About
This skill runs a Trailmark structural review gate on code changes to detect security regressions like new entrypoints, tainted paths, or removed authorization. It's designed for use during PR reviews, branch checks, or release diffs to identify graph-level security issues before merging. The analysis focuses on attack surface expansion, privilege boundary drift, and reachable sensitive sinks.
Quick Install
Claude Code
Recommendednpx skills add trailofbits/skills -a claude-code/plugin add https://github.com/trailofbits/skillsgit clone https://github.com/trailofbits/skills.git ~/.claude/skills/trailmark-review-gateCopy and paste this command in Claude Code to install this skill
Documentation
Trailmark Review Gate
Apply deterministic security gate rules to Trailmark structural diff evidence. This skill does not replace line-level review. It produces a compact structural packet reviewers can cite while they inspect the code.
When to Use
- Reviewing a branch, pull request, release diff, or fix commit
- Checking whether a change expands attack surface
- Looking for removed validation or authorization on reachable paths
- Comparing before/after taint, privilege-boundary, blast-radius, or complexity signals
- Producing graph evidence for a differential review
When NOT to Use
- Single-snapshot analysis. Use
trailmarkortrailmark-structural. - Text-diff review only. Use
differential-review. - Full vulnerability discovery. Use an audit or bug-finding workflow.
- One static finding. Use
trailmark-finding-triage. - Tooling is unavailable and the user wants manual review only.
Rationalizations to Reject
| Rationalization | Why It Is Wrong | Required Action |
|---|---|---|
| "The line diff is small, so no graph gate is needed" | Small changes can create new call paths | Compare before/after graphs |
| "Graph gate passed, so the PR is secure" | The gate only checks structural regressions | Still perform line-level review |
| "Trailmark failed, so pass the gate" | Tool failure is unknown risk, not success | Emit UNKNOWN |
| "Tests pass, so removed validation is fine" | Tests may miss affected entrypoint paths | Review the removed path manually |
| "Only new code matters" | Removed auth, validation, and callers can be higher risk than additions | Review removals and path changes |
Workflow
Review Gate Progress:
- [ ] Step 1: Resolve before/after inputs
- [ ] Step 2: Build graph-evolution evidence
- [ ] Step 3: Normalize structural changes
- [ ] Step 4: Apply gate rules
- [ ] Step 5: Emit review packet and actions
Step 1: Resolve Inputs
Accept two refs, a branch name, a commit range, or before/after directories.
Do not check out branches unnecessarily. Prefer git diff, git show, and
git worktrees, following the graph-evolution snapshot workflow.
Step 2: Build Graph Evidence
Run graph-evolution or equivalent Trailmark before/after graph analysis.
Both snapshots must run engine.preanalysis() so taint, privilege-boundary,
blast-radius, complexity, and entrypoint signals are available.
Record Trailmark version and any feature probes. If graph construction fails,
emit UNKNOWN.
Step 3: Normalize Changes
Normalize evidence into:
- added, removed, and modified nodes
- added and removed edges
- entrypoint set changes
- taint membership changes
- privilege-boundary membership changes
- blast-radius changes
- complexity changes
- newly reachable sensitive sinks
- unresolved, proxy, or dynamic edge changes
Step 4: Apply Gate Rules
Apply the rules in references/gate-rules.md. Gate verdicts are:
| Verdict | Meaning |
|---|---|
FAIL | A high-risk structural regression needs review before acceptance |
WARN | A meaningful graph change needs reviewer attention |
PASS | No configured structural gate fired |
UNKNOWN | Trailmark failed or evidence is too incomplete |
Step 5: Emit Packet
Write the packet using
references/output-format.md, then hand it to
the branch reviewer. Use
references/review-integration.md when
combining this packet with differential-review or another PR review process.
Requirements
- Never mutate the user's working branch while comparing refs.
- Never report
PASSwhen Trailmark failed. - Separate graph evidence from manual security judgment.
- Include exact changed nodes or paths for every
FAILandWARN. - Include limitations when parser, proxy, unresolved-call, or dynamic-dispatch uncertainty affects the verdict.
GitHub Repository
Frequently asked questions
What is the trailmark-review-gate skill?
trailmark-review-gate is a Claude Skill by trailofbits. Skills package instructions and resources that Claude loads on demand, so Claude can perform trailmark-review-gate-related tasks without extra prompting.
How do I install trailmark-review-gate?
Use the install commands on this page: add trailmark-review-gate to Claude Code as a plugin, or clone its repository into your skills directory, then restart Claude so it picks up the skill.
What category does trailmark-review-gate belong to?
trailmark-review-gate is in the Testing category.
Is trailmark-review-gate free to use?
Yes. trailmark-review-gate is listed on AIMCP and free to install.
Related Skills
This Claude Skill runs the lm-evaluation-harness to benchmark LLMs across 60+ standardized academic tasks like MMLU and GSM8K. It's designed for developers to compare model quality, track training progress, or report academic results. The tool supports various backends including HuggingFace and vLLM models.
This skill provides comprehensive knowledge for implementing Cloudflare Cron Triggers to schedule Workers using cron expressions. It covers setting up periodic tasks, maintenance jobs, and automated workflows while handling common issues like invalid cron expressions and timezone problems. Developers can use it for configuring scheduled handlers, testing cron triggers, and integrating with Workflows and Green Compute.
This Claude Skill provides a Playwright-based toolkit for testing local web applications through Python scripts. It enables frontend verification, UI debugging, screenshot capture, and log viewing while managing server lifecycles. Use it for browser automation tasks but run scripts directly rather than reading their source code to avoid context pollution.
This skill helps developers complete finished work by verifying tests pass and then presenting structured integration options. It guides the workflow for merging, creating PRs, or cleaning up branches after implementation is done. Use it when your code is ready and tested to systematically finalize the development process.
