Kreator · trailofbits
Pembaruan terakhir · 24 Agu 2026
audit-prep-assistant
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).
Hanya sandbox
Target pemasangan
Prompt pemasangan Codex
Install the "audit-prep-assistant" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/audit-prep-assistant. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-audit-prep-assistant","task":"Install audit-prep-assistant","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Profil aset
Riset dan pekerjaan pengetahuan
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Skenario
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Kecocokan Agent
Claude Code + CLI + Codex
Cocok untuk Codex, Claude Code, Cursor, CLI, atau Agent khusus.
Pasang
Siap
npx skills add trailofbits/skills --skill audit-prep-assistant
Pemeliharaan
Terkini
Diperbarui hari ini
Risiko
Berisiko
Permission surface may require sandboxing
Kualitas GitHub
6.8K
85/100 Kualitas · 74/100 Kepercayaan
Tag cakupan
Catatan ulasan
Permission surface may require sandboxing · Financial research output is not financial advice; require human review before any live investment decision
Kartu adopsi Agent
Kepercayaan, audit, dan kesiapan pemasangan dalam sekali lihat
Skor ini menggabungkan metadata repositori publik, sinyal ulasan OpenAgentSkill, kebaruan pemeliharaan, dan kesiapan pemasangan. Ini adalah sinyal shortlist, bukan pengganti peninjauan manusia.
Kualitas
Sangat baikHigh-confidence pick with strong adoption and healthy maintenance signals.
Kepercayaan
Hanya sandboxKandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.
Audit
BerisikoTinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Trust Score OpenAgentSkill v5
Hanya sandbox
Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.
Star
6.8K star GitHub
Aktivitas repositori
6.8K star dan 585 fork
Pemeliharaan
Diperbarui hari ini
Lisensi
CC-BY-SA-4.0
Pasang
npx skills add trailofbits/skills --skill audit-prep-assistant
Keamanan pemasangan
Jalur pemasangan paket atau runtime standar
Cakupan izin
shell or command execution, filesystem or document access
Hasil Agent
Belum ada data hasil Agent
Dokumentasi
Konteks README/SKILL.md kuat
Ringkasan risiko
Tinjau sebelum produksi
- The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
- Financial research output is not financial advice; require human review before any live investment decision.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
Kesiapan pemasangan
Jalur pemasangan tersedia
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Lisensi dinyatakan
- Belum ada bukti hasil Agent-Proven
Metadata yang dapat dibaca Agent
Data keputusan yang dapat dibaca mesin untuk skill ini.
Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.
View technical data+
Metadata yang dapat dibaca Agent
Data keputusan yang dapat dibaca mesin untuk skill ini.
Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.
Tugas yang sesuai
- alur kerja GitHub automation
- Tim Claude Code
- Tim yang menghargai sinyal adopsi GitHub
- Inspect repository metadata
Agent yang sesuai
Keputusan pemasangan
- Perintah
- npx skills add trailofbits/skills --skill audit-prep-assistant
- Kebijakan
- Blokir
- Tinjauan manusia
- Ya
Kepercayaan dan risiko
- Kepercayaan
- 66/100
- Audit
- 83/100
- Tingkat risiko
- Berisiko
Lingkar hasil
- Endpoint
- /api/agent/outcome
- ID event
- resolve
- Hasil
- 5
Perintah pemasangan
npx skills add trailofbits/skills --skill audit-prep-assistantJangan gunakan ketika
- Tim yang membutuhkan SLA dengan dukungan vendor
- production agents without a repository review
- The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
- No OpenAgentSkill engagement data yet
- Audit risk risky exceeds max_risk=medium
Keamanan Agent v2
51/100 · Hindari pemasangan otomatis
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Tinggi
Eksekusi shell atau perintah
Metadata skill merujuk terminal, CLI, shell, subprocess, atau alur kerja eksekusi perintah.
Sedang
Akses jaringan
Skill kemungkinan mengambil halaman jarak jauh, API, repositori, atau layanan eksternal.
Sedang
Akses sistem file
Skill dapat membaca atau menulis file proyek, dokumen, artefak yang dihasilkan, atau status workspace lokal.
Sedang
Akses database
Skill dapat memeriksa skema, mengkueri database, atau bekerja dengan penyimpanan persisten.
- Audit risk risky exceeds max_risk=medium
- Petunjuk izin berisiko tinggi: eksekusi shell atau perintah
- Permission surface may require sandboxing
Rencana resolusi Agent
Biarkan Agent memverifikasi kecocokan sebelum memasang.
API Resolve mengembalikan skill utama, alternatif, kebijakan keamanan, catatan audit, target pemasangan, dan prompt siap pakai.
Buka JSON
/api/agent/resolve?task=Use%20audit-prep-assistant%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Teks Resolve
/api/agent/resolve?task=Use%20audit-prep-assistant%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Serah-terima pemasangan
/api/skills/trailofbits-audit-prep-assistant/install
Agent harus memeriksa
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Salin prompt
Task: Use audit-prep-assistant in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20audit-prep-assistant%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-audit-prep-assistant/install
Install command: npx skills add trailofbits/skills --skill audit-prep-assistant
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Serah-terima Agent
Berikan jalur pemasangan kepada Agent, bukan direktori lain.
Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.
Serah-terima pemasangan
/api/skills/trailofbits-audit-prep-assistant/install
Format teks LLM
/api/skills/trailofbits-audit-prep-assistant/install?format=text
Cari alternatif
/api/skills/search?q=audit-prep-assistant&limit=3
Prompt Agent
Use audit-prep-assistant for this task. Review https://www.openagentskill.com/api/skills/trailofbits-audit-prep-assistant/install, then install with: npx skills add trailofbits/skills --skill audit-prep-assistantMetadata Registry
Profil yang dapat dibaca Agent untuk pemilihan skill otomatis.
API Registry menyediakan sinyal keputusan, kepercayaan, audit, use case, dan pemasangan tanpa mengikis UI.
Manifest
/api/registry/manifest/trailofbits-audit-prep-assistant
Teks LLM
/api/registry/manifest/trailofbits-audit-prep-assistant?format=text
Alias pemasangan
/api/registry/install/trailofbits-audit-prep-assistant
Rekomendasikan
/api/registry/recommend?task=Use%20audit-prep-assistant%20in%20an%20agent%20workflow&limit=3
Kecocokan Agent
GitHub automation
Platform
Claude Code
Laporan audit
Berisiko · 83/100
Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Panel keputusan Agent
Pilihan utama untuk GitHub automation
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Peran di stack
Pilihan utama
Kecocokan utama
GitHub automation
Label kepercayaan
Siap produksi
Jalur pemasangan
Perintah siap
Gunakan saat
- alur kerja GitHub automation
- Tim Claude Code
- Tim yang menghargai sinyal adopsi GitHub
Bukti
- 6,823 star GitHub
- recent repository activity
- install command or GitHub repo available
- profil kualitas 85/100
tinjau dulu
- The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
- No OpenAgentSkill engagement data yet
Jalur implementasi
- 1Pasang di Agent sandbox dan jalankan satu tugas GitHub automation dari awal hingga akhir.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Profil kepercayaan
Hanya sandbox
Kandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.
Adopsi GitHub
Lulus6.8K star GitHub
Aktivitas star/fork
Lulus6.8K star dan 585 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
LulusDiperbarui hari ini
Kejelasan lisensi
LulusCC-BY-SA-4.0
Sinyal positif
- Tinjauan AI disetujui
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Repositori yang baru dipelihara
- Large GitHub adoption signal
- Perintah pemasangan tidak memiliki pola berisiko tinggi yang jelas
- Loop hasil siap tetapi membutuhkan eksekusi Agent nyata pertama
Tinjau sebelum memasang
- The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
- Financial research output is not financial advice; require human review before any live investment decision.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Permission surface: shell or command execution, filesystem or document access
- Belum ada laporan hasil Agent nyata
- Tinjauan manusia diperlukan sebelum pemasangan tanpa pengawasan
Tindakan yang disarankan
Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.
Profil kualitas
Sangat baik kandidat untuk alur kerja Agent
High-confidence pick with strong adoption and healthy maintenance signals.
Kecocokan alur kerja
Gunakan skill ini pada skenario berikut
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Search private knowledge
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Kecocokan alur kerja
Tambahkan ke alur kerja lengkap
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Daftar alternatif
Bandingkan sebelum memasang
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Ringkasan
--- name: audit-prep-assistant description: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). ---
# Audit Prep Assistant
## Purpose
Helps prepare for a security review using Trail of Bits' checklist. A well-prepared codebase makes the review process smoother and more effective.
**Use this**: 1-2 weeks before your security audit
---
## The Preparation Process
### Step 1: Set Review Goals
Helps define what you want from the review:
**Key Questions**: - What's the overall security level you're aiming for? - What areas concern you most? - Previous audit issues? - Complex components? - Fragile parts? - What's the worst-case scenario for your project?
Documents goals to share with the assessment team.
---
### Step 2: Resolve Easy Issues
Runs static analysis and helps fix low-hanging fruit:
**Run Static Analysis**:
For Solidity: ```bash slither . --exclude-dependencies ```
For Rust: ```bash dylint --all ```
For Go: ```bash golangci-lint run ```
For Go/Rust/C++: ```bash # CodeQL and Semgrep checks ```
Then I'll: - Triage all findings - Help fix easy issues - Document accepted risks
**Increase Test Coverage**: - Analyze current coverage - Identify untested code - Suggest new tests - Run full test suite
**Remove Dead Code**: - Find unused functions/variables - Identify unused libraries - Locate stale features - Suggest cleanup
**Goal**: Clean static analysis report, high test coverage, minimal dead code
---
### Step 3: Ensure Code Accessibility
Helps make code clear and accessible:
**Provide Detailed File List**: - List all files in scope - Mark out-of-scope files - Explain folder structure - Document dependencies
**Create Build Instructions**: - Write step-by-step setup guide - Test on fresh environment - Document dependencies and versions - Verify build succeeds
**Freeze Stable Version**: - Identify commit hash for review - Create dedicated branch - Tag release version - Lock dependencies
**Identify Boilerplate**: - Mark copied/forked code - Highlight your modifications - Document third-party code - Focus review on your code
---
### Step 4: Generate Documentation
Helps create documentation:
**Flowcharts and Sequence Diagrams**: - Map primary workflows - Show component relationships - Visualize data flow - Identify critical paths
**User Stories**: - Define user roles - Document use cases - Explain interactions - Clarify expectations
**On-chain/Off-chain Assumptions**: - Data validation procedures - Oracle information - Bridge assumptions - Trust boundaries
**Actors and Privileges**: - List all actors - Document roles - Define privileges - Map access controls
**External Developer Docs**: - Link docs to code - Keep synchronized - Explain architecture - Document APIs
**Function Documentation**: - System and function invariants - Parameter ranges (min/max values) - Arithmetic formulas and precision loss - Complex logic explanations - NatSpec for Solidity
**Glossary**: - Define domain terms - Explain acronyms - Consistent terminology - Business logic concepts
**Video Walkthroughs** (optional): - Complex workflows - Areas of concern - Architecture overview
---
## How I Work
When invoked, I will:
1. **Help set review goals** - Ask about concerns and document them 2. **Run static analysis** - Execute appropriate tools for your platform 3. **Analyze test coverage** - Identify gaps and suggest improvements 4. **Find dead code** - Search for unused code and libraries 5. **Review accessibility** - Check build instructions and scope clarity 6. **Generate documentation** - Create flowcharts, user stories, glossaries 7. **Create prep checklist** - Track what's done and what's remaining
Adapts based on: - Your platform (Solidity, Rust, Go, etc.) - Available tools - Existing documentation - Review timeline
---
## Rationalizations (Do Not Skip)
| Rationalization | Why It's Wrong | Required Action | |-----------------|----------------|-----------------| | "README covers setup, no need for detailed build instructions" | READMEs assume context auditors don't have | Test build on fresh environment, document every dependency version | | "Static analysis already ran, no need to run again" | Codebase changed since last run | Execute static analysis tools, generate fresh report | | "Test coverage looks decent" | "Looks decent" isn't measured coverage | Run coverage tools, identify specific untested code paths | | "Not much dead code to worry about" | Dead code hides during manual review | Use automated detection tools to find unused functions/variables | | "Architecture is straightforward, no diagrams needed" | Text descriptions miss visual patterns | Generate actual flowcharts and sequence diagrams | | "Can freeze version right before audit" | Last-minute freezing creates rushed handoff | Identify and document commit hash now, create dedicated branch | | "Terms are self-explanatory" | Domain knowledge isn't universal | Create comprehensive glossary with all domain-specific terms | | "I'll do this step later" | Steps build on each other - skipping creates gaps | Complete all 4 steps sequentially, track progress with checklist |
---
## Example Output
When I finish helping you prepare, you'll have concrete deliverables like:
``` === AUDIT PREP PACKAGE ===
Project: DeFi DEX Protocol Audit Date: March 15, 2024 Preparation Status: Complete
---
## REVIEW GOALS DOCUMENT
Security Objectives: - Verify economic security of liquidity pool swaps - Validate oracle manipulation resistance - Assess flash loan attack vectors
Areas of Concern: 1. Complex AMM pricing calculation (src/SwapRouter.sol:89-156) 2. Multi-hop swap routing logic (src/Router.sol) 3. Oracle price aggregation (src/PriceOracle.sol:45-78)
Worst-Case Scenario: - Flash loan attack drains liquidity pools via oracle manipulation
Questions for Auditors: - Can the AMM pricing model produce negative slippage under edge cases? - Is the slippage protection sufficient to prevent sandwich attacks? - How resilient is the system to temporary oracle failures?
---
## STATIC ANALYSIS REPORT
Slither Scan Results: ✓ High: 0 issues ✓ Medium: 0 issues ⚠ Low: 2 issues (triaged - documented in TRIAGE.md) ℹ Info: 5 issues (code style, acceptable)
Tool: slither . --exclude-dependencies Date: March 1, 2024 Status: CLEAN (all critical issues resolved)
---
## TEST COVERAGE REPORT
Overall Coverage: 94% - Statements: 1,245 / 1,321 (94%) - Branches: 456 / 498 (92%) - Functions: 89 / 92 (97%)
Uncovered Areas: - Emergency pause admin functions (tested manually) - Governance migration path (one-time use)
Command: forge coverage Status: EXCELLENT
---
## CODE SCOPE
In-Scope Files (8): ✓ src/SwapRouter.sol (456 lines) ✓ src/LiquidityPool.sol (234 lines) ✓ src/PairFactory.sol (389 lines) ✓ src/PriceOracle.sol (167 lines) ✓ src/LiquidityManager.sol (298 lines) ✓ src/Governance.sol (201 lines) ✓ src/FlashLoan.sol (145 lines) ✓ src/RewardsDistributor.sol (178 lines)
Out-of-Scope: - lib/ (OpenZeppelin, external dependencies) - test/ (test contracts) - scripts/ (deployment scripts)
Total In-Scope: 2,068 lines of Solidity
---
## BUILD INSTRUCTIONS
Prerequisites: - Foundry 0.2.0+ - Node.js 18+ - Git
Setup: ```bash git clone https://github.com/project/repo.git cd repo git checkout audit-march-2024 # Frozen branch forge install forge build forge test ```
Verification: ✓ Build succeeds without errors ✓ All 127 tests pass ✓ No warnings from compiler
---
## DOCUMENTATION
Generated Artifacts: ✓ ARCHITECTURE.md - System overview with diagrams ✓ USER_STORIES.md - 12 user interaction flows ✓ GLOSSARY.md - 34 domain terms defined ✓ docs/diagrams/contract-interactions.png ✓ docs/diagrams/swap-flow.png ✓ docs/diagrams/state-machine.png
NatSpec Coverage: 100% of public functions
---
## DEPLOYMENT INFO
Network: Ethereum Mainnet Commit: abc123def456 (audit-march-2024 branch) Deployed Contracts: - SwapRouter: 0x1234... - PriceOracle: 0x5678... [... etc]
---
PACKAGE READY FOR AUDIT ✓ Next Step: Share with Trail of Bits assessment team ```
---
## What You'll Get
**Review Goals Document**: - Security objectives - Areas of concern - Worst-case scenarios - Questions for auditors
**Clean Codebase**: - Triaged static analysis (or clean report) - High test coverage - No dead code - Clear scope
**Accessibility Package**: - File list with scope - Build instructions - Frozen commit/branch - Boilerplate identified
**Documentation Suite**: - Flowcharts and diagrams - User stories - Architecture docs - Actor/privilege map - Inline code comments - Glossary - Video walkthroughs (if created)
**Audit Prep Checklist**: - [ ] Review goals documented - [ ] Static analysis clean/triaged - [ ] Test coverage >80% - [ ] Dead code removed - [ ] Build instructions verified - [ ] Stable version frozen - [ ] Flowcharts created - [ ] User stories documented - [ ] Assumptions documented - [ ] Actors/privileges listed - [ ] Function docs complete - [ ] Glossary created
---
## Timeline
**2 weeks before audit**: - Set review goals - Run static analysis - Start fixing issues
**1 week before audit**: - Increase test coverage - Remove dead code - Freeze stable version - Start documentation
**Few days before audit**: - Complete documentation - Verify build instructions - Create final checklist - Send package to auditors
---
## Ready to Prep
Let me know when you're ready and I'll help you prepare for your security review!
Detail teknis
- Versi
- 1.0.0
- Lisensi
- CC-BY-SA-4.0
- Pembaruan terakhir
- 24 Agu 2026
- Diterbitkan
- 24 Agu 2026
Ringkasan keputusan
Pilihan utama
6,823 star GitHub
Audit
Tinjauan pemasangan
Tinjauan pemasangan dan adopsi
- Keamanan
- 75/100
- Pemeliharaan
- 100/100
- Pasang
- 92/100
Bukti tervalidasi Agent
Bukti tervalidasi Agent
Laporan hasil setelah resolve, tinjau, pasang, dan satu eksekusi terbatas.
- Tingkat sukses
- —
- Kegagalan terbaru
- —
- Hasil
- 0
- Kualitas output
- —
- Gagal
- 0
- Tidak relevan
- 0
- Pemasangan
- 0
- Diblokir risiko
- 0
- Perlu penyiapan
- 0
- Produksi
- 0
Belum ada data hasil Agent. Eksekusi pertama dapat melaporkan keberhasilan, kebutuhan setup, blok risiko, kegagalan, atau tidak relevan melalui /api/agent/outcome.
Pasang
Tambahkan ke alur Agent
Gratis dan sumber terbuka. Tinjau laporan sebelum memasang pada Agent produksi.
Siklus pertumbuhan
Kit berbagi
Draf berbasis skenario untuk audit-prep-assistant, siap untuk posting manual di X.
audit-prep-assistant: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals... 6.8K stars https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant?ref=x
Balasan opsional dengan perintah pemasangan
Listing + install path for audit-prep-assistant: https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant?ref=x Install: npx skills add trailofbits/skills --skill audit-prep-assistant
Sumber listing
Diindeks Registry
Listing ini diindeks dari sumber publik dan belum ditandai resmi hingga klaim pemelihara disetujui.
- Kreator
- trailofbits
- Sumber
- trailofbits/skills
- Diindeks oleh
- Indeks komunitas OpenAgentSkill
Atribusi menautkan ke repositori publik atau profil kreator. Kreator dapat mengklaim listing untuk memperbarui sinyal kepemilikan.
Klaim skill iniKlaim pemilik
Klaim listing skill ini
Listing Diindeks Registry ini dikaitkan dengan trailofbits, tetapi belum ditandai resmi. Klaim untuk menambahkan sinyal pemilik terverifikasi dan membuat pembaruan peluncuran, pemasangan, serta audit berikutnya lebih tepercaya.
Kit backlink kreator
Tambahkan badge bukti ke README Anda
Tampilkan listing kanonis, sinyal kepercayaan dan audit saat ini, serta bukti Agent-Proven nyata di tempat pengembang mengevaluasi repositori.
[](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)
[](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)
[](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant/audit)
[](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)Penulis
trailofbits
@trailofbits
Tag
Kecocokan platform
Sinyal kesehatan
- Star GitHub
- 6.8K
- Skor kualitas
- 50/100
- Push GitHub terakhir
- 24 Agu 2026
- Petunjuk framework
- Tidak diketahui
- Tampilan OpenAgentSkill
- 0
- Salinan pemasangan
- 0
- Klik keluar
- 0
Sinyal komunitas
Bagikan apakah skill ini bermanfaat untuk alur kerja Agent Anda. Masukan gabungan meningkatkan peringkat dari waktu ke waktu.
Kepercayaan & keamanan
Hanya sandbox
- Adopsi GitHub6.8K star GitHubLulus
- Aktivitas star/fork6.8K star dan 585 fork; aktivitas issue tidak tersedia dalam metadata saat iniLulus
- Pemeliharaan terbaruDiperbarui hari iniLulus
- Kejelasan lisensiCC-BY-SA-4.0Lulus
- Kelengkapan README/SKILL.mdMetadata memuat konteks penggunaan dan alur kerja yang cukupLulus
- Risiko dependensi/runtimecommand execution surface, database surfaceInfo
Skill terkait
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Star