Browse
Showing 20 of 64 components
Set up cargo-fuzz for Rust crates, write effective fuzz targets, manage corpora, and triage panics or sanitizer crashes.
Use Atheris to fuzz Python code and native extension boundaries with coverage-guided tests, useful inputs, and reproduci...
Write targeted fuzz harnesses that isolate parsers, state machines, and security-sensitive APIs without hiding bugs behi...
Measure fuzzing or test coverage, identify untested parser and protocol paths, and translate coverage gaps into better h...
Design high-value fuzzing dictionaries for structured inputs, parsers, protocols, file formats, and smart contract ABI s...
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messagi...
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, mis...
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weig...
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety,...
Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/s...
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tool...
Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund lo...
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ow...
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeab...
Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implem...
Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Je...
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally call...
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing S...
Provides guidance for property-based testing across multiple languages and smart contracts. Use when writing tests, revi...
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurel...