跳转到主要内容
此内容尚未提供您的语言版本,正在以英文显示。

Graph Evolution

技能 活跃

Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes. Detects new attack paths, complexity shifts, blast radius growth, taint propagation changes, and privilege boundary modifications that text diffs miss. Use when comparing code between commits or tags, analyzing structural evolution, detecting attack surface growth, reviewing what changed between audit snapshots, or finding security-relevant changes that text diffs miss.

目的

To provide security analysts with automated detection of security-relevant structural changes between code snapshots that traditional text diffs miss.

功能

  • Compares Trailmark code graphs at two source code snapshots
  • Surfaces security-relevant structural changes
  • Detects new attack paths, complexity shifts, and privilege boundary modifications
  • Automates graph building, pre-analysis, and structural diffing
  • Generates security-focused markdown reports

使用场景

  • Comparing two git refs to understand structural changes
  • Auditing commit ranges for security-relevant evolution
  • Detecting new attack paths introduced by code changes
  • Finding functions with increased blast radius or complexity

非目标

  • Line-level code review (use differential-review)
  • Single-snapshot analysis (use trailmark skill directly)
  • Diagram generation from a single snapshot (use diagramming-code skill)

Trust

  • warning:Issues Attention13 issues were opened and 4 closed in the last 90 days, indicating a closure rate below 10% and slow maintainer response.

安装

请先添加 Marketplace

/plugin marketplace add trailofbits/skills
/plugin install trailmark@trailofbits

质量评分

95 /100
1 day ago 分析

信任信号

最近提交3 days ago
星标5.2k
许可证CC-BY-SA-4.0
状态
查看源代码

类似扩展

Metal

100

Extract the conceptual essence of a repository as skills, agents, and teams — the project's roles, procedures, and coordination patterns expressed as agentskills.io-standard definitions. Reads an arbitrary codebase and produces generalized definitions that capture WHAT the project does and WHO operates it, without replicating HOW it does it. Use when onboarding to a new codebase and wanting to understand its conceptual architecture, when bootstrapping an agentic system from an existing project, when studying a project's organizational DNA for cross-pollination, or when creating a skill/agent/team library inspired by a reference implementation.

技能
pjt222

Lean Ctx

100

AI 代理的上下文运行时 — 包含 59 个 MCP 工具、10 种读取模式、95+ 种 shell 模式、支持 18 种语言的 tree-sitter AST。将 LLM 上下文压缩高达 99%。用于读取文件、运行 shell 命令、搜索代码或探索目录。如果不存在,则自动安装。

技能
yvgude

Pathfinder

100

将代码库映射为按功能分组的流程图,识别不同功能之间的重复关注点,并提出统一的架构。在被要求“寻找理想路径”、统一重复系统或在重构前审计架构时使用。输出一个建议的统一流程图以及针对每个系统的“制定计划”提示。

技能
thedotmack

Codacy Audit

100

Codacy Cloud workflow for this repository -- run Codacy's analyzers locally before `git push` (mirrors what Codacy CI runs), and fetch/cluster Codacy issues for any PR via the v3 API. Use when the user mentions Codacy, "codacy analysis", `codacy-analysis-cli`, "codacy issues on PR", "fix codacy CI", "codacy markdownlint findings", or any Codacy gate failing on a netdata-org PR. Ships scripts analyze-local.sh (docker/binary runner for codacy-analysis-cli) and pr-issues.sh (paginated v3 issue fetch + group-by tool/pattern/severity/file). Token-safe -- CODACY_TOKEN never reaches assistant-visible stdout. Read-only by design in the current SOW; write actions (mark FP, mark fixed) are deferred.

技能
netdata

Domain Extract

100

Extract domain knowledge from existing project sources and generate domain rules. Also handles vault sync and domain listing.

技能
luiseiman

Auto Optimize

100

自动化分析、评估、设计和优化目标项目。将 VibeGuard 集成作为基线扫描,修复过程遵循 VibeGuard 规范,并在最后运行合规性检查。支持 auto-run-agent 自主执行。

技能
majiayu000