mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
trailmark
Source code graph analysis for security auditing. Parses code into queryable graphs of functions, classes, and calls, then uses that structure for diagram generation, mutation testing triage, protocol verification, and differential review.
These skills target Trailmark 0.2.x. Prefer --language auto,
trailmark.parse.detect_languages(), and QueryEngine.preanalysis()
instead of older 0.1.x-era manual language detection workflows.
Prerequisites
Trailmark (source) must be installed:
uv pip install trailmark
Skills
| Skill | Description |
|---|---|
trailmark |
Build and query multi-language code graphs with pre-analysis passes (blast radius, taint, privilege boundaries, entrypoints) |
diagramming-code |
Generate Mermaid diagrams from code graphs (call graphs, class hierarchies, complexity heatmaps, data flow) |
crypto-protocol-diagram |
Extract protocol message flow from source code or specs (RFC, ProVerif, Tamarin) into sequence diagrams |
genotoxic |
Triage mutation testing results using graph analysis — classify survived mutants as false positives, missing tests, or fuzzing targets |
vector-forge |
Mutation-driven test vector generation — find coverage gaps via mutation testing, then generate Wycheproof-style vectors that close them |
graph-evolution |
Compare code graphs at two snapshots to surface security-relevant structural changes text diffs miss |
mermaid-to-proverif |
Convert Mermaid sequence diagrams into ProVerif formal verification models |
audit-augmentation |
Project SARIF and weAudit findings onto code graphs as annotations and subgraphs |
trailmark-summary |
Quick structural overview (auto-detected languages, entry points, dependencies) for vivisect/galvanize |
trailmark-structural |
Full structural analysis with all pre-analysis passes (blast radius, taint, privilege boundaries, complexity) |
Directory Structure
trailmark/
├── .claude-plugin/
│ └── plugin.json
├── README.md
└── skills/
├── trailmark/ # Core graph querying
├── diagramming-code/ # Mermaid diagram generation
│ └── scripts/diagram.py
├── crypto-protocol-diagram/ # Protocol flow extraction
│ └── examples/
├── genotoxic/ # Mutation testing triage
├── vector-forge/ # Mutation-driven test vector generation
│ └── references/
├── graph-evolution/ # Structural diff
│ └── scripts/graph_diff.py
├── mermaid-to-proverif/ # Sequence diagram → ProVerif
│ └── examples/
├── audit-augmentation/ # SARIF/weAudit integration
├── trailmark-summary/ # Quick overview for vivisect/galvanize
└── trailmark-structural/ # Full structural analysis
Related Skills
| Skill | Use For |
|---|---|
mutation-testing |
Guidance for running mutation frameworks (mewt, muton) — use before genotoxic for triage |
differential-review |
Text-level security diff review — complements graph-evolution's structural analysis |
audit-context-building |
Deep architectural context before vulnerability hunting |