LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

audit-augmentation

Augments Trailmark code graphs with external audit findings from SARIF static analysis results and weAudit annotation files. Maps findings to graph nodes by file and line overlap, creates severity-based subgraphs, and enables cross-referencing findings with pre-analysis data (blast radius, taint, etc.). Use when projecting SARIF results onto a code graph, overlaying weAudit annotations, cross-referencing Semgrep or CodeQL findings with call graph data, or visualizing audit findings in the contex

5,841stars513forksUpdated 6/24/2026
SecurityCode Review#security#static-analysis#sarif#code-audit#trailmark

Security Assessment

Low Risk(75/100)

Detected risks:

Remote Code Execution([references/formats.md] exec()
Security Score75/100

About audit-augmentation

A security-tooling skill that projects external audit findings onto Trailmark code graphs. It maps SARIF static analysis results and weAudit annotation files to graph nodes by file path and line-range overlap, creates severity-based subgraphs, and enables cross-referencing those findings with pre-analysis data such as blast radius and taint. It applies when importing Semgrep, CodeQL, or other SARIF-producing tool results into a graph, overlaying weAudit annotations, querying which functions carry high-severity findings, or visualizing audit coverage alongside code structure.

The recommended workflow builds the graph and runs `engine.preanalysis()` first so that findings can be related to blast radius and taint context, then locates the input files (SARIF typically emitted by tools like `semgrep --sarif -o results.sarif` or CodeQL, and weAudit stored at `.vscode/<username>.weaudit`), runs augmentation, inspects results, and cross-references with pre-analysis subgraphs. Both a CLI (`uv run trailmark augment {targetDir} --sarif ... --weaudit ...`) and a programmatic QueryEngine API (`augment_sarif`, `augment_weaudit`, `findings`, `subgraph`, `annotations_of`) are provided. Augmentation results report matched and unmatched finding counts plus the subgraphs created; unmatched findings are flagged for investigation because they may indicate parsing gaps or out-of-scope files.

Findings are stored as standard Trailmark annotations with kinds `finding` (tool-generated) or `audit_note` (human notes) and sources like `sarif:<tool>` or `weaudit:<author>`. The skill creates severity- and tool-scoped subgraphs such as `sarif:error`, `sarif:warning`, `sarif:note`, per-tool subgraphs, and weAudit subgraphs by severity and entry type. Matching normalizes finding paths against the graph root, selects nodes whose line ranges overlap, and prefers the tightest span; SARIF relative, absolute, and file:// URIs are handled and weAudit 0-indexed lines are converted to 1-indexed automatically. It is explicitly not for running static analysis tools or building the graph itself (use the trailmark skill), and a SARIF 2.1.0 and weAudit format reference lives in references/formats.md.

FAQ

What inputs does the skill accept?

It accepts SARIF static analysis results (e.g., from Semgrep or CodeQL) and weAudit annotation files, which are typically stored at `.vscode/<username>.weaudit` within the workspace.

Do I need to run pre-analysis first?

Yes. The skill requires running `engine.preanalysis()` before augmenting so findings can be cross-referenced with blast radius and taint data; skipping it removes that context.

What are unmatched findings and why do they matter?

Unmatched findings are those whose file/line locations did not overlap any parsed code unit. The skill says to report the unmatched count and investigate when high, since it may signal parsing gaps or out-of-scope files.

Which subgraphs are created during augmentation?

It creates severity-based SARIF subgraphs (`sarif:error`, `sarif:warning`, `sarif:note`), per-tool subgraphs like `sarif:<tool>`, and weAudit subgraphs by severity (`weaudit:high/medium/low`) and entry type (`weaudit:findings`, `weaudit:notes`).

How are findings matched to graph nodes?

Findings are matched by normalizing the file path against the graph's root, selecting nodes whose line ranges overlap, and preferring the tightest match; SARIF relative/absolute/file:// paths are handled and weAudit 0-indexed lines are converted to 1-indexed.

All Files

4 files
agents/openai.yaml0.1 KB
View
assets/trail-of-bits-mark.svg3.0 KB
View
SKILL.md6.7 KB
View
references/formats.md3.3 KB
View

Install audit-augmentation

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

trailofbits/skills

Related Skills

tigris-security-access-control

3

rebuttal-writing

362

building-blocks

189

docs-search

189