index.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Fix review issues in archetype profiles
- Align patterns-archetypes.md table with authoritative archetype files
for Technical Expert, Socializer, Philosopher, Debater, Administrator
- Standardize "Moderate" to "Mid" in Trailblazer H1
- Split merged Organization/Environment FlashPoints rows into separate
rows in Facilitator, Socializer, Traditionalist
- Remove leaked PDF source references from Debater, Technical Expert,
Traditionalist variations sections
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Move SKILL.md and scripts/ into a named subdirectory matching the
frontmatter name. Both Claude Code and OpenCode discover skills at
skills/<name>/SKILL.md where <name> must match the frontmatter name
field.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Replace third-party codex-mcp-server with Codex CLI's built-in MCP server
Swap `uvx codex-mcp-server` (third-party Python package) for `codex mcp-server`
(built-in to the Codex CLI). Eliminates the Python/uvx dependency and uses
OpenAI's officially maintained MCP server instead.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Gitignore uv.lock at repo root
No root pyproject.toml exists — the lockfile is a stale artifact from
an accidental uv invocation.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix stale references to third-party codex-mcp-server
Update root README table and .gitignore comment to reflect the switch
to Codex CLI's built-in MCP server.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Iterative fix-review loop that automatically refines Claude Code skills
until they meet quality standards. Uses the plugin-dev:skill-reviewer
agent for automated review cycles with a stop hook to continue the loop.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Import four plugins from skills-internal and clean up README
Import seatbelt-sandboxer, supply-chain-risk-auditor, zeroize-audit,
and let-fate-decide from skills-internal. Remove dead humanizer and
skill-extractor directories. Fold "About Trail of Bits" into the
license line.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix CI: shellcheck SC2317 and let-fate-decide description mismatch
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Import agentic-actions-auditor from skills-internal
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix review issues across 5 imported plugins
- Fix empty array expansion crash under set -u on macOS bash 3.2
(emit_rust_mir.sh, emit_asm.sh, emit_ir.sh)
- Fix copy-paste error in seatbelt-sandboxer README ("variant analysis")
- Remove references to non-existent leak-hunter skill
- Update agentic-actions-auditor license to match repo CC-BY-SA-4.0
- Add PEP 723 metadata to check_rust_asm_{aarch64,x86}.py
- Replace unsafe xargs trim with parameter expansion in track_dataflow.sh
- Add json_escape function to analyze_asm.sh, analyze_heap.sh,
track_dataflow.sh for safe JSON construction with backslashes
- Add allowed-tools frontmatter to seatbelt-sandboxer and
supply-chain-risk-auditor SKILL.md
- Add minimum finding count assertions to run_smoke.sh
- Fix double period typo in supply-chain-risk-auditor SKILL.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
codex-review-schema.json failed OpenAI structured output validation
because required arrays didn't include all sibling property keys when
additionalProperties: false was set. Made optional fields nullable
and added them to required to satisfy the constraint.
Update Gemini model from gemini-3-pro-preview to gemini-3.1-pro-preview
following the Feb 19 release.
Bump version 1.5.0 → 1.5.1.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Add .mcp.json to auto-start the codex-mcp-server when the plugin is
installed, providing codex_ask, codex_exec, and codex_review MCP tools.
The MCP tool descriptions are self-documenting — no separate skill
docs needed. Bump version to 1.5.0.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* ci: enforce pre-commit formatting hooks in CI
check-yaml, check-json, end-of-file-fixer, and trailing-whitespace
only ran locally via pre-commit. Contributors who skip pre-commit
can introduce formatting drift (see #97). Add a CI job using
pre-commit/action to enforce these four hooks on every PR.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* ci: consolidate lint jobs into single pre-commit pass
Run all pre-commit hooks (ruff, shellcheck, shfmt, check-yaml,
check-json, end-of-file-fixer, trailing-whitespace) in one job
instead of separate CI jobs per tool. Fixes the extra_args error
where pre-commit run only accepts one hook ID positionally.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* style: fix trailing whitespace and EOF in semgrep-rule-creator
Pre-commit hooks caught two files missed by the earlier formatting
PR: trailing blank line in quick-reference.md and trailing
whitespace plus missing final newline in workflow.md.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Pre-commit hooks auto-fixed missing newlines at EOF and trailing
whitespace to satisfy end-of-file-fixer and trailing-whitespace checks.
Co-authored-by: Dallas McIntyre <dkmcintyre@safaricircuits.com>
Co-authored-by: Claude Code <noreply@anthropic.com>
* Fix culture-index SKILL.md standards compliance
- Switch description to third-person voice, remove "PDF vision" mention
that contradicts body's prohibition on visual estimation
- Add allowed-tools to frontmatter (Bash, Read, Grep, Glob, Write)
- Add required "When to Use" and "When NOT to Use" sections
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Bump culture-index version to 1.1.0
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Switch second-opinion Codex path from codex review to codex exec
Use codex exec with --output-schema and -o (--output-last-message)
instead of codex review. This eliminates context waste from verbose
[thinking] and [exec] blocks by capturing only the structured JSON
review output to a file. Uses OpenAI's published code review prompt
that GPT-5.2-codex was specifically trained on.
Also lowers default reasoning from xhigh to high, removes the
--base/--commit prompt limitation (all scopes now support project
context and focus instructions), and adds a JSON schema for
structured findings output.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix review issues: untracked files, hardcoded paths, schema naming
- Include untracked files in uncommitted scope diff using
git ls-files + git diff --no-index, matching the coverage
that codex review --uncommitted previously provided
- Replace hardcoded /tmp/ paths with mktemp for portability
- Rename absolute_file_path to file_path in schema since
git diff produces relative paths
- Capture stderr to a log file instead of /dev/null for
faster error diagnosis without retry
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix PR review findings: schema constraints, flag naming, citation
- Add required and additionalProperties: false to JSON schema
- Use -o (short flag) consistently; clarify --output-last-message
- Add cookbook citation URL for the code review prompt
- Add || true to git diff --no-index (exits 1 on diff found)
- Fix schema.json → codex-review-schema.json in SKILL.md quick ref
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Restore xhigh reasoning effort, fix cookbook citation URL
- Change reasoning effort back to xhigh from high
- Update cookbook URL to canonical developers.openai.com domain
(old cookbook.openai.com returns 308 redirect)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
The Gemini `/security:scan-deps` command scans the entire project
dependency tree regardless of what changed. This wastes time when
reviewing small config or code changes that don't involve dependencies.
Now the scan only runs when the diff actually touches manifest files
(package.json, Gemfile, requirements.txt, Cargo.toml, go.mod, etc.).
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add spec-compliance-checker agent to spec-to-code-compliance plugin
Introduces a formal agent definition for the full specification-to-code
compliance workflow. Updates SKILL.md to reference agent and bumps
version to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix {baseDir} paths and bump marketplace.json version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #82
- Normalize double hyphens to em dashes in agent rationalizations table
for consistency with SKILL.md formatting conventions
- Add invocation example to SKILL.md Agent section
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add function-analyzer agent to audit-context-building plugin
Introduces a formal agent definition for ultra-granular per-function
analysis. Updates SKILL.md Section 8 to reference agent and bumps
version to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix {baseDir} paths and bump marketplace.json version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #83
- Wrap long SKILL.md line (239 chars -> multi-line) for readability
- Trim verbose agent description frontmatter
- Add "When NOT to Use" section to agent file per project standards
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Fix Gemini heredoc patterns that prevent variable expansion
Single-quoted heredoc delimiters (<<'PROMPT') suppress shell
substitution, so $(cat /tmp/review-diff.txt) was passed to
Gemini as literal text. Replaced all heredoc patterns with
pipe-based construction ({ printf ...; cat ...; } | gemini)
which avoids both the quoting bug and shell metacharacter
issues from unquoted heredocs (diffs contain $ and backticks).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Bump second-opinion version in marketplace.json to match plugin.json
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Clarify marketplace.json path in CLAUDE.md PR checklist
The checklist said `.claude-plugin/marketplace.json` which is
ambiguous — every plugin has its own `.claude-plugin/` directory.
Specify that the marketplace.json is at the repo root, distinct
from each plugin's `.claude-plugin/plugin.json`.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add semgrep-scanner and semgrep-triager agents to static-analysis plugin
Introduces formal agent definitions for the scanning and triage
workflows. Updates SKILL.md to reference agents and bumps version
to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix {baseDir} paths and bump marketplace.json version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #80
- Update scanner-task-prompt.md to reference semgrep-scanner subagent
type instead of Bash (consistent with SKILL.md Step 4 change)
- Update triage-task-prompt.md to reference semgrep-triager subagent
type instead of general-purpose (consistent with SKILL.md Step 5 change)
- Add Agents Included section to README.md documenting new agents
- Fix Agents table column header in SKILL.md from "Type" to "Tools"
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use fully-qualified agent type names for semgrep subagents
Plugin agents require the `plugin-name:agent-name` format at runtime,
but the skill referenced bare names (`semgrep-scanner`, `semgrep-triager`)
causing "Agent type not found" errors when spawning scan/triage Tasks.
Also adds agent types to the Step 3 plan template and pre-scan checklist
so they appear in generated plans and survive context clearing.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Explicit semgrep scan allow
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: axelm-tob <axel.mierczuk@trailofbits.com>
* Remove fix-review plugin (moved to skills-internal)
This plugin is only useful for internal audit workflows and was
added to the public repo by mistake.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Remove empty Audit Lifecycle section from README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- Fix "sequentially" → "parallel" in Question 1 to match Running Both section
- Document Codex context limitation for --base/--commit (skill will not
create AGENTS.md; inform user of the limitation instead)
- Add Codex output parsing guidance (summarize findings, don't dump 55KB
of raw thinking/exec blocks)
- Document EPERM/sandbox errors as expected (codex review is sandboxed,
cannot run tests or builds)
- Bump version to 1.2.0
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- Fix Codex --base/--commit prompt passing: the positional [PROMPT] arg
is mutually exclusive with these flags (confirmed via CLI), and stdin
via `-` is also rejected. Document the AGENTS.md workaround instead.
- Remove upfront `command -v` availability checks. Just run the tool and
handle errors — saves a turn and avoids mishandled control flow.
- Run Codex and Gemini reviews in parallel (both are read-only, no
shared state) instead of sequentially.
- Expand error handling table with explicit per-extension install URLs.
- Bump version to 1.1.0.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Shells out to OpenAI Codex CLI and Google Gemini CLI to get
independent code reviews from different models on uncommitted
changes, branch diffs, or specific commits.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Map individual plugin authors to their plugins so they receive review
requests on PRs that touch their work. Each plugin rule includes both
the author and @dguido to ensure visibility.
Plugins authored by Trail of Bits org or Dan Guido use the default rule.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Add documentation for new YARA 4.5.0 features:
- Unreferenced string prefix (`$_`) to suppress unused warnings
- `--strict-escape` flag for catching invalid regex escapes
- `CALLBACK_MSG_TOO_SLOW_SCANNING` for slow rule detection
Core guidance (atom theory, string quality, performance optimization)
validated against current expert sources and remains accurate.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Add yara-authoring skill for YARA detection rule authoring
Comprehensive skill for writing high-quality YARA detection rules:
- Core guidance on string selection, atom optimization, and FP reduction
- Platform-specific patterns for PE, JavaScript, npm packages, VS Code extensions
- Expert patterns from Neo23x0 signature-base and Stairwell research
- Unicode steganography detection (Variation Selectors per Veracode research)
- Supply chain attack patterns (Discord webhooks, credential theft, postinstall hooks)
- Decision trees for string quality, all/any selection, and FP debugging
- Scripts: yara_lint.py for style validation, atom_analyzer.py for string quality
Reference documents cover:
- strings.md: String types, modifiers, JS obfuscation patterns
- performance.md: Atom theory, regex discipline, short-circuit optimization
- testing.md: Goodware validation, supply chain package testing
- style-guide.md: Naming conventions and metadata requirements
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Move yara-authoring to Malware Analysis section
YARA is primarily used for malware detection and classification,
so this is a better categorization than Code Auditing.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Rename 10 command files that contained `:` in their filenames, which is
invalid on Windows filesystems (reserved for drive letters).
The `trailofbits:` namespace is preserved in the frontmatter `name` field,
so slash commands like `/trailofbits:audit-context` continue to work.
Fixes#51
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
- Tighten frontmatter description to name specific tools (uv, ruff, ty)
and migration triggers (pip/Poetry/mypy/black) for better matching
- Document UV_PROJECT_ENVIRONMENT variable for container/host workflows
- Add Container/Host Development section explaining separate venv usage
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Custom args in .pre-commit-config.yaml replace default args rather
than extend them. The shfmt hook's default args include --write, but
our custom args (-i 2 -ci) were missing it. Without --write, shfmt
outputs to stdout and exits 0 regardless of formatting issues.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Add BATS test suite for intercept-legacy-python hook
- Add 64 tests covering all code paths: early exits, allow cases
(uv run, diagnostics, search tools), deny cases (python/pip
execution, uv pip, piped commands, compound commands)
- Add test_helper.bash with run_hook, assert_allow, assert_deny,
and assert_suggestion_contains helpers
- Add bats job to CI workflow
- Fix hook to properly detect python execution in piped commands
like `python script.py | grep foo` and `find . | xargs python`
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix CI failures in hook test suite
- Suppress jq stderr in run_hook_no_uv to avoid "Broken pipe" error
when hook script exits early due to missing uv
- Fix shfmt formatting: remove trailing backslash, single space before
inline comments
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Align prek auto-update cooldown to 7 days
Update the recommended --cooldown-days value from 3 to 7 to match
the project's CLAUDE.md standard. A 7-day cooldown provides a
reasonable window for the community to detect compromised releases.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Update modern-python for ruff and ty compatibility
- Remove deprecated ANN101/ANN102 rules (removed in ruff 0.8.0)
- Fix ty config section: tool.ty → tool.ty.terminal
- Fix ty rule name: possibly-unbound → possibly-unresolved-reference
- Update SKILL.md ignore list to match reference docs
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
- Rewrite "When to Use" with specific, outcome-focused triggers
- Add security tools section (shellcheck, detect-secrets, actionlint, zizmor, pip-audit, Dependabot)
- Add prek and ty to core tools
- Group into Core Tools, Security Tools, and Standards sections
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Consolidate modern-python security documentation
Security content was fragmented across prek.md, migration-checklist.md,
and SKILL.md with no clear entry point. Users had to hunt across files
to understand security setup.
Changes:
- Add references/security-setup.md as single source of truth for all 6
security tools (shellcheck, detect-secrets, actionlint, zizmor,
pip-audit, Dependabot)
- Add Security Tools subsection to SKILL.md tool overview
- Simplify migration-checklist.md security items with links
- Add cross-references from prek.md to security-setup.md
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix pip-audit command and add installation instructions
- Fix pip-audit command: use `. ` (project path) instead of
`--requirement pyproject.toml` which expects requirements.txt format
- Add Tool Installation section with brew, uv, and alternative methods
- Remove duplicate prek configuration (already documented in prek.md)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add templates and improve security docs organization
- Create templates/ with copy-paste-ready pre-commit and dependabot configs
- Move Tool Installation before Quick Setup in security-setup.md
- Consolidate prek installation into security-setup.md
- Fix detect-secrets to use --report (non-interactive)
- Replace inline dependabot config with template reference
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix PR review issues: remove ty hook, update dependabot docs
- Remove ty pre-commit hook (no official hook exists yet, astral-sh/ty#269)
- Update dependabot.md to reference template instead of inline YAML
- Fix pip-audit CI command to use project scanning (uv run pip-audit .)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
- Add migration-checklist.md for gradual adoption of strict typing
- Bump minimum Python from 3.10 to 3.11 throughout
- Fix ty.rules in Full Project Setup to be strict from day 1
(migration guidance now lives in migration-checklist.md)
- Use [tool.ty.environment] for python-version (correct syntax)
- Add pip-audit to dependency groups for supply chain security
- Update references with clearer examples
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Add claude-in-chrome-troubleshooting plugin
Diagnose and fix Claude in Chrome MCP extension connectivity issues,
particularly the native host conflict between Claude.app (Cowork) and
Claude Code CLI.
Also creates marketplace.json with all existing plugins.
Original skill by @jeffzwang from @ExaAILabs.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove personal email from plugin.json
CI requires opensource@trailofbits.com or no email.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Skills were nested two levels deep under category directories
(development-guidelines/, not-so-smart-contracts-scanners/), but
Claude Code only discovers skills at one level: skills/<skill-name>/SKILL.md.
Move all 11 skills directly under skills/ for proper discovery.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Reapply "Add firebase-apk-scanner skill for auditing Firebase in APKs"
This reverts commit 555a17ce2e.
* Fix shellcheck and shfmt lint errors in scanner.sh
- Convert spaces to tabs for consistent indentation (shfmt)
- Add shellcheck disable for intentionally unused CYAN color variable
- Remove unused manifest_proj variable
- Replace for loops over find with while read loops (SC2044)
- Separate local declarations from assignments (SC2155)
- Replace sed calls with parameter expansion where possible (SC2001)
- Fix printf format string to avoid variable interpolation (SC2059)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Address code review feedback for firebase-apk-scanner
- Rename .claude_plugin/ to .claude-plugin/ to match convention
- Add plugin to root README.md under new "Mobile Security" category
- Change skill name from firebase-scan to firebase-apk-scanner for consistency
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix shfmt formatting in burp-search.sh
Convert spaces to tabs in case statement for consistent formatting.
This fixes a pre-existing CI failure.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix shfmt formatting to use 2-space indentation per CI config
CI runs `shfmt -i 2 -ci` (2-space indent with case indentation).
Reformat both shell scripts to match.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix remaining shellcheck warnings in scanner.sh
- SC2015: Replace `A && B || C` with proper if-then-else
- SC2002: Remove useless cat, pass file directly to jq
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add disable-model-invocation to prevent automatic triggering
This skill makes external HTTP requests and performs security testing,
so it should only run when explicitly invoked via /firebase-apk-scanner.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* ci: add lint enforcement with ruff, shellcheck, and shfmt
Add pre-commit hooks (prek) and GitHub Actions CI to enforce Python and
shell linting across the repository.
- Add root pyproject.toml with ruff configuration (line-length=100, py311)
- Add .pre-commit-config.yaml with ruff, shellcheck, shfmt, and standard hooks
- Add .github/workflows/lint.yml with SHA-pinned actions
- Update .github/dependabot.yml with root pip ecosystem entry
- Fix existing lint violations:
- Auto-fix imports and formatting with ruff
- Fix duplicate dict key in ct_analyzer (contentequals -> arrays.contentequals)
- Add noqa comment for required sys.path manipulation in extract_pdf.py
- Format shell scripts with shfmt (case statement indentation)
- Add per-file-ignores for ct_analyzer's long opcode tables and style patterns
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: use 2-space indentation for shell scripts
Change shfmt configuration from 4-space to 2-space indentation
to match CLAUDE.md standards.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Add trophy case for bugs found using skills
- Add Trophy Case section to README with table of discovered bugs
- Add suggested attribution line for external bug reports
- Add GitHub issue template for trophy case submissions
- Remove CC BY-SA badge image (keep text link)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Clarify bug title field in issue template
Make it clear that the bug title will be used as link text in the table.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* Add static-analysis plugin from internal repo
Migrate the static-analysis plugin which provides:
- CodeQL skill for deep security analysis with taint tracking
- Semgrep skill for fast pattern-based security scanning
- SARIF parsing skill with jq queries and Python helpers
Author: Axel Mierczuk
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix hardcoded path in sarif-parsing SKILL.md
Replace /home/user/proj/ with /path/to/project/ to pass the
hardcoded path CI check. The CI excludes /path/to patterns.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>