Oathe Security Badge

Is trailofbits/skills safe?

Yes. trailofbits/skills is safe to install. Oathe's behavioral security audit gave the skills skill by trailofbits a trust score of 89/100 with 4 findings, none critical or high. Report updated

https://github.com/trailofbits/skills/

89
SAFE

Is trailofbits/skills safe to install?

This is Trail of Bits' public Claude Code skills repository, containing 30+ legitimate security analysis plugins from a well-known and reputable security research firm. The repository is fully open source, comprehensively documented, and all skills require explicit user invocation with no auto-executing or install-time code. The credential file accesses detected during monitoring are attributable to the Oathe audit infrastructure's setup/teardown phase based on timing analysis (accesses preceded GitHub clone by 5 seconds) and are confirmed benign by intact canary files. The skill collection is a high-quality, professionally maintained security toolkit appropriate for authorized security assessments.

What security issues were found in trailofbits/skills?

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 82/100 · 25%
Code Execution 87/100 · 20%
Clone Behavior 92/100 · 10%
Canary Integrity 87/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (4)

LOW Honeypot Credential Files Read-Accessed During Monitoring -12 ▶

inotifywait captured read-only opens of /home/oc-exec/.env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and .config/gcloud/application_default_credentials.json at 01:00:20. This timestamp precedes GitHub network connections (01:00:25) by five seconds, strongly indicating the accesses originated from the Oathe audit infrastructure's setup or teardown phase rather than any skill code. The auditd PATH records at epoch 1789434044.461 show all accesses as read-only. Canary integrity check confirmed all files unmodified.

LOW Tool Shim Interceptors in modern-python Plugin -8 ▶

The modern-python plugin ships executable shim scripts for python, python3, pip, pip3, uv, and pipx in hooks/shims/. Symlinks python3->python and pip3->pip are present. These shims intercept tool invocations to enforce modern Python conventions per the plugin's documented purpose. Each shim has a corresponding .bats test file demonstrating transparent, tested behavior. No malicious payload detected, but they modify command execution paths when the plugin hooks are active.

INFO Large Collection of User-Invocable Executable Scripts -5 ▶

Across 30+ plugins, the repository includes numerous Python scripts (collect.py, render.py, generate_sarif.py, assemble_findings.py, etc.), bash scripts (smoke-test.sh, run_*.sh, scanner.sh), and JavaScript workflows. These perform legitimate security analysis tasks. All require explicit user command or skill invocation; no install-time or clone-time auto-execution mechanisms are present.

INFO Broad Agent Tool Permissions Appropriate for Security Auditing Context -5 ▶

Multiple skills declare broad allowed-tools including Bash, Write, WebFetch, and Agent. When installed and invoked, Claude gains significant capability over the user's filesystem and can spawn subagents. This is architecturally appropriate for the claimed security auditing use cases but represents meaningful privilege when granted. Users should ensure they invoke these skills only on codebases they own or are authorized to audit.

Should I install trailofbits/skills?

Oathe's verdict for trailofbits/skills is SAFE with a trust score of 89/100. Recommendation: Install.