Security Skills Integration
Trail of Bits security skills integration guide for comprehensive vulnerability detection and secure development.
Prerequisites
- Claude Code CLI installed and authenticated
- Python 3.11+ (for skills that require Python)
- Git (for version control operations)
Step 1: Add the Trail of Bits Marketplace
/plugin marketplace add trailofbits/skills
Step 2: Install Core Security Skills
Essential Security Review Skills
| Skill | Purpose | Command |
|---|---|---|
| Audit Context Building | Deep line-by-line analysis | /plugin install trailofbits/skills/plugins/audit-context-building |
| Differential Review | Risk-based PR review | /plugin install trailofbits/skills/plugins/differential-review |
| Variant Analysis | Find similar vulnerabilities | /plugin install trailofbits/skills/plugins/variant-analysis |
| Fix Review | Validate security patches | /plugin install trailofbits/skills/plugins/fix-review |
Static Analysis & Detection
| Skill | Purpose | Command |
|---|---|---|
| Static Analysis | CodeQL, Semgrep, SARIF | /plugin install trailofbits/skills/plugins/static-analysis |
| Semgrep Rule Creator | Custom detection rules | /plugin install trailofbits/skills/plugins/semgrep-rule-creator |
| Insecure Defaults | Dangerous fail-open configs | /plugin install trailofbits/skills/plugins/insecure-defaults |
Specialized Security
| Skill | Purpose | Command |
|---|---|---|
| Constant-Time Analysis | Timing side-channels | /plugin install trailofbits/skills/plugins/constant-time-analysis |
| Property-Based Testing | Systematic testing | /plugin install trailofbits/skills/plugins/property-based-testing |
Step 3: Verify Installation
/plugin menu # List installed plugins
/skills # List available skills