agentic-actions-audito…
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly
$ npx -y skills add trailofbits/skills --skill trailmark-review-gate --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/trailmark-review-gateContext preview
The summary Claude sees to decide when to auto-load this skill.
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly
name: trailmark-review-gate description: "Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge." allowed-tools: - Bash - Read - Grep - Glob - Write
Apply deterministic security gate rules to Trailmark structural diff evidence. This skill does not replace line-level review. It produces a compact structural packet reviewers can cite while they inspect the code.
complexity signals
| Rationalization | Why It Is Wrong | Required Action | |---|---|---| | "The line diff is small, so no graph gate is needed" | Small changes can create new call paths | Compare before/after graphs | | "Graph gate passed, so the PR is secure" | The gate only checks structural regressions | Still perform line-level review | | "Trailmark failed, so pass the gate" | Tool failure is unknown risk, not success | Emit `UNKNOWN` | | "Tests pass, so removed validation is fine" | Tests may miss affected entrypoint paths | Review the removed path manually | | "Only new code matters" | Removed auth, validation, and callers can be higher risk than additions | Review removals and path changes |
Review Gate Progress: - [ ] Step 1: Resolve before/after inputs - [ ] Step 2: Build graph-evolution evidence - [ ] Step 3: Normalize structural changes - [ ] Step 4: Apply gate rules - [ ] Step 5: Emit review packet and actions
Accept two refs, a branch name, a commit range, or before/after directories. Do not check out branches unnecessarily. Prefer `git diff`, `git show`, and git worktrees, following the `graph-evolution` snapshot workflow.
Run `graph-evolution` or equivalent Trailmark before/after graph analysis. Both snapshots must run `engine.preanalysis()` so taint, privilege-boundary, blast-radius, complexity, and entrypoint signals are available.
Record Trailmark version and any feature probes. If graph construction fails, emit `UNKNOWN`.
Normalize evidence into:
Apply the rules in [references/gate-rules.md](references/gate-rules.md). Gate verdicts are:
| Verdict | Meaning | |---|---| | `FAIL` | A high-risk structural regression needs review before acceptance | | `WARN` | A meaningful graph change needs reviewer attention | | `PASS` | No configured structural gate fired | | `UNKNOWN` | Trailmark failed or evidence is too incomplete |
Write the packet using [references/output-format.md](references/output-format.md), then hand it to the branch reviewer. Use [references/review-integration.md](references/review-integration.md) when combining this packet with `differential-review` or another PR review process.
uncertainty affects the verdict.
A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an…
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access…
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems,…
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…