guidelines-advisor
An agent skill by trailofbits, from trailofbits/skills. Tags: architecture, documentation, security, strategy, testing.
What it does
Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Use when asking whether a smart contract project follows development best practices, reviewing on-chain/off-chain split, upgradeability, or delegatecall proxy patterns against guidelines, or seeking recommendations on contract design, inheritance, events, documentation, dependencies, or test strategy.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill guidelines-advisor
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/building-secure-contracts/skills/guidelines-advisor ~/.claude/skills/guidelines-advisor
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/building-secure-contracts/skills/guidelines-advisor/SKILL.md
- Branch
- main
- Collection
- building-secure-contracts
- Updated
- 2026-09-19
Related skills
- audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.
- open-sourcing — This skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public".
- secure-workflow-guide — Guides through Trail of Bits' 5-step secure development workflow.
- address-sanitizer — Builds and runs code under AddressSanitizer to catch buffer overflows, use-after-free, and other memory errors during fuzzing or tests.
- atheris — Sets up and runs Atheris, the coverage-guided Python fuzzer built on libFuzzer.
- audit-context-building — Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.