trailmark-summary
Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list. Use when vivisect or galvanize needs a quick structural overview. Triggers: trailmark summary, code summary, structural overview.
Security Assessment
About trailmark-summary
Trailmark Summary runs a quick structural overview of a codebase by invoking `trailmark analyze --language auto --summary` on a target directory. It returns auto-detected languages, an entry point count, and a dependency list, and is triggered by phrases like "trailmark summary," "code summary," and "structural overview." It is intended as a fast orientation step — for example, Vivisect Phase 0 needing a structural overview before decomposition, Galvanize Phase 1 needing detected languages and entry point count, or quick orientation on an unfamiliar codebase before deeper analysis.
It is deliberately scoped to a lightweight summary. For full structural analysis with all passes, hotspot scores, or taint data, the trailmark-structural skill should be used; for detailed code graph queries, the main trailmark skill applies. The skill also pushes back on common rationalizations, insisting that manual code reading is not a substitute because it misses parser-based language detection, dependency data, and entry point enumeration, and that partial output is not acceptable when any of the three required outputs is missing.
Execution follows four steps. First it checks that trailmark is available by running `trailmark analyze --help`, falling back to `uv run trailmark analyze --help`; if neither works it reports "trailmark is not installed" and stops without running any install command, since the user must install trailmark themselves. Second it detects languages using Trailmark's parse API by calling `detect_languages` from `trailmark.parse`, retrying under `uv run` if the import fails, and reporting if no supported languages are found. Third it runs the summary with auto-detection, again with a `uv run` fallback. Fourth it verifies the output contains all three of the detected languages, an `Entrypoints:` line, and a `Dependencies:` line, reporting any gap rather than fabricating output. The final return is the detected language list plus the full Trailmark summary output.
FAQ
What does this skill return?
It returns auto-detected languages, an entry point count, and a dependency list by running `trailmark analyze --language auto --summary` on the target directory.
When should I use trailmark-summary instead of trailmark-structural?
Use it for a quick structural overview or orientation. If you need full structural analysis with all passes, hotspot scores, or taint data, use trailmark-structural instead; for detailed code graph queries use the main trailmark skill.
What happens if trailmark is not installed?
The skill reports "trailmark is not installed" and returns. It will not run pip install, uv pip install, git clone, or any install command, since the user must install trailmark themselves.
How does it handle a codebase with no supported languages?
It detects languages with Trailmark's parse API (`detect_languages` from `trailmark.parse`), and if the result is an empty list it reports that Trailmark found no supported languages under the target and returns.
How is the output verified?
The output must include all three of the detected languages, an `Entrypoints:` line, and a `Dependencies:` line. If any are missing, the skill reports the gap rather than fabricating output.
Install trailmark-summary
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
trailofbits/skills