Trail of Bits' security review skill for PRs, commits, and diffs: risk-first analysis with git history, blast radius, and honest coverage limits.
AppSec
Application security work: threat modelling, code-level vulnerability review and bug-bounty triage.
6 skills and 1 MCP server tagged AppSec.
Skills
OpenAI's skill for language- and framework-specific secure coding: detect the stack, load the matching reference guidance, then write secure-by-default code, flag critical issues passively, or produce a prioritised vulnerability report with fixes.
OpenAI's skill for repository-grounded threat modelling: derive trust boundaries, assets and attacker capabilities from the actual code, rank abuse paths by likelihood and impact, and write a reviewable Markdown threat model.
Skill: Zeroize Audit
by Trail of Bits
Finds secrets left in memory in C, C++ and Rust — including wipes the compiler deleted — and requires IR or assembly evidence before calling one optimized away.
Skill: Supply Chain Risk Auditor
by Trail of Bits
Audits npm, PyPI and Go dependencies for advisories, abandoned upstreams, publisher concentration and install-time scripts — measured by scripts, not estimated.
Skill: Constant-Time Analysis
by Trail of Bits
Compiles cryptographic code and reads the emitted assembly for variable-time instructions, then triages which flagged operations actually touch secrets.
MCP servers
Official read-only MCP server for HackerOne bug bounty reports, programs, and remediation data.
Related tags
Tags that appear alongside this one, ranked by how often.