# Trail of Bits Claude Code Config

Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits

Repository: https://github.com/trailofbits/claude-code-config
Canonical: https://ross.abutalabs.com/products/trail-of-bits-claude-code-config
Language: Shell
License Family: other
Topics: claude, claude-code, claude-code-cli, developer-tool
Last push: 2026-08-24T19:47:25+00:00

## Health v2 (maintenance only)
Score: 60/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 35, longevity 15
- inputs: {"age_days": 210, "days_push": 9, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2079, forks 158 (observed 2026-08-28T04:06:11.440128+00:00)

## What it is
A Claude Code plugin marketplace from Trail of Bits offering skills for AI-assisted security analysis, code auditing, and vulnerability detection. It includes plugins for smart contract security, C/Rust code review, differential review, and audit workflows, and is also compatible with Codex.

## Use cases
- audit smart contracts for security vulnerabilities
- run security-focused code review on C or Rust codebases
- find AI agent vulnerabilities in GitHub Actions workflows
- build context about a codebase before hunting for bugs
- verify false positives in security bug analysis
- review code changes for security regressions with git history
- extract data from Burp Suite project files

## When to choose
- you use Claude Code or Codex and want expert security-audit skills
- you need structured workflows for vulnerability detection and code auditing
- you audit smart contracts or systems-level code

## When to avoid
- you need a standalone scanner rather than AI-agent skills
- you don't use Claude Code or a compatible agent platform
- you need general-purpose development assistance unrelated to security

## Facets
- artifact type: plugin
- maturity: active
- function: security, vulnerability-scanning, code-review, agent-framework, prompt-engineering, developer-tools
- domain: security, developer-tools, blockchain, penetration-testing, artificial-intelligence
- platform: cli, cross-platform, python
- tags: claude-code, agent-skills, security-audit, smart-contracts, marketplace, trail-of-bits, codex

## Member repositories
- trailofbits/claude-code-config (main) score 60
- trailofbits/skills (plugin) score 60

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:11.440128+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:41:42.018971+00:00, confidence not recorded.
  - readme: https://github.com/trailofbits/claude-code-config (fetched 2026-08-28T04:06:11.440128+00:00, sha 3e111ebd5458)
- Data as of 2026-08-30T08:39:29.467469+00:00.
