Runs full Trailmark structural analysis on Trailmark 0.2.x by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege boundaries, and attack surface. Use when vivisect needs detailed structural data for a target. Triggers: structural analysis, blast radius, taint analysis, complexity hotspots.
Trailmark Structural Analysis runs a full structural pass on a codebase using Trailmark 0.2.x. It builds a Trailmark graph and runs `engine.preanalysis()` to compute all four pre-analysis passes, reporting hotspots, taint, blast radius, privilege boundaries, and attack surface. It is triggered by phrases like "structural analysis," "blast radius," "taint analysis," and "complexity hotspots," and is intended for cases such as Vivisect Phase 1 needing detailed structural data, detailed pre-analysis passes for a specific target scope, or generating complexity and taint data for audit prioritization.
It is not meant for a quick overview (use trailmark-summary), for ad-hoc code graph queries (use the main trailmark skill), or for a single small file where structural analysis adds no value. The skill rejects shortcuts: summary analysis is insufficient because it skips taint, blast radius, and privilege boundary data; running a single pass misses cross-references between passes; manual analysis misses what tooling catches; and empty pass output does not mean failure since some passes legitimately produce no data for some codebases.
Execution proceeds in four steps. First it confirms trailmark is available via `trailmark analyze --help` with a `uv run` fallback, and if neither works it reports "trailmark is not installed" and returns without running any install command, since the user must install it. Second it detects languages with Trailmark's parse API by calling `detect_languages` from `trailmark.parse`, retrying under `uv run` if the import fails and stopping if no supported languages are found. Third it runs the full structural analysis through `QueryEngine`: it builds the engine from the directory with language auto, runs `preanalysis()`, and assembles a JSON payload containing languages, the engine summary, the preanalysis results, attack surface and complexity hotspots (each capped at 25 entries), and a per-subgraph summary of node counts and sample IDs. Fourth it verifies the output includes languages, summary, preanalysis, hotspots (possibly empty), and subgraphs with counts and sample IDs, returning the full JSON payload regardless of whether some subgraphs have zero nodes.
It builds a Trailmark graph and runs preanalysis() to compute all four pre-analysis passes, reporting hotspots, taint, blast radius, privilege boundaries, and attack surface.
trailmark-summary gives only a quick overview and skips taint, blast radius, and privilege boundary data. This skill runs the full structural analysis with all four passes for detailed audit prioritization.
It targets Trailmark 0.2.x, building a graph and running engine.preanalysis() to compute all four pre-analysis passes.
Empty output is treated as normal, not a failure — some passes produce no data for some codebases, for example when there are no privilege boundaries. It returns the full JSON payload regardless.
No. If neither `trailmark analyze --help` nor the `uv run` fallback works, it reports "trailmark is not installed" and returns. It does not run pip install, uv pip install, or git clone; the user must install it.
Quick Setup:
.claude/skills/Repository
trailofbits/skills