sharp-edges
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.
Security Assessment
Detected risks:
About sharp-edges
The sharp-edges skill is designed to help developers and security professionals identify APIs, configuration schemas, and interface designs that are prone to misuse and security mistakes. It targets areas where the 'easy path' for developers inadvertently introduces vulnerabilities, such as insecure defaults, improper cryptographic algorithm choices, or configurations that allow dangerous options. By evaluating code and systems for footguns and other risky design patterns, it ensures that secure practices are the path of least resistance, following the 'pit of success' principle where safe usage is the default outcome.
This skill provides several key capabilities, including detecting algorithm and mode selection footguns, recognizing dangerous default values, and assessing cryptographic API ergonomics. It can identify parameters or configuration options that could lead developers to insecure choices, highlight places where documentation alone is insufficient to prevent mistakes, and provide guidance for redesigning APIs to be misuse-resistant. The autonomous agent, sharp-edges-analyzer, performs a structured four-phase analysis, encompassing surface identification, edge case probing, threat modeling, and validation of findings, allowing comprehensive evaluation across language-specific libraries and interfaces.
Sharp-edges is primarily intended for code reviewers, security auditors, and developers designing libraries or APIs with security implications. It is useful when reviewing API design decisions, auditing configuration schemas, assessing cryptography and authentication interfaces, or any situation where the interface exposes security-relevant decisions to users. However, it is not meant for detecting implementation bugs, business logic flaws, or performance optimizations, as these require separate analysis approaches.
FAQ
When should I use the sharp-edges skill?
Use it when reviewing API or library designs, auditing configuration schemas, evaluating cryptographic interfaces, or assessing authentication and authorization systems for misuse resistance.
Can sharp-edges identify performance or logic bugs?
No, this skill focuses on design-level security risks and misuse patterns. Performance issues and business logic flaws require other analysis tools.
What languages or platforms does sharp-edges support?
The agent can read language-specific references on demand, making it adaptable to multiple programming environments. However, it analyzes design and configuration patterns rather than executing platform-specific code.
How does sharp-edges handle default configurations?
It identifies dangerous defaults, such as zero timeouts or empty values that disable security, and recommends secure defaults or misuse-resistant patterns.
Does using sharp-edges replace standard code reviews?
No, it complements standard reviews by focusing on secure-by-default design principles, footguns, and developer misuse patterns rather than implementation bugs.
All Files
16 filesInstall sharp-edges
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
trailofbits/skills