mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Spec-to-Code Compliance
Specification-to-code compliance checker for blockchain audits with evidence-based alignment analysis.
Author: Omar Inuwa
When to Use
Use this skill when you need to:
- Verify that code implements exactly what documentation specifies
- Find gaps between intended behavior and actual implementation
- Audit smart contracts against whitepapers or design documents
- Identify undocumented code behavior or unimplemented spec claims
What It Does
This skill performs deterministic, evidence-based alignment between specifications and code:
- Documentation Discovery - Finds all spec sources (whitepapers, READMEs, design notes)
- Spec Intent Extraction - Normalizes all intended behavior into structured format
- Code Behavior Analysis - Line-by-line semantic analysis of actual implementation
- Alignment Comparison - Maps spec items to code with match types and confidence scores
- Divergence Classification - Categorizes misalignments by severity (Critical/High/Medium/Low)
Key Principle
Zero speculation. Every claim must be backed by:
- Exact quotes from documentation (section/title)
- Specific code references (file + line numbers)
- Confidence scores (0-1) for all mappings
Installation
/plugin install trailofbits/skills/plugins/spec-to-code-compliance
Phases
- Documentation Discovery - Identify all spec sources
- Format Normalization - Create clean spec corpus
- Spec Intent IR - Extract all intended behavior
- Code Behavior IR - Line-by-line code analysis
- Alignment IR - Compare spec to code
- Divergence Classification - Categorize misalignments
- Final Report - Generate audit-grade compliance report
Match Types
full_match- Code exactly implements specpartial_match- Incomplete implementationmismatch- Spec says X, code does Ymissing_in_code- Spec claim not implementedcode_stronger_than_spec- Code adds behaviorcode_weaker_than_spec- Code misses requirements
Anti-Hallucination Rules
- If spec is silent: classify as UNDOCUMENTED
- If code adds behavior: classify as UNDOCUMENTED CODE PATH
- If unclear: classify as AMBIGUOUS
- Every claim must quote original text or line numbers
Related Skills
context-building- Deep code understandingissue-writer- Format compliance gaps as findings