Security audit preparation assistant
Get a codebase review-ready before an external security audit — review goals, static analysis triage, test coverage, dead-code removal, documentation
- What
- Get a codebase review-ready before an external security audit — review goals, static analysis triage, test coverage, dead-code removal, documentation
- Cost
- Free
- Needs
- a codebase heading toward an external security audit; the platform's static analysis tools installed (e.g. slither, dylint, golangci-lint); a few days to two weeks of prep time
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — Trail of Bits' own audit-prep checklist, aimed at the 1–2 weeks before an external security review: set review goals (security objectives, areas of concern, worst-case scenarios, questions for the auditors), resolve easy issues first (run the right static analyzers per platform — slither for Solidity, dylint for Rust, golangci-lint for Go, CodeQL/Semgrep — triage every finding, raise test coverage toward untested code paths, remove dead code and unused libraries), make the code accessible (file list with scope, build instructions verified on a fresh environment, frozen commit/branch/tag, boilerplate vs original code identified), and generate the documentation auditors actually need (flowcharts and sequence diagrams, user stories, on-chain/off-chain assumptions, actors and privilege maps, function invariants and NatSpec, a glossary, optional video walkthroughs). It explicitly attacks the common rationalizations for skipping prep ("coverage looks decent", "I'll freeze later", "architecture is straightforward"), and ships an example audit-prep package as the target output. Honest caveats: **defensive use only — preparing your own code for review; it is not a substitute for the actual audit**; strongest on Solidity/Rust/Go stacks; CC-BY-SA-4.0 licensed (share-alike). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a codebase heading toward an external security audit; the platform's static analysis tools installed (e.g. slither, dylint, golangci-lint); a few days to two weeks of prep time Install "Security audit preparation assistant" for me. It gives the agent Trail of Bits' audit-prep checklist: set review goals, triage static analysis findings, raise test coverage, remove dead code, make the code accessible (scope, build instructions, frozen version), and generate auditor documentation (flowcharts, user stories, assumptions, actor/privilege maps, function docs, glossary) — with explicit rebuttals of the usual prep-skipping rationalizations. CC-BY-SA-4.0 licensed; defensive prep only, not a substitute for the audit. Repository: https://github.com/trailofbits/skills/blob/main/plugins/building-secure-contracts/skills/audit-prep-assistant/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "audit-prep-assistant". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the static analyzers for your stack, gather the files in audit scope, block out prep time). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.