Sep 23, 2026

Trail of Bits Ships a 44-Plugin Security Marketplace for Claude Code

A 7k-star plugin marketplace from the Trail of Bits security firm — code auditing, verification, reverse engineering, and development plugins loadable into Claude Code or Codex from one marketplace.

#tutorial#security#testing#debugging

Security review is where general-purpose agents drift the most — they hallucinate vulnerability classes and miss language-specific pitfalls. trailofbits/skills is a 7k-star plugin marketplace from Trail of Bits, the security research firm, packaging its audit workflows into 44 installable plugins for Claude Code — and Codex can load the same marketplace through its Claude marketplace compatibility.

Why This Skill Matters

The README organizes the catalog into nine categories: Smart Contract Security, Code Auditing, Malware Analysis, Verification, Reverse Engineering, Mobile Security, Development, Team Management, and Tooling. These are named methodologies, not prompt stubs. rust-review covers the safe/unsafe boundary, memory safety, concurrency, panic-DoS, FFI, and the async runtime, with SARIF output. fp-check runs systematic false-positive verification with mandatory gate reviews. differential-review does security-focused review of code changes with git history analysis.

The results are real: the repo's trophy case credits constant-time-analysis with finding a timing side-channel in ML-DSA signing, filed upstream as RustCrypto/signatures PR #1144.

Installation

Add the marketplace to Claude Code, then browse:

/plugin marketplace add trailofbits/skills
/plugin menu

For Codex, the README documents a direct path:

codex plugin marketplace add trailofbits/skills
codex plugin list
codex plugin add <plugin-name>@trailofbits

For local development you can add the marketplace from a parent directory of a clone — the README's example uses /plugins marketplace add ./skills from the folder containing the repo.

Real Workflow: Security-Review a Rust Crate

  1. Install the matching plugin from the marketplace menu — for this task, rust-review.
  2. Point your agent at the code and name the review scope:
Review the crates in this workspace for memory safety and concurrency issues.
Use the rust-review skill and report findings in SARIF.
  1. Work through the findings with the follow-up plugins. variant-analysis searches the rest of the codebase for similar vulnerabilities; post-patch-validation checks a fix for missed variants and regressions with reproducible failures.
  2. Before you report anything upstream, run the false-positive discipline: fp-check exists precisely to verify candidates with mandatory gate reviews, so you do not ship a hallucinated bug to a maintainer.

The same shape works elsewhere: yara-authoring for detection rules, supply-chain-risk-auditor for npm, PyPI, and Go dependency risk, semgrep-rule-variant-creator to port existing Semgrep rules to a new target language with test-driven validation.

Tips

  • building-secure-contracts bundles vulnerability scanners for 6 blockchains and 5 development guideline assistants — the README's own numbers — if smart contracts are your surface.
  • github-triage merges ready bot/approved PRs and reviews unreviewed ones via subagents, which pairs well with the security plugins in a maintenance window.
  • The marketplace doubles as a general development kit: modern-python covers uv, ruff, and pytest; open-sourcing prepares a repository for public release with secrets hygiene and licensing checks.
  • Contributions follow AGENTS.md guidelines, and the repo asks you to run make check before pushing — most of CI runs locally that way.

When Not to Use This

The plugins encode security-audit methodology; they assume you can act on findings — patching, disclosure, and severity calls stay with you. Licensing is CC BY-SA 4.0 rather than a permissive code license, which matters if you redistribute modified skill text. And for a quick one-off lint of a small script, a single targeted plugin from the menu beats loading the whole catalog.


See the leaderboard for more skills.