创作者 · trailofbits
最近更新 · 2026年8月24日
code-maturity-assessor
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing. Produces professional scorecard with e
审查后安装
安装目标
Codex 安装提示词
Install the "code-maturity-assessor" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/code-maturity-assessor. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing. Produces professional scorecard with evidence-based ratings and actionable recommendations. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-code-maturity-assessor","task":"Install code-maturity-assessor","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.供给资产档案
研究与知识工作
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
场景
研究 Agent
I need my agent to research a topic, compare sources, and produce a concise report.
适配 Agent
Claude Code + CLI + Codex
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add trailofbits/skills --skill code-maturity-assessor
维护状态
新鲜
今天有推送
风险
需审查
Financial research output is not financial advice; require human review before any live investment decision
GitHub 质量
6.8K
86/100 质量 · 87/100 信任
覆盖标签
审查说明
Financial research output is not financial advice; require human review before any live investment decision · Financial research output is not financial advice; require human review before any live investment decision.
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
优秀高置信候选,具有较强的采用度与健康维护信号。
信任
审查后安装适合加入候选清单,但 Agent 在运行前应审查审计说明、安装策略和结果证据。
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
在人工审查或沙盒验证后作为首选候选。
Stars
6.8K 个 GitHub Stars
仓库活跃度
6.8K 个 Star,585 个 Fork
维护状态
今天有推送
许可证
CC-BY-SA-4.0
安装
npx skills add trailofbits/skills --skill code-maturity-assessor
安装安全性
标准软件包或运行时安装路径
权限范围
文件系统或文档访问
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
View technical data+
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- 研究 Agent 工作流
- Claude Code 团队
- 重视 GitHub 采用信号的团队
- 检索来源
适用 Agent
安装决策
- 命令
- npx skills add trailofbits/skills --skill code-maturity-assessor
- 策略
- 审查
- 人工审查
- 是
信任与风险
- 信任
- 79/100
- 审计
- 89/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- 没有内部安全审查的高合规环境
- 暂未有 OpenAgentSkill 使用反馈数据
- Financial research output is not financial advice; require human review before any live investment decision
- Financial research output is not financial advice; require human review before any live investment decision.
Agent 安全 v2
73/100 · 安装前审查
可用候选,但 Agent 在安装前应展示权限与审计说明。
在真实工作区安装前需要人工批准。
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- Financial research output is not financial advice; require human review before any live investment decision
Agent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20code-maturity-assessor%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20code-maturity-assessor%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/trailofbits-code-maturity-assessor/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use code-maturity-assessor in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-maturity-assessor%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-code-maturity-assessor/install
Install command: npx skills add trailofbits/skills --skill code-maturity-assessor
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/trailofbits-code-maturity-assessor/install
LLM 文本格式
/api/skills/trailofbits-code-maturity-assessor/install?format=text
寻找替代方案
/api/skills/search?q=code-maturity-assessor&limit=3
Agent 提示词
Use code-maturity-assessor for this task. Review https://www.openagentskill.com/api/skills/trailofbits-code-maturity-assessor/install, then install with: npx skills add trailofbits/skills --skill code-maturity-assessorRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Agent 决策面板
适合 研究 Agent 的首选
将其作为优先候选,再在你的 Agent 环境中验证 README 与安装路径。
栈中角色
首选
主要匹配
研究 Agent
信任标签
可用于生产
安装路径
命令已就绪
适用场景
- 研究 Agent 工作流
- Claude Code 团队
- 重视 GitHub 采用信号的团队
证据
- 6,823 个 GitHub Stars
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 86/100 质量档案
先审查
- 暂未有 OpenAgentSkill 使用反馈数据
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次研究 Agent任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
审查后安装
适合加入候选清单,但 Agent 在运行前应审查审计说明、安装策略和结果证据。
GitHub 采用度
通过6.8K 个 GitHub Stars
Star/Fork 活跃度
通过6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过今天有推送
许可证清晰度
通过CC-BY-SA-4.0
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- Large GitHub adoption signal
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
在人工审查或沙盒验证后作为首选候选。
质量档案
优秀 适用于 Agent 工作流的候选
高置信候选,具有较强的采用度与健康维护信号。
工作流匹配
在这些场景使用此 Skill
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Search private knowledge
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
工作流匹配
加入完整工作流
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
概览
--- name: code-maturity-assessor description: Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing. Produces professional scorecard with evidence-based ratings and actionable recommendations. ---
# Code Maturity Assessor
## Purpose
Systematically assesses codebase maturity using Trail of Bits' 9-category framework. Provides evidence-based ratings and actionable recommendations.
**Framework**: Building Secure Contracts - Code Maturity Evaluation v0.1.0
---
## How This Works
### Phase 1: Discovery Explores the codebase to understand: - Project structure and platform - Contract/module files - Test coverage - Documentation availability
### Phase 2: Analysis For each of 9 categories, I'll: - **Search the code** for relevant patterns - **Read key files** to assess implementation - **Present findings** with file references - **Ask clarifying questions** about processes I can't see in code - **Determine rating** based on criteria
### Phase 3: Report Generates: - Executive summary - Maturity scorecard (ratings for all 9 categories) - Detailed analysis with evidence - Priority-ordered improvement roadmap
---
## Rating System
- **Missing (0)**: Not present/not implemented - **Weak (1)**: Several significant improvements needed - **Moderate (2)**: Adequate, can be improved - **Satisfactory (3)**: Above average, minor improvements - **Strong (4)**: Exceptional, only small improvements possible
**Rating Logic**: - ANY "Weak" criteria → **Weak** - NO "Weak" + SOME "Moderate" unmet → **Moderate** - ALL "Moderate" + SOME "Satisfactory" met → **Satisfactory** - ALL "Satisfactory" + exceptional practices → **Strong**
---
## The 9 Categories
I assess 9 comprehensive categories covering all aspects of code maturity. For detailed criteria, analysis approaches, and rating thresholds, see [ASSESSMENT_CRITERIA.md](resources/ASSESSMENT_CRITERIA.md).
### Quick Reference:
**1. ARITHMETIC** - Overflow protection mechanisms - Precision handling and rounding - Formula specifications - Edge case testing
**2. AUDITING** - Event definitions and coverage - Monitoring infrastructure - Incident response planning
**3. AUTHENTICATION / ACCESS CONTROLS** - Privilege management - Role separation - Access control testing - Key compromise scenarios
**4. COMPLEXITY MANAGEMENT** - Function scope and clarity - Cyclomatic complexity - Inheritance hierarchies - Code duplication
**5. DECENTRALIZATION** - Centralization risks - Upgrade control mechanisms - User opt-out paths - Timelock/multisig patterns
**6. DOCUMENTATION** - Specifications and architecture - Inline code documentation - User stories - Domain glossaries
**7. TRANSACTION ORDERING RISKS** - MEV vulnerabilities - Front-running protections - Slippage controls - Oracle security
**8. LOW-LEVEL MANIPULATION** - Assembly usage - Unsafe code sections - Low-level calls - Justification and testing
**9. TESTING & VERIFICATION** - Test coverage - Fuzzing and formal verification - CI/CD integration - Test quality
For complete assessment criteria including what I'll analyze, what I'll ask you, and detailed rating thresholds (WEAK/MODERATE/SATISFACTORY/STRONG), see [ASSESSMENT_CRITERIA.md](resources/ASSESSMENT_CRITERIA.md).
---
## Example Output
When the assessment is complete, you'll receive a comprehensive maturity report including:
- **Executive Summary**: Overall score, top 3 strengths, top 3 gaps, priority recommendations - **Maturity Scorecard**: Table with all 9 categories rated with scores and notes - **Detailed Analysis**: Category-by-category breakdown with evidence (file:line references) - **Improvement Roadmap**: Priority-ordered recommendations (CRITICAL/HIGH/MEDIUM) with effort estimates
For a complete example assessment report, see [EXAMPLE_REPORT.md](resources/EXAMPLE_REPORT.md).
---
## Assessment Process
When invoked, I will:
1. **Explore codebase** - Find contract/module files - Identify test files - Locate documentation
2. **Analyze each category** - Search for relevant code patterns - Read key implementations - Assess against criteria - Collect evidence
3. **Interactive assessment** - Present my findings with file references - Ask about processes I can't see in code - Discuss borderline cases - Determine ratings together
4. **Generate report** - Executive summary - Maturity scorecard table - Detailed category analysis with evidence - Priority-ordered improvement roadmap
---
## Rationalizations (Do Not Skip)
| Rationalization | Why It's Wrong | Required Action | |-----------------|----------------|-----------------| | "Found some findings, assessment complete" | Assessment requires evaluating ALL 9 categories | Complete assessment of all 9 categories with evidence for each | | "I see events, auditing category looks good" | Events alone don't equal auditing maturity | Check logging comprehensiveness, testing, incident response processes | | "Code looks simple, complexity is low" | Visual simplicity masks composition complexity | Analyze cyclomatic complexity, dependency depth, state machine transitions | | "Not a DeFi protocol, MEV category doesn't apply" | MEV extends beyond DeFi (governance, NFTs, games) | Verify with transaction ordering analysis before declaring N/A | | "No assembly found, low-level category is N/A" | Low-level risks include external calls, delegatecall, inline assembly | Search for all low-level patterns before skipping category | | "This is taking too long" | Thorough assessment requires time per category | Complete all 9 categories, ask clarifying questions about off-chain processes | | "I can rate this without evidence" | Ratings without file:line references = unsubstantiated claims | Collect concrete code evidence for every category assessment | | "User will know what to improve" | Vague guidance = no action | Provide priority-ordered roadmap with specific improvements and effort estimates |
---
## Report Format
For detailed report structure and templates, see [REPORT_FORMAT.md](resources/REPORT_FORMAT.md).
### Structure:
1. **Executive Summary** - Project name and platform - Overall maturity (average rating) - Top 3 strengths - Top 3 critical gaps - Priority recommendations
2. **Maturity Scorecard** - Table with all 9 categories - Ratings and scores - Key findings notes
3. **Detailed Analysis** - Per-category breakdown - Evidence with file:line references - Gaps and improvement actions
4. **Improvement Roadmap** - CRITICAL (immediate) - HIGH (1-2 months) - MEDIUM (2-4 months) - Effort estimates and impact
---
## Ready to Begin
**Estimated Time**: 30-40 minutes
**I'll need**: - Access to full codebase - Your knowledge of processes (monitoring, incident response, team practices) - Context about the project (DeFi, NFT, infrastructure, etc.)
Let's assess this codebase!
技术详情
- 版本
- 1.0.0
- 许可证
- CC-BY-SA-4.0
- 最近更新
- 2026年8月24日
- 发布时间
- 2026年8月24日
决策摘要
首选
6,823 个 GitHub Stars
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 code-maturity-assessor 准备的场景化草稿,可手动发布到 X。
code-maturity-assessor: Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codeb... 6.8K stars https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor?ref=x
可选:带安装命令的回复
Listing + install path for code-maturity-assessor: https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor?ref=x Install: npx skills add trailofbits/skills --skill code-maturity-assessor
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- trailofbits
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 trailofbits,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor)
[](https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor)
[](https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor/audit)
[](https://www.openagentskill.com/skills/trailofbits-code-maturity-assessor)作者
trailofbits
@trailofbits
平台适配
健康信号
- GitHub Stars
- 6.8K
- 质量评分
- 50/100
- 最近 GitHub 推送
- 2026年8月24日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 0
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
审查后安装
- GitHub 采用度6.8K 个 GitHub Stars通过
- Star/Fork 活跃度6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息通过
- 近期维护今天有推送通过
- 许可证清晰度CC-BY-SA-4.0通过
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险公开元数据中未发现主要依赖风险提示通过
相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Stars