Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
| Date | Stars |
|---|---|
| 2026-07-31 | 6364 |
| 2026-08-02 | 6364 |
| 2026-08-06 | 6364 |
Today
— stars today
This week
— stars this week
This month
— stars this month
Momentum
0.0
growth rate 0.00%/day
# Trail of Bits Skills Marketplace A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility. > Also see: [claude-code-config](https://github.com/trailofbits/claude-code-config) · [skills-curated](https://github.com/trailofbits/skills-curated) · [claude-code-devcontainer](https://github.com/trailofbits/claude-code-devcontainer) · [dropkit](https://github.com/trailofbits/dropkit) ## Installation ### Claude Code Marketplace ``` /plugin marketplace add trailofbits/skills ``` ### Browse and Install Plugins ``` /plugin menu ``` ### Codex Codex supports Claude plugin marketplaces directly, so this repository does not need Codex-specific sidecar metadata. Install the marketplace with: ```sh codex plugin marketplace add trailofbits/skills codex plugin list codex plugin add <plugin-name>@trailofbits ``` ### Local Development To add the marketplace locally (e.g., for testing or development), navigate to the **parent directory** of this repository: ``` cd /path/to/parent # e.g., if repo is at ~/projects/skills, be in ~/projects /plugins marketplace add ./skills ``` ## Available Plugins ### Smart Contract Security | Plugin | Description | |--------|-------------| | [building-secure-contracts](plugins/building-secure-contracts/) | Smart contract security toolkit with vulnerability scanners for 6 blockchains | | [entry-point-analyzer](plugins/entry-point-analyzer/) | Identify state-changing entry points in smart contracts for security auditing | ### Code Auditing | Plugin | Description | |--------|-------------| | [agentic-actions-auditor](plugins/agentic-actions-auditor/) | Audit GitHub Actions workflows for AI agent security vulnerabilities | | [audit-context-building](plugins/audit-context-building/) | Build deep architectural context through ultra-granular code analysis | | [burpsuite-project-parser](plugins/burpsuite-project-parser/) | Search and extract data from Burp Suite project files | | [c-review](plugins/c-review/) | Comprehensive C/C++ security review with clustered parallel workers and SARIF output | | [differential-review](plugins/differential-review/) | Security-focused differential review of code changes with git history analysis | | [dimensional-analysis](plugins/dimensional-analysis/) | Annotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs | | [fp-check](plugins/fp-check/) | Systematic false positive verification for security bug analysis with mandatory gate reviews | | [insecure-defaults](plugins/insecure-defaults/) | Detect insecure default configurations, hardcoded credentials, and fail-open security patterns | | [rust-review](plugins/rust-review/) | Comprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and async runtime with SARIF output | | [semgrep-rule-creator](plugins/semgrep-rule-creator/) | Create and refine Semgrep rules for custom vulnerability detection | | [semgrep-rule-variant-creator](plugins/semgrep-rule-variant-creator/) | Port existing Semgrep rules to new target languages with test-driven validation | | [sharp-edges](plugins/sharp-edges/) | Identify error-prone APIs, dangerous configurations, and footgun designs | | [static-analysis](plugins/static-analysis/) | Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing | | [supply-chain-risk-auditor](plugins/supply-chain-risk-auditor/) | Audit supply-chain threat landscape of project dependencies | | [testing-handbook-skills](plugins/testing-handbook-skills/) | Skills from the [Testing Handbook](https://appsec.guide): fuzzers, static analysis, sanitizers, coverage | | [trailmark](plugins/trailmark/) | Code graph analysis, bounded subagent context slicing, Mermaid diagrams, mutation testing triage, and protocol verification | | [variant-analysis](plugins/variant-analys
Excerpt of 8,856 characters
Read on GitHubDan Guido · Trail of Bits · United States
53
9
9
9
6
@trailofbits
6
4
Benjamin Samuels · Trail of Bits
3
3
Jay Little
2
Evan Sultanik · @trailofbits · United States
2
2
Jonathan Hefner · United States
1
Leon.C
1
1
Lixin2026
1
1
1
Artem Dinaburg
1
1
Would you bet a product on this? Bounded 0–100 and slow moving.
matched fp:8ad5919013f4b4db, llm:Repository description: 'Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows'; topics: agent-skills
matched fp:8ad5919013f4b4db, llm:Repository description: 'Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows'; topics: agent-skills
matched fp:8ad5919013f4b4db, llm:Repository description: 'Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows'; topics: agent-skills