Files
Lixin2026 d5fe2e6a78 feat(codex): add UI metadata for skills (#175)
* feat(codex): add skill UI metadata

* Use official Trail of Bits logo

* fix: resolve code review findings for PR #175

Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.

P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
  all 38 plugins with skills and point every openai.yaml at
  ../../assets/trail-of-bits-mark.svg (the supported plugin-level
  shared asset pattern). Icons now resolve for marketplace
  installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
  openai.yaml resolved nowhere (.codex/skills is not a Codex
  discovery root) and PR #173 removes the whole .codex/ tree

P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
  marketplace.json so installed clients pick up the metadata

Verified:
- Static check replicating Codex's resolution algorithm: all 73
  yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
  resolved iconSmall/iconLarge and brand_color #D83A34
  (claude-in-chrome-troubleshooting fails to load on main due to
  a pre-existing 64-char qualified-name limit, fixed by #173's
  rename; zeroize-audit's manifest mcpServers object is likewise
  a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
  pass

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(codex): use skill-local icon assets

---------

Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 12:28:41 -04:00
..

Entry Point Analyzer

A Claude skill for systematically identifying state-changing entry points in smart contract codebases to guide security audits.

Purpose

When auditing smart contracts, examining each file or function individually is inefficient. What auditors need is to start from entry points—the externally callable functions that represent the attack surface. This skill automates the identification and classification of state-changing entry points, excluding view/pure/read-only functions that cannot directly cause loss of funds or state corruption.

Supported Languages

Language File Extensions Framework Support
Solidity .sol OpenZeppelin, custom modifiers
Vyper .vy Native patterns
Solana .rs Anchor, Native
Move .move Aptos, Sui
TON .fc, .func, .tact FunC, Tact
CosmWasm .rs cw-ownable, cw-controllers

Access Classifications

The skill categorizes entry points into four levels:

  1. Public (Unrestricted) — Callable by anyone; highest audit priority
  2. Role-Restricted — Limited to specific roles (admin, governance, guardian, etc.)
  3. Review Required — Ambiguous access patterns needing manual verification
  4. Contract-Only — Internal integration points (callbacks, hooks)

Output

Generates a structured markdown report with:

  • Summary table of entry point counts by category
  • Detailed tables for each access level
  • Function signatures with file:line references
  • Restriction patterns and role assignments
  • List of analyzed files

Usage

Trigger the skill with requests like:

  • "Analyze the entry points in this codebase"
  • "Find all external functions and access levels"
  • "List audit flows for src/core/"
  • "What privileged operations exist in this project?"

Directory Filtering

Specify a subdirectory to limit scope:

  • "Analyze only src/core/"
  • "Find entry points in contracts/protocol/"

Role Detection

The skill infers roles from common patterns:

Pattern Detected Role
onlyOwner, msg.sender == owner Owner
onlyAdmin, ADMIN_ROLE Admin
onlyGovernance, governance Governance
onlyGuardian, onlyPauser Guardian
onlyKeeper, onlyRelayer Keeper/Relayer
onlyStrategy, strategist Strategist
Dynamic checks (authorized[msg.sender]) Review Required

Installation

/plugin install trailofbits/skills/plugins/entry-point-analyzer

License

See LICENSE.txt for terms.