LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

trailmark-structural

Runs full Trailmark structural analysis on Trailmark 0.2.x by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege boundaries, and attack surface. Use when vivisect needs detailed structural data for a target. Triggers: structural analysis, blast radius, taint analysis, complexity hotspots.

5,841stars513forksUpdated 6/24/2026
SecurityCode Review#security#static-analysis#trailmark#code-analysis#taint-analysis

Security Assessment

Safe(100/100)
Security Score100/100

About trailmark-structural

Trailmark Structural Analysis runs a full structural pass on a codebase using Trailmark 0.2.x. It builds a Trailmark graph and runs `engine.preanalysis()` to compute all four pre-analysis passes, reporting hotspots, taint, blast radius, privilege boundaries, and attack surface. It is triggered by phrases like "structural analysis," "blast radius," "taint analysis," and "complexity hotspots," and is intended for cases such as Vivisect Phase 1 needing detailed structural data, detailed pre-analysis passes for a specific target scope, or generating complexity and taint data for audit prioritization.

It is not meant for a quick overview (use trailmark-summary), for ad-hoc code graph queries (use the main trailmark skill), or for a single small file where structural analysis adds no value. The skill rejects shortcuts: summary analysis is insufficient because it skips taint, blast radius, and privilege boundary data; running a single pass misses cross-references between passes; manual analysis misses what tooling catches; and empty pass output does not mean failure since some passes legitimately produce no data for some codebases.

Execution proceeds in four steps. First it confirms trailmark is available via `trailmark analyze --help` with a `uv run` fallback, and if neither works it reports "trailmark is not installed" and returns without running any install command, since the user must install it. Second it detects languages with Trailmark's parse API by calling `detect_languages` from `trailmark.parse`, retrying under `uv run` if the import fails and stopping if no supported languages are found. Third it runs the full structural analysis through `QueryEngine`: it builds the engine from the directory with language auto, runs `preanalysis()`, and assembles a JSON payload containing languages, the engine summary, the preanalysis results, attack surface and complexity hotspots (each capped at 25 entries), and a per-subgraph summary of node counts and sample IDs. Fourth it verifies the output includes languages, summary, preanalysis, hotspots (possibly empty), and subgraphs with counts and sample IDs, returning the full JSON payload regardless of whether some subgraphs have zero nodes.

FAQ

What data does this skill compute?

It builds a Trailmark graph and runs preanalysis() to compute all four pre-analysis passes, reporting hotspots, taint, blast radius, privilege boundaries, and attack surface.

How does it differ from trailmark-summary?

trailmark-summary gives only a quick overview and skips taint, blast radius, and privilege boundary data. This skill runs the full structural analysis with all four passes for detailed audit prioritization.

Which Trailmark version does it target?

It targets Trailmark 0.2.x, building a graph and running engine.preanalysis() to compute all four pre-analysis passes.

What does it do if a subgraph or pass produces no data?

Empty output is treated as normal, not a failure — some passes produce no data for some codebases, for example when there are no privilege boundaries. It returns the full JSON payload regardless.

Will it install trailmark for me if it is missing?

No. If neither `trailmark analyze --help` nor the `uv run` fallback works, it reports "trailmark is not installed" and returns. It does not run pip install, uv pip install, or git clone; the user must install it.

All Files

3 files
SKILL.md3.8 KB
View
agents/openai.yaml0.1 KB
View
assets/trail-of-bits-mark.svg3.0 KB
View

Install trailmark-structural

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

trailofbits/skills

Related Skills

tigris-security-access-control

3

rebuttal-writing

362

building-blocks

189

docs-search

189