‹ 返回总目录
开发工具 最近更新08-04

code-maturity-assessor

| 2026-08-01 收录

☆ 收藏
🛒 📚 AI提效实战指南 · 图解Skill🛒 📱 大流量手机卡 · 低月租📣 加入推广 · 佣金80-300/张 ›

🛍️ 更多精选好物 ›

📊 公开数据一览

📦 榜单安装量5.5K
⭐ GitHub Stars6,427(fork 555)
🗓️ 最近推送2026-08-04
🌱 项目创建2026-01-14
💻 语言 / LicensePython · CC-BY-SA-4.0
🐛 开放Issue42

📝 工具简介

Trail of Bits出品的Claude Code skills,专攻安全研究、漏洞检测和审计工作流。

📖 怎么用

安装方式和 codeql 一样,都是 Trail of Bits 的 marketplace。Claude Code 跑 `/plugin marketplace add trailofbits/skills` 再 `/plugin menu` 选装。Codex 跑 `codex plugin marketplace add trailofbits/skills` 然后 `codex plugin list` 和 `codex plugin add <plugin-name>@trailofbits`。本地装就 `cd /path/to/parent` 后 `/plugins marketplace add ./skills`。装好后直接用自然语言触发代码成熟度评估。

📋 迷你测评

Trail of Bits出的Claude Code技能,专攻安全研究和漏洞审计。亮点是背靠专业安全团队,工作流更靠谱。没给数字,但审计方向明确。

📄 README 要点

这也是Trail of Bits的插件市场,跟上面那个是同一个仓库,功能定位一样,都是给AI辅助安全分析、测试和开发加技能。安装方式也类似,Claude Code和Codex都能用。里面同样有智能合约安全工具,带漏洞扫描功能。适合安全工程师或者开发者,想用AI帮自己检查代码成熟度和安全性,尤其是智能合约这块,能省不少人工审查的时间。

查看英文原文
Trail of Bits Skills Marketplace A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility. Also see: claude code config · skills curated · claude code devcontainer · dropkit Installation Claude Code Marketplace [安装/使用命令见下方] Browse and Install Plugins [安装/使用命令见下方] Codex Codex supports Claude plugin marketplaces directly, so this repository does not need Codex specific sidecar metadata. Install the marketplace with: [安装/使用命令见下方] Local Development To add the marketplace locally (e.g., for testing or development), navigate to the parent directory of this repository: [安装/使用命令见下方] Available Plugins Smart Contract Security Plugin Description building secure contracts Smart contract security toolkit with vulnerability scanners for 6 blockchains entry point analyzer Identify state changing entry points in smart contracts for security auditing Code Auditing Plugin Description agentic actions auditor Audit GitHub Actions workflows for AI agent security vulnerabilities audit context building Build deep architectural context through ultra granular code analysis burpsuite project parser Search and extract data from Burp Suite project files c review Comprehensive C/C++ security review with clustered parallel workers and SARIF output differential review Security focused differential review of code changes with git history analysis dimensional analysis Annotate codebases with dimensional analysis comments to detect unit mismatches and formula bugs fp check Systematic false positive verification for security bug analysis with mandatory gate reviews insecure defaults Detect insecure default configurations, hardcoded credentials, and fail open security patterns rust review Comprehensive Rust security review covering safe/unsafe boundary, memory safety, concurrency, panic DoS, FFI, and async runtime with SARIF output semgr

💬 评论(0)

交流使用体验、避坑建议;违规内容将被删除

💬 意见反馈 / 联系客服

数据来源:skills.sh 榜单 + GitHub 公开数据,非人工实测,仅供参考