agentic-actions-audito…
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings ledger, escalation when fixes stop converging, and a mechanical scope guard. Reviews are performed by the plugin-dev skill-reviewer agent. Use
$ npx -y skills add trailofbits/skills --skill skill-improver --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/skill-improverContext preview
The summary Claude sees to decide when to auto-load this skill.
Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings ledger, escalation when fixes stop converging, and a mechanical scope guard. Reviews are performed by the plugin-dev skill-reviewer agent. Use
name: skill-improver
description: "Runs an autonomous review-and-fix improvement loop over a Claude Code skill until a review comes back clean, with a cross-round findings ledger, escalation when fixes stop converging, and a mechanical scope guard. Reviews are performed by the plugin-dev skill-reviewer agent. Use to fix skill quality issues, iteratively refine a skill, or resume a loop after an escalation ('fix my skill', 'improve this skill until it passes review', 'skill improvement loop'). NOT for a one-time review — use the plugin-dev skill-reviewer agent directly."
argument-hint: "<SKILL_NAME_OR_PATH> [--max-rounds N]"
allowed-tools: Bash Glob Read TaskOutput TaskStop WorkflowImprove a Claude Code skill by running `/code-improver:improve` — a dynamic workflow that loops a reviewer and a fixer subagent until a review reports zero critical/major findings, then strips its own residue. This entry point wires the loop to the `plugin-dev:skill-reviewer` agent, so the **plugin-dev plugin must be installed** (marketplace `claude-plugins-official`). The loop, its ledger, and its guards live in the workflow; this skill resolves the target and relays the outcome.
The user provided: `$ARGUMENTS` (if empty, take the target skill from the conversation).
1. If the input ends with `/SKILL.md` and the file exists, use its directory 2. If the input is a directory containing `SKILL.md`, use that path 3. Otherwise `Glob(pattern="**/SKILL.md")` and filter by skill name or path substring:
The loop is the dynamic workflow `workflows/improve.js` in this plugin. Launch it by path: `scriptPath` takes a resolved absolute path, and the Workflow tool's `name` resolves built-in and project workflows, so a marketplace-installed one may not answer to `code-improver:improve`. Try in order, first hit wins — the home directories come before `.` so an installed copy beats a checkout of this marketplace:
1. `Bash: ls -d -- "${CLAUDE_PLUGIN_ROOT}/workflows/improve.js"` 2. `Bash: ls -d -- "${CODEX_PLUGIN_ROOT}/workflows/improve.js"` (if that variable is set instead) 3. `Bash: find ~/.claude ~/.codex . -maxdepth 7 -path '*/code-improver/workflows/improve.js' -print -quit 2>/dev/null`
Use the path exactly as printed. Its plugin directory — the path with `/workflows/improve.js` removed — is `pluginRoot`. If all three come back empty, try `{name: "code-improver:improve"}` once; if that is unavailable too, stop and say the loop could not be located. Do not assemble a path by hand and do not improvise the loop.
Run it with the Workflow tool, `{scriptPath: "<the path from step 2>", args: {...}}`:
{
"target": "<resolved absolute path>",
"reviewer": {
"kind": "agent",
"name": "plugin-dev:skill-reviewer",
"notes": "The target is a Claude Code skill directory; review it as a skill (frontmatter, triggering description, progressive disclosure, referenced files)."
},
"pluginRoot": "<the plugin directory from step 2>",
"maxRounds": 5
}through to the workflow name — the workflow then searches for itself.
touch; by default the workflow scopes to the skill's plugin directory.
The workflow runs in the background and needs no babysitting: it reviews, fixes, re-reviews, checks scope after every fix round, and can only complete on a clean review. It never commits; all changes stay in the working tree.
**If the Workflow tool is unavailable or denied, stop and say so.** Do not improvise the loop inline with direct edits — the ledger, scope guard, and escalation guarantees live in the workflow, and an inline imitation has none of them (observed failure: an inline fallback "fixed" a finding by weakening the documented guarantee, exactly what the loop exists to prevent).
**If the result is `halted: "reviewer-unavailable"`, relay it and stop.** The reviewer this skill names is not installed; tell the user to install the `plugin-dev` plugin from the `claude-plugins-official` marketplace and re-run. Do not review the skill yourself.
**Do not end your turn while the loop is running.** The Workflow tool returns a task id immediately; the result comes later. In an interactive session the completion notification re-invokes you — wait for it. In a non-interactive run (scripted, CI, eval) there is no later turn: stopping abandons the loop mid-round, so after launching, poll the task (TaskOutput with the returned task id, or sleep-and-recheck) until it completes, then relay the result. A session that answers "the loop is running, I'll report later" has lost the run.
The workflow returns a structured result. Report it honestly — the distinctions matter:
Report rounds used, remaining minor findings (`open_minor_count`), and the artifact paths (`ledger_path`, `metrics`).
issues. Say plainly: **capped, NOT converged**, and list `open_blocking`. Do not present this as success.
non-decreasing counts, or a fix relocating a problem). Relay the escalation message and finding ids to the user: this needs a design decision, not more rounds.
unavailable reviewer, or a finalize pass whos
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an…
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access…
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems,…
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…