mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Dimensional Analysis Plugin
Add dimensional annotations to codebases and detect dimensional bugs. Uses an annotation format inspired by Reserve Protocol's Solidity conventions, but applicable to any language or protocol performing numeric arithmetic with mixed units, precisions, or scaling factors.
Overview
This plugin runs one automatic workflow:
- Discover the dimensional vocabulary in your codebase (tokens, shares, prices, etc.)
- Annotate your code with dimensional comments like
D18{tok},D27{UoA/tok} - Propagate dimensions through arithmetic and call paths
- Validate dimensional consistency and detect bugs
Annotation Format
Based on Reserve Protocol's format (shown here in Solidity, but adaptable to any language):
// State variables
uint256 public tvlFee; // D18{1/s} demurrage fee on AUM
uint256 public lastPoke; // {s}
// Struct fields
struct RebalanceLimits {
uint256 low; // D18{BU/share} (0, 1e27]
uint256 spot; // D18{BU/share} (0, 1e27]
uint256 high; // D18{BU/share} (0, 1e27]
}
// Function parameters (NatSpec)
/// @param weights D27{tok/BU} Basket weight ranges
/// @param prices D27{UoA/tok} Prices for each token
/// @return price D27{buyTok/sellTok}
// Inline arithmetic
// D27{buyTok/sellTok} = D27{UoA/sellTok} * D27 / D27{UoA/buyTok}
uint256 startPrice = Math.mulDiv(sellPrices.high, D27, buyPrices.low);
Usage
The skill always executes in full-auto mode. Any supplied mode argument is ignored.
Workflow orchestration for all four phases lives in skills/dimensional-analysis/SKILL.md.
Automatic Behavior
- Uses existing
DIMENSIONAL_UNITS.mdif present; otherwise auto-generates and saves it - Persists
DIMENSIONAL_SCOPE.jsonas a source-of-truth manifest for large repos - Applies annotations directly without approval gates
- Uses best-guess inference for uncertainties and flags them in output
- Reports results in a single summary at the end
Coverage Guarantees
- All in-scope arithmetic files from scanner output are required scope (CRITICAL/HIGH/MEDIUM/LOW)
- Discoverer narrowing (for vocabulary speed) does not reduce annotation or validation scope
- Each in-scope file must be marked as completed in Phase 2, Phase 3, and Phase 4 before finalization
Agents
| Agent | Purpose |
|---|---|
arithmetic-scanner |
Scans repo for files with dimensional arithmetic to scope discovery |
dimension-discoverer |
Discovers dimensional vocabulary from naming, interfaces, and patterns |
dimension-annotator |
Adds dimensional annotations at anchor points (comments only) |
dimension-propagator |
Propagates dimensional annotations through arithmetic and call chains, reporting mismatches |
dimension-validator |
Validates dimensional consistency and detects bugs |
Requirements
- A codebase performing numeric arithmetic with mixed units, precisions, or scaling factors
- Most effective for DeFi protocols (Solidity, Rust/Anchor, CosmWasm, etc.) but works with any language
- Optional for Solidity projects: slither-mcp for enhanced static analysis
References
See the references/ directory for:
dimension-algebra.md- Rules for dimensional arithmeticcommon-dimensions.md- DeFi dimension vocabularybug-patterns.md- Dimensional bug patterns with examplesannotate.md- Full annotated protocol examples (ERC-4626, AMM, Lending)
Author
Coriolan Pinhas & Benjamin Samuels - Trail of Bits