作成者 · trailofbits
最終更新 · 2026年8月24日
audit-context-building
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass.
レビュー後にインストール
インストール先
Codex インストールプロンプト
Install the "audit-context-building" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/audit-context-building/skills/audit-context-building. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-audit-context-building","task":"Install audit-context-building","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.供給アセットの概要
コーディングと開発 Agent
コードレビュー、リポジトリ分析、テスト、CI、GitHub、DevOps、開発ワークフロー向けのスキルです。
シナリオ
コーディング Agent
リポジトリを理解し、コードを編集し、プルリクエストをレビューできるコーディング Agent が必要です。
Agent 適合
Claude Code + CLI + Codex
Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。
インストール
準備完了
npx skills add trailofbits/skills --skill audit-context-building
メンテナンス
新しい
本日プッシュ
リスク
試用可
Quality score needs review
GitHub 品質
6.8K
86/100 品質 · 86/100 信頼
対象タグ
レビュー注記
Quality score needs review
Agent 導入スコアカード
信頼、監査、インストール準備状況を一目で確認
公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。
品質
優秀採用度と保守性のシグナルが強い高信頼候補です。
信頼
レビュー後にインストール有望な候補ですが、Agent は実行前に監査メモ、インストールポリシー、成果エビデンスを確認する必要があります。
監査
試用可インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。
OpenAgentSkill Trust Score v5
Agent インストール候補
人による確認またはサンドボックス検証後に第一候補として使用します。
スター
GitHub スター 6.8K
リポジトリ活動
スター 6.8K、フォーク 585
メンテナンス
本日プッシュ
ライセンス
CC-BY-SA-4.0
インストール
npx skills add trailofbits/skills --skill audit-context-building
インストール安全性
標準パッケージまたはランタイムのインストールパス
権限範囲
filesystem or document access, database access
Agent の成果
Agent の成果データはまだありません
ドキュメント
README/SKILL.md の文脈が十分です
リスク概要
低いメタデータリスク
- Quality score needs review
インストール準備状況
インストールパスを利用可能
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- ライセンスが明示されています
- Agent-Proven の成果エビデンスはまだありません
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
View technical data+
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
適したタスク
- ワークフロー自動化 ワークフロー
- Claude Code チーム
- GitHub 採用シグナルを重視するチーム
- Move data between tools
適した Agent
インストール判断
- コマンド
- npx skills add trailofbits/skills --skill audit-context-building
- ポリシー
- レビュー
- 人によるレビュー
- はい
信頼とリスク
- 信頼
- 83/100
- 監査
- 89/100
- リスクレベル
- 試用可
成果ループ
- エンドポイント
- /api/agent/outcome
- イベント ID
- resolve
- 成果
- 5
インストールコマンド
npx skills add trailofbits/skills --skill audit-context-building使わない場合
- ベンダー提供の SLA が必要なチーム
- 内部セキュリティレビューのない高コンプライアンス環境
- OpenAgentSkill の利用フィードバックはまだありません
- Quality score needs review
- Production credentials, payments, or irreversible account changes without explicit human review
Agent セーフティ v2
69/100 · インストール前にレビュー
公開メタデータに高リスクな権限ヒントはなく、監査と安全性のシグナルは良好です。
監査ページを確認してから、サンドボックスのワークフローで Agent のインストールを許可してください。
中
ネットワークアクセス
Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。
中
ファイルシステムアクセス
Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。
中
データベースアクセス
Skill はスキーマを確認し、データベースを照会し、永続ストアを扱う可能性があります。
- Quality score needs review
Agent 解決プラン
インストール前に Agent に適合性を検証させます。
Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。
JSON を開く
/api/agent/resolve?task=Use%20audit-context-building%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve テキスト
/api/agent/resolve?task=Use%20audit-context-building%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
インストール引き継ぎ
/api/skills/trailofbits-audit-context-building/install
Agent が確認すべきこと
- Resolve API でタスク適合と代替を確認。
- 監査・信頼スコアと安全ポリシーの警告を確認。
- Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。
プロンプトをコピー
Task: Use audit-context-building in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20audit-context-building%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-audit-context-building/install
Install command: npx skills add trailofbits/skills --skill audit-context-building
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 引き継ぎ
別のディレクトリではなく、インストール経路を Agent に渡します。
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
インストール引き継ぎ
/api/skills/trailofbits-audit-context-building/install
LLM テキスト形式
/api/skills/trailofbits-audit-context-building/install?format=text
代替を探す
/api/skills/search?q=audit-context-building&limit=3
Agent プロンプト
Use audit-context-building for this task. Review https://www.openagentskill.com/api/skills/trailofbits-audit-context-building/install, then install with: npx skills add trailofbits/skills --skill audit-context-buildingRegistry メタデータ
自動スキル選択用の Agent 可読プロファイル。
Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。
Manifest
/api/registry/manifest/trailofbits-audit-context-building
LLM テキスト
/api/registry/manifest/trailofbits-audit-context-building?format=text
インストール別名
/api/registry/install/trailofbits-audit-context-building
推奨
/api/registry/recommend?task=Use%20audit-context-building%20in%20an%20agent%20workflow&limit=3
Agent 判断パネル
ワークフロー自動化 向けの第一候補
有力候補として扱い、自分の Agent スタックで README とインストール経路を検証してください。
スタック内の役割
第一候補
主な適合
ワークフロー自動化
信頼ラベル
本番対応
インストールパス
コマンド準備済み
使う場面
- ワークフロー自動化 ワークフロー
- Claude Code チーム
- GitHub 採用シグナルを重視するチーム
根拠
- GitHub スター 6,823
- 最近のリポジトリ活動
- インストールコマンドまたは GitHub リポジトリが利用可能
- 品質プロファイル 86/100
先にレビュー
- OpenAgentSkill の利用フィードバックはまだありません
実装パス
- 1サンドボックスの Agent にインストールし、ワークフロー自動化 タスクを一度最初から最後まで実行します。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信頼プロファイル
レビュー後にインストール
有望な候補ですが、Agent は実行前に監査メモ、インストールポリシー、成果エビデンスを確認する必要があります。
GitHub 採用度
合格GitHub スター 6.8K
スター/フォーク活動
合格スター 6.8K、フォーク 585; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格本日プッシュ
ライセンスの明確さ
合格CC-BY-SA-4.0
良いシグナル
- AI レビュー承認済み
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- 最近保守されたリポジトリ
- Large GitHub adoption signal
- インストールコマンドに明確な高リスクパターンはありません
- 成果ループは準備済みですが、最初の実行が必要です
インストール前にレビュー
- Quality score needs review
- 実際の Agent 成果レポートはまだありません
- 無人インストールの前に人によるレビューが必要です
推奨アクション
人による確認またはサンドボックス検証後に第一候補として使用します。
品質プロファイル
優秀 Agent ワークフロー向けの候補
採用度と保守性のシグナルが強い高信頼候補です。
ワークフロー適合
このスキルを使うシナリオ
Automate repeated work
Workflow automation
I need my agent to automate a repeated workflow across tools and files.
Reduce risk
Security and compliance
I need my agent to scan a project for security risks and summarize what needs attention.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
ワークフロー適合
完全なワークフローに追加
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
代替候補
インストール前に比較
このタスクに適する可能性のある類似スキル。
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
概要
--- name: audit-context-building description: Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass. allowed-tools: Task Read Grep Glob ---
# Audit Context Building
Build understanding, not verdicts. This runs before anyone hunts for bugs, and feeds that work.
## When to Use
At the start of an audit, a threat model, or an architecture review, when the code is unfamiliar. Also when an earlier pass produced findings nobody could judge, because no one had mapped out how the system fits together.
## When NOT to Use
Do not name vulnerabilities, suggest fixes, write proofs-of-concept, or rate severity. Those belong to the hunting phase, which runs next and with the whole picture in hand. When the code counts on something and nothing checks it, record that plainly and move on — whether it matters is decided later.
Not worth the tokens on code you already understand.
## Do not analyze in this context
The analysis is long, and this context needs to survive to use it. Dispatch it:
- **A codebase, or more than one function** — run `/audit-context-building:audit-context <path>`. It orients, analyzes each function in its own subagent, and writes `audit-context/DOSSIER.md` plus one file per function under `audit-context/functions/`. Only compact records return here. - **A single function** — dispatch the `audit-context-building:function-analyzer` agent at it. It writes its prose to disk and returns a record.
Then work from what comes back: the index, the unenforced assumptions, the open questions. Read a function's file when you need its detail.
The workflow is what enforces this, not this text: a subagent bound to a return schema cannot return prose. Treat this section as routing, and route.
## What comes back, and how to read it
Each record lists what must always be true (with the line that shows it), what the function takes on faith (with whatever establishes it), which functions it calls and what it needs from each, and anything still unclear. The dossier adds the rules that span several functions, who can reach what, and where the complicated parts cluster.
Two things matter more than the rest:
- **Assumptions marked `nothing found`.** The code counts on something being true and nothing anywhere makes it true. This is the most useful thing to hand the hunting phase. - **The open questions.** An honest list of what is still unclear beats a confident answer that turns out to be wrong. Carry them forward instead of closing them out.
Where two records disagree, both are quoted rather than quietly reconciled. That is a fact about the code, not a flaw in the analysis.
## The format
[ANALYSIS_FORMAT.md](resources/ANALYSIS_FORMAT.md) defines it, and [FUNCTION_MICRO_ANALYSIS_EXAMPLE.md](resources/FUNCTION_MICRO_ANALYSIS_EXAMPLE.md) works through examples in C and Solidity. Read them when extending this plugin or deciding whether a record can be trusted.
The format is the same whatever the target. What changes is what fills each slot, and what counts as a call you cannot see inside. [DOMAIN_NOTES.md](resources/DOMAIN_NOTES.md) maps that across smart contracts, C and C++, decompiled firmware, and web services — read it when the target is not plain source code.
**The rule that matters most: follow the calls.** Whether a function is correct usually depends on something another function does, and you cannot see that from the caller alone. A limit looks enforced because the value came back from a function whose name suggests it was checked. So read the function being called, follow every path through it rather than only the one that succeeds, and say what makes each assumption true. When nothing does, use those words: `nothing found`. Every claim cites a line, or becomes an open question.
技術詳細
- バージョン
- 1.0.0
- ライセンス
- CC-BY-SA-4.0
- 最終更新
- 2026年8月24日
- 公開日
- 2026年8月24日
判断の要約
第一候補
GitHub スター 6,823
Agent 実証エビデンス
Agent 実証エビデンス
Resolve、レビュー、インストール、限定実行後の成果レポート。
- 成功率
- —
- 直近の失敗
- —
- 成果
- 0
- 出力品質
- —
- 失敗
- 0
- 非該当
- 0
- インストール数
- 0
- リスクによりブロック
- 0
- 設定が必要
- 0
- 本番
- 0
Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。
成長ループ
共有キット
audit-context-building 用のシナリオベース草案です。X へ手動投稿できます。
audit-context-building: Understand a codebase before looking for bugs in it - what each function assumes, what it gua... 6.8K stars https://www.openagentskill.com/skills/trailofbits-audit-context-building?ref=x
任意:インストールコマンド付きの返信
Listing + install path for audit-context-building: https://www.openagentskill.com/skills/trailofbits-audit-context-building?ref=x Install: npx skills add trailofbits/skills --skill audit-context-building
掲載元
Registry により登録
この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。
- 作成者
- trailofbits
- インデックス作成者
- OpenAgentSkill コミュニティインデックス
帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。
このスキルを申請所有者の申請
このスキル掲載を申請
この Registry により登録 掲載は trailofbits に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。
クリエイター被リンクキット
README にエビデンスバッジを追加
開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。
[](https://www.openagentskill.com/skills/trailofbits-audit-context-building)
[](https://www.openagentskill.com/skills/trailofbits-audit-context-building)
[](https://www.openagentskill.com/skills/trailofbits-audit-context-building/audit)
[](https://www.openagentskill.com/skills/trailofbits-audit-context-building)作者
trailofbits
@trailofbits
プラットフォーム適合
健全性シグナル
- GitHub スター
- 6.8K
- 品質スコア
- 50/100
- 最終 GitHub プッシュ
- 2026年8月24日
- フレームワークのヒント
- 不明
- OpenAgentSkill 閲覧数
- 0
- インストールコピー数
- 0
- 外部クリック
- 0
コミュニティシグナル
このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。
信頼と安全性
レビュー後にインストール
- GitHub 採用度GitHub スター 6.8K合格
- スター/フォーク活動スター 6.8K、フォーク 585; 現在のメタデータでは Issue 活動を利用できません合格
- 最近のメンテナンス本日プッシュ合格
- ライセンスの明確さCC-BY-SA-4.0合格
- README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
- 依存関係/ランタイムのリスク公開メタデータに重大な依存関係リスクのヒントはありません合格
関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K スターMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K スターNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K スターInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K スター