LaunchKit · 2026
Back to skills
Trail of Bits

Trail of Bits

21 skills available

1
ask-questions-if-underspecified

Guides an AI agent to pause and ask clarifying questions when a request has ambiguous objectives, unclear scope, or missing constraints.

2
building-secure-contracts

A collection of 11 skills for smart contract security across Algorand, Cairo, Cosmos, Solana, Substrate, and TON.

3
culture-index

Interprets Culture Index behavioral assessments for individuals and teams.

4
audit-context-building

A structured analysis skill for the pre-audit phase of code review.

5
burpsuite-project-parser

Searches and extracts data from Burp Suite project files (.

6
differential-review

Runs security-focused differential reviews on PRs, commits, and diffs.

7
constant-time-analysis

Detects timing side-channel vulnerabilities in cryptographic code across 12 languages.

8
dwarf-expert

Adds deep knowledge of the DWARF debug format (versions 3-5) to an agent.

9
claude-in-chrome-troubleshooting

Diagnoses and fixes connectivity failures between the Claude in Chrome MCP extension and Claude Code CLI on macOS.

10
entry-point-analyzer

Analyzes smart contract codebases to map all state-changing entry points for security audits.

11
modern-python

Configures Python projects with uv, ruff, and ty — the modern replacements for pip, flake8/black, and mypy.

12
property-based-testing

Guides property-based testing across Python, JavaScript, Rust, and Solidity/Vyper.

13
insecure-defaults

Detects fail-open security vulnerabilities where applications run insecurely due to missing or weak configuration.

14
firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations by decompiling the app, extracting Firebase configuration, and actively testing endpoints for vulnerabilities.

15
semgrep-rule-creator

Creates custom Semgrep rules for detecting security vulnerabilities and code patterns.

16
semgrep-rule-variant-creator

Takes an existing Semgrep rule and ports it to one or more target languages.

17
sharp-edges

Evaluates whether APIs, configurations, and interfaces are resistant to developer misuse.

18
static-analysis

Static analysis toolkit combining CodeQL, Semgrep, and SARIF parsing for security vulnerability detection.

19
spec-to-code-compliance

Verifies that a smart contract codebase implements exactly what its specification documents describe.

20
testing-handbook-skills

A meta-skill that reads the Trail of Bits Application Security Testing Handbook and generates Claude Code skills from it.

21
variant-analysis

Variant analysis skill for finding similar vulnerabilities across a codebase after an initial bug is identified.