spec-to-code-compliance
An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, code-quality, documentation, research.
What it does
Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the code does that no document mentions. Use when comparing an implementation against a whitepaper, protocol spec, or design document.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill spec-to-code-compliance
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/spec-to-code-compliance/skills/spec-to-code-compliance ~/.claude/skills/spec-to-code-compliance
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/spec-to-code-compliance/skills/spec-to-code-compliance/SKILL.md
- Branch
- main
- Collection
- spec-to-code-compliance
- Updated
- 2026-09-19
Related skills
- audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.
- variant-analysis — Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. ").
- stitch::extract-design-md — md) directly from frontend source code — React, Vue, Svelte, Angular, plain HTML/CSS, or any web framework.
- deep-research — Generate format-controlled research reports with evidence tracking, citations, source governance, and multi-pass synthesis.
- spec-miner — Reverse-engineering specialist that extracts specifications from existing codebases.
- audit-context-building — Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.