trailmark-finding-triage
An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, security, trailmark, triage.
What it does
Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence. Use when deciding whether one candidate issue is reachable, prioritizing a finding before PoC work, preparing evidence for exploit validation, or checking whether a static-analysis result is actionable.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill trailmark-finding-triage
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/trailmark/skills/trailmark-finding-triage ~/.claude/skills/trailmark-finding-triage
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/trailmark/skills/trailmark-finding-triage/SKILL.md
- Branch
- main
- Collection
- trailmark
- Updated
- 2026-09-19
Related skills
- audit-augmentation — x binary-analysis graph exports. ).
- graph-evolution — Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes.
- trailmark — Builds and queries multi-language source and binary code graphs for security analysis. toml`, and SQL schema graphs.
- trailmark-review-gate — Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths.
- trailmark-structural — 5+ data such as proxy counts, subgraph edges, type/reference summaries, and entrypoint attributes.
- trailmark-variant-neighborhood — Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions.