agentic-actions-audito…
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. Reviews are performed by an installed PR-review skill (default: pr-review-toolkit's review-pr). Use
$ npx -y skills add trailofbits/skills --skill pr-improver --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/pr-improverContext preview
The summary Claude sees to decide when to auto-load this skill.
Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. Reviews are performed by an installed PR-review skill (default: pr-review-toolkit's review-pr). Use
name: pr-improver
description: "Runs an autonomous review-and-fix improvement loop over the current branch's changes until a PR review comes back clean, scoped mechanically to the directories the branch touched. Reviews are performed by an installed PR-review skill (default: pr-review-toolkit's review-pr). Use to fix review findings on a branch before opening or updating a pull request ('clean up this branch', 'fix this PR until review passes', 'run review-and-fix on my changes'). NOT for a one-time review — run the PR-review skill directly."
argument-hint: "[BASE_BRANCH] [--reviewer <skill-or-agent>] [--max-rounds N]"
allowed-tools: Bash Glob Read TaskOutput TaskStop WorkflowImprove the current branch by running `/code-improver:improve` — a dynamic workflow that loops a PR reviewer and a fixer subagent over the branch's changes until a review reports zero critical/major findings. The loop, its ledger, and its guards live in the workflow; this skill derives the scope from the branch diff and relays the outcome.
The user provided: `$ARGUMENTS` (if empty, take base branch and preferences from the conversation).
1. Repo root: `git rev-parse --show-toplevel`. Fail loudly outside a repository. 2. Base: the argument if given, else the repository's default branch (`git symbolic-ref refs/remotes/origin/HEAD` → its short name, falling back to `main`). Refuse to run when the current branch IS the base — there is no diff to improve. 3. Changed files: `git diff --name-only <base>...HEAD`. If empty, say so and stop. 4. Scope: the changed files' **directories**, widened — per-file globs are too tight (PR fixes legitimately add tests next to changed code). Map each changed file to its repo-relative directory glob `<dir>/**` (`**` at the repo root only if files at the root changed), then deduplicate and drop globs covered by another.
The loop is the dynamic workflow `workflows/improve.js` in this plugin. Launch it by path: `scriptPath` takes a resolved absolute path, and the Workflow tool's `name` resolves built-in and project workflows, so a marketplace-installed one may not answer to `code-improver:improve`. Try in order, first hit wins — the home directories come before `.` so an installed copy beats a checkout of this marketplace:
1. `Bash: ls -d -- "${CLAUDE_PLUGIN_ROOT}/workflows/improve.js"` 2. `Bash: ls -d -- "${CODEX_PLUGIN_ROOT}/workflows/improve.js"` (if that variable is set instead) 3. `Bash: find ~/.claude ~/.codex . -maxdepth 7 -path '*/code-improver/workflows/improve.js' -print -quit 2>/dev/null`
Use the path exactly as printed. Its plugin directory — the path with `/workflows/improve.js` removed — is `pluginRoot`. If all three come back empty, try `{name: "code-improver:improve"}` once; if that is unavailable too, stop and say the loop could not be located. Do not assemble a path by hand and do not improvise the loop.
Run it with the Workflow tool, `{scriptPath: "<the path from step 2>", args: {...}}`:
{
"target": "<repo root>",
"reviewer": {
"kind": "skill",
"name": "pr-review-toolkit:review-pr",
"notes": "Review the working tree's changes against <base> as a pull request: correctness, tests, error handling, and the review dimensions the skill prescribes."
},
"scope": ["<derived-dir-glob>/**"],
"pluginRoot": "<the plugin directory from step 2>",
"maxRounds": 5
}names a different PR reviewer (skill or agent), use it, with kind set accordingly.
through to the workflow name — the workflow then searches for itself.
plugin, narration strip and docs pass on.
The loop's baseline snapshot is the tree at loop start — its scope guard protects the branch's uncommitted work; the PR's own commits are what the reviewer reviews.
The workflow runs in the background and needs no babysitting: it reviews, fixes, re-reviews, checks scope after every fix round, and can only complete on a clean review. It never commits; all changes stay in the working tree.
**If the Workflow tool is unavailable or denied, stop and say so.** Do not improvise the loop inline with direct edits — the ledger, scope guard, and escalation guarantees live in the workflow, and an inline imitation has none of them.
**If the result is `halted: "reviewer-unavailable"`, relay it and stop.** The reviewer is not installed in this session; tell the user which plugin provides it (the default needs `pr-review-toolkit`) and re-run after installing. Do not review the branch yourself.
**Do not end your turn while the loop is running.** The Workflow tool returns a task id immediately; the result comes later. In an interactive session the completion notification re-invokes you — wait for it. In a non-interactive run (scripted, CI, eval) there is no later turn: stopping abandons the loop mid-round, so after launching, poll the task (TaskOutput with the returned task id, or sleep-and-recheck) until it completes, then relay the result. A session that answers "the loop is running, I'll report later" has lost the run.
The workflow returns a structured result. Report it honestly — the distinctions matter:
Report rounds used, remaining minor findings (`open_minor_count`), and the artifact paths (`ledger_path`, `metrics`).
issues. Say plainly: **capped, NOT conve
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an…
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access…
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems,…
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…