/ct-check
Detects timing side-channels in cryptographic code
$ npx -y skills add trailofbits/skills --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ct-check
Context preview
What this command does when you run it.
Detects timing side-channels in cryptographic code
Command definition
ct-check.mdname: trailofbits:ct-check description: Detects timing side-channels in cryptographic code argument-hint: "<source-file> [--warnings] [--json] [--arch <arch>]" allowed-tools: Bash Read Grep Glob
Check Constant-Time Properties
**Arguments:** $ARGUMENTS
Parse arguments: 1. **Source file** (required): Path to source file to analyze 2. **Flags** (optional): `--warnings`, `--json`, `--arch <arch>`, `--opt-level <level>`, `--func <pattern>`
Invoke the `constant-time-analysis` skill with these arguments for the full workflow.
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Other commands on trailofbits-skills.
- /burp-search
Searches Burp Suite project files for security analysis
Open command - /diff-review
Performs security-focused differential review of code changes
Open command - /entry-points
Identifies state-changing entry points in smart contracts
Open command - /scan-apk
Scans Android APKs for Firebase security misconfigurations
Open command - /audit
Audit a file, directory, or whole repo for insecure default configuration: fallback secrets, default credentials, fail-open switches, weak crypto, permissive access, debug leakage. Parallel sweeps collect candidates, then a refuting verifier traces each one to the security
Open command - /semgrep-rule
Creates Semgrep rules with test-first methodology
Open command

