What problem does it solve?
Security audits in codebases are often fragmented between automated static analysis and manual reviews. This Skill provides a two-track architecture that wraps Trail of Bits plugins for language-agnostic auditing, supplying project-specific context and a unified workflow.
Core Features & Use Cases
- Two-track workflow: tool-based static analysis (Track A) and AI-based deep reviews (Track B) operate independently but converge on a final assessment.
- Context-aware security: integrates architectural context, dependency graphs, and trust boundaries to improve finding relevance.
- Lifecycle-driven decisions: uses Finding Analysis, FP gates, and confidence scoring to drive human-in-the-loop decisions and remediation planning.
- Cross-cutting capabilities: supports entry-point analysis, compliance checks, variant hunting, and differential reviews for evolving codebases.
Quick Start
Run a complete security audit cycle against your project to generate findings and structured recommendations.