Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge.
npx skills add https://github.com/trailofbits/skills --skill trailmark-review-gate
Apply deterministic security gate rules to Trailmark structural diff evidence.
This skill does not replace line-level review. It produces a compact structural
packet reviewers can cite while they inspect the code.
complexity signals
trailmark or trailmark-structural.differential-review.trailmark-finding-triage.| Rationalization | Why It Is Wrong | Required Action |
|---|---|---|
| "The line diff is small, so no graph gate is needed" | Small changes can create new call paths | Compare before/after graphs |
| "Graph gate passed, so the PR is secure" | The gate only checks structural regressions | Still perform line-level review |
| "Trailmark failed, so pass the gate" | Tool failure is unknown risk, not success | Emit UNKNOWN |
| "Tests pass, so removed validation is fine" | Tests may miss affected entrypoint paths | Review the removed path manually |
| "Only new code matters" | Removed auth, validation, and callers can be higher risk than additions | Review removals and path changes |
Review Gate Progress:
- [ ] Step 1: Resolve before/after inputs
- [ ] Step 2: Build graph-evolution evidence
- [ ] Step 3: Normalize structural changes
- [ ] Step 4: Apply gate rules
- [ ] Step 5: Emit review packet and actions
Accept two refs, a branch name, a commit range, or before/after directories.
Do not check out branches unnecessarily. Prefer git diff, git show, and
git worktrees, following the graph-evolution snapshot workflow.
Run graph-evolution or equivalent Trailmark before/after graph analysis.
Both snapshots must run engine.preanalysis() so taint, privilege-boundary,
blast-radius, complexity, and entrypoint signals are available.
Record Trailmark version and any feature probes. If graph construction fails,
emit UNKNOWN.
Normalize evidence into:
Apply the rules in references/gate-rules.md.
Gate verdicts are:
| Verdict | Meaning |
|---|---|
| FAIL | A high-risk structural regression needs review before acceptance |
| WARN | A meaningful graph change needs reviewer attention |
| PASS | No configured structural gate fired |
| UNKNOWN | Trailmark failed or evidence is too incomplete |
Write the packet using
references/output-format.md, then hand it to
the branch reviewer. Use
references/review-integration.md when
combining this packet with differential-review or another PR review process.
PASS when Trailmark failed.FAIL and WARN.uncertainty affects the verdict.
Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation
Use when completing tasks, implementing major features, or before merging to verify work meets requirements
Execute git commit with conventional commit message analysis, intelligent staging, and message generation. Use when user asks to commit changes, create a git commit, or mentions "/commit". Supports: (1) Auto-detecting type and scope from changes, (2) Generating conventional commit messages from diff, (3) Interactive commit with optional type/scope/description overrides, (4) Intelligent file staging for logical grouping
Comprehensive GitHub code review with AI-powered swarm coordination
Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.
Use this skill to review code. It supports both local changes (staged or working tree) and remote Pull Requests (by ID or URL). It focuses on correctness, maintainability, and adherence to project standards.
Refactor bloated AGENTS.md, CLAUDE.md, or similar agent instruction files to follow progressive disclosure principles. Splits monolithic files into organized, linked documentation.
Create high-quality git commits: review/stage intended changes, split into logical commits, and write clear commit messages (including Conventional Commits). Use when the user asks to commit, craft a commit message, stage changes, or split work into multiple commits.
Take trailofbits/trailmark-review-gate from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.