@trailofbits

创作者 · trailofbits

最近更新 · 2026年8月24日

audit-prep-assistant

审查 · 66已收录

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).

OpenAgentSkill 信任评分
66/100

仅限沙盒

质量85/100
审计83/100
Stars6.8K
Verified installs0

安装目标

Codex 安装提示词

Install the "audit-prep-assistant" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/audit-prep-assistant. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-audit-prep-assistant","task":"Install audit-prep-assistant","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.

供给资产档案

研究与知识工作

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

浏览赛道

场景

RAG and knowledge

I need my agent to build a RAG workflow over documents and retrieve reliable context.

适配 Agent

Claude Code + CLI + Codex

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add trailofbits/skills --skill audit-prep-assistant

维护状态

新鲜

今天有推送

风险

高风险

Permission surface may require sandboxing

GitHub 质量

6.8K

85/100 质量 · 74/100 信任

覆盖标签

研究RAG and knowledge安全agent-skill

审查说明

Permission surface may require sandboxing · Financial research output is not financial advice; require human review before any live investment decision

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

优秀
85

高置信候选,具有较强的采用度与健康维护信号。

信任

仅限沙盒
66

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

审计

高风险
83

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

仅限沙盒

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

6.8K 个 GitHub Stars

仓库活跃度

6.8K 个 Star,585 个 Fork

维护状态

今天有推送

许可证

CC-BY-SA-4.0

安装

npx skills add trailofbits/skills --skill audit-prep-assistant

安装安全性

标准软件包或运行时安装路径

权限范围

shell or command execution, filesystem or document access

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

View technical data+

适用任务

  • GitHub automation 工作流
  • Claude Code 团队
  • 重视 GitHub 采用信号的团队
  • Inspect repository metadata

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

安装决策

命令
npx skills add trailofbits/skills --skill audit-prep-assistant
策略
阻止
人工审查

信任与风险

信任
66/100
审计
83/100
风险级别
高风险

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add trailofbits/skills --skill audit-prep-assistant

不适用场景

  • 需要厂商支持 SLA 的团队
  • production agents without a repository review
  • The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
  • 暂未有 OpenAgentSkill 使用反馈数据
  • Audit risk risky exceeds max_risk=medium

Agent 安全 v2

51/100 · 避免自动安装

Blocked for auto-install阻止

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

数据库访问

Skill 可能检查 Schema、查询数据库或处理持久化存储。

  • Audit risk risky exceeds max_risk=medium
  • 高风险权限提示:Shell 或命令执行
  • Permission surface may require sandboxing

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use audit-prep-assistant in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20audit-prep-assistant%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-audit-prep-assistant/install
Install command: npx skills add trailofbits/skills --skill audit-prep-assistant
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use audit-prep-assistant for this task. Review https://www.openagentskill.com/api/skills/trailofbits-audit-prep-assistant/install, then install with: npx skills add trailofbits/skills --skill audit-prep-assistant

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

96/100

GitHub automation

平台

Claude Code

审计报告

高风险 · 83/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

适合 GitHub automation 的首选

将其作为优先候选,再在你的 Agent 环境中验证 README 与安装路径。

96
就绪度
采用
阶段

栈中角色

首选

主要匹配

GitHub automation

信任标签

可用于生产

安装路径

命令已就绪

适用场景

  • GitHub automation 工作流
  • Claude Code 团队
  • 重视 GitHub 采用信号的团队

证据

  • 6,823 个 GitHub Stars
  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 85/100 质量档案

先审查

  • The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
  • 暂未有 OpenAgentSkill 使用反馈数据

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

仅限沙盒

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

66
OpenAgentSkill 信任评分

GitHub 采用度

通过

6.8K 个 GitHub Stars

Star/Fork 活跃度

通过

6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

今天有推送

许可证清晰度

通过

CC-BY-SA-4.0

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • Large GitHub adoption signal
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Permission surface: shell or command execution, filesystem or document access
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

质量档案

优秀 适用于 Agent 工作流的候选

高置信候选,具有较强的采用度与健康维护信号。

85
GitHub Stars
6.8K
新鲜度
今天
安装就绪
许可证
CC-BY-SA-4.0
安装前审查: The SKILL.md excerpt in the prompt is truncated, but the full file appears complete and well-structured.

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: audit-prep-assistant description: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). ---

# Audit Prep Assistant

## Purpose

Helps prepare for a security review using Trail of Bits' checklist. A well-prepared codebase makes the review process smoother and more effective.

**Use this**: 1-2 weeks before your security audit

---

## The Preparation Process

### Step 1: Set Review Goals

Helps define what you want from the review:

**Key Questions**: - What's the overall security level you're aiming for? - What areas concern you most? - Previous audit issues? - Complex components? - Fragile parts? - What's the worst-case scenario for your project?

Documents goals to share with the assessment team.

---

### Step 2: Resolve Easy Issues

Runs static analysis and helps fix low-hanging fruit:

**Run Static Analysis**:

For Solidity: ```bash slither . --exclude-dependencies ```

For Rust: ```bash dylint --all ```

For Go: ```bash golangci-lint run ```

For Go/Rust/C++: ```bash # CodeQL and Semgrep checks ```

Then I'll: - Triage all findings - Help fix easy issues - Document accepted risks

**Increase Test Coverage**: - Analyze current coverage - Identify untested code - Suggest new tests - Run full test suite

**Remove Dead Code**: - Find unused functions/variables - Identify unused libraries - Locate stale features - Suggest cleanup

**Goal**: Clean static analysis report, high test coverage, minimal dead code

---

### Step 3: Ensure Code Accessibility

Helps make code clear and accessible:

**Provide Detailed File List**: - List all files in scope - Mark out-of-scope files - Explain folder structure - Document dependencies

**Create Build Instructions**: - Write step-by-step setup guide - Test on fresh environment - Document dependencies and versions - Verify build succeeds

**Freeze Stable Version**: - Identify commit hash for review - Create dedicated branch - Tag release version - Lock dependencies

**Identify Boilerplate**: - Mark copied/forked code - Highlight your modifications - Document third-party code - Focus review on your code

---

### Step 4: Generate Documentation

Helps create documentation:

**Flowcharts and Sequence Diagrams**: - Map primary workflows - Show component relationships - Visualize data flow - Identify critical paths

**User Stories**: - Define user roles - Document use cases - Explain interactions - Clarify expectations

**On-chain/Off-chain Assumptions**: - Data validation procedures - Oracle information - Bridge assumptions - Trust boundaries

**Actors and Privileges**: - List all actors - Document roles - Define privileges - Map access controls

**External Developer Docs**: - Link docs to code - Keep synchronized - Explain architecture - Document APIs

**Function Documentation**: - System and function invariants - Parameter ranges (min/max values) - Arithmetic formulas and precision loss - Complex logic explanations - NatSpec for Solidity

**Glossary**: - Define domain terms - Explain acronyms - Consistent terminology - Business logic concepts

**Video Walkthroughs** (optional): - Complex workflows - Areas of concern - Architecture overview

---

## How I Work

When invoked, I will:

1. **Help set review goals** - Ask about concerns and document them 2. **Run static analysis** - Execute appropriate tools for your platform 3. **Analyze test coverage** - Identify gaps and suggest improvements 4. **Find dead code** - Search for unused code and libraries 5. **Review accessibility** - Check build instructions and scope clarity 6. **Generate documentation** - Create flowcharts, user stories, glossaries 7. **Create prep checklist** - Track what's done and what's remaining

Adapts based on: - Your platform (Solidity, Rust, Go, etc.) - Available tools - Existing documentation - Review timeline

---

## Rationalizations (Do Not Skip)

| Rationalization | Why It's Wrong | Required Action | |-----------------|----------------|-----------------| | "README covers setup, no need for detailed build instructions" | READMEs assume context auditors don't have | Test build on fresh environment, document every dependency version | | "Static analysis already ran, no need to run again" | Codebase changed since last run | Execute static analysis tools, generate fresh report | | "Test coverage looks decent" | "Looks decent" isn't measured coverage | Run coverage tools, identify specific untested code paths | | "Not much dead code to worry about" | Dead code hides during manual review | Use automated detection tools to find unused functions/variables | | "Architecture is straightforward, no diagrams needed" | Text descriptions miss visual patterns | Generate actual flowcharts and sequence diagrams | | "Can freeze version right before audit" | Last-minute freezing creates rushed handoff | Identify and document commit hash now, create dedicated branch | | "Terms are self-explanatory" | Domain knowledge isn't universal | Create comprehensive glossary with all domain-specific terms | | "I'll do this step later" | Steps build on each other - skipping creates gaps | Complete all 4 steps sequentially, track progress with checklist |

---

## Example Output

When I finish helping you prepare, you'll have concrete deliverables like:

``` === AUDIT PREP PACKAGE ===

Project: DeFi DEX Protocol Audit Date: March 15, 2024 Preparation Status: Complete

---

## REVIEW GOALS DOCUMENT

Security Objectives: - Verify economic security of liquidity pool swaps - Validate oracle manipulation resistance - Assess flash loan attack vectors

Areas of Concern: 1. Complex AMM pricing calculation (src/SwapRouter.sol:89-156) 2. Multi-hop swap routing logic (src/Router.sol) 3. Oracle price aggregation (src/PriceOracle.sol:45-78)

Worst-Case Scenario: - Flash loan attack drains liquidity pools via oracle manipulation

Questions for Auditors: - Can the AMM pricing model produce negative slippage under edge cases? - Is the slippage protection sufficient to prevent sandwich attacks? - How resilient is the system to temporary oracle failures?

---

## STATIC ANALYSIS REPORT

Slither Scan Results: ✓ High: 0 issues ✓ Medium: 0 issues ⚠ Low: 2 issues (triaged - documented in TRIAGE.md) ℹ Info: 5 issues (code style, acceptable)

Tool: slither . --exclude-dependencies Date: March 1, 2024 Status: CLEAN (all critical issues resolved)

---

## TEST COVERAGE REPORT

Overall Coverage: 94% - Statements: 1,245 / 1,321 (94%) - Branches: 456 / 498 (92%) - Functions: 89 / 92 (97%)

Uncovered Areas: - Emergency pause admin functions (tested manually) - Governance migration path (one-time use)

Command: forge coverage Status: EXCELLENT

---

## CODE SCOPE

In-Scope Files (8): ✓ src/SwapRouter.sol (456 lines) ✓ src/LiquidityPool.sol (234 lines) ✓ src/PairFactory.sol (389 lines) ✓ src/PriceOracle.sol (167 lines) ✓ src/LiquidityManager.sol (298 lines) ✓ src/Governance.sol (201 lines) ✓ src/FlashLoan.sol (145 lines) ✓ src/RewardsDistributor.sol (178 lines)

Out-of-Scope: - lib/ (OpenZeppelin, external dependencies) - test/ (test contracts) - scripts/ (deployment scripts)

Total In-Scope: 2,068 lines of Solidity

---

## BUILD INSTRUCTIONS

Prerequisites: - Foundry 0.2.0+ - Node.js 18+ - Git

Setup: ```bash git clone https://github.com/project/repo.git cd repo git checkout audit-march-2024 # Frozen branch forge install forge build forge test ```

Verification: ✓ Build succeeds without errors ✓ All 127 tests pass ✓ No warnings from compiler

---

## DOCUMENTATION

Generated Artifacts: ✓ ARCHITECTURE.md - System overview with diagrams ✓ USER_STORIES.md - 12 user interaction flows ✓ GLOSSARY.md - 34 domain terms defined ✓ docs/diagrams/contract-interactions.png ✓ docs/diagrams/swap-flow.png ✓ docs/diagrams/state-machine.png

NatSpec Coverage: 100% of public functions

---

## DEPLOYMENT INFO

Network: Ethereum Mainnet Commit: abc123def456 (audit-march-2024 branch) Deployed Contracts: - SwapRouter: 0x1234... - PriceOracle: 0x5678... [... etc]

---

PACKAGE READY FOR AUDIT ✓ Next Step: Share with Trail of Bits assessment team ```

---

## What You'll Get

**Review Goals Document**: - Security objectives - Areas of concern - Worst-case scenarios - Questions for auditors

**Clean Codebase**: - Triaged static analysis (or clean report) - High test coverage - No dead code - Clear scope

**Accessibility Package**: - File list with scope - Build instructions - Frozen commit/branch - Boilerplate identified

**Documentation Suite**: - Flowcharts and diagrams - User stories - Architecture docs - Actor/privilege map - Inline code comments - Glossary - Video walkthroughs (if created)

**Audit Prep Checklist**: - [ ] Review goals documented - [ ] Static analysis clean/triaged - [ ] Test coverage >80% - [ ] Dead code removed - [ ] Build instructions verified - [ ] Stable version frozen - [ ] Flowcharts created - [ ] User stories documented - [ ] Assumptions documented - [ ] Actors/privileges listed - [ ] Function docs complete - [ ] Glossary created

---

## Timeline

**2 weeks before audit**: - Set review goals - Run static analysis - Start fixing issues

**1 week before audit**: - Increase test coverage - Remove dead code - Freeze stable version - Start documentation

**Few days before audit**: - Complete documentation - Verify build instructions - Create final checklist - Send package to auditors

---

## Ready to Prep

Let me know when you're ready and I'll help you prepare for your security review!

技术详情

版本
1.0.0
许可证
CC-BY-SA-4.0
最近更新
2026年8月24日
发布时间
2026年8月24日

决策摘要

首选

96
就绪
采用
阶段

6,823 个 GitHub Stars

审计

安装审查

安装与采用审查

83
高风险
安全性
75/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 audit-prep-assistant 准备的场景化草稿,可手动发布到 X。

策展说明
audit-prep-assistant: Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals...

6.8K stars

https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for audit-prep-assistant:
https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant?ref=x

Install: npx skills add trailofbits/skills --skill audit-prep-assistant
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
trailofbits
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 trailofbits,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/trailofbits-audit-prep-assistant?metric=listed&label=Listed)](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/trailofbits-audit-prep-assistant?metric=trust&label=Trust)](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/trailofbits-audit-prep-assistant?metric=audit&label=Audit)](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/trailofbits-audit-prep-assistant?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/trailofbits-audit-prep-assistant)

作者

T

trailofbits

@trailofbits

平台适配

健康信号

GitHub Stars
6.8K
质量评分
50/100
最近 GitHub 推送
2026年8月24日
框架提示
未知
OpenAgentSkill 浏览量
0
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

仅限沙盒

66
  • GitHub 采用度6.8K 个 GitHub Stars通过
  • Star/Fork 活跃度6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息通过
  • 近期维护今天有推送通过
  • 许可证清晰度CC-BY-SA-4.0通过
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险command execution surface, database surface信息