# trailofbits/skills: a Claude Code plugin marketplace for security review work

> Trail of Bits ships its audit tooling as Claude Code plugins, from Semgrep rule authoring to supply chain risk checks. The marketplace installs in two commands, and it is aimed at people already running AI agents over real code.

**trailofbits/skills** — Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

- Repository: https://github.com/trailofbits/skills
- Stars: 7,307 · Forks: 623
- Language: Python
- License: CC-BY-SA-4.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/trailofbits-skills

## What the Trail of Bits skills marketplace actually packages

This repository is not a scanner. It is a plugin marketplace: a directory of skills that extend an AI coding agent with instructions, workflows and helper scripts for security work. The README describes it as "a Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows." The audience is narrow and specific. It is for security engineers, auditors and developers who already run Claude Code or Codex against a real repository and want the agent to follow a repeatable procedure rather than invent one per session. The plugin list shows what that means in practice. There are smart contract plugins for six blockchains, code auditing plugins for C/C++, Rust and general static analysis, verification plugins covering mutation testing and property-based testing, and a malware analysis plugin for YARA rule authoring. The topics list on the repository is a single entry, agent-skills, which is an accurate summary of the scope.

## How a skill reaches the agent: marketplace metadata, then skill files

The mechanism is file-based, not a service. The repository root holds a .claude-plugin/ directory containing marketplace.json, which is the manifest the agent reads to discover what is available. Each plugin lives under plugins/ in its own directory, and the README's plugin table links directly to those paths, so a reader can inspect a plugin before installing it. Some skills also carry an agents/openai.yaml file. The README states that skills including that file need interface.display_name and interface.short_description inside it, because plugin metadata does not supply those fields. That detail matters for anyone publishing through a ChatGPT workspace: a missing field causes an import to fail, and the README says to sync the repository again after a metadata fix is published. There is no server component and no runtime dependency graph described. The agent loads the instruction files and follows them, which means the quality of the output depends on the quality of the prose and scripts in each plugin directory. That is the design trade-off worth naming: the repository is as good as its individual skills, and the README does not grade them.

## Installing trailofbits/skills in Claude Code, Codex or a workspace

Claude Code installs the marketplace with a slash command. The README gives this example, run inside Claude Code:

```bash
/plugin marketplace add trailofbits/skills
```

After that, the plugin menu lists what is available so you can browse and install individual plugins:

```bash
/plugin menu
```

Codex supports Claude plugin marketplaces directly, so the README states the repository needs no Codex-specific sidecar metadata. The three commands are:

```sh
codex plugin marketplace add trailofbits/skills
codex plugin list
codex plugin add <plugin-name>@trailofbits
```

The third command takes a plugin name from the README's table, for example static-analysis, followed by @trailofbits. For local development or testing, the README says to navigate to the parent directory of the repository, not the repository itself, and add it by relative path:

```bash
cd /path/to/parent
/plugins marketplace add ./skills
```

Note the path in that last example is /plugins, while the marketplace add command earlier in the README is /plugin. Copy both forms exactly as written rather than normalising them. For a ChatGPT workspace, the README points at .claude-plugin/marketplace.json for workspace imports.

## Where the repository's own checks stop

The Makefile is unusually candid about its limits, and that candour is worth reading before you rely on it. The check target is the default goal and runs validator self-tests, eval self-tests, lint, shell tests, bats, Python tests, JS tests and validation. After it passes, the Makefile prints that this is "most of CI, but not the loadability checks, the version-increment check, or the non-ruff pre-commit hooks." A green local run is therefore not the same signal as a green pipeline. The self-test targets exist because, in the authors' words, "a checker that has silently stopped matching reports a clean repo forever; that failure mode has shipped here more than once." The eval self-tests follow the same logic: an eval that has stopped discriminating reports a passing skill forever. Two constraints are easy to miss. The Makefile is marked .NOTPARALLEL, so the targets are not run concurrently. And RUFF_VERSION is pinned to 0.14.13, with a comment that it must match the ruff-pre-commit revision in .pre-commit-config.yaml, so bumping one without the other breaks the validator self-test assertion.

## The wrong tool for a CI gate

If what you need is a scanner that runs unattended in a pipeline and fails a build on a finding, this marketplace is the wrong shape. It delivers skills to an interactive agent. Several plugins wrap existing tools rather than implement detection themselves: static-analysis covers CodeQL, Semgrep and SARIF parsing, and semgrep-rule-creator produces and refines Semgrep rules rather than replacing Semgrep. The agent is in the loop, which is the point for review work and a liability for a gate that must run the same way every time. A second limitation is the licence. The repository is CC-BY-SA-4.0, a content licence written for prose and documentation, applied here to a tree that also contains Python and shell scripts under .github/scripts and the plugins. That is the licence the repository carries; whether it suits your distribution model is a question for your own counsel, not something this article can settle. Third, the README does not document rollback or uninstall steps for an added marketplace, so plan how you will remove a plugin before you add one.

## How this differs from a curated skill list

The closest comparison inside the same organisation is skills-curated, which the README links alongside claude-code-config, codex-config, claude-code-devcontainer, dropkit and coop. The difference is provenance and testing rather than topic. This repository is the marketplace with the plugin tree, the Makefile, the validator self-tests and the per-plugin eval harnesses. A curated list is a selection; this is a distribution point with checks attached. The practical consequence is that a plugin here arrives with an eval harness that the Makefile can exercise via eval-self-tests, discovered rather than listed so a new plugin's evals are covered the day they land. If you only want a reading list of prompts, the curated repository is lighter. If you want the validators, the self-tests and the plugin metadata format, you want this one.

## Maintenance, licence and upgrade cost

The last push was on 2026-09-16, six days before this article's reference point, and the repository is not archived. The Makefile's design tells you what upgrading costs. Because RUFF_VERSION must track the ruff-pre-commit revision, and because the validator self-test asserts that match, a routine dependency bump can fail the self-test rather than the lint step. The self-test targets run before validate deliberately, so a broken validator surfaces early instead of reporting a clean repository. No releases are listed for this repository, so there is no version number to pin against; you track the main branch. The licence is CC-BY-SA-4.0 as stated in the repository, and the LICENSE file is at the root. Nothing in the README describes a support commitment or a compatibility policy for the plugin metadata format.

## Conclusion

Adopt it if you already drive Claude Code or Codex over a codebase and want the agent to follow a defined review procedure instead of improvising one. Skip it if you need a standalone scanner with a CI exit code; several of these plugins wrap tools such as Semgrep and CodeQL rather than replacing them. Before trusting any plugin, open its directory under plugins/ and read the skill files, because that is where the actual instructions live. Then run make check from a clone to confirm the validators and eval harnesses still detect what they claim to detect.

## FAQ

### How do I install skills from trailofbits/skills in Claude Code?

Run /plugin marketplace add trailofbits/skills inside Claude Code, then /plugin menu to browse and install individual plugins. The README gives both commands in that order.

### How do I use trailofbits/skills in Codex?

Codex supports Claude plugin marketplaces directly, so the README gives three commands: codex plugin marketplace add trailofbits/skills, codex plugin list, and codex plugin add <plugin-name>@trailofbits. No Codex-specific sidecar metadata is needed.

### How do I install skills from trailofbits/skills in a ChatGPT workspace?

Use the repository's .claude-plugin/marketplace.json for the workspace import. Skills that include agents/openai.yaml also need interface.display_name and interface.short_description in that file, and after a metadata fix is published you sync the repository again to retry failed imports.

### How do I install trailofbits/skills in Codex from the command line?

The README lists codex plugin marketplace add trailofbits/skills, then codex plugin list, then codex plugin add <plugin-name>@trailofbits, where the plugin name comes from the README's plugin table.

### How do I use skills from trailofbits/skills in Claude?

Add the marketplace with /plugin marketplace add trailofbits/skills, then install the plugins you want from /plugin menu. The skills then run as part of your Claude Code session against the code you point it at.

## Sources

- [Issues](https://github.com/trailofbits/skills/issues)
- [License: CC-BY-SA-4.0](https://github.com/trailofbits/skills/blob/main/LICENSE)
- [README](https://github.com/trailofbits/skills/blob/main/README.md)
- [trailofbits/skills on GitHub](https://github.com/trailofbits/skills)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/trailofbits-skills
