Skills tagged analysis: 108 agent skills for Claude Code
algorand-vulnerability-scanner — Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations.
amazon-braket — Runs quantum computing workflows on AWS through Amazon Braket — discovering devices (QPUs and simulators) and their availability.
amazon-neptune — Provides authoritative guidance on Amazon Neptune Database and Neptune Analytics for graph, knowledge-graph.
audit-context-building — Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.
aws-ai-ml — Selects, deploys, and customizes AI models on Amazon SageMaker.
aws-database — Routes any task involving AWS databases — choosing, comparing, recommending, getting started with.
benchmark-due-diligence — Runs adversarial due-diligence on a benchmark the user envies — a founder, KOL, company.
claude-usage-analyst — Analyze Claude Code and Claude Desktop Code token usage, cost, quota burn, model mix, cache read/write, and 5-hour block consumption using ccusage evidence.
code-maturity-assessor — Systematic code maturity assessment using Trail of Bits' 9-category framework.
codeql — Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis.
competitor-profiling — When the user wants to research, profile, or analyze competitors from their URLs. ' Input is a list of competitor URLs.
competitors — When the user wants to create competitor comparison or alternative pages for SEO and sales enablement.
competitors-analysis — Discover, clone, update, and analyze competitor repositories with evidence-based competitive intelligence.
constant-time-analysis — Detects timing side-channel vulnerabilities in cryptographic code.
constant-time-testing — Measures timing side channels in cryptographic implementations by running them.
continue-claude-code-work — Continues interrupted Claude Code work only after local history has been read and reconciled.
continue-codex-work — Continues interrupted OpenAI Codex work only after read-codex-history verifies the selected rollout identity and complete fork/compaction lineage.
coordinating-multi-space-devops-agent — Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session — route questions to the right space (prod vs staging vs knowledge).
cosmos-vulnerability-scanner — Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence.
coverage-analysis — Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output.
crypto-protocol-diagram — spthy) models and generates Mermaid sequenceDiagrams with cryptographic annotations.
customer-research — When the user wants to conduct, analyze, or synthesize customer research.
deep-research — Generate format-controlled research reports with evidence tracking, citations, source governance, and multi-pass synthesis.
design-md — Analyze Stitch projects and synthesize a semantic design system into DESIGN.md files
diagramming-code — Generates Mermaid diagrams from Trailmark code graphs.
differential-review — Performs security-focused differential review of code changes.
dimensional-analysis — Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling.
dwarf-expert — Analyzes DWARF debug information in compiled binaries.
entry-point-analyzer — Analyzes smart contract codebases to identify state-changing entry points for security auditing.
exploring-data-catalog — Full inventory and audit of AWS Glue Data Catalog assets across S3 Tables, Redshift-federated, and remote Iceberg catalogs.
finding-data-lake-assets — Resolve data lake and lakehouse asset references across Glue Data Catalog, S3, S3 Tables, and Redshift.
firebase-apk-scanner — Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions.
let-fate-decide — Draws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated.
product-marketing — When the user wants to create or update their product marketing context document.
prompt-optimizer — Transform vague prompts into precise, well-structured specifications using EARS (Easy Approach to Requirements Syntax) methodology.
property-based-testing — Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.
prospecting — When the user wants to find, qualify, and build a list of prospects to reach out to — across B2B SaaS, general B2B, or local small businesses.
qa-expert — This skill should be used when establishing comprehensive QA testing processes for any software project.
read-claude-code-history — Reads, searches, and exports local Claude Code history without resuming work.
read-claude-web-conversation — ai/chat/... ai/share/... ai's internal API from inside the user's logged-in Chrome, and download its FILES too (uploads, deliverables).
read-codex-history — Reads, searches, and exports local OpenAI Codex history without continuing the old task.
seo — Comprehensive SEO analysis for any website or business type.
seo-audit — Full website SEO audit with parallel subagent delegation.
seo-audit — When the user wants to audit, review, or diagnose SEO issues on their site.
seo-cluster — SERP-based semantic topic clustering for content architecture planning.
seo-content — Content quality and E-E-A-T analysis with AI citation readiness assessment.
seo-page — Deep single-page SEO analysis covering on-page elements, content quality, technical meta tags, schema, images, and performance.
seo-plan — Strategic SEO planning for new or existing websites. Industry-specific templates, competitive analysis, content strategy, and implementation roadmap.
seo-profound — Profound LLM citation tracker (extension). Time-series brand citation rates across ChatGPT, Perplexity, and other LLMs.
seo-seranking — SE Ranking AI visibility analyst (extension). Tracks AI Share-of-Voice across ChatGPT, Gemini, Perplexity, AI Overviews, and AI Mode in a single query.
seo-sxo — Search Experience Optimization: reads Google SERPs backwards to detect page-type mismatches, derives user stories from search intent signals.
seo-technical — Technical SEO audit across 9 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured data, JavaScript rendering.
signup — When the user wants to optimize signup, registration, account creation, or trial activation flows.
slicing-code-context — Selects bounded, graph-informed source slices with Trailmark and delegates focused code analysis or patch-proposal work to a smaller subagent.
solana-vulnerability-scanner — Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
spec-to-code-compliance — Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent.
stitch::extract-design-md — md) directly from frontend source code — React, Vue, Svelte, Angular, plain HTML/CSS, or any web framework.
substrate-vulnerability-scanner — Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks.
supply-chain-risk-auditor — Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree.
threat-modeling-with-aws-security-agent — Run an AWS Security Agent threat model review on spec/design documents. md for security posture changes, or STRIDE analysis.
tibo-reset-codex — 查询 ChatGPT/Codex 重置公告及多个 Pro 账号的剩余额度、备用 Full reset;复用 Google 登录逐个核实并恢复网页账号,换算北京时间。区分 Tibo 官宣、未官宣的平台静默重置、banked reset 与账户级周期重置。Use when.
token-integration-analyzer — Token integration and implementation analyzer based on Trail of Bits' token integration checklist.
ton-vulnerability-scanner — Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts.
trailmark — Builds and queries multi-language source and binary code graphs for security analysis. toml`, and SQL schema graphs.
trailmark-finding-triage — Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function.
trailmark-review-gate — Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths.
trailmark-structural — 5+ data such as proxy counts, subgraph edges, type/reference summaries, and entrypoint attributes.
trailmark-summary — Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list.