について
このスキルは、コード変更に対してTrailmarkの構造レビューゲートを実行し、新しいエントリーポイント、汚染されたパス、認可の削除などのセキュリティ退行を検出します。PRレビュー、ブランチチェック、リリース差分分析時に使用することを想定しており、マージ前にグラフレベルのセキュリティ問題を特定します。分析は、攻撃対象領域の拡大、権限境界のドリフト、到達可能な機密シンクに焦点を当てています。
クイックインストール
Claude Code
推奨npx skills add trailofbits/skills -a claude-code/plugin add https://github.com/trailofbits/skillsgit clone https://github.com/trailofbits/skills.git ~/.claude/skills/trailmark-review-gateこのコマンドをClaude Codeにコピー&ペーストしてスキルをインストールします
ドキュメント
Trailmark Review Gate
Apply deterministic security gate rules to Trailmark structural diff evidence. This skill does not replace line-level review. It produces a compact structural packet reviewers can cite while they inspect the code.
When to Use
- Reviewing a branch, pull request, release diff, or fix commit
- Checking whether a change expands attack surface
- Looking for removed validation or authorization on reachable paths
- Comparing before/after taint, privilege-boundary, blast-radius, or complexity signals
- Producing graph evidence for a differential review
When NOT to Use
- Single-snapshot analysis. Use
trailmarkortrailmark-structural. - Text-diff review only. Use
differential-review. - Full vulnerability discovery. Use an audit or bug-finding workflow.
- One static finding. Use
trailmark-finding-triage. - Tooling is unavailable and the user wants manual review only.
Rationalizations to Reject
| Rationalization | Why It Is Wrong | Required Action |
|---|---|---|
| "The line diff is small, so no graph gate is needed" | Small changes can create new call paths | Compare before/after graphs |
| "Graph gate passed, so the PR is secure" | The gate only checks structural regressions | Still perform line-level review |
| "Trailmark failed, so pass the gate" | Tool failure is unknown risk, not success | Emit UNKNOWN |
| "Tests pass, so removed validation is fine" | Tests may miss affected entrypoint paths | Review the removed path manually |
| "Only new code matters" | Removed auth, validation, and callers can be higher risk than additions | Review removals and path changes |
Workflow
Review Gate Progress:
- [ ] Step 1: Resolve before/after inputs
- [ ] Step 2: Build graph-evolution evidence
- [ ] Step 3: Normalize structural changes
- [ ] Step 4: Apply gate rules
- [ ] Step 5: Emit review packet and actions
Step 1: Resolve Inputs
Accept two refs, a branch name, a commit range, or before/after directories.
Do not check out branches unnecessarily. Prefer git diff, git show, and
git worktrees, following the graph-evolution snapshot workflow.
Step 2: Build Graph Evidence
Run graph-evolution or equivalent Trailmark before/after graph analysis.
Both snapshots must run engine.preanalysis() so taint, privilege-boundary,
blast-radius, complexity, and entrypoint signals are available.
Record Trailmark version and any feature probes. If graph construction fails,
emit UNKNOWN.
Step 3: Normalize Changes
Normalize evidence into:
- added, removed, and modified nodes
- added and removed edges
- entrypoint set changes
- taint membership changes
- privilege-boundary membership changes
- blast-radius changes
- complexity changes
- newly reachable sensitive sinks
- unresolved, proxy, or dynamic edge changes
Step 4: Apply Gate Rules
Apply the rules in references/gate-rules.md. Gate verdicts are:
| Verdict | Meaning |
|---|---|
FAIL | A high-risk structural regression needs review before acceptance |
WARN | A meaningful graph change needs reviewer attention |
PASS | No configured structural gate fired |
UNKNOWN | Trailmark failed or evidence is too incomplete |
Step 5: Emit Packet
Write the packet using
references/output-format.md, then hand it to
the branch reviewer. Use
references/review-integration.md when
combining this packet with differential-review or another PR review process.
Requirements
- Never mutate the user's working branch while comparing refs.
- Never report
PASSwhen Trailmark failed. - Separate graph evidence from manual security judgment.
- Include exact changed nodes or paths for every
FAILandWARN. - Include limitations when parser, proxy, unresolved-call, or dynamic-dispatch uncertainty affects the verdict.
GitHub リポジトリ
よくある質問
trailmark-review-gate Skillとは何ですか?
trailmark-review-gate はtrailofbits が作成した Claude Skillです。Skillは、Claudeが必要に応じて読み込む指示とリソースをまとめ、追加の指示なしで trailmark-review-gate に関連するタスクを実行できるようにします。
trailmark-review-gate をインストールするには?
このページのインストールコマンドを使用してください。trailmark-review-gate をプラグインとして Claude Code に追加するか、リポジトリを skills ディレクトリにクローンし、Claudeを再起動してSkillを読み込みます。
trailmark-review-gate はどのカテゴリに属しますか?
trailmark-review-gate は テスト カテゴリに属します。
trailmark-review-gate は無料で利用できますか?
はい。trailmark-review-gate は AIMCP に掲載されており、無料でインストールできます。
関連スキル
このClaudeスキルは、lm-evaluation-harnessを実行し、MMLUやGSM8Kなど60以上の標準化学術タスクでLLMをベンチマークします。開発者がモデルの品質を比較し、トレーニングの進捗を追跡し、学術的な結果を報告するために設計されています。このツールはHuggingFaceやvLLMモデルを含む様々なバックエンドをサポートしています。
このスキルは、cron式を使用してWorkersをスケジュールするためのCloudflare Cron Triggersの実装に関する包括的な知識を提供します。定期的なタスクの設定、メンテナンスジョブ、自動化されたワークフローの構築を網羅し、無効なcron式やタイムゾーン問題といった一般的な課題への対処法も含みます。開発者はこれを使用して、スケジュールされたハンドラーの設定、cronトリガーのテスト、WorkflowsやGreen Computeとの連携を構成できます。
このClaude Skillは、Playwrightベースのツールキットを提供し、Pythonスクリプトを通じてローカルWebアプリケーションのテストを可能にします。フロントエンドの検証、UIデバッグ、スクリーンショット撮影、ログ表示を実現し、サーバーライフサイクルを管理します。ブラウザ自動化タスクにご利用いただけますが、コンテキストの汚染を避けるため、スクリプトのソースコードを読むのではなく直接実行してください。
このスキルは、開発者がテストの合格を確認し、構造化された統合オプションを提示することで、完成した作業を仕上げることを支援します。実装が完了した後のマージ、PR作成、ブランチの整理といったワークフローを案内します。コードが準備できてテスト済みの際に使用し、開発プロセスを体系的に完了させましょう。
