Commit Graph

  • 78bcf4c086 remaining fixes from vanhauser-thc (#75) Paweł Płatek 2026-02-11 17:38:58 +01:00
  • ebcffa8d3e Bump astral-sh/ruff-action from 3.5.1 to 3.6.1 in the all group (#76) dependabot[bot] 2026-02-11 11:38:23 -05:00
  • 1d843475e7 Add debug-buttercup skill (#73) Ronald Eytchison 2026-02-10 23:40:38 -05:00
  • f1d166608b Sync devcontainer skill with upstream trailofbits/claude-code-devcontainer (#71) Dan Guido 2026-02-10 06:49:17 -05:00
  • 543816914a Add devcontainer-setup plugin (#26) dm 2026-02-10 12:12:28 +01:00
  • d98cfc79ad Fix second-opinion skill issues found in live testing (#70) (#70) Dan Guido 2026-02-10 02:05:44 -05:00
  • 211ecdec1c Fix second-opinion skill: broken Codex prompt passing, unnecessary upfront checks, parallel reviews (#69) Dan Guido 2026-02-10 01:30:17 -05:00
  • bf125052d4 Add second-opinion skill for external LLM code reviews (#68) Dan Guido 2026-02-10 00:57:34 -05:00
  • f821e35473 codeql skills merge and improve (#67) Paweł Płatek 2026-02-06 17:34:43 +01:00
  • 51e02cc659 Merge and improve semgrep skills (#65) Paweł Płatek 2026-02-06 17:32:20 +01:00
  • a50696e205 add @dariushoule to codeowners for insecure-defaults (#62) Darius Houle 2026-01-31 23:18:56 -07:00
  • c9b644a8c2 update version of plugins with updates and a note about doing this for future claudes (#61) Jay Little 2026-01-31 01:02:26 -05:00
  • 6fd5fd8961 Fix yara-authoring plugin.json author format (#60) Dan Guido 2026-01-30 19:30:34 -05:00
  • 241012bf95 Update yara-authoring to 2.0.0 in marketplace.json (#59) Dan Guido 2026-01-30 19:28:00 -05:00
  • c180c526d5 Fix YARA-X skill weaknesses and add real examples (#58) Dan Guido 2026-01-30 18:53:29 -05:00
  • 47d974837a Add plugin-specific code owners to CODEOWNERS (#57) Dan Guido 2026-01-30 12:21:50 -05:00
  • 7934f0b5b9 Improve semgrep-rule-creator based on testing (#56) ahpaleus 2026-01-30 17:53:58 +01:00
  • c78e4219ea Update YARA skill for YARA 4.5.x features (#55) Dan Guido 2026-01-30 03:25:14 -05:00
  • f2faec9cd1 Add yara-authoring skill for YARA detection rule authoring (#54) Dan Guido 2026-01-30 02:51:41 -05:00
  • 650f6e3700 Fix copy quality issues across skill descriptions (#53) Dan Guido 2026-01-29 14:37:24 -05:00
  • 45e2ed25bc Fix Windows compatibility: remove colons from command filenames (#52) Dan Guido 2026-01-29 11:07:05 -05:00
  • bb5c353abc Improve modern-python skill description and add UV_PROJECT_ENVIRONMENT (#50) Dan Guido 2026-01-29 01:40:59 -05:00
  • a6ed466329 Add trailofbits: prefixed slash commands to 9 plugins (#49) Dan Guido 2026-01-29 00:11:55 -05:00
  • 09b6ebe643 Improve semgrep-rule-creator skill (#46) ahpaleus 2026-01-29 00:22:10 +01:00
  • 3fd5bababa Add a skill for auditing insecure default configurations (#48) Darius Houle 2026-01-28 13:55:40 -07:00
  • 1a2151e4dc Update pytest config to modern [tool.pytest] syntax (#45) johnniemorrow 2026-01-28 13:55:37 -05:00
  • 319283694d Bump actions/checkout from 6.0.1 to 6.0.2 in the all group (#47) dependabot[bot] 2026-01-28 13:50:03 -05:00
  • 39dd47e05b Add --write flag to shfmt pre-commit hook (#44) Dan Guido 2026-01-26 21:44:57 -05:00
  • e9dec942d1 Add BATS test suite for intercept-legacy-python hook (#43) Dan Guido 2026-01-26 21:37:30 -05:00
  • 4aeaa737f6 Add hook to modern-python to intercept python3 and pip calls (#40) William Tan 2026-01-26 19:03:08 -05:00
  • 7e513fef5c Update modern-python skill for tool compatibility (#41) Dan Guido 2026-01-26 17:46:10 -05:00
  • 0c9da5d813 Update modern-python README to reflect current skill coverage (#39) Dan Guido 2026-01-26 14:27:24 -05:00
  • bcd1d25c76 Fix Python version in README (3.10 -> 3.11) (#38) Dan Guido 2026-01-26 14:20:32 -05:00
  • bdf72dd5ee Consolidate modern-python security documentation (#37) Dan Guido 2026-01-26 14:14:09 -05:00
  • 1feef63b6f Improve modern-python skill with migration guide and Python 3.11 (#36) Dan Guido 2026-01-26 13:10:33 -05:00
  • 4e5828f6f2 Add modern python best practices skill (#22) William Tan 2026-01-26 12:36:49 -05:00
  • 2a7b3d9cd5 Add claude-in-chrome-troubleshooting plugin (#35) Dan Guido 2026-01-26 02:04:56 -05:00
  • 7af5b1ba68 Flatten building-secure-contracts skill directory structure (#34) Dan Guido 2026-01-25 20:31:38 -05:00
  • aa9dd931dd Improve Move references in entry-point-analyzer (#30) Sam Blackshear 2026-01-23 15:26:14 -08:00
  • 721e016efe Clean up semgrep-rule-creator skill (#31) ahpaleus 2026-01-23 17:08:24 +01:00
  • efd95a05ab fix ct-analyzer loading ct-analyzer-search Scott Arciszewski 2026-01-22 20:05:53 -05:00
  • c4c6275ec1 remove hardcoded credentials from pattern matching examples fix-semgrep-rule-creator-docs-reference Maciej Domanski 2026-01-22 16:26:24 +01:00
  • 5d766fc025 fix semgrep-rule-creator docs reference in Key Requirements (#29) ahpaleus 2026-01-22 16:26:22 +01:00
  • 676b30f30f remove Common Patterns by Language section Maciej Domanski 2026-01-22 16:21:45 +01:00
  • 55e025f55f improve test annotation documentation with language examples Maciej Domanski 2026-01-22 16:18:25 +01:00
  • fb7e216beb clarify test command requires rule directory context Maciej Domanski 2026-01-22 16:13:32 +01:00
  • 9b7d83c3b2 remove reference to non-existent semgrep skill Maciej Domanski 2026-01-22 16:12:23 +01:00
  • d683f46e83 add language caveat to quote equivalence comment Maciej Domanski 2026-01-22 16:09:51 +01:00
  • e831593f1c standardize verification checkpoint wording without checkmark Maciej Domanski 2026-01-22 16:00:42 +01:00
  • 5e5b3246db consolidate workflow.md steps to match SKILL.md 6-step structure Maciej Domanski 2026-01-22 15:58:59 +01:00
  • 0f0e5b5738 use recommended severity values instead of legacy ERROR Maciej Domanski 2026-01-22 15:52:42 +01:00
  • 8c800374e7 fix documentation requirement scope in Strictness Level section Maciej Domanski 2026-01-22 15:51:20 +01:00
  • 8ba2a18503 remove quote variants optimization guidance Maciej Domanski 2026-01-22 15:40:20 +01:00
  • e307b1ff9d simplify appsec.guide link description Maciej Domanski 2026-01-22 15:33:00 +01:00
  • 9a29f4c862 fix documentation requirements to be unconditional Maciej Domanski 2026-01-22 15:31:27 +01:00
  • 684cc68dd5 fix task completion criteria contradiction in workflow.md Maciej Domanski 2026-01-22 15:28:47 +01:00
  • ab9f8f602f fix semgrep-rule-creator docs reference in Key Requirements Maciej Domanski 2026-01-22 15:23:30 +01:00
  • c87e01d870 fix description for CVE-2026-22705 (#25) Scott Arciszewski 2026-01-21 11:23:15 -05:00
  • 0acae14f47 rm burp skill from generation (#24) Paweł Płatek 2026-01-21 13:30:20 +01:00
  • 30630582aa Add firebase-apk-scanner plugin to marketplace.json (#23) Ali 2026-01-21 12:15:19 +13:00
  • e827fa624b Add firebase-apk-scanner skill for auditing Firebase in APKs (#21) Dan Guido 2026-01-20 12:44:54 -05:00
  • f8775bb63a add codeowners (#20) Benjamin Samuels 2026-01-20 09:11:55 -08:00
  • 555a17ce2e Revert "Add firebase-apk-scanner skill for auditing Firebase in APKs" Dan Guido 2026-01-20 12:03:15 -05:00
  • 7f894a7b54 Add firebase-apk-scanner skill for auditing Firebase in APKs - Add scanner.sh for comprehensive Firebase misconfiguration detection - Extract configs from google-services.json, XML resources, smali, assets - Test auth (signup, anonymous, email enumeration), RTDB, Firestore, Storage buckets, Cloud Functions, and Remote Config - Fix script path to use {baseDir} for correct skill invocation - Add required "When to Use", "When NOT to Use", and "Rationalizations to Reject" sections per contribution guidelines nicksellier 2026-01-20 11:37:33 -05:00
  • 144e181b6a Clean up branch to only include humanizer skill feat/humanizer-skill Dan Guido 2026-01-20 11:06:02 -05:00
  • da18f0efc8 fix and improve aflpp skill (#15) van Hauser 2026-01-20 16:32:26 +01:00
  • e1427d920d Add semgrep-rule-variant-creator skill (#17) ahpaleus 2026-01-20 16:14:33 +01:00
  • d8ca0a9a20 Add skill-extractor plugin feat/skill-extractor Dan Guido 2026-01-18 19:17:10 -05:00
  • 7376c0dbc5 Add humanizer plugin for removing AI writing patterns Dan Guido 2026-01-18 21:24:21 -05:00
  • 119e23e7d3 feat: add skill discoverability for OpenSkills and other agents feat/skill-discoverability Dan Guido 2026-01-18 12:10:11 -05:00
  • fd46c1caa7 Bump actions/checkout from 4.2.2 to 6.0.1 in the all group (#11) dependabot[bot] 2026-01-16 15:43:37 -05:00
  • fd367ad81b ci: add lint enforcement with ruff, shellcheck, and shfmt (#10) Dan Guido 2026-01-16 15:13:46 -05:00
  • abe80a6d6f fix(burpsuite-project-parser): add cross-platform default paths (#9) Dan 2026-01-16 10:53:14 -08:00
  • 219ee11896 Clarify documentation requirement for Semgrep rules (#6) ahpaleus 2026-01-15 16:50:20 +01:00
  • 751a8f6b31 Harden validate workflow with explicit permissions (#5) Dan Guido 2026-01-14 23:46:02 -05:00
  • 67eeb40bbe Add trophy case for bugs found using skills (#4) Dan Guido 2026-01-14 21:00:42 -05:00
  • 4f5139d01d Add static-analysis plugin from internal repo (#3) Dan Guido 2026-01-14 19:11:03 -05:00
  • fee47e2a68 Bump actions/checkout from 4.2.2 to 6.0.1 in the all group (#1) dependabot[bot] 2026-01-14 16:04:14 -05:00
  • 695119c312 Initial release of Trail of Bits Skills Marketplace Dan Guido 2026-01-14 15:24:03 -05:00