Sep 23, 2026
Trail of Bits Ships a 44-Plugin Security Marketplace for Claude Code
A 7k-star plugin marketplace from the Trail of Bits security firm — code auditing, verification, reverse engineering, and development plugins loadable into Claude Code or Codex from one marketplace.
Security review is where general-purpose agents drift the most — they hallucinate vulnerability classes and miss language-specific pitfalls. trailofbits/skills is a 7k-star plugin marketplace from Trail of Bits, the security research firm, packaging its audit workflows into 44 installable plugins for Claude Code — and Codex can load the same marketplace through its Claude marketplace compatibility.
Why This Skill Matters
The README organizes the catalog into nine categories: Smart Contract Security, Code Auditing, Malware Analysis, Verification, Reverse Engineering, Mobile Security, Development, Team Management, and Tooling. These are named methodologies, not prompt stubs. rust-review covers the safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and the async runtime, with SARIF output. fp-check runs systematic false-positive verification with mandatory gate reviews. differential-review does security-focused review of code changes with git history analysis.
The results are real: the repo's trophy case credits constant-time-analysis with finding a timing side-channel in ML-DSA signing, filed upstream as RustCrypto/signatures PR #1144.
Installation
Add the marketplace to Claude Code, then browse:
/plugin marketplace add trailofbits/skills
/plugin menu
For Codex, the README documents a direct path:
codex plugin marketplace add trailofbits/skills
codex plugin list
codex plugin add <plugin-name>@trailofbits
For local development you can add the marketplace from a parent directory of a clone — the README's example uses /plugins marketplace add ./skills from the folder containing the repo.
Real Workflow: Security-Review a Rust Crate
- Install the matching plugin from the marketplace menu — for this task,
rust-review. - Point your agent at the code and name the review scope:
Review the crates in this workspace for memory safety and concurrency issues.
Use the rust-review skill and report findings in SARIF.
- Work through the findings with the follow-up plugins.
variant-analysissearches the rest of the codebase for similar vulnerabilities;post-patch-validationchecks a fix for missed variants and regressions with reproducible failures. - Before you report anything upstream, run the false-positive discipline:
fp-checkexists precisely to verify candidates with mandatory gate reviews, so you do not ship a hallucinated bug to a maintainer.
The same shape works elsewhere: yara-authoring for detection rules, supply-chain-risk-auditor for npm, PyPI, and Go dependency risk, semgrep-rule-variant-creator to port existing Semgrep rules to a new target language with test-driven validation.
Tips
building-secure-contractsbundles vulnerability scanners for 6 blockchains and 5 development guideline assistants — the README's own numbers — if smart contracts are your surface.github-triagemerges ready bot/approved PRs and reviews unreviewed ones via subagents, which pairs well with the security plugins in a maintenance window.- The marketplace doubles as a general development kit:
modern-pythoncovers uv, ruff, and pytest;open-sourcingprepares a repository for public release with secrets hygiene and licensing checks. - Contributions follow
AGENTS.mdguidelines, and the repo asks you to runmake checkbefore pushing — most of CI runs locally that way.
When Not to Use This
The plugins encode security-audit methodology; they assume you can act on findings — patching, disclosure, and severity calls stay with you. Licensing is CC BY-SA 4.0 rather than a permissive code license, which matters if you redistribute modified skill text. And for a quick one-off lint of a small script, a single targeted plugin from the menu beats loading the whole catalog.
See the leaderboard for more skills.