mirror of
https://github.com/trailofbits/skills.git
synced 2026-09-14 14:28:48 +08:00
kumarak/codeql-cpp-data-extensions
13 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
ca08fc8a91 |
Commit plugin lockfiles; unblock Dependabot (#213)
* Commit plugin lockfiles so Dependabot can do something useful The uv ecosystem config added in #206 pointed at four directories that declare PEP 621 ranges and carry no lockfile. With nothing to pin, Dependabot's only available action is raising the lower bound of an already-open range — which changes nothing about what installs and only drops support for older versions. It opened five such PRs within a minute of #206 merging (#208-#212), all no-ops: the existing ranges already resolved to exactly the versions being proposed as new floors. The one directory that did have a lockfile, constant-time-analysis, produced no PR at all, because there was genuinely nothing to update. That is the whole diagnosis. Lockfiles committed for the other four. .gitignore ignored uv.lock globally, which is why they were missing; constant-time-analysis's was tracked only because it predates the rule. Now scoped to the root file (ephemeral — there is no root pyproject.toml) with plugin lockfiles explicitly allowed, matching the pattern already used for .mcp.json. Also fixes two bugs #206 introduced: - The version-increment check failed all five Dependabot PRs, and Dependabot can neither bump a plugin version nor label its own PR, so every future dependency PR would have been permanently red. Exempted by actor. - The 'no-version-bump' label was documented in AGENTS.md and wired into validate.yml but never created, so the escape hatch did not exist. Created. * Re-run CI with the no-version-bump label applied The version-increment check fired on this PR: adding uv.lock under plugins/<name>/ counts as touching those plugins. Correct behaviour — the lockfiles pin exactly what the existing ranges already resolve to, so nothing changes for anyone installing these plugins, which is what the label is for. First real use of the escape hatch created in this same PR. * Fix the three findings from this PR's review A local uv setting leaked into all four new lockfiles. /etc/uv/uv.toml on ToB machine images sets exclude-newer = "1 week", so every lock carried an [options] block with exclude-newer-span = "P1W" and pinned versions resolved a week stale — diverging from constant-time-analysis/uv.lock, which predates this PR and has no such block. Regenerated with UV_NO_CONFIG=1. That cooldown is the org's supply-chain posture and it belongs in dependabot.yml's 'cooldown: default-days: 7', where it already is; baking it into committed lockfiles was my environment leaking, not a decision. "EVERY directory here must carry a committed uv.lock" was enforced by a comment, which is precisely the anti-pattern AGENTS.md tells people to avoid. Now a validator check: it parses the uv ecosystem block out of dependabot.yml and asserts a uv.lock beside each listed directory. Scoped to that block rather than grepping for '- /plugins/...' so a future ecosystem's paths are not swept in, and it errors if the block exists but no directories parse out — otherwise the checker could inspect zero items and report clean, which is the exact failure it exists to prevent. Three self-test fixtures, and verified by deleting a real lockfile and confirming CI would go red. The Dependabot exemption keyed on github.actor, which on a synchronize event is whoever pushed. A human adding one commit to a Dependabot branch would re-arm the version check and turn the PR red — making the follow-up bump mandatory exactly where the comment says it is discretionary. Keyed on PR authorship now. |
||
|
|
8ea3b6a700 |
Move the contribution checklist into machinery (#206)
* Add validator self-test, structural checks, and make check The repo documented ~53 rules in AGENTS.md and machine-enforced 6 of them. This closes the gap for the ones a machine can decide, and adds the guard that keeps the checkers honest. New error-level checks (all currently pass, so none of this blocks anyone today): agent files must use `tools:` while skills use `allowed-tools:` (the loader silently ignores the wrong key, so the restriction just does not apply); subagent_type must be namespaced or the dispatch fails at runtime; plugin dir names kebab-case and <=64 chars; plugin README present, listed rather than stat'd so `Readme.md` fails on Linux CI the way it should; semver format; the forbidden runtime sidecars AGENTS.md already banned but nothing checked; and version-increment against the base branch, which is the gap that let |
||
|
|
83f9240beb |
build(deps): Bump the all group across 1 directory with 2 updates (#204)
Bumps the all group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [actions/setup-python](https://github.com/actions/setup-python). Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `actions/setup-python` from 6.2.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Dan Guido <dan@trailofbits.com> |
||
|
|
39e10bd31e | build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 in the all group (#191) | ||
|
|
c910ecf739 |
Bump actions/checkout from 6.0.2 to 6.0.3 in the all group (#182)
Bumps the all group with 1 update: [actions/checkout](https://github.com/actions/checkout). Updates `actions/checkout` from 6.0.2 to 6.0.3 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f09e5c729a |
Remove legacy codex compatiblity scripts/shims. (#173)
* Remove legacy codex compatiblity scripts/shims. Codex supports claude plugins so this shouldn't be necessary. Add a script to test the plugin loadablility in both claude and codex * fix: resolve code review findings for PR #173 Review findings addressed (4 reviewers: pr-review-toolkit agents, Codex gpt-5.3-codex, direct diff review): P2 fixed: - Bump versions for the 5 substantively changed plugins in both plugin.json and marketplace.json (gh-cli 1.5.0 new skill, claude-in-chrome-troubleshooting 1.1.0 skill rename, modern-python 1.5.1 / skill-improver 1.0.3 hooks change, zeroize-audit 0.1.1 MCP config relocation) so clients pick up the changes - README Codex install: replace unpasteable /plugins slash-command block with verified CLI syntax (codex plugin marketplace add) - check_claude_loadability: parse_json_output now fails fast with command context on empty CLI output instead of returning None - check_codex_loadability: surface skipped RPC error messages in timeout failures instead of a bare TimeoutError P3 fixed: - Both checkers: error out when marketplace.json lists no plugins instead of passing vacuously Dismissed: - @latest CLI installs in validate.yml: deliberate; the check validates against the clients users actually run - select.select portability: CI-only script on ubuntu-latest - Divergent mcpServers validation between checkers: intentional; the Codex checker enforces the repo's .mcp.json convention Verified: ruff, prek, validate_plugin_metadata.py, and both loadability checks pass end-to-end (39 plugins, 74 skills, 2 MCP servers load in Claude Code and Codex) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
aab484c5b7 |
Add Codex-native skill installation support (#123)
* Add Codex-native skill installation support * Document Codex install commands in README * Enforce Codex skill mappings in CI * Fix review issues in Codex skill support - Fix ruff line-length violations in validate_codex_skills.py - Rewrite gh-cli SKILL.md description to third-person voice - Fix misleading error messages: describe actual symlink fix instead of referencing the user-local installer script - Add early check for missing .codex/skills/ directory - Distinguish dangling symlinks from mismatched symlinks - Add defensive ValueError handling in rel() - Add PLUGINS_DIR existence guard - Add install count and zero-install warning to installer - Add SOURCE_DIR existence check to installer Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|
|
f4b2a7218f |
better ci validations, fix marketplace error (#85)
* better ci validations, fix marketplace error * fix lints * fix lint script * fix lint script2 * fix ruff errors * fix abs path regex * fix shellcheck lint * fix: resolve code review findings for PR #85 - Remove dead CHANGED_FILES code path (unreachable in CI) - Add version and description consistency checks between plugin.json and marketplace.json - Eliminate duplicate plugin.json reads via parse_plugin_json() - Fix bats test discovery for filenames with spaces (print0/xargs -0) - Sync marketplace.json with plugin.json for 5 pre-existing mismatches (second-opinion version, ask-questions/burpsuite/fix-review/insecure-defaults descriptions) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: gh-cli bats tests fail when gh is in /usr/bin The _no_gh test helpers used PATH=/usr/bin:/bin to exclude gh, but on Ubuntu CI runners gh is installed at /usr/bin/gh. Fix by creating a temp directory with symlinks to only jq and bash. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: improve plugin descriptions for better skill triggering - ask-questions-if-underspecified: restore trigger context ("asking questions") while keeping invocation constraint - burpsuite-project-parser: drop filler "directly from the command line", use outcome-oriented "for security analysis" - insecure-defaults: restore specific scenarios (hardcoded credentials, fallback secrets, weak auth defaults) for better matching Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
543816914a |
Add devcontainer-setup plugin (#26)
* Add devcontainer-setup plugin for Claude Code development environments Creates pre-configured devcontainers with Claude Code and language-specific tooling. Supports Python, Node/TypeScript, Rust, and Go projects with automatic detection and configuration. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Add plugin to marketplace list * Fix the post install command * Fix YARN installation * Install fzf from GitHub and add plugin marketplaces - Install fzf from GitHub releases instead of apt (Ubuntu 24.04's apt version lacks shell integration) - Add Claude plugin marketplace setup for anthropics/skills and trailofbits/skills in post_install.py Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Fix linting issues in devcontainer-setup plugin - Use contextlib.suppress instead of try-except-pass (SIM105) - Fix case statement indentation in install.sh for shfmt Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Exclude /home/vscode from hardcoded path check Standard devcontainer user path should not be flagged as a personal hardcoded path. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Sync devcontainer-setup with upstream claude-code-devcontainer Sync resources with https://github.com/trailofbits/claude-code-devcontainer: - Add Python 3.13 via uv and Node 22 via fnm to base Dockerfile - Add ast-grep for AST-based code search - Include network isolation tools (iptables, ipset) by default - Add Tailscale feature for secure networking - Add NPM security settings (ignore-scripts, 24-hour release delay) - Add init: true and updateRemoteUserUID: true to devcontainer.json - Expand .zshrc with fnm integration, fzf config, and more aliases - Update post_install.py to print to stderr and add ghostty terminal features - Integrate delta config into .gitconfig.local - Move marketplace plugin installation from post_install.py to Dockerfile Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Sync devcontainer-setup resources with upstream Align with https://github.com/trailofbits/claude-code-devcontainer: - Move PATH env before Claude install - Remove -p fzf from Oh My Zsh, download fzf shell integration separately - Add FZF_VERSION arg for shell integration download - Use uv run --no-project for post_install.py - Add fzf sourcing to .zshrc - Add symlink resolution and update command to install.sh Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Address PR review comments and sync with upstream devcontainer DarkaMaul's review comments: - Restore SHA256 hash on base image for reproducibility - Sort apt packages alphabetically within category groups - Install fzf from GitHub releases (v0.67.0) instead of old apt package - Remove Tailscale feature (not generic enough for template) Upstream sync (3 new commits from claude-code-devcontainer): - Add bubblewrap and socat for Claude Code sandboxing - Add exec, upgrade, and mount commands to devc CLI - Mount .devcontainer/ read-only to prevent container escape on rebuild Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Harden devcontainer templates from multi-agent review findings - Pin uv to 0.10.0 with SHA256 digest (supply chain security) - Add SYS_ADMIN capability guard to install.sh (prevents defeating read-only .devcontainer mount) - Fix mount filter to use target paths instead of source prefixes (was broken when PROJECT_SLUG was substituted) - Fix temp file leak in extract_mounts_to_file - Remove claude-yolo alias (unsafe pattern for a template) - Remove dead POWERLEVEL9K_DISABLE_GITSTATUS and NODE_OPTIONS configs - Remove unnecessary terminal profile definitions - Default timezone to UTC instead of America/New_York - Remove stale Tailscale reference from SKILL.md - Fix line length violations throughout install.sh Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Restore claude-yolo alias and POWERLEVEL9K_DISABLE_GITSTATUS The claude-yolo alias is intentional for devcontainer use. POWERLEVEL9K_DISABLE_GITSTATUS is needed because zsh-in-docker installs Powerlevel10k, whose gitstatus can be slow in large repos. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Restore NODE_OPTIONS, terminal profiles, and re-clone URL NODE_OPTIONS 4GB heap is intentional for Claude Code in containers. Terminal profiles are useful in VS Code dropdown. Re-clone message needs the full URL to be actionable. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com> Co-authored-by: Dan Guido <dan@trailofbits.com> |
||
|
|
319283694d | Bump actions/checkout from 6.0.1 to 6.0.2 in the all group (#47) | ||
|
|
751a8f6b31 |
Harden validate workflow with explicit permissions (#5)
- Add `permissions: contents: read` to follow least privilege - Add concurrency limits to cancel redundant workflow runs - Add job name for clearer GitHub Actions UI Fixes CodeQL alert #2 (actions/missing-workflow-permissions) Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com> |
||
|
|
fee47e2a68 |
Bump actions/checkout from 4.2.2 to 6.0.1 in the all group (#1)
Bumps the all group with 1 update: [actions/checkout](https://github.com/actions/checkout). Updates `actions/checkout` from 4.2.2 to 6.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/11bd71901bbe5b1630ceea73d27597364c9af683...8e8c483db84b4bee98b60c0593521ed34d9990e8) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
695119c312 |
Initial release of Trail of Bits Skills Marketplace
16 plugins for security analysis, smart contract auditing, and verification: Smart Contract Security: - building-secure-contracts - entry-point-analyzer Code Auditing: - audit-context-building - burpsuite-project-parser - differential-review - semgrep-rule-creator - sharp-edges - testing-handbook-skills - variant-analysis Verification: - constant-time-analysis - property-based-testing - spec-to-code-compliance Audit Lifecycle: - fix-review Reverse Engineering: - dwarf-expert Development: - ask-questions-if-underspecified Team Management: - culture-index Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |