Trail of Bits Skills
Leading#6 in Skillsmedium confidence
Security-focused SKILL.md skills from a top audit firm (~6k★) — CodeQL and Semgrep vulnerability detection wired into the agent's workflow. Niche but high-signal.Our read
Why it ranks #6
~6.2k GitHub stars are modest beside general coding tools, but Trail of Bits' security-audit reputation and specialized CodeQL/Semgrep workflows give this collection unusually high signal in its niche.Here is the catch
niche collection rather than a general coding toolkit
effective use requires security-domain expertise
some workflows depend on heavyweight external analysis tools
Does this well
authored by a respected security research and audit firm
encodes concrete specialist workflows rather than generic prompts
valuable for repeatable vulnerability-analysis tasks
Pricing
Checked by hand on 2026-07-23. Prices in this category change often — if this looks wrong, it probably is.
Key features
CodeQL vulnerability workflowsSemgrep rule developmentsecurity audit methodologysmart-contract and systems analysis
Sources we read
Quick facts
More in this area
The rest of the Skills column.- 1SuperpowersThe recognized leader of the Claude Code skills ecosystem (~260k★): composable SKILL.md skills chaining brainstorming, planning, subagent-driven TDD and code review.
- 2Anthropic Skills (official)Anthropic's official SKILL.md skill library (~164k★) — production-grade skills like webapp testing, MCP-server building and document editing that any agent can load.
- 3awesome-claude-skillsThe most-starred curated directory of Agent Skills (~70k★): one place to discover and install community SKILL.md skills for coding and beyond.
- 4Vercel Agent SkillsVercel's official SKILL.md collection (~29k★): React/Next.js performance and composition best-practices plus project auditing and instant deploys.
- 5agentskills.io (open standard + registry)The open Agent Skills spec and directory (~23k★) — discover SKILL.md skills that work across Claude Code, Codex, Gemini CLI, Cursor and more.
- 7DietrichGebert/ponytailRuleset that pushes coding agents down a ladder — reuse, stdlib, one-liner — before writing new code, plus over-engineering review and audit commands.