{"slug":"trailofbits-guidelines-advisor","name":"guidelines-advisor","description":"Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.","long_description":"---\nname: guidelines-advisor\ndescription: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.\n---\n\n# Guidelines Advisor\n\n## Purpose\n\nSystematically analyzes the codebase and provides guidance based on Trail of Bits' development guidelines:\n\n1. **Generate documentation and specifications** (plain English descriptions, architectural diagrams, code documentation)\n2. **Optimize on-chain/off-chain architecture** (only if applicable)\n3. **Review upgradeability patterns** (if your project has upgrades)\n4. **Check delegatecall/proxy implementations** (if present)\n5. **Assess implementation quality** (functions, inheritance, events)\n6. **Identify common pitfalls**\n7. **Review dependencies**\n8. **Evaluate test suite and suggest improvements**\n\n**Framework**: Building Secure Contracts - Development Guidelines\n\n---\n\n## How This Works\n\n### Phase 1: Discovery & Context\nExplores the codebase to understand:\n- Project structure and platform\n- Contract/module files and their purposes\n- Existing documentation\n- Architecture patterns (proxies, upgrades, etc.)\n- Testing setup\n- Dependencies\n\n### Phase 2: Documentation Generation\nHelps create:\n- Plain English system description\n- Architectural diagrams (using Slither printers for Solidity)\n- Code documentation recommendations (NatSpec for Solidity)\n\n### Phase 3: Architecture Analysis\nAnalyzes:\n- On-chain vs off-chain component distribution (if applicable)\n- Upgradeability approach (if applicable)\n- Delegatecall proxy patterns (if present)\n\n### Phase 4: Implementation Review\nAssesses:\n- Function composition and clarity\n- Inheritance structure\n- Event logging practices\n- Common pitfalls presence\n- Dependencies quality\n- Testing coverage and techniques\n\n### Phase 5: Recommendations\nProvides:\n- Prioritized improvement suggestions\n- Best practice guidance\n- Actionable next steps\n\n---\n\n## Assessment Areas\n\nI analyze 11 comprehensive areas covering all aspects of smart contract development. For detailed criteria, best practices, and specific checks, see [ASSESSMENT_AREAS.md](resources/ASSESSMENT_AREAS.md).\n\n### Quick Reference:\n\n1. **Documentation & Specifications**\n   - Plain English system descriptions\n   - Architectural diagrams\n   - NatSpec completeness (Solidity)\n   - Documentation gaps identification\n\n2. **On-Chain vs Off-Chain Computation**\n   - Complexity analysis\n   - Gas optimization opportunities\n   - Verification vs computation patterns\n\n3. **Upgradeability**\n   - Migration vs upgradeability trade-offs\n   - Data separation patterns\n   - Upgrade procedure documentation\n\n4. **Delegatecall Proxy Pattern**\n   - Storage layout consistency\n   - Initialization patterns\n   - Function shadowing risks\n   - Slither upgradeability checks\n\n5. **Function Composition**\n   - Function size and clarity\n   - Logical grouping\n   - Modularity assessment\n\n6. **Inheritance**\n   - Hierarchy depth/width\n   - Diamond problem risks\n   - Inheritance visualization\n\n7. **Events**\n   - Critical operation coverage\n   - Event naming consistency\n   - Indexed parameters\n\n8. **Common Pitfalls**\n   - Reentrancy patterns\n   - Integer overflow/underflow\n   - Access control issues\n   - Platform-specific vulnerabilities\n\n9. **Dependencies**\n   - Library quality assessment\n   - Version management\n   - Dependency manager usage\n   - Copied code detection\n\n10. **Testing & Verification**\n    - Coverage analysis\n    - Fuzzing techniques\n    - Formal verification\n    - CI/CD integration\n\n11. **Platform-Specific Guidance**\n    - Solidity version recommendations\n    - Compiler warning checks\n    - Inline assembly warnings\n    - Platform-specific tools\n\nFor complete details on each area including what I'll check, analyze, and recommend, see [ASSESSMENT_AREAS.md](resources/ASSESSMENT_AREAS.md).\n\n---\n\n## Example Output\n\nWhen the analysis is complete, you'll receive comprehensive guidance covering:\n\n- System documentation with plain English descriptions\n- Architectural diagrams and documentation gaps\n- Architecture analysis (on-chain/off-chain, upgradeability, proxies)\n- Implementation review (functions, inheritance, events, pitfalls)\n- Dependencies and testing evaluation\n- Prioritized recommendations (CRITICAL, HIGH, MEDIUM, LOW)\n- Overall assessment and path to production\n\nFor a complete example analysis report, see [EXAMPLE_REPORT.md](resources/EXAMPLE_REPORT.md).\n\n---\n\n## Deliverables\n\nI provide four comprehensive deliverable categories:\n\n### 1. System Documentation\n- Plain English descriptions\n- Architectural diagrams\n- Documentation gaps analysis\n\n### 2. Architecture Analysis\n- On-chain/off-chain assessment\n- Upgradeability review\n- Proxy pattern security review\n\n### 3. Implementation Review\n- Function composition analysis\n- Inheritance assessment\n- Events coverage\n- Pitfall identification\n- Dependencies evaluation\n- Testing analysis\n\n### 4. Prioritized Recommendations\n- CRITICAL (address immediately)\n- HIGH (address before deployment)\n- MEDIUM (address for production quality)\n- LOW (nice to have)\n\nFor detailed templates and examples of each deliverable, see [DELIVERABLES.md](resources/DELIVERABLES.md).\n\n---\n\n## Assessment Process\n\nWhen invoked, I will:\n\n1. **Explore the codebase**\n   - Identify all contract/module files\n   - Find existing documentation\n   - Locate test files\n   - Check for proxies/upgrades\n   - Identify dependencies\n\n2. **Generate documentation**\n   - Create plain English system description\n   - Generate architectural diagrams (if tools available)\n   - Identify documentation gaps\n\n3. **Analyze architecture**\n   - Assess on-chain/off-chain distribution (if applicable)\n   - Review upgradeability approach (if applicable)\n   - Audit proxy patterns (if present)\n\n4. **Review implementation**\n   - Analyze functions, inheritance, events\n   - Check for common pitfalls\n   - Assess dependencies\n   - Evaluate testing\n\n5. **Provide recommendations**\n   - Present findings with file references\n   - Ask clarifying questions about design decisions\n   - Suggest prioritized improvements\n   - Offer actionable next steps\n\n---\n\n## Rationalizations (Do Not Skip)\n\n| Rationalization | Why It's Wrong | Required Action |\n|-----------------|----------------|-----------------|\n| \"System is simple, description covers everything\" | Plain English descriptions miss security-critical details | Complete all 5 phases: documentation, architecture, implementation, dependencies, recommendations |\n| \"No upgrades detected, skip upgradeability section\" | Upgradeability can be implicit (ownable patterns, delegatecall) | Search for proxy patterns, delegatecall, storage collisions before declaring N/A |\n| \"Not applicable\" without verification | Premature scope reduction misses vulnerabilities | Verify with explicit codebase search before skipping any guideline section |\n| \"Architecture is straightforward, no analysis needed\" | Obvious architectures have subtle trust boundaries | Analyze on-chain/off-chain distribution, access control flow, external dependencies |\n| \"Common pitfalls don't apply to this codebase\" | Every codebase has common pitfalls | Systematically check all guideline pitfalls with grep/code search |\n| \"Tests exist, testing guideline is satisfied\" | Test existence ≠ test quality | Check coverage, property-based tests, integration tests, failure cases |\n| \"I can provide generic best practices\" | Generic advice isn't actionable | Provide project-specific findings with file:line references |\n| \"User knows what to improve from findings\" | Findings without prioritization = no action plan | Generate prioritized improvement roadmap with specific next steps |\n\n---\n\n## Notes\n\n- I'll only analyze relevant sections (won't hallucinate about upgrades if not present)\n- I'll adapt to your platform (Solidity, Rust, Cairo, etc.)\n- I'll use available tools (Slither, etc.) but work without them if unavailable\n- I'll provide file references and line numbers for all findings\n- I'll ask questions about design decisions I can't infer from code\n\n---\n\n## Ready to Begin\n\n**What I'll need**:\n- Access to your codebase\n- Context about your project goals\n- Any existing documentation or specifications\n- Information about deployment plans\n\nLet's analyze your codebase and improve it using Trail of Bits' best practices!\n","tagline":"Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. ","category":"research","tags":["agent-skill"],"author":"trailofbits","verified":false,"attribution":{"status":"registry_indexed","statusLabel":"Registry indexed","shortLabel":"REGISTRY INDEXED","sourceLabel":"recursive skill source sync","sourceDetail":"trailofbits/skills","creatorName":"trailofbits","creatorUrl":"https://github.com/trailofbits","sourceUrl":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","indexedBy":"OpenAgentSkill community index","claimUrl":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor#claim-this-skill","claimCta":"Claim this skill","trustNote":"This listing was indexed from public sources and is not marked official until a maintainer claim is approved.","publicNote":"Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals."},"stats":{"stars":6823,"forks":585,"verified_installs":0,"successful_runs":0,"total_outcomes":0,"rating":0,"review_count":0,"quality_score":50.09},"quality":{"score":85,"tier":"excellent","label":"Excellent","summary":"High-confidence pick with strong adoption and healthy maintenance signals.","signals":[{"label":"GitHub stars","value":"6.8K","tone":"positive"},{"label":"Freshness","value":"Today","tone":"positive"},{"label":"Install ready","value":"Yes","tone":"positive"},{"label":"License","value":"CC-BY-SA-4.0","tone":"neutral"}],"warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed."]},"trust":{"version":"trust-score-v5","score":68,"base_score":76,"outcome_confidence":0,"tier":"review","label":"Sandbox only","summary":"Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.","recommendedAction":"Run only in a sandbox and compare close alternatives before using it for real work.","decision":{"install_policy":"human_review_before_install","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["68/100 Trust Score v5","76/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":94,"weight":0.13,"status":"pass","detail":"6.8K GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":88,"weight":0.08,"status":"pass","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"Pushed today"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"CC-BY-SA-4.0"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":82,"weight":0.12,"status":"pass","detail":"database surface"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":74,"weight":0.07,"status":"info","detail":"filesystem or document access, database access"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"pass","label":"GitHub adoption","detail":"6.8K GitHub stars"},{"status":"pass","label":"Stars/forks activity","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"Pushed today"},{"status":"pass","label":"License clarity","detail":"CC-BY-SA-4.0"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"pass","label":"Dependency/runtime risk","detail":"database surface"},{"status":"pass","label":"Install availability","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"info","label":"Permission surface","detail":"filesystem or document access, database access"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Large GitHub adoption signal","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"6.8K GitHub stars","repoActivity":"6.8K stars, 585 forks","lastPushed":"Pushed today","license":"CC-BY-SA-4.0","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","install":"npx skills add trailofbits/skills --skill guidelines-advisor","installSafety":"standard package or runtime install path","permissionSurface":"filesystem or document access, database access","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"human_review_before_install"},"installReadiness":{"ready":true,"command":"npx skills add trailofbits/skills --skill guidelines-advisor","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","Pushed today","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v3","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["research","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add trailofbits/skills --skill guidelines-advisor","trust_score":68,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["research","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":76,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout."}}},"trust_score_v5":{"version":"trust-score-v5","score":68,"base_score":76,"outcome_confidence":0,"tier":"review","label":"Sandbox only","summary":"Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.","recommendedAction":"Run only in a sandbox and compare close alternatives before using it for real work.","decision":{"install_policy":"human_review_before_install","auto_install_allowed":false,"human_review_required":true,"sandbox_first":true,"agent_action":"Compare alternatives before installing.","reasoning":["68/100 Trust Score v5","76/100 Trust Score v4 baseline","Needs more real agent outcomes before unattended install","Install path is available","Review before production"],"review_required_when":["The workspace contains production secrets, payments, private customer data, or irreversible actions.","The install command requests shell, network, credential, database, or broad filesystem access.","Outcome evidence is missing, recently failed, or required human review.","Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"]},"dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":94,"weight":0.13,"status":"pass","detail":"6.8K GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":88,"weight":0.08,"status":"pass","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"Pushed today"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"CC-BY-SA-4.0"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":82,"weight":0.12,"status":"pass","detail":"database surface"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":74,"weight":0.07,"status":"info","detail":"filesystem or document access, database access"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"pass","label":"GitHub adoption","detail":"6.8K GitHub stars"},{"status":"pass","label":"Stars/forks activity","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"Pushed today"},{"status":"pass","label":"License clarity","detail":"CC-BY-SA-4.0"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"pass","label":"Dependency/runtime risk","detail":"database surface"},{"status":"pass","label":"Install availability","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"info","label":"Permission surface","detail":"filesystem or document access, database access"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Large GitHub adoption signal","Install command has no obvious high-risk pattern","Outcome loop is ready but needs first real agent run"],"warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review","No real agent outcome reports yet","Human review required before unattended installation"],"evidence":{"stars":"6.8K GitHub stars","repoActivity":"6.8K stars, 585 forks","lastPushed":"Pushed today","license":"CC-BY-SA-4.0","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","install":"npx skills add trailofbits/skills --skill guidelines-advisor","installSafety":"standard package or runtime install path","permissionSurface":"filesystem or document access, database access","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet","agentProvenScore":0,"outcomeConfidence":"0%","installPolicy":"human_review_before_install"},"installReadiness":{"ready":true,"command":"npx skills add trailofbits/skills --skill guidelines-advisor","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","Pushed today","Trust Score v5 requires review or sandbox-only use before install."]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Compare alternatives before installing."},"outcome_loop":{"version":"openagentskill-agent-outcome-v3","required_after_install":true,"endpoint":"/api/agent/outcome","method":"POST","event_id_source":"feedback.event_id, install_receipt.resolve_event_id, or decision_packet.outcome_feedback.event_id","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"required_fields":["event_id","skill_slug","task"],"quality_fields":["task_success","output_quality","error_type","human_review_required","used_in_production","workspace","evidence_url","time_to_useful_ms"],"ranking_inputs_updated":["Trust Score v5 outcome confidence","Agent Proven Score","Resolve ranking task-fit evidence","Skill detail machine-readable metadata","Outcome leaderboard"]},"agent_contract":{"suited_tasks":["research","agent-skill"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"install_command":"npx skills add trailofbits/skills --skill guidelines-advisor","trust_score":68,"trust_version":"trust-score-v5","risk_level":"medium","do_not_use_when":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"before_install":["Read the audit page and machine-readable metadata.","Confirm the install command, license, and permission surface fit the workspace.","Get explicit human approval or choose an alternative before installing."],"after_run":["Report the outcome to /api/agent/outcome using the resolve event id.","Include output_quality, workspace, human_review_required, and evidence_url when available.","Re-resolve before broad production rollout."]},"bestFor":["research","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"],"backward_compatible":{"trust_score_v4":{"version":"trust-score-v4","score":76,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout."}}},"trust_score_v4":{"version":"trust-score-v4","score":76,"tier":"strong","label":"Strong shortlist","summary":"Good trust signals with a few areas worth checking before rollout.","recommendedAction":"Test in a sandbox workflow and compare its install path with close alternatives.","dimensions":[{"id":"github_adoption","label":"GitHub adoption","score":94,"weight":0.13,"status":"pass","detail":"6.8K GitHub stars"},{"id":"repo_activity","label":"Stars/forks activity","score":88,"weight":0.08,"status":"pass","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"id":"maintenance","label":"Recent maintenance","score":100,"weight":0.14,"status":"pass","detail":"Pushed today"},{"id":"license","label":"License clarity","score":86,"weight":0.09,"status":"pass","detail":"CC-BY-SA-4.0"},{"id":"documentation","label":"README/SKILL.md completeness","score":86,"weight":0.14,"status":"pass","detail":"Metadata includes enough usage and workflow context"},{"id":"dependency_risk","label":"Dependency/runtime risk","score":82,"weight":0.12,"status":"pass","detail":"database surface"},{"id":"installability","label":"Install availability","score":92,"weight":0.1,"status":"pass","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"id":"install_safety","label":"Install command safety","score":92,"weight":0.1,"status":"pass","detail":"standard package or runtime install path"},{"id":"permission_surface","label":"Permission surface","score":74,"weight":0.07,"status":"info","detail":"filesystem or document access, database access"},{"id":"repository","label":"Repository evidence","score":86,"weight":0.04,"status":"pass","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"id":"review_status","label":"Review status","score":66,"weight":0.05,"status":"info","detail":"AI review data available"},{"id":"agent_outcomes","label":"Agent Proven outcomes","score":54,"weight":0.13,"status":"info","detail":"No agent outcome data yet"}],"checks":[{"status":"pass","label":"GitHub adoption","detail":"6.8K GitHub stars"},{"status":"pass","label":"Stars/forks activity","detail":"6.8K stars, 585 forks; issue activity unavailable in current metadata"},{"status":"pass","label":"Recent maintenance","detail":"Pushed today"},{"status":"pass","label":"License clarity","detail":"CC-BY-SA-4.0"},{"status":"pass","label":"README/SKILL.md completeness","detail":"Metadata includes enough usage and workflow context"},{"status":"pass","label":"Dependency/runtime risk","detail":"database surface"},{"status":"pass","label":"Install availability","detail":"npx skills add trailofbits/skills --skill guidelines-advisor"},{"status":"pass","label":"Install command safety","detail":"standard package or runtime install path"},{"status":"info","label":"Permission surface","detail":"filesystem or document access, database access"},{"status":"pass","label":"Repository evidence","detail":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor"},{"status":"info","label":"Review status","detail":"AI review data available"},{"status":"info","label":"Agent Proven outcomes","detail":"No agent outcome data yet"},{"status":"warn","label":"Ownership","detail":"No approved owner claim yet"},{"status":"info","label":"OpenAgentSkill usage","detail":"No local usage activity yet"},{"status":"info","label":"Agent outcomes","detail":"No agent outcome data yet"}],"strengths":["AI review approved","Install path is available","Repository evidence is available","Recently maintained repository","Large GitHub adoption signal","Install command has no obvious high-risk pattern"],"warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"],"evidence":{"stars":"6.8K GitHub stars","repoActivity":"6.8K stars, 585 forks","lastPushed":"Pushed today","license":"CC-BY-SA-4.0","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","install":"npx skills add trailofbits/skills --skill guidelines-advisor","installSafety":"standard package or runtime install path","permissionSurface":"filesystem or document access, database access","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"installReadiness":{"ready":true,"command":"npx skills add trailofbits/skills --skill guidelines-advisor","policy":"human_review_before_install","label":"Human review before install","notes":["Install path is available","Repository evidence is available","License is declared","No Agent Proven outcome evidence yet","Pushed today"]},"agentCompatibility":["Codex","Claude Code","Cursor","OpenAgentSkill CLI"],"riskSummary":{"level":"medium","label":"Review before production","notes":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"outcomeEvidence":{"total":0,"successes":0,"failures":0,"notRelevant":0,"successRate":null,"installAttempts":0,"riskBlocked":0,"setupRequired":0,"installSuccessRate":null,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"recentSuccessRate":null,"recentFailureRate":null,"uniqueAgents":0,"agentProvenScore":0,"agentProvenLabel":"Needs first agent run","lastOutcomeAt":null,"label":"No agent outcome data yet"},"autoInstall":{"allowed":false,"sandboxRequired":true,"policy":"human_review_before_install","reason":"Human review or sandbox validation is required before automatic installation."},"bestFor":["research","agent-skill"],"doNotUseFor":["Production credentials, payments, or irreversible account changes without explicit human review","Sensitive private data before reviewing repository code, license, and permission surface","Automatic installation in a production workspace"],"knownRisks":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"outcome_stats":null,"safety":{"score":64,"level":"review_before_install","label":"Review before install","safety_tier":{"tier":"reviewed","label":"Reviewed with permission notes","badge":"REVIEWED","summary":"Usable candidate, but the agent should surface permission and audit notes before installation.","recommended_action":"Require human approval before installing into a real workspace.","auto_install_policy":"review","reasons":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","64/100 agent safety score"]},"auto_install_allowed":false,"human_review_required":true,"blocked":false,"audit_risk":"needs_review","permission_hints":[{"id":"network","label":"Network access","reason":"Skill likely fetches remote pages, APIs, repositories, or external services.","severity":"medium"},{"id":"filesystem","label":"Filesystem access","reason":"Skill may read or write project files, documents, generated artifacts, or local workspace state.","severity":"medium"},{"id":"database","label":"Database access","reason":"Skill may inspect schemas, query databases, or work with persistent stores.","severity":"medium"}],"policy_warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed."],"constraints_applied":{"max_risk":"medium","needs_install_command":true,"min_stars":0}},"safety_gate":{"tier":"reviewed","label":"Reviewed with permission notes","badge":"REVIEWED","auto_install_policy":"review","auto_install_allowed":false,"blocked":false,"human_review_required":true,"recommended_action":"Require human approval before installing into a real workspace.","reasons":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","64/100 agent safety score"]},"eval":{"version":"openagentskill-skill-eval-v1","status":"review","score":78,"risk_level":"medium","decision":{"recommendation":"manual_review","reason":"Require human approval before installing into a real workspace.","auto_install_allowed":false,"policy":"review","human_review_required":true},"blockers":[],"warnings":["Trust score: Good trust signals with a few areas worth checking before rollout.","Audit score: Needs review","Agent safety gate: Usable candidate, but the agent should surface permission and audit notes before installation.","Permission surface: filesystem or document access, database access","The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review"],"validation_plan":["Inspect repository, README/SKILL.md, license, and recent commits before production use.","Install in an isolated workspace or sandbox with no production secrets available.","Run the smallest representative task and record files touched, commands run, network access, and outputs.","Compare the selected skill against at least one alternative when the eval status is review or failed.","Promote only after the agent reports a successful verification result and unresolved warnings are accepted."],"checks":[{"id":"task_fit","label":"Task fit","status":"pass","score":84,"required_for_auto_install":true,"detail":"Task wording matches this skill metadata.","evidence":["Evaluate guidelines-advisor before installing it in an agent workflow","research","Research agents workflows; Claude Code teams; teams that value GitHub adoption signals"]},{"id":"install_path","label":"Install path","status":"pass","score":92,"required_for_auto_install":true,"detail":"Install handoff is available.","evidence":["npx skills add trailofbits/skills --skill guidelines-advisor"]},{"id":"install_safety","label":"Install command safety","status":"pass","score":92,"required_for_auto_install":true,"detail":"standard package or runtime install path","evidence":["npx skills add trailofbits/skills --skill guidelines-advisor"]},{"id":"trust_score","label":"Trust score","status":"warn","score":76,"required_for_auto_install":true,"detail":"Good trust signals with a few areas worth checking before rollout.","evidence":["Strong shortlist","6.8K GitHub stars","CC-BY-SA-4.0"]},{"id":"audit_score","label":"Audit score","status":"warn","score":84,"required_for_auto_install":true,"detail":"Needs review","evidence":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed."]},{"id":"agent_safety_gate","label":"Agent safety gate","status":"warn","score":64,"required_for_auto_install":true,"detail":"Usable candidate, but the agent should surface permission and audit notes before installation.","evidence":["Require human approval before installing into a real workspace.","The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed."]},{"id":"readme_skillmd_completeness","label":"README/SKILL.md completeness","status":"pass","score":86,"required_for_auto_install":false,"detail":"Metadata includes enough usage and workflow context","evidence":["Strong README/SKILL.md context"]},{"id":"license_clarity","label":"License clarity","status":"pass","score":86,"required_for_auto_install":true,"detail":"CC-BY-SA-4.0","evidence":["CC-BY-SA-4.0"]},{"id":"recent_maintenance","label":"Recent maintenance","status":"pass","score":100,"required_for_auto_install":false,"detail":"Pushed today","evidence":["Pushed today"]},{"id":"permission_surface","label":"Permission surface","status":"warn","score":74,"required_for_auto_install":true,"detail":"filesystem or document access, database access","evidence":["Network access: medium","Filesystem access: medium","Database access: medium"]},{"id":"alternatives","label":"Alternatives available","status":"info","score":55,"required_for_auto_install":false,"detail":"No close alternatives were found in the current shortlist.","evidence":[]}],"endpoints":{"web":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor/evals","api":"/api/agent/evals?slug=trailofbits-guidelines-advisor","text":"/api/agent/evals?slug=trailofbits-guidelines-advisor&format=text"}},"agent_readable_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"trailofbits-guidelines-advisor","name":"guidelines-advisor","description":"Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.","category":"research","url":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","github_repo":"trailofbits/skills"},"suited_tasks":["Research agents workflows","Claude Code teams","teams that value GitHub adoption signals","Search sources","Extract claims","Synthesize findings","Inspect source files","Explain architecture"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add trailofbits/skills --skill guidelines-advisor","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install trailofbits-guidelines-advisor"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"guidelines-advisor\" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"guidelines-advisor\" as a Claude Code skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"guidelines-advisor\" from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/trailofbits-guidelines-advisor/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/trailofbits-guidelines-advisor"},"trust":{"score":76,"label":"Strong shortlist","version":"trust-score-v4","install_policy":"human_review_before_install","evidence":{"stars":"6.8K GitHub stars","repoActivity":"6.8K stars, 585 forks","lastPushed":"Pushed today","license":"CC-BY-SA-4.0","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","install":"npx skills add trailofbits/skills --skill guidelines-advisor","installSafety":"standard package or runtime install path","permissionSurface":"filesystem or document access, database access","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["research","agent-skill"],"known_risks":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":84,"risk_level":"needs_review","risk_label":"Needs review","warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review"]},"safety_gate":{"tier":"reviewed","label":"Reviewed with permission notes","auto_install_policy":"review","auto_install_allowed":false,"human_review_required":true,"blocked":false,"recommended_action":"Require human approval before installing into a real workspace."},"quality":{"score":85,"label":"Excellent"},"supply":{"track":"Research and knowledge work","scenario":"Research agents","maintenance":"Pushed today","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","production agents without a repository review","The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","No OpenAgentSkill engagement data yet","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review","Production credentials, payments, or irreversible account changes without explicit human review"],"agent_contract":{"task_input":"Use guidelines-advisor in an agent workflow","recommended_action":"Require human approval before installing into a real workspace.","install_policy":"review","minimum_review_before_use":["Trust: 76/100 Strong shortlist","Audit: 84/100 Needs review","Safety: 64/100 Review before install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"trailofbits-guidelines-advisor (guidelines-advisor)","install_command":"npx skills add trailofbits/skills --skill guidelines-advisor","risk_summary":"Needs review; Reviewed with permission notes; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"trailofbits-guidelines-advisor","task":"Use guidelines-advisor in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor","api":"https://www.openagentskill.com/api/agent/skills/trailofbits-guidelines-advisor","audit":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=trailofbits-guidelines-advisor&task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/trailofbits-guidelines-advisor/install","manifest":"https://www.openagentskill.com/api/registry/manifest/trailofbits-guidelines-advisor"}},"machine_metadata":{"version":"openagentskill-agent-metadata-v2","skill":{"slug":"trailofbits-guidelines-advisor","name":"guidelines-advisor","description":"Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.","category":"research","url":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","github_repo":"trailofbits/skills"},"suited_tasks":["Research agents workflows","Claude Code teams","teams that value GitHub adoption signals","Search sources","Extract claims","Synthesize findings","Inspect source files","Explain architecture"],"suited_agents":["Codex","Claude Code","Cursor","OpenAgentSkill CLI","CLI"],"install":{"command":"npx skills add trailofbits/skills --skill guidelines-advisor","ready":true,"targets":[{"id":"openagentskill-cli","label":"CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install trailofbits-guidelines-advisor"},{"id":"codex","label":"Codex","kind":"agent-prompt","value":"Install the \"guidelines-advisor\" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"claude-code","label":"Claude Code","kind":"agent-prompt","value":"Add \"guidelines-advisor\" as a Claude Code skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."},{"id":"cursor","label":"Cursor","kind":"agent-prompt","value":"Turn \"guidelines-advisor\" from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes."}],"handoff_url":"https://www.openagentskill.com/api/skills/trailofbits-guidelines-advisor/install","manifest_url":"https://www.openagentskill.com/api/registry/manifest/trailofbits-guidelines-advisor"},"trust":{"score":76,"label":"Strong shortlist","version":"trust-score-v4","install_policy":"human_review_before_install","evidence":{"stars":"6.8K GitHub stars","repoActivity":"6.8K stars, 585 forks","lastPushed":"Pushed today","license":"CC-BY-SA-4.0","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","install":"npx skills add trailofbits/skills --skill guidelines-advisor","installSafety":"standard package or runtime install path","permissionSurface":"filesystem or document access, database access","documentation":"Strong README/SKILL.md context","agentOutcomes":"No agent outcome data yet"},"outcome_evidence":{"total":0,"successes":0,"failures":0,"not_relevant":0,"success_rate":null,"recent_success_rate":null,"recent_failure_rate":null,"install_attempts":0,"install_success_rate":null,"risk_blocked":0,"setup_required":0,"avg_output_quality":null,"production_outcomes":0,"last_outcome_at":null,"label":"No agent outcome data yet"},"auto_install":{"allowed":false,"sandbox_required":true,"reason":"Human review or sandbox validation is required before automatic installation."},"best_for":["research","agent-skill"],"known_risks":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Quality score needs review"]},"agent_proven":{"version":"agent-proven-v1","score":0,"tier":"unproven","label":"Needs first agent run","summary":"No agent outcome reports yet. Use Resolve, run one narrow sandbox task, then report the result.","metrics":{"totalOutcomes":0,"successfulOutcomes":0,"failedOutcomes":0,"installAttempts":0,"installSuccessRate":null,"successRate":null,"recentSuccessRate":null,"recentFailureRate":null,"riskBlocked":0,"setupRequired":0,"notRelevant":0,"avgOutputQuality":null,"avgTimeToUsefulMs":null,"productionOutcomes":0,"humanReviewRequired":0,"uniqueAgents":0,"lastOutcomeAt":null},"signals":[],"penalties":["No real agent outcome evidence yet"]},"audit":{"score":84,"risk_level":"needs_review","risk_label":"Needs review","warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review"]},"safety_gate":{"tier":"reviewed","label":"Reviewed with permission notes","auto_install_policy":"review","auto_install_allowed":false,"human_review_required":true,"blocked":false,"recommended_action":"Require human approval before installing into a real workspace."},"quality":{"score":85,"label":"Excellent"},"supply":{"track":"Research and knowledge work","scenario":"Research agents","maintenance":"Pushed today","risk":"Needs review"},"alternative_skills":[],"do_not_use_when":["teams that need a vendor-supported SLA","production agents without a repository review","The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","No OpenAgentSkill engagement data yet","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review","Production credentials, payments, or irreversible account changes without explicit human review"],"agent_contract":{"task_input":"Use guidelines-advisor in an agent workflow","recommended_action":"Require human approval before installing into a real workspace.","install_policy":"review","minimum_review_before_use":["Trust: 76/100 Strong shortlist","Audit: 84/100 Needs review","Safety: 64/100 Review before install","Review repository, license, install command, and permission surface before production use."],"expected_agent_output":{"selected_skill":"trailofbits-guidelines-advisor (guidelines-advisor)","install_command":"npx skills add trailofbits/skills --skill guidelines-advisor","risk_summary":"Needs review; Reviewed with permission notes; Review before production","verification_result":"Report the smallest successful task, files touched, warnings, and any missing setup."}},"outcome_feedback":{"endpoint":"https://www.openagentskill.com/api/agent/outcome","method":"POST","requires_resolve_event_id":true,"event_id_source":"Use install_receipt.outcome_feedback.event_id or feedback.event_id returned by /api/agent/resolve for the current task.","expected_outcomes":["success","failed","not_relevant","blocked_by_risk","setup_required"],"payload_template":{"event_id":"<install_receipt.outcome_feedback.event_id or feedback.event_id from /api/agent/resolve>","skill_slug":"trailofbits-guidelines-advisor","task":"Use guidelines-advisor in an agent workflow","agent":"codex","outcome":"success","install_used":true,"risk_blocked":false,"setup_required":false,"task_success":true,"output_quality":4,"error_type":null,"human_review_required":false,"workspace":"sandbox","time_to_useful_ms":120000,"notes":"Report the smallest successful task, setup friction, files touched, and risk notes."}},"endpoints":{"web":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor","api":"https://www.openagentskill.com/api/agent/skills/trailofbits-guidelines-advisor","audit":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor/audit","eval":"https://www.openagentskill.com/api/agent/evals?slug=trailofbits-guidelines-advisor&task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&max_risk=medium","resolve":"https://www.openagentskill.com/api/agent/resolve?task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&agent=codex&max_risk=medium","receipt":"https://www.openagentskill.com/api/agent/receipt?task=Use%20guidelines-advisor%20in%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text","install":"https://www.openagentskill.com/api/skills/trailofbits-guidelines-advisor/install","manifest":"https://www.openagentskill.com/api/registry/manifest/trailofbits-guidelines-advisor"}},"supply_profile":{"track":{"slug":"research","label":"Research and knowledge work","shortLabel":"Research","description":"Deep research, source comparison, literature review, RAG, knowledge search, and reports."},"scenario":{"label":"Research agents","description":"I need my agent to research a topic, compare sources, and produce a concise report.","useCases":[{"slug":"research-agents","title":"Research agents"},{"slug":"coding-agents","title":"Coding agents"},{"slug":"rag-knowledge","title":"RAG and knowledge"}]},"applicableAgents":["Claude Code","CLI","Codex","Cursor"],"install":{"ready":true,"command":"npx skills add trailofbits/skills --skill guidelines-advisor","primaryTarget":"CLI","targetCount":4},"githubQuality":{"stars":6823,"starsLabel":"6.8K","forks":585,"license":"CC-BY-SA-4.0","qualityScore":85,"trustScore":76,"auditScore":84},"maintenance":{"status":"fresh","label":"Pushed today","daysSincePush":0,"lastPushedAt":"2026-08-24T13:20:11+00:00"},"risk":{"level":"needs_review","label":"Needs review","requiresReview":true,"notes":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review","Needs review"]},"coverageTags":["Research","Research agents","agent-skill"]},"audit":{"audit_score":84,"risk_level":"needs_review","risk_label":"Needs review","quality_score":85,"trust_score":76,"maintenance_score":100,"security_score":81,"install_score":92,"warnings":["The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.","Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.","The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.","Quality score needs review"]},"quality_signals":{"model":"v2","star_score":26.84,"usage_score":0,"review_score":5.25,"metadata_score":3,"freshness_score":15},"platforms":["Claude Code"],"use_cases":[{"slug":"research-agents","title":"Research agents","url":"https://www.openagentskill.com/use-cases/research-agents"},{"slug":"coding-agents","title":"Coding agents","url":"https://www.openagentskill.com/use-cases/coding-agents"},{"slug":"rag-knowledge","title":"RAG and knowledge","url":"https://www.openagentskill.com/use-cases/rag-knowledge"},{"slug":"browser-automation","title":"Browser automation","url":"https://www.openagentskill.com/use-cases/browser-automation"}],"stacks":[{"slug":"research-report-agent","title":"Research report agent","url":"https://www.openagentskill.com/collections/research-report-agent"},{"slug":"coding-review-agent","title":"Coding review agent","url":"https://www.openagentskill.com/collections/coding-review-agent"},{"slug":"rag-knowledge-base","title":"RAG knowledge base","url":"https://www.openagentskill.com/collections/rag-knowledge-base"}],"install":"npx skills add trailofbits/skills --skill guidelines-advisor","install_targets":[{"id":"openagentskill-cli","label":"CLI","title":"OpenAgentSkill CLI","kind":"command","value":"npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install trailofbits-guidelines-advisor","description":"Resolve policy, run the source installer safely, and report a verified install receipt.","copyLabel":"Copy command"},{"id":"codex","label":"Codex","title":"Codex install prompt","kind":"agent-prompt","value":"Install the \"guidelines-advisor\" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"codex\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Give Codex a repo-aware install prompt when the skill is not available through a local CLI.","copyLabel":"Copy prompt"},{"id":"claude-code","label":"Claude Code","title":"Claude Code skill prompt","kind":"agent-prompt","value":"Add \"guidelines-advisor\" as a Claude Code skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor. Inspect the skill instructions, place the reusable skill files in the appropriate local skills location for this project, and report the activation steps. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"claude-code\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this prompt to ask Claude Code to add the skill and explain the local activation steps.","copyLabel":"Copy prompt"},{"id":"cursor","label":"Cursor","title":"Cursor rule prompt","kind":"agent-prompt","value":"Turn \"guidelines-advisor\" from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor into a reusable Cursor project rule or agent instruction. Preserve the core workflow, adapt paths to this repo, and keep the rule scoped to tasks where it is relevant. Skill purpose: Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {\"event_id\":\"install_<unique-id>\",\"skill_slug\":\"trailofbits-guidelines-advisor\",\"task\":\"Install guidelines-advisor\",\"agent\":\"cursor\",\"outcome\":\"success\",\"install_used\":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.","description":"Use this when installing as Cursor project rules or reusable agent instructions.","copyLabel":"Copy prompt"}],"repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","github_repo":"trailofbits/skills","version":"1.0.0","license":"CC-BY-SA-4.0","urls":{"web":"https://www.openagentskill.com/skills/trailofbits-guidelines-advisor","repository":"https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor","api":"/api/agent/skills/trailofbits-guidelines-advisor","install_api":"/api/skills/trailofbits-guidelines-advisor/install"},"meta":{"created_at":"2026-08-24T13:24:47.131681+00:00","updated_at":"2026-08-24T13:24:47.131681+00:00","agent_friendly":true}}