dimensional-analysis
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol, offchain code, or other blockchain-related codebase with arith
- 0
- Installs
- —
- Rating
- —
- Success rate
- 6
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 53dcf9ca425f3203… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Dimensional Analysis Skill
This skill orchestrates a dimensional-analysis pipeline for codebases that perform numeric computations with mixed units, precisions, or scaling factors. The main skill context is a workflow controller only: it delegates scanning, vocabulary discovery, annotation, propagation, and validation to specialized subagents, then manages batching, persistence, retries, coverage gates, and final reporting.
When to Use
- Annotating a codebase with unit/dimension comments (e.g.,
D18{tok},D27{UoA/tok}) - Performing dimensional analysis on DeFi protocols, financial code, or scientific computations
- Hunting for arithmetic bugs caused by unit mismatches, missing scaling, or precision loss
- Auditing codebases with mixed decimal precisions or fixed-point arithmetic
When NOT to Use
- Codebases with no numeric arithmetic or unit conversions — there is nothing to annotate
- Pure integer counting logic (loop indices, array lengths) with no physical or financial dimensions
- When you only need a quick spot-check of a single formula — read the code directly instead of running the full pipeline
Execution Mode
This skill runs in one mode only: full-auto.
This is a workflow-based skill that delegates step-specific work to specialized agents via the Task tool. You orchestrate the overall process, manage coverage and state persistence, and ensure that every in-scope file is processed through each step of the pipeline.
- Always run the full pipeline in this order: Step 1 -> Step 2 -> Step 3 -> Step 4.
- The main skill context must not perform repository-wide dimensional analysis, annotation, propagation, or bug validation itself when a dedicated subagent exists for that step.
- The main skill context may inspect artifacts, manifests, and subagent outputs only as needed to route work, build prompts, persist state, and determine completion.
- Any mode argument provided by the caller is ignored.
- Report all results at the end in a single summary.
When you start a step, report it:
Starting Step: Step {n}
Scope and Coverage Guarantees
This skill must audit all in-scope arithmetic files, including large repositories.
- In-scope files are defined by Step 1 scanner output (
filesarray), across all priority tiers (CRITICAL, HIGH, MEDIUM, LOW). - If Step 1 narrows inputs for vocabulary discovery (for example, CRITICAL/HIGH only), that narrowing applies to discovery only. It never reduces annotation or validation scope.
arithmetic-scannerpersists the in-scope file manifest toDIMENSIONAL_SCOPE.jsonin the project root, and that manifest is the source of truth for Steps 2-4.- A file is considered fully covered only when all three statuses are present:
step2: anchor annotation completed (or explicit no-anchor result)step3: propagation completed (or explicit no-propagation result)step4: validation completed
dimension-discovererpersists the discovered dimensional vocabulary toDIMENSIONAL_UNITS.mdin the project root for reuse by later steps and future runs.- When a file ends in a terminal
BLOCKEDstate, persist the blocking reason and retry count inDIMENSIONAL_SCOPE.jsonand reflect the same file incoverage.unprocessed_files. - Do not finish while any in-scope file remains unprocessed in any step.
Delegation Contract
arithmetic-scannerowns repository scanning, arithmetic-file prioritization, and writingDIMENSIONAL_SCOPE.json.dimension-discovererowns dimensional vocabulary discovery, unit inference, and writingDIMENSIONAL_UNITS.md.dimension-annotatorowns annotation format decisions, anchor-point edits, and comment-writing behavior.dimension-propagatorowns propagation logic, inferred annotations, and mismatch reporting during tracing.dimension-validatorowns bug detection, red-flag evaluation, rationalization rejection, and confirmation or refutation of propagated mismatches.- The main skill context must not substitute its own dimensional reasoning for skipped or unlaunched subagents. If a step requires specialized reasoning, launch the corresponding subagent.
- Use reference files as subagent support material. Pass them to the relevant step in prompts instead of treating them as instructions for the main skill context.
Workflow
Follow these sections in order. Do not advance until the current step satisfies its completion gate.
Shared Orchestration Rules
DIMENSIONAL_SCOPE.jsonandDIMENSIONAL_UNITS.mdlive in the project root.- The main skill context verifies Step 1 artifacts but does not write either Step 1 artifact itself.
DIMENSIONAL_SCOPE.json.in_scope_filesis the source of truth for Steps 2-4. Never derive later scope from discovery-only inputs.- When a later step reaches terminal
BLOCKED, persist the matchingstep*_reasonandstep*_retry_countfields on the file entry inDIMENSIONAL_SCOPE.json. coverage.unprocessed_filesmust be derived from terminalBLOCKEDentries inDIMENSIONAL_SCOPE.jsonusing{ "path": "...", "blocked_step": "step2|step3|step4", "reason": "...", "retry_count": 1 }.- A step may retry a
BLOCKEDfile once with a focused prompt. If it is stillBLOCKED, keep the documented reason and continue. Do not finalize while any file remainsPENDING.
Step 1: Vocabulary and Scope Discovery
If cached artifacts cannot be reused, delegate repository scanning to arithmetic-scanner and vocabulary discovery to dimension-discoverer. Do not do that step-specific analysis directly in the main skill context.
- Check whether
DIMENSIONAL_UNITS.mdandDIMENSIONAL_SCOPE.jsonalready exist in the project root. - If both exist, read them and confirm:
DIMENSIONAL_SCOPE.json.project_rootmatches the current repo rootDIMENSIONAL_SCOPE.jsoncontainsin_scope_files,discoverer_focus_files,recommended_discovery_order, and per-filestep2,step3,step4fieldsDIMENSIONAL_UNITS.mdis a usable dimensional vocabulary for this repo
- If either artifact is stale, malformed, missing required structure, or clearly for another repo, discard reuse and rerun the rest of Step 1.
- If both artifacts are valid, reuse them directly. If
in_scope_filesis empty, skip Steps 2-4 and produce final output with zero findings. - Otherwise use the
Tasktool to spawn thearithmetic-scanneragent. Its prompt must include:- project root path
- absolute output path for
DIMENSIONAL_SCOPE.json - instruction to write the Step 1 scope manifest to disk and return the same scope data in its report
- The scanner owns Step 1 scope persistence. It must:
- identify dimensional-arithmetic files and prioritize them as usual
- write
DIMENSIONAL_SCOPE.jsonwithproject_root,in_scope_files,discoverer_focus_files, andrecommended_discovery_order - initialize every in-scope file with
step2: "PENDING",step3: "PENDING", andstep4: "PENDING" - still write an empty manifest when no arithmetic files are found
- still narrow
discoverer_focus_filesto CRITICAL/HIGH when more than 50 arithmetic files are found, while keeping all priorities inin_scope_files
- After the scanner completes, read
DIMENSIONAL_SCOPE.jsonfrom disk and confirm it exists and contains the required Step 1 fields before continuing. - Use the
Tasktool to spawn thedimension-discovereragent. Its prompt must include:- project root path
- absolute path to
DIMENSIONAL_SCOPE.json - absolute output path for
DIMENSIONAL_UNITS.md - prioritized
discoverer_focus_fileswith each file's path, priority, score, and category recommended_discovery_order
- The discoverer owns Step 1 vocabulary persistence. It must read
DIMENSIONAL_SCOPE.jsonas the Step 1 source of truth and writeDIMENSIONAL_UNITS.mdwithBase Units,Derived Units, andPrecision Prefixessections. Ifin_scope_filesis empty, it must still write the same headings with empty sections. - Step 1 is complete only when both artifacts exist on disk, pass the reuse checks above, and correctly represent the zero-file case. If
in_scope_filesis empty after the discoverer writesDIMENSIONAL_UNITS.md, skip Steps 2-4 and produce final output with zero findings.
Step 2: Anchor Annotation
The main skill context must not add annotations itself. Use the Task tool to spawn dimension-annotator agents for all anchor-point annotation work. For full examples and annotation format details, see [{baseDir}/references/annotate.md]({baseDir}/references/annotate.md).
- Read
DIMENSIONAL_SCOPE.jsonand build batches fromin_scope_files. Every in-scope file, including MEDIUM and LOW priority files, must receive a Step 2 outcome. - Batch files instead of spawning one agent per file:
<= 10files: one batch11-30files: one batch per category> 30files: one batch per category, splitting categories larger than 10 files into sub-batches of about 8 files
- Launch categories in Step 1 recommended discovery order: math libraries, then oracles, then core logic, then peripheral. Batches inside the same category may run in parallel.
- Before launching annotators, set
step2 = "PENDING"for every in-scope file and persist the updatedDIMENSIONAL_SCOPE.json. - Each annotator prompt must include:
- absolute path to
DIMENSIONAL_UNITS.md - absolute path to
DIMENSIONAL_SCOPE.json - assigned file paths in order
- each file's category and matched patterns from scanner output
- summary of previously annotated interfaces or types from earlier batches, when applicable
- required per-file status output:
ANNOTATED,REVIEWED_NO_ANCHOR_CHANGES, orBLOCKEDplus a one-line justification
- absolute path to
- After each batch, immediately persist each assigned file to exactly one Step 2 status:
ANNOTATEDREVIEWED_NO_ANCHOR_CHANGESBLOCKED
- If a file is
BLOCKED, also persiststep2_reasonandstep2_retry_count. Retry eachBLOCKEDfile once with a focused prompt. - Do not continue to Step 3 while any file remains
PENDINGin on-disk manifest state.
Step 3: Dimension Propagation
The main skill context must not perform propagation reasoning itself. Use the Task tool to spawn dimension-propagator agents to extend annotations through arithmetic, function calls, and assignments. For algebra details, see [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md).
- Read
DIMENSIONAL_SCOPE.jsonand build propagation batches fromin_scope_files. Every in-scope file must receive a Step 3 outcome. - Use the same batching rules and category ordering as Step 2.
- Before launching propagators, confirm every file already has a non-pending Step 2 status.
- Then set
step3 = "PENDING"for every in-scope file and persist the updated manifest. - Each propagator prompt must include:
- absolute path to
DIMENSIONAL_UNITS.md - absolute path to
DIMENSIONAL_SCOPE.json - assigned file paths in order
- each file's category and matched patterns
- summary of Step 2 anchor annotations for the assigned files and any upstream interfaces they depend on
- required per-file status output:
PROPAGATED,REVIEWED_NO_PROPAGATION_CHANGES, orBLOCKEDplus a one-line justification
- absolute path to
- After each batch, immediately persist each assigned file to exactly one Step 3 status:
PROPAGATEDREVIEWED_NO_PROPAGATION_CHANGESBLOCKED
- If a file is
BLOCKED, also persiststep3_reasonandstep3_retry_count. Retry eachBLOCKEDfile once with a focused prompt. - After all propagators complete, aggregate:
- annotations added by confidence level (
CERTAIN,INFERRED,UNCERTAIN) - mismatches found, with severities for validator deduplication
- coverage gaps that could not be inferred
- annotations added by confidence level (
- Do not continue to Step 4 while any file remains
PENDINGin on-disk manifest state.
Step 4: Bug Detection
The main skill context must not perform bug detection itself. Use the Task tool to spawn dimension-validator agents to detect dimensional bugs in annotated code. For examples, red flags, rationalization checks, and standard vocabulary, see [{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md), [{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md), and [{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md). DO NOT DETECT BUGS IN ANY OTHER STEP.
- Validate every file in
DIMENSIONAL_SCOPE.json.in_scope_files. - Use this priority order without skipping lower tiers:
- files with CRITICAL or HIGH Step 3 mismatches
- remaining CRITICAL and HIGH scanner-priority files
- remaining MEDIUM and LOW files
- Before launching validators, confirm every file already has a non-pending Step 3 status.
- Then set
step4 = "PENDING"for every in-scope file and persist the updated manifest. - Spawn one
dimension-validatoragent per file. For large repos, run them in waves of roughly 10-30 files to keep orchestration stable. - Each validator prompt must include:
- absolute path to
DIMENSIONAL_UNITS.md - absolute path to
DIMENSIONAL_SCOPE.json - the single file path to validate
- a summary of anchor and propagated annotations in the file
- Step 3 mismatch summaries for the file, including mismatch IDs
- cross-file function signatures or return dimensions needed for call-boundary checks
- required per-file status output:
VALIDATEDorBLOCKED
- absolute path to
- After each wave, immediately persist each file to exactly one Step 4 status:
VALIDATEDBLOCKED
- If a file is
BLOCKED, also persiststep4_reasonandstep4_retry_count. Retry eachBLOCKEDfile once with a focused prompt. - Deduplicate findings:
- confirmed Step 3 mismatches keep their original IDs and severities
- refuted Step 3 mismatches are noted as false positives and excluded from final counts
- genuinely new findings receive new
DIM-XXXIDs
- Aggregate confirmed findings, new findings, refuted findings, coverage summary, and final
coverage.unprocessed_files. - Step 4 is complete only when
DIMENSIONAL_SCOPE.json.in_scope_filescontains nostep4: "PENDING"entries.
Reference Documentation
Pass these references to the relevant subagent when a step needs them:
[{baseDir}/references/dimension-algebra.md]({baseDir}/references/dimension-algebra.md)- Propagator and validator algebra rules[{baseDir}/references/common-dimensions.md]({baseDir}/references/common-dimensions.md)- Validator vocabulary reference[{baseDir}/references/bug-patterns.md]({baseDir}/references/bug-patterns.md)- Validator bug-pattern and red-flag reference[{baseDir}/references/annotate.md]({baseDir}/references/annotate.md)- Annotator format and example reference
Final Output
At the end of the analysis, provide a structured summary unless some other output format has been specified:
{
"mode": "full-auto",
"project_root": "<path>",
"vocabulary": {
"base_units": ["..."],
"derived_units": ["..."],
"precision_prefixes": ["..."]
},
"annotations": {
"total_added": 0,
"by_file": {}
},
"findings": {
"critical": 0,
"high": 0,
"medium": 0,
"details": []
},
"uncertainties_resolved": 0,
"coverage": {
"in_scope_files": 0,
"anchor_reviewed_files": "0/0",
"propagation_reviewed_files": "0/0",
"validation_reviewed_files": "0/0",
"annotated_functions": "0/0",
"annotated_variables": "0/0",
"unprocessed_files": [
{
"path": "/path/to/repo/contracts/LegacyMath.sol",
"blocked_step": "step3",
"reason": "Parser could not process generated source",
"retry_count": 1
}
]
}
}
Completion Checklist
You are NOT done until all of these are true:
File Coverage Gates
-
DIMENSIONAL_UNITS.mdexists in the project root -
DIMENSIONAL_SCOPE.jsonexists in the project root and is the source of truth for downstream coverage - Every in-scope arithmetic file discovered in Step 1 appears in
DIMENSIONAL_SCOPE.json.in_scope_files - Every in-scope file has a non-
PENDINGStep 2 status (ANNOTATED,REVIEWED_NO_ANCHOR_CHANGES, orBLOCKED) - Every in-scope file has a non-
PENDINGStep 3 status (PROPAGATED,REVIEWED_NO_PROPAGATION_CHANGES, orBLOCKED) - Every in-scope file has a non-
PENDINGStep 4 status (VALIDATEDorBLOCKED) - No in-scope file remains
PENDINGin any step - Any
BLOCKEDfile has a documented reason in the final output -
coverage.unprocessed_filesexactly matches the final set of terminalBLOCKEDfiles after retries, usingpath,blocked_step,reason, andretry_count
Summary Report
- Final summary JSON/report provided
- Final coverage counters match
DIMENSIONAL_SCOPE.json - List of modified files provided when edits occurred
- Any dimensional mismatches or bugs found are summarized
- Any remaining blocked or unprocessed files are called out with reasons
If DIMENSIONAL_SCOPE.json and the final report disagree, reconcile the report or continue processing until they match.
Do not claim completion from agent intent alone; completion is determined by manifest coverage and final reported statuses.
Files
6- SKILL.md
0434b5ec9517.4 KB - agents/openai.yaml
8eb086b9be245 B - references/annotate.md
c7d1a0987d11.7 KB - references/bug-patterns.md
36818df67f11.7 KB - references/common-dimensions.md
5743496a387.3 KB - references/dimension-algebra.md
e60adc21086.3 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from trailofbits/skills8
Builds and runs code under AddressSanitizer to catch buffer overflows, use-after-free, and other memory errors during fuzzing or tests. Covers -fsanitize=address builds, ASAN_OPTIONS, reading the crash report, LeakSanitizer, and the overhead and platform trade-offs. Use when fuzzing C/C++ or Rust th
Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. Covers instrumentation modes, parallel main and secondary campaigns, persistent mode, corpus minimization, and crash triage. Use when scaling fuzzing across cores, fuzzing a mature C/C++ codeba
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary p
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
Sets up and runs Atheris, the coverage-guided Python fuzzer built on libFuzzer. Covers TestOneInput harnesses, FuzzedDataProvider, instrumenting both pure Python and native C extensions, and running under AddressSanitizer. Use when fuzzing a Python package, hunting memory corruption in a Python C ex
Augments Trailmark code graphs with external audit findings from SARIF static analysis results, weAudit annotation files, and version-gated Trailmark 0.4.x binary-analysis graph exports. Maps findings to graph nodes by file and line overlap, creates severity-based subgraphs, and enables cross-refere
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass.
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). Use when preparing your own codebase
Related security skillsscan passed
Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppS
Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployme
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use
Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization headers via httpBatchLink headers(), WebSocket connectionPara