MCP HubMCP Hub
SKILL·F32D02

trailmark-review-gate

trailofbits
更新日 1 month ago
3 閲覧
6,918
596
6,918
GitHubで表示
テストai

について

このスキルは、コード変更に対してTrailmarkの構造レビューゲートを実行し、新しいエントリーポイント、汚染されたパス、認可の削除などのセキュリティ退行を検出します。PRレビュー、ブランチチェック、リリース差分分析時に使用することを想定しており、マージ前にグラフレベルのセキュリティ問題を特定します。分析は、攻撃対象領域の拡大、権限境界のドリフト、到達可能な機密シンクに焦点を当てています。

クイックインストール

Claude Code

推奨
メイン
npx skills add trailofbits/skills -a claude-code
プラグインコマンド代替
/plugin add https://github.com/trailofbits/skills
Git クローン代替
git clone https://github.com/trailofbits/skills.git ~/.claude/skills/trailmark-review-gate

このコマンドをClaude Codeにコピー&ペーストしてスキルをインストールします

ドキュメント

Trailmark Review Gate

Apply deterministic security gate rules to Trailmark structural diff evidence. This skill does not replace line-level review. It produces a compact structural packet reviewers can cite while they inspect the code.

When to Use

  • Reviewing a branch, pull request, release diff, or fix commit
  • Checking whether a change expands attack surface
  • Looking for removed validation or authorization on reachable paths
  • Comparing before/after taint, privilege-boundary, blast-radius, or complexity signals
  • Producing graph evidence for a differential review

When NOT to Use

  • Single-snapshot analysis. Use trailmark or trailmark-structural.
  • Text-diff review only. Use differential-review.
  • Full vulnerability discovery. Use an audit or bug-finding workflow.
  • One static finding. Use trailmark-finding-triage.
  • Tooling is unavailable and the user wants manual review only.

Rationalizations to Reject

RationalizationWhy It Is WrongRequired Action
"The line diff is small, so no graph gate is needed"Small changes can create new call pathsCompare before/after graphs
"Graph gate passed, so the PR is secure"The gate only checks structural regressionsStill perform line-level review
"Trailmark failed, so pass the gate"Tool failure is unknown risk, not successEmit UNKNOWN
"Tests pass, so removed validation is fine"Tests may miss affected entrypoint pathsReview the removed path manually
"Only new code matters"Removed auth, validation, and callers can be higher risk than additionsReview removals and path changes

Workflow

Review Gate Progress:
- [ ] Step 1: Resolve before/after inputs
- [ ] Step 2: Build graph-evolution evidence
- [ ] Step 3: Normalize structural changes
- [ ] Step 4: Apply gate rules
- [ ] Step 5: Emit review packet and actions

Step 1: Resolve Inputs

Accept two refs, a branch name, a commit range, or before/after directories. Do not check out branches unnecessarily. Prefer git diff, git show, and git worktrees, following the graph-evolution snapshot workflow.

Step 2: Build Graph Evidence

Run graph-evolution or equivalent Trailmark before/after graph analysis. Both snapshots must run engine.preanalysis() so taint, privilege-boundary, blast-radius, complexity, and entrypoint signals are available.

Record Trailmark version and any feature probes. If graph construction fails, emit UNKNOWN.

Step 3: Normalize Changes

Normalize evidence into:

  • added, removed, and modified nodes
  • added and removed edges
  • entrypoint set changes
  • taint membership changes
  • privilege-boundary membership changes
  • blast-radius changes
  • complexity changes
  • newly reachable sensitive sinks
  • unresolved, proxy, or dynamic edge changes

Step 4: Apply Gate Rules

Apply the rules in references/gate-rules.md. Gate verdicts are:

VerdictMeaning
FAILA high-risk structural regression needs review before acceptance
WARNA meaningful graph change needs reviewer attention
PASSNo configured structural gate fired
UNKNOWNTrailmark failed or evidence is too incomplete

Step 5: Emit Packet

Write the packet using references/output-format.md, then hand it to the branch reviewer. Use references/review-integration.md when combining this packet with differential-review or another PR review process.

Requirements

  • Never mutate the user's working branch while comparing refs.
  • Never report PASS when Trailmark failed.
  • Separate graph evidence from manual security judgment.
  • Include exact changed nodes or paths for every FAIL and WARN.
  • Include limitations when parser, proxy, unresolved-call, or dynamic-dispatch uncertainty affects the verdict.

GitHub リポジトリ

trailofbits/skills
パス: plugins/trailmark/skills/trailmark-review-gate
0
agent-skills
FAQ

よくある質問

trailmark-review-gate Skillとは何ですか?

trailmark-review-gate はtrailofbits が作成した Claude Skillです。Skillは、Claudeが必要に応じて読み込む指示とリソースをまとめ、追加の指示なしで trailmark-review-gate に関連するタスクを実行できるようにします。

trailmark-review-gate をインストールするには?

このページのインストールコマンドを使用してください。trailmark-review-gate をプラグインとして Claude Code に追加するか、リポジトリを skills ディレクトリにクローンし、Claudeを再起動してSkillを読み込みます。

trailmark-review-gate はどのカテゴリに属しますか?

trailmark-review-gate は テスト カテゴリに属します。

trailmark-review-gate は無料で利用できますか?

はい。trailmark-review-gate は AIMCP に掲載されており、無料でインストールできます。

関連スキル

evaluating-llms-harness
テスト

このClaudeスキルは、lm-evaluation-harnessを実行し、MMLUやGSM8Kなど60以上の標準化学術タスクでLLMをベンチマークします。開発者がモデルの品質を比較し、トレーニングの進捗を追跡し、学術的な結果を報告するために設計されています。このツールはHuggingFaceやvLLMモデルを含む様々なバックエンドをサポートしています。

スキルを見る
cloudflare-cron-triggers
テスト

このスキルは、cron式を使用してWorkersをスケジュールするためのCloudflare Cron Triggersの実装に関する包括的な知識を提供します。定期的なタスクの設定、メンテナンスジョブ、自動化されたワークフローの構築を網羅し、無効なcron式やタイムゾーン問題といった一般的な課題への対処法も含みます。開発者はこれを使用して、スケジュールされたハンドラーの設定、cronトリガーのテスト、WorkflowsやGreen Computeとの連携を構成できます。

スキルを見る
webapp-testing
テスト

このClaude Skillは、Playwrightベースのツールキットを提供し、Pythonスクリプトを通じてローカルWebアプリケーションのテストを可能にします。フロントエンドの検証、UIデバッグ、スクリーンショット撮影、ログ表示を実現し、サーバーライフサイクルを管理します。ブラウザ自動化タスクにご利用いただけますが、コンテキストの汚染を避けるため、スクリプトのソースコードを読むのではなく直接実行してください。

スキルを見る
finishing-a-development-branch
テスト

このスキルは、開発者がテストの合格を確認し、構造化された統合オプションを提示することで、完成した作業を仕上げることを支援します。実装が完了した後のマージ、PR作成、ブランチの整理といったワークフローを案内します。コードが準備できてテスト済みの際に使用し、開発プロセスを体系的に完了させましょう。

スキルを見る