askill
Superlend

Superlend

Publisher on askill

0 total stars
Skills17
Updated 2/2/2026
GitHub
semgrep
semgrep
Superlend2/2/2026

Run Semgrep static analysis for fast security scanning and pattern matching. Use when asked to scan code with Semgrep, write custom YAML rules, find vulnerabilities quickly, use taint mode, or set up...

0
AI 95
semgrep-rule-creator
semgrep-rule-creator
Superlend2/2/2026

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

0
AI 92
variant-analysis
variant-analysis
Superlend2/2/2026

Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing s...

0
AI 92
secure-workflow-guide
secure-workflow-guide
Superlend2/2/2026

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, he...

0
AI 92
code-maturity-assessor
code-maturity-assessor
Superlend2/2/2026

Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation...

0
AI 88
algorand-vulnerability-scanner
algorand-vulnerability-scanner
Superlend2/2/2026

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand pr...

0
AI 88
ruzzy
ruzzy
Superlend2/2/2026

Ruzzy is a coverage-guided Ruby fuzzer by Trail of Bits. Use for fuzzing pure Ruby code and Ruby C extensions.

0
AI 88
cosmos-vulnerability-scanner
cosmos-vulnerability-scanner
Superlend2/2/2026

Scans Cosmos SDK blockchains for 9 consensus-critical vulnerabilities including non-determinism, incorrect signers, ABCI panics, and rounding errors. Use when auditing Cosmos chains or CosmWasm contra...

0
AI 82
fuzzing-obstacles
fuzzing-obstacles
Superlend2/2/2026

Techniques for patching code to overcome fuzzing obstacles. Use when checksums, global state, or other barriers block fuzzer progress.

0
AI 82
token-integration-analyzer
token-integration-analyzer
Superlend2/2/2026

Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, asse...

0
AI 78
dwarf-expert
dwarf-expert
Superlend2/2/2026

Provides expertise for analyzing DWARF debug files and understanding the DWARF debug format/standard (v3-v5). Triggers when understanding DWARF information, interacting with DWARF files, answering DWA...

0
AI 78
semgrep-rule-variant-creator
semgrep-rule-variant-creator
Superlend2/2/2026

Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test...

0
AI 76
fix-review
fix-review
Superlend2/2/2026

Verifies that git commits address security audit findings without introducing bugs. This skill should be used when the user asks to "verify these commits fix the audit findings", "check if TOB-XXX was...

0
AI 76
atheris
atheris
Superlend2/2/2026

Atheris is a coverage-guided Python fuzzer based on libFuzzer. Use for fuzzing pure Python code and Python C extensions.

0
AI 72
audit-prep-assistant
audit-prep-assistant
Superlend2/2/2026

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and genera...

0
AI 62
ask-questions-if-underspecified
ask-questions-if-underspecified
Superlend2/2/2026

Clarify requirements before implementing. Use when serious doubts arise.

0
insecure-defaults
insecure-defaults
Superlend2/2/2026

Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or ana...

0
Showing all 17 skills.