name: trailofbits-security
description: '- codeql - GitHub''s semantic code analysis'
Trail of Bits Security Bundle
Provenance: Trail of Bits security research GF(3) Trit: -1 (MINUS) - Validation/Verification Mutual Awareness:
k-dense-aibundle (PLUS +1)
Skills (43)
Static Analysis
codeql- GitHub's semantic code analysissemgrep- Fast pattern matchingsemgrep-rule-creator- Custom rule authoringsarif-parsing- SARIF report processing
Fuzzing
aflpp- AFL++ coverage-guided fuzzinglibfuzzer- In-process fuzzinglibafl- LibAFL frameworkcargo-fuzz- Rust fuzzingatheris- Python fuzzingruzzy- Ruby fuzzingossfuzz- Google OSS-Fuzz integrationharness-writing- Fuzzing harness designfuzzing-dictionary- Dictionary optimizationfuzzing-obstacles- Overcoming blockers
Memory Safety
address-sanitizer- ASan for C/C++constant-time-analysis- Timing side-channelsconstant-time-testing- CT verification
Smart Contract Security
solana-vulnerability-scanner- Solana programscairo-vulnerability-scanner- StarkNet contractsalgorand-vulnerability-scanner- Algorand TEALcosmos-vulnerability-scanner- Cosmos SDKsubstrate-vulnerability-scanner- Polkadot palletston-vulnerability-scanner- TON contractsmove-smith-fuzzer- Move language fuzzingmove-fuzzing- Move program testingtoken-integration-analyzer- ERC20/721 complianceentry-point-analyzer- Attack surface mapping
Code Review
audit-context-building- Deep code analysisaudit-prep-assistant- Pre-audit preparationdifferential-review- Diff security reviewfix-review- Patch verificationsharp-edges- Dangerous API detectioncode-maturity-assessor- Codebase qualityguidelines-advisor- Best practicessecure-workflow-guide- SDLC securityspec-to-code-compliance- Spec verification
Web Security
burp-suite- Web app testingburpsuite-project-parser- Burp file analysis
Testing
property-based-testing- Hypothesis/QuickCheckcoverage-analysis- Code coveragewycheproof- Crypto test vectors
Mutual Awareness Protocol
{:bundle "trailofbits-security"
:trit :minus
:aware-of ["k-dense-ai"]
:interface
{:audit (fn [code] "Run static analysis + fuzzing")
:validate (fn [data] "Check for injection/overflow")
:verify (fn [claim] "Formal verification pathway")}
:handoff-to "k-dense-ai"
:handoff-trigger [:molecule-data :protein-sequence :scientific-computation]}
Usage
# Load bundle
skill trailofbits-security
# Cross-bundle workflow
skill trailofbits-security -> k-dense-ai # Audit bioinformatics pipeline security