Graph Evolution

Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes. Detects new attack paths, complexity shifts, blast radius growth, taint propagation changes, and privilege boundary modifications that text diffs miss. Use when comparing c...

概览

Graph Evolution is a SKILL.md-based agent skill sourced from trailofbits/skills. It is categorized under security and is listed for Claude Code, Claude. The source description focuses on: Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes. Detects new attack paths, complexity shifts, blast radius growth, taint propagation changes, and privilege bound... AIToolly summarizes this page as a directory entry rather than copying the full third-party skill content, so users can evaluate the source, compatibility, and practical fit before installing it.

使用场景

Evaluate Graph Evolution before adding it to an AI agent workflow.
Use Graph Evolution as a starting point for repeatable security tasks.
Compare Graph Evolution with related skills from skills and other GitHub repositories.

安装说明

# Review source first
open https://github.com/trailofbits/skills/blob/main/plugins/trailmark/skills/graph-evolution/SKILL.md

Copy or clone the skill folder into your agent skills directory after reviewing its instructions and scripts.

安全提示

Review the source SKILL.md, referenced scripts, permissions, and external services before installing Graph Evolution. Treat third-party skills like code dependencies, especially when they can read files, call APIs, or run commands.

相关 Skills

Cargo Fuzz

trailofbits/skills

安全

cargo-fuzz 是使用 Cargo 的 Rust 项目的事实标准模糊测试工具。用于通过 libFuzzer 后端对 Rust 代码进行模糊测试。

Claude CodeClaude
securityresearch
6,407 Stars已链接来源

Yara Rule Authoring

trailofbits/skills

安全

指导编写用于恶意软件识别的高质量 YARA-X 检测规则。在编写、审查或优化 YARA 规则时使用。涵盖命名规范、字符串选择、性能优化、从旧版 YARA 迁移以及减少误报。触发词:YARA、YARA-X、恶意软件检测、威胁狩猎、IOC、签名、crx 模块、dex 模块。

Claude CodeClaude
designsecurity
6,407 Stars已链接来源

Agentforce D360 Analyze

forcedotcom/sf-skills

安全

单个 Agentforce 会话的 Data Cloud 360° 视图。当用户要求通过会话 ID(Agent Session UUID `019d…` 或 MessagingSession ID `0Mw…`)追踪、检查、总结或描述特定的 Agentforce 会话时,TRIGGER。当用户尚无会话 ID 时,也会在会话发现(按时间、代理、渠道、结果或对话文本查找/列出/搜索会话)时触发。对于设计时架构问题(请改用 agentforce-architecture-analyze)或运行时性能/日志,请 NOT TRIGGER。

pythondata
783 StarsApache-2.0

Security Audit

TerminalSkills/skills

安全

通过扫描 OWASP Top 10 漏洞、检查依赖项中的已知 CVE、检测泄露的机密和 API 密钥,并生成优先修复建议,对代码库进行全面的安全审计。此技能结合了静态分析模式与依赖项审计工具。

CodexClaude Code
securityaudit
72 StarsApache-2.0