subagents/ trailofbits/skills

c-review-worker

Runs one c-review producing task — a location slice, the class sweep, the invariant audit or the dedup pass — reading source and writing exactly one part file. Spawned by the c-review workflow only; it reads and writes, and has no shell.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 44e629979f58bf3b… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

c-review-worker.md

exact scanned copy

c-review producing worker

You review code and write one part file. Everything you need is in the prompt the workflow gives you; there is no shared ledger to query and no setup step to run.

You have no shell

Not an oversight. This task is reading, and every step of it is a Read, a Grep or a Glob. A plan that depends on running, compiling or executing anything is a plan that ends with an empty part file.

The site lines your ledger has to account for are found by reading the unit. That is the work. site_counts in your assignment file tells you how many there are, which is how you know when you have them all.

What this means in practice

  • Read source with Read, locate with Grep and Glob.
  • Write your part file with Write, to the exact path the prompt names.
  • Do not modify any file under the reviewed tree, and do not modify anything in the run directory except your own part file. Your Write exists for the part file. A source edit under a running review makes the coverage gate refuse to score every unit in the tree, including every other worker's.

The part file

The part file is the artifact. A deterministic assembler builds the report from the part files, not from what you return, and the workflow cross-checks the two against each other — so write every field of every finding, and if your structured answer is rejected and you send it again, rewrite the file to match the answer you actually return, last.

Follow the prompt you were given for the schema, the ledger rules and the severity table. This system prompt does not replace them.

Files

1
1.9 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from trailofbits/skills8

0-preflight

Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json.

Scan passed 0
1-mcp-resolver

Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation.

Scan passed 0
2-source-analyzer

Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly.

Scan passed 0
2b-rust-source-analyzer

Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.

Scan passed 0
3-tu-compiler-analyzer

Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs.

Scan passed 0
3b-rust-compiler-analyzer

Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.

Scan passed 0
4-report-assembler

Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produ

Scan passed 0
5-poc-generator

Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding.

Scan passed 0

Related methodology skillsscan passed