51 Commits
Author SHA1 Message Date
Dan GuidoandClaude Opus 4.6 540111a52a Add adversarial-modeler agent to differential-review (#84)
* Add adversarial-modeler agent to differential-review plugin

Introduces a formal agent definition for adversarial threat modeling
on high-risk code changes. Updates SKILL.md to reference agent and
bumps version to 1.1.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix {baseDir} paths and bump marketplace.json version

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve code review findings for PR #84

- Fix decision tree formatting: use correct tree syntax (first
  child uses branch connector, last child uses end connector)
- Add "When NOT to Use" section to adversarial-modeler agent per
  contributing guidelines

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-28 21:12:06 -04:00
Dan GuidoandClaude Opus 4.6 5f0a765877 Add sharp-edges-analyzer agent to sharp-edges (#81)
* Add sharp-edges-analyzer agent to sharp-edges plugin

Introduces a formal agent definition for the sharp edges analysis
workflow. Updates SKILL.md to reference agent and bumps version
to 1.1.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump sharp-edges version to 1.1.0 in marketplace.json

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve code review findings for PR #81

- Add examples column to agent severity classification table
- Add language-specific.md combined quick reference to agent
- Document agent in plugin README.md

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-28 21:10:55 -04:00
Dan GuidoandClaude Opus 4.6 5c15f4f564 Add archetype deep profiles to culture-index skill (#126)
* Add 17 archetype deep profile references to culture-index skill

Convert Culture Index archetype PDFs into structured markdown reference
files with consistent format: core traits, strengths, challenges,
management approach, risk profile, FlashPoints, variations, and summary.

Add Influencer to the archetype summary table in patterns-archetypes.md
and register all archetype files in the SKILL.md reference index.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix review issues in archetype profiles

- Align patterns-archetypes.md table with authoritative archetype files
  for Technical Expert, Socializer, Philosopher, Debater, Administrator
- Standardize "Moderate" to "Mid" in Trailblazer H1
- Split merged Organization/Environment FlashPoints rows into separate
  rows in Facilitator, Socializer, Traditionalist
- Remove leaked PDF source references from Debater, Technical Expert,
  Traditionalist variations sections

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-17 13:50:09 -04:00
Dan GuidoandClaude Opus 4.6 c6097699e4 Fix burpsuite-project-parser skill directory structure (#115)
Move SKILL.md and scripts/ into a named subdirectory matching the
frontmatter name. Both Claude Code and OpenCode discover skills at
skills/<name>/SKILL.md where <name> must match the frontmatter name
field.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-03 21:24:19 -08:00
Dan GuidoandClaude Opus 4.6 19c463e3f6 Import fp-check plugin from skills-internal (#113)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-03 08:40:15 -08:00
Dan GuidoandClaude Opus 4.6 1a868d25d2 second-opinion: use Codex CLI's built-in MCP server (#110)
* Replace third-party codex-mcp-server with Codex CLI's built-in MCP server

Swap `uvx codex-mcp-server` (third-party Python package) for `codex mcp-server`
(built-in to the Codex CLI). Eliminates the Python/uvx dependency and uses
OpenAI's officially maintained MCP server instead.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Gitignore uv.lock at repo root

No root pyproject.toml exists — the lockfile is a stale artifact from
an accidental uv invocation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix stale references to third-party codex-mcp-server

Update root README table and .gitignore comment to reflect the switch
to Codex CLI's built-in MCP server.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 01:03:31 -05:00
Dan GuidoandClaude Opus 4.6 3b378ebd47 Import skill-improver plugin from skills-internal (#109)
Iterative fix-review loop that automatically refines Claude Code skills
until they meet quality standards. Uses the plugin-dev:skill-reviewer
agent for automated review cycles with a stop hook to continue the loop.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:34:59 -05:00
Dan GuidoandClaude Opus 4.6 ed41cd7ceb Import five plugins from skills-internal (#108)
* Import four plugins from skills-internal and clean up README

Import seatbelt-sandboxer, supply-chain-risk-auditor, zeroize-audit,
and let-fate-decide from skills-internal. Remove dead humanizer and
skill-extractor directories. Fold "About Trail of Bits" into the
license line.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix CI: shellcheck SC2317 and let-fate-decide description mismatch

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Import agentic-actions-auditor from skills-internal

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix review issues across 5 imported plugins

- Fix empty array expansion crash under set -u on macOS bash 3.2
  (emit_rust_mir.sh, emit_asm.sh, emit_ir.sh)
- Fix copy-paste error in seatbelt-sandboxer README ("variant analysis")
- Remove references to non-existent leak-hunter skill
- Update agentic-actions-auditor license to match repo CC-BY-SA-4.0
- Add PEP 723 metadata to check_rust_asm_{aarch64,x86}.py
- Replace unsafe xargs trim with parameter expansion in track_dataflow.sh
- Add json_escape function to analyze_asm.sh, analyze_heap.sh,
  track_dataflow.sh for safe JSON construction with backslashes
- Add allowed-tools frontmatter to seatbelt-sandboxer and
  supply-chain-risk-auditor SKILL.md
- Add minimum finding count assertions to run_smoke.sh
- Fix double period typo in supply-chain-risk-auditor SKILL.md

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 10:21:20 -05:00
Dan GuidoandClaude Opus 4.6 60ab7b0fe0 Fix second-opinion Codex schema validation and update Gemini model (#103)
codex-review-schema.json failed OpenAI structured output validation
because required arrays didn't include all sibling property keys when
additionalProperties: false was set. Made optional fields nullable
and added them to required to satisfy the constraint.

Update Gemini model from gemini-3-pro-preview to gemini-3.1-pro-preview
following the Feb 19 release.

Bump version 1.5.0 → 1.5.1.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-20 13:56:28 -07:00
Dan GuidoandClaude Opus 4.6 c557d2a269 Bundle codex-mcp-server into second-opinion plugin (#95)
Add .mcp.json to auto-start the codex-mcp-server when the plugin is
installed, providing codex_ask, codex_exec, and codex_review MCP tools.
The MCP tool descriptions are self-documenting — no separate skill
docs needed. Bump version to 1.5.0.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-18 23:49:35 -07:00
Dan GuidoandClaude Opus 4.6 224f51731e ci: enforce pre-commit formatting hooks in CI (#99)
* ci: enforce pre-commit formatting hooks in CI

check-yaml, check-json, end-of-file-fixer, and trailing-whitespace
only ran locally via pre-commit. Contributors who skip pre-commit
can introduce formatting drift (see #97). Add a CI job using
pre-commit/action to enforce these four hooks on every PR.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci: consolidate lint jobs into single pre-commit pass

Run all pre-commit hooks (ruff, shellcheck, shfmt, check-yaml,
check-json, end-of-file-fixer, trailing-whitespace) in one job
instead of separate CI jobs per tool. Fixes the extra_args error
where pre-commit run only accepts one hook ID positionally.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: fix trailing whitespace and EOF in semgrep-rule-creator

Pre-commit hooks caught two files missed by the earlier formatting
PR: trailing blank line in quick-reference.md and trailing
whitespace plus missing final newline in workflow.md.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 10:20:31 -07:00
9f7f8adad9 style: fix formatting issues across 27 plugin files (#98)
Pre-commit hooks auto-fixed missing newlines at EOF and trailing
whitespace to satisfy end-of-file-fixer and trailing-whitespace checks.

Co-authored-by: Dallas McIntyre <dkmcintyre@safaricircuits.com>
Co-authored-by: Claude Code <noreply@anthropic.com>
2026-02-18 10:09:58 -07:00
Dan GuidoandClaude Opus 4.6 4c854b712e Fix culture-index SKILL.md standards compliance (#96)
* Fix culture-index SKILL.md standards compliance

- Switch description to third-person voice, remove "PDF vision" mention
  that contradicts body's prohibition on visual estimation
- Add allowed-tools to frontmatter (Bash, Read, Grep, Glob, Write)
- Add required "When to Use" and "When NOT to Use" sections

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump culture-index version to 1.1.0

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-17 21:32:35 -07:00
Dan GuidoandClaude Opus 4.6 776ccc812c second-opinion: switch Codex from codex review to codex exec (#93)
* Switch second-opinion Codex path from codex review to codex exec

Use codex exec with --output-schema and -o (--output-last-message)
instead of codex review. This eliminates context waste from verbose
[thinking] and [exec] blocks by capturing only the structured JSON
review output to a file. Uses OpenAI's published code review prompt
that GPT-5.2-codex was specifically trained on.

Also lowers default reasoning from xhigh to high, removes the
--base/--commit prompt limitation (all scopes now support project
context and focus instructions), and adds a JSON schema for
structured findings output.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix review issues: untracked files, hardcoded paths, schema naming

- Include untracked files in uncommitted scope diff using
  git ls-files + git diff --no-index, matching the coverage
  that codex review --uncommitted previously provided
- Replace hardcoded /tmp/ paths with mktemp for portability
- Rename absolute_file_path to file_path in schema since
  git diff produces relative paths
- Capture stderr to a log file instead of /dev/null for
  faster error diagnosis without retry

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix PR review findings: schema constraints, flag naming, citation

- Add required and additionalProperties: false to JSON schema
- Use -o (short flag) consistently; clarify --output-last-message
- Add cookbook citation URL for the code review prompt
- Add || true to git diff --no-index (exits 1 on diff found)
- Fix schema.json → codex-review-schema.json in SKILL.md quick ref

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Restore xhigh reasoning effort, fix cookbook citation URL

- Change reasoning effort back to xhigh from high
- Update cookbook URL to canonical developers.openai.com domain
  (old cookbook.openai.com returns 308 redirect)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-17 03:05:33 -07:00
Dan GuidoandClaude Opus 4.6 b9ac28c214 Add links to related Trail of Bits repos in README (#92)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 16:06:52 -05:00
Dan GuidoandClaude Opus 4.6 d3630e5193 Skip dep scan when diff doesn't touch dependency files (#91)
The Gemini `/security:scan-deps` command scans the entire project
dependency tree regardless of what changed. This wastes time when
reviewing small config or code changes that don't involve dependencies.

Now the scan only runs when the diff actually touches manifest files
(package.json, Gemfile, requirements.txt, Cargo.toml, go.mod, etc.).

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 14:33:36 -05:00
Dan GuidoandClaude Opus 4.6 962f7433a1 Add spec-compliance-checker agent to spec-to-code-compliance (#82)
* Add spec-compliance-checker agent to spec-to-code-compliance plugin

Introduces a formal agent definition for the full specification-to-code
compliance workflow. Updates SKILL.md to reference agent and bumps
version to 1.1.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix {baseDir} paths and bump marketplace.json version

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve code review findings for PR #82

- Normalize double hyphens to em dashes in agent rationalizations table
  for consistency with SKILL.md formatting conventions
- Add invocation example to SKILL.md Agent section

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 08:09:08 +04:00
Dan GuidoandClaude Opus 4.6 271c095d31 Add function-analyzer agent to audit-context-building (#83)
* Add function-analyzer agent to audit-context-building plugin

Introduces a formal agent definition for ultra-granular per-function
analysis. Updates SKILL.md Section 8 to reference agent and bumps
version to 1.1.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix {baseDir} paths and bump marketplace.json version

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve code review findings for PR #83

- Wrap long SKILL.md line (239 chars -> multi-line) for readability
- Trim verbose agent description frontmatter
- Add "When NOT to Use" section to agent file per project standards

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 08:08:06 +04:00
Dan GuidoandClaude Opus 4.6 42466c4600 Fix Gemini heredoc patterns that prevent variable expansion (#87)
* Fix Gemini heredoc patterns that prevent variable expansion

Single-quoted heredoc delimiters (<<'PROMPT') suppress shell
substitution, so $(cat /tmp/review-diff.txt) was passed to
Gemini as literal text. Replaced all heredoc patterns with
pipe-based construction ({ printf ...; cat ...; } | gemini)
which avoids both the quoting bug and shell metacharacter
issues from unquoted heredocs (diffs contain $ and backticks).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Bump second-opinion version in marketplace.json to match plugin.json

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Clarify marketplace.json path in CLAUDE.md PR checklist

The checklist said `.claude-plugin/marketplace.json` which is
ambiguous — every plugin has its own `.claude-plugin/` directory.
Specify that the marketplace.json is at the repo root, distinct
from each plugin's `.claude-plugin/plugin.json`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 19:53:29 -05:00
9600b3d9e6 Add semgrep-scanner and semgrep-triager agents to static-analysis (#80)
* Add semgrep-scanner and semgrep-triager agents to static-analysis plugin

Introduces formal agent definitions for the scanning and triage
workflows. Updates SKILL.md to reference agents and bumps version
to 1.1.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix {baseDir} paths and bump marketplace.json version

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve code review findings for PR #80

- Update scanner-task-prompt.md to reference semgrep-scanner subagent
  type instead of Bash (consistent with SKILL.md Step 4 change)
- Update triage-task-prompt.md to reference semgrep-triager subagent
  type instead of general-purpose (consistent with SKILL.md Step 5 change)
- Add Agents Included section to README.md documenting new agents
- Fix Agents table column header in SKILL.md from "Type" to "Tools"

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use fully-qualified agent type names for semgrep subagents

Plugin agents require the `plugin-name:agent-name` format at runtime,
but the skill referenced bare names (`semgrep-scanner`, `semgrep-triager`)
causing "Agent type not found" errors when spawning scan/triage Tasks.

Also adds agent types to the Step 3 plan template and pre-scan checklist
so they appear in generated plans and survive context clearing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Explicit semgrep scan allow

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: axelm-tob <axel.mierczuk@trailofbits.com>
2026-02-12 11:17:57 -05:00
Dan GuidoandClaude Opus 4.6 15f6b1c880 Remove fix-review plugin (moved to skills-internal) (#86)
* Remove fix-review plugin (moved to skills-internal)

This plugin is only useful for internal audit workflows and was
added to the public repo by mistake.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Remove empty Audit Lifecycle section from README

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 09:31:01 -05:00
Dan GuidoandClaude Opus 4.6 f1d166608b Sync devcontainer skill with upstream trailofbits/claude-code-devcontainer (#71)
- Dockerfile: use multi-stage build for uv (ARG actually used now)
- Dockerfile: reorder installs to match upstream (git-delta → uv → fzf)
- devcontainer.json: remove UV_VERSION/FZF_VERSION build args (handled by Dockerfile ARGs)
- .zshrc: sync fzf comment wording

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 06:49:17 -05:00
Dan GuidoandClaude Opus 4.6 d98cfc79ad Fix second-opinion skill issues found in live testing (#70) (#70)
- Fix "sequentially" → "parallel" in Question 1 to match Running Both section
- Document Codex context limitation for --base/--commit (skill will not
  create AGENTS.md; inform user of the limitation instead)
- Add Codex output parsing guidance (summarize findings, don't dump 55KB
  of raw thinking/exec blocks)
- Document EPERM/sandbox errors as expected (codex review is sandboxed,
  cannot run tests or builds)
- Bump version to 1.2.0

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 02:05:44 -05:00
Dan GuidoandClaude Opus 4.6 211ecdec1c Fix second-opinion skill: broken Codex prompt passing, unnecessary upfront checks, parallel reviews (#69)
- Fix Codex --base/--commit prompt passing: the positional [PROMPT] arg
  is mutually exclusive with these flags (confirmed via CLI), and stdin
  via `-` is also rejected. Document the AGENTS.md workaround instead.
- Remove upfront `command -v` availability checks. Just run the tool and
  handle errors — saves a turn and avoids mishandled control flow.
- Run Codex and Gemini reviews in parallel (both are read-only, no
  shared state) instead of sequentially.
- Expand error handling table with explicit per-extension install URLs.
- Bump version to 1.1.0.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 01:30:17 -05:00
Dan GuidoandClaude Opus 4.6 bf125052d4 Add second-opinion skill for external LLM code reviews (#68)
Shells out to OpenAI Codex CLI and Google Gemini CLI to get
independent code reviews from different models on uncommitted
changes, branch diffs, or specific commits.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-10 00:57:34 -05:00
Dan GuidoandClaude Opus 4.5 6fd5fd8961 Fix yara-authoring plugin.json author format (#60)
Change author from string to object to match plugin schema.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 19:30:34 -05:00
Dan GuidoandClaude Opus 4.5 241012bf95 Update yara-authoring to 2.0.0 in marketplace.json (#59)
Sync version and description with plugin.json.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 19:28:00 -05:00
Dan GuidoandClaude Opus 4.5 c180c526d5 Fix YARA-X skill weaknesses and add real examples (#58)
* Fix YARA-X skill weaknesses and add real examples

Address verified weaknesses in the YARA-X skill based on research:

## Module Documentation Fixes
- Fix CRX module: add missing fields (id, version, raw_name,
  raw_description, homepage_url, optional_host_permissions, signatures)
- Fix DEX module: correct function names to singular (contains_string,
  contains_method, contains_class), add header structure, integrity
  functions (checksum, signature), and collection documentation

## Real Examples with Attribution
- Replace synthetic examples with real, attributed rules:
  - MAL_Win_Remcos: Elastic Security production rules
  - MAL_Mac_ProtonRAT: Airbnb BinaryAlert macOS detection
  - MAL_NPM_SupplyChain: Stairwell chalk/debug attack patterns
  - SUSP_JS_Obfuscation: imp0rtp3/js-yara-rules patterns

## Reduced PE Bias
- Add macOS malware detection section with Mach-O magic bytes
- Add JavaScript detection decision tree
- Add Resources section with quality YARA repositories
- Expand platform considerations table

## Testing Improvements
- Add free VirusTotal alternatives (YARA-CI, YaraDbg, NIST NSRL)
- Add guidance for building local goodware corpora
- Add macOS XProtect reference

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Update YARA-X skill tool recommendations

- Add FLOSS to Essential Toolkit for obfuscated/stack string extraction
- Remove Binarly (now enterprise-only, no free alternative)
- Add yarGen → YARA-X validation step (yr check + yr fmt)
- Add yr dump section for file analysis before rule writing
- Expand FLOSS documentation with string types and Go/Rust support

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 18:53:29 -05:00
Dan GuidoandClaude Opus 4.5 47d974837a Add plugin-specific code owners to CODEOWNERS (#57)
Map individual plugin authors to their plugins so they receive review
requests on PRs that touch their work. Each plugin rule includes both
the author and @dguido to ensure visibility.

Plugins authored by Trail of Bits org or Dan Guido use the default rule.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 12:21:50 -05:00
Dan GuidoandClaude Opus 4.5 c78e4219ea Update YARA skill for YARA 4.5.x features (#55)
Add documentation for new YARA 4.5.0 features:
- Unreferenced string prefix (`$_`) to suppress unused warnings
- `--strict-escape` flag for catching invalid regex escapes
- `CALLBACK_MSG_TOO_SLOW_SCANNING` for slow rule detection

Core guidance (atom theory, string quality, performance optimization)
validated against current expert sources and remains accurate.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 03:25:14 -05:00
Dan GuidoandClaude Opus 4.5 f2faec9cd1 Add yara-authoring skill for YARA detection rule authoring (#54)
* Add yara-authoring skill for YARA detection rule authoring

Comprehensive skill for writing high-quality YARA detection rules:

- Core guidance on string selection, atom optimization, and FP reduction
- Platform-specific patterns for PE, JavaScript, npm packages, VS Code extensions
- Expert patterns from Neo23x0 signature-base and Stairwell research
- Unicode steganography detection (Variation Selectors per Veracode research)
- Supply chain attack patterns (Discord webhooks, credential theft, postinstall hooks)
- Decision trees for string quality, all/any selection, and FP debugging
- Scripts: yara_lint.py for style validation, atom_analyzer.py for string quality

Reference documents cover:
- strings.md: String types, modifiers, JS obfuscation patterns
- performance.md: Atom theory, regex discipline, short-circuit optimization
- testing.md: Goodware validation, supply chain package testing
- style-guide.md: Naming conventions and metadata requirements

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Move yara-authoring to Malware Analysis section

YARA is primarily used for malware detection and classification,
so this is a better categorization than Code Auditing.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 02:51:41 -05:00
Dan GuidoandClaude Opus 4.5 650f6e3700 Fix copy quality issues across skill descriptions (#53)
- Fix typo: "araise" → "arise" in ask-questions-if-underspecified
- Remove stray "(project, gitignored)" metadata from 11 skill descriptions
- Fix voice consistency: second-person → third-person in descriptions
- Fix voice consistency: first-person → third-person in body content
- Remove "Comprehensive" filler word from 2 descriptions

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-29 14:37:24 -05:00
Dan GuidoandClaude Opus 4.5 45e2ed25bc Fix Windows compatibility: remove colons from command filenames (#52)
Rename 10 command files that contained `:` in their filenames, which is
invalid on Windows filesystems (reserved for drive letters).

The `trailofbits:` namespace is preserved in the frontmatter `name` field,
so slash commands like `/trailofbits:audit-context` continue to work.

Fixes #51

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-29 11:07:05 -05:00
Dan GuidoandClaude Opus 4.5 bb5c353abc Improve modern-python skill description and add UV_PROJECT_ENVIRONMENT (#50)
- Tighten frontmatter description to name specific tools (uv, ruff, ty)
  and migration triggers (pip/Poetry/mypy/black) for better matching
- Document UV_PROJECT_ENVIRONMENT variable for container/host workflows
- Add Container/Host Development section explaining separate venv usage

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-29 01:40:59 -05:00
Dan GuidoandClaude Opus 4.5 a6ed466329 Add trailofbits: prefixed slash commands to 9 plugins (#49)
Add slash commands that wrap existing skills for easier invocation:
- /trailofbits:scan-apk - Firebase APK security scanner
- /trailofbits:burp-search - Burp Suite project file search
- /trailofbits:entry-points - Smart contract entry point analyzer
- /trailofbits:variants - Vulnerability variant analysis
- /trailofbits:semgrep-rule - Semgrep rule creator
- /trailofbits:diff-review - Differential security review
- /trailofbits:ct-check - Constant-time analysis
- /trailofbits:spec-compliance - Spec-to-code compliance checker
- /trailofbits:audit-context - Audit context builder

Also rename existing fix-review command to trailofbits:fix-review
for consistency with the naming convention.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-29 00:11:55 -05:00
Dan GuidoandClaude Opus 4.5 39dd47e05b Add --write flag to shfmt pre-commit hook (#44)
Custom args in .pre-commit-config.yaml replace default args rather
than extend them. The shfmt hook's default args include --write, but
our custom args (-i 2 -ci) were missing it. Without --write, shfmt
outputs to stdout and exits 0 regardless of formatting issues.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 21:44:57 -05:00
Dan GuidoandClaude Opus 4.5 e9dec942d1 Add BATS test suite for intercept-legacy-python hook (#43)
* Add BATS test suite for intercept-legacy-python hook

- Add 64 tests covering all code paths: early exits, allow cases
  (uv run, diagnostics, search tools), deny cases (python/pip
  execution, uv pip, piped commands, compound commands)
- Add test_helper.bash with run_hook, assert_allow, assert_deny,
  and assert_suggestion_contains helpers
- Add bats job to CI workflow
- Fix hook to properly detect python execution in piped commands
  like `python script.py | grep foo` and `find . | xargs python`

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix CI failures in hook test suite

- Suppress jq stderr in run_hook_no_uv to avoid "Broken pipe" error
  when hook script exits early due to missing uv
- Fix shfmt formatting: remove trailing backslash, single space before
  inline comments

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 21:37:30 -05:00
Dan GuidoandClaude Opus 4.5 7e513fef5c Update modern-python skill for tool compatibility (#41)
* Align prek auto-update cooldown to 7 days

Update the recommended --cooldown-days value from 3 to 7 to match
the project's CLAUDE.md standard. A 7-day cooldown provides a
reasonable window for the community to detect compromised releases.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Update modern-python for ruff and ty compatibility

- Remove deprecated ANN101/ANN102 rules (removed in ruff 0.8.0)
- Fix ty config section: tool.ty → tool.ty.terminal
- Fix ty rule name: possibly-unbound → possibly-unresolved-reference
- Update SKILL.md ignore list to match reference docs

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 17:46:10 -05:00
Dan GuidoandClaude Opus 4.5 0c9da5d813 Update modern-python README to reflect current skill coverage (#39)
- Rewrite "When to Use" with specific, outcome-focused triggers
- Add security tools section (shellcheck, detect-secrets, actionlint, zizmor, pip-audit, Dependabot)
- Add prek and ty to core tools
- Group into Core Tools, Security Tools, and Standards sections

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 14:27:24 -05:00
Dan GuidoandClaude Opus 4.5 bcd1d25c76 Fix Python version in README (3.10 -> 3.11) (#38)
The skill content consistently uses 3.11 as the minimum version.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 14:20:32 -05:00
Dan GuidoandClaude Opus 4.5 bdf72dd5ee Consolidate modern-python security documentation (#37)
* Consolidate modern-python security documentation

Security content was fragmented across prek.md, migration-checklist.md,
and SKILL.md with no clear entry point. Users had to hunt across files
to understand security setup.

Changes:
- Add references/security-setup.md as single source of truth for all 6
  security tools (shellcheck, detect-secrets, actionlint, zizmor,
  pip-audit, Dependabot)
- Add Security Tools subsection to SKILL.md tool overview
- Simplify migration-checklist.md security items with links
- Add cross-references from prek.md to security-setup.md

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix pip-audit command and add installation instructions

- Fix pip-audit command: use `. ` (project path) instead of
  `--requirement pyproject.toml` which expects requirements.txt format
- Add Tool Installation section with brew, uv, and alternative methods
- Remove duplicate prek configuration (already documented in prek.md)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Add templates and improve security docs organization

- Create templates/ with copy-paste-ready pre-commit and dependabot configs
- Move Tool Installation before Quick Setup in security-setup.md
- Consolidate prek installation into security-setup.md
- Fix detect-secrets to use --report (non-interactive)
- Replace inline dependabot config with template reference

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix PR review issues: remove ty hook, update dependabot docs

- Remove ty pre-commit hook (no official hook exists yet, astral-sh/ty#269)
- Update dependabot.md to reference template instead of inline YAML
- Fix pip-audit CI command to use project scanning (uv run pip-audit .)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 14:14:09 -05:00
Dan GuidoandClaude Opus 4.5 1feef63b6f Improve modern-python skill with migration guide and Python 3.11 (#36)
- Add migration-checklist.md for gradual adoption of strict typing
- Bump minimum Python from 3.10 to 3.11 throughout
- Fix ty.rules in Full Project Setup to be strict from day 1
  (migration guidance now lives in migration-checklist.md)
- Use [tool.ty.environment] for python-version (correct syntax)
- Add pip-audit to dependency groups for supply chain security
- Update references with clearer examples

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 13:10:33 -05:00
Dan GuidoandClaude Opus 4.5 2a7b3d9cd5 Add claude-in-chrome-troubleshooting plugin (#35)
* Add claude-in-chrome-troubleshooting plugin

Diagnose and fix Claude in Chrome MCP extension connectivity issues,
particularly the native host conflict between Claude.app (Cowork) and
Claude Code CLI.

Also creates marketplace.json with all existing plugins.

Original skill by @jeffzwang from @ExaAILabs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Remove personal email from plugin.json

CI requires opensource@trailofbits.com or no email.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-26 02:04:56 -05:00
Dan GuidoandClaude Opus 4.5 7af5b1ba68 Flatten building-secure-contracts skill directory structure (#34)
Skills were nested two levels deep under category directories
(development-guidelines/, not-so-smart-contracts-scanners/), but
Claude Code only discovers skills at one level: skills/<skill-name>/SKILL.md.

Move all 11 skills directly under skills/ for proper discovery.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-25 20:31:38 -05:00
Dan GuidoandClaude Opus 4.5 e827fa624b Add firebase-apk-scanner skill for auditing Firebase in APKs (#21)
* Reapply "Add firebase-apk-scanner skill for auditing Firebase in APKs"

This reverts commit 555a17ce2e.

* Fix shellcheck and shfmt lint errors in scanner.sh

- Convert spaces to tabs for consistent indentation (shfmt)
- Add shellcheck disable for intentionally unused CYAN color variable
- Remove unused manifest_proj variable
- Replace for loops over find with while read loops (SC2044)
- Separate local declarations from assignments (SC2155)
- Replace sed calls with parameter expansion where possible (SC2001)
- Fix printf format string to avoid variable interpolation (SC2059)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Address code review feedback for firebase-apk-scanner

- Rename .claude_plugin/ to .claude-plugin/ to match convention
- Add plugin to root README.md under new "Mobile Security" category
- Change skill name from firebase-scan to firebase-apk-scanner for consistency

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix shfmt formatting in burp-search.sh

Convert spaces to tabs in case statement for consistent formatting.
This fixes a pre-existing CI failure.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix shfmt formatting to use 2-space indentation per CI config

CI runs `shfmt -i 2 -ci` (2-space indent with case indentation).
Reformat both shell scripts to match.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix remaining shellcheck warnings in scanner.sh

- SC2015: Replace `A && B || C` with proper if-then-else
- SC2002: Remove useless cat, pass file directly to jq

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Add disable-model-invocation to prevent automatic triggering

This skill makes external HTTP requests and performs security testing,
so it should only run when explicitly invoked via /firebase-apk-scanner.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 12:44:54 -05:00
Dan Guido 555a17ce2e Revert "Add firebase-apk-scanner skill for auditing Firebase in APKs"
This reverts commit 7f894a7b54.
2026-01-20 12:03:15 -05:00
Dan GuidoandClaude Opus 4.5 fd367ad81b ci: add lint enforcement with ruff, shellcheck, and shfmt (#10)
* ci: add lint enforcement with ruff, shellcheck, and shfmt

Add pre-commit hooks (prek) and GitHub Actions CI to enforce Python and
shell linting across the repository.

- Add root pyproject.toml with ruff configuration (line-length=100, py311)
- Add .pre-commit-config.yaml with ruff, shellcheck, shfmt, and standard hooks
- Add .github/workflows/lint.yml with SHA-pinned actions
- Update .github/dependabot.yml with root pip ecosystem entry
- Fix existing lint violations:
  - Auto-fix imports and formatting with ruff
  - Fix duplicate dict key in ct_analyzer (contentequals -> arrays.contentequals)
  - Add noqa comment for required sys.path manipulation in extract_pdf.py
  - Format shell scripts with shfmt (case statement indentation)
- Add per-file-ignores for ct_analyzer's long opcode tables and style patterns

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: use 2-space indentation for shell scripts

Change shfmt configuration from 4-space to 2-space indentation
to match CLAUDE.md standards.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-16 15:13:46 -05:00
Dan GuidoandClaude Opus 4.5 751a8f6b31 Harden validate workflow with explicit permissions (#5)
- Add `permissions: contents: read` to follow least privilege
- Add concurrency limits to cancel redundant workflow runs
- Add job name for clearer GitHub Actions UI

Fixes CodeQL alert #2 (actions/missing-workflow-permissions)

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-14 23:46:02 -05:00
Dan GuidoandClaude Opus 4.5 67eeb40bbe Add trophy case for bugs found using skills (#4)
* Add trophy case for bugs found using skills

- Add Trophy Case section to README with table of discovered bugs
- Add suggested attribution line for external bug reports
- Add GitHub issue template for trophy case submissions
- Remove CC BY-SA badge image (keep text link)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Clarify bug title field in issue template

Make it clear that the bug title will be used as link text in the table.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-14 21:00:42 -05:00
Dan GuidoandClaude Opus 4.5 4f5139d01d Add static-analysis plugin from internal repo (#3)
* Add static-analysis plugin from internal repo

Migrate the static-analysis plugin which provides:
- CodeQL skill for deep security analysis with taint tracking
- Semgrep skill for fast pattern-based security scanning
- SARIF parsing skill with jq queries and Python helpers

Author: Axel Mierczuk

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix hardcoded path in sarif-parsing SKILL.md

Replace /home/user/proj/ with /path/to/project/ to pass the
hardcoded path CI check. The CI excludes /path/to patterns.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-14 19:11:03 -05:00
Dan GuidoandClaude Opus 4.5 695119c312 Initial release of Trail of Bits Skills Marketplace
16 plugins for security analysis, smart contract auditing, and verification:

Smart Contract Security:
- building-secure-contracts
- entry-point-analyzer

Code Auditing:
- audit-context-building
- burpsuite-project-parser
- differential-review
- semgrep-rule-creator
- sharp-edges
- testing-handbook-skills
- variant-analysis

Verification:
- constant-time-analysis
- property-based-testing
- spec-to-code-compliance

Audit Lifecycle:
- fix-review

Reverse Engineering:
- dwarf-expert

Development:
- ask-questions-if-underspecified

Team Management:
- culture-index

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-14 15:24:03 -05:00