Audit Context Building
Understand a codebase before looking for bugs in it. Reads it function by function, records what each one assumes and depends on, and saves the write-ups to files instead of filling up the conversation.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 2.0.2
- Author
- Omar Inuwa
What Audit Context Building is
Audit Context Building is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Audit Context Building adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Audit Context Building
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install audit-context-building@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Audit Context Building in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/audit-context-building/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Understand a codebase before you go looking for bugs in it.
Author: Omar Inuwa
What it does
It reads the code function by function and writes up three things about each one: what it assumes is already true, what it promises to whatever calls it, and what it depends on elsewhere. Those write-ups go into files. You get back a short summary and a list of the spots worth a closer look.
It does not report vulnerabilities. That is the next job, and it goes much better once this one is done.
Why this exists
Claude can already read a function and explain it well. This plugin is not here to teach it that. It is here for three things Claude cannot do for itself:
You don't have to remember it exists. A workflow only runs when someone types its name. This skill notices the situation instead — you are starting an audit, or opening a codebase nobody on the team knows — and starts the right one for you.
It splits the work up. One helper runs per function, all at the same time, each writing its notes straight to a file. Ask Claude to do the same job directly and it works through the functions one at a time, filling its working memory with the notes until there is no room left to actually use them.
Every write-up comes out the same shape. That matters most in one specific case: when the code counts on something being true and nothing anywhere checks it. That always gets recorded the same way, with the words nothing found. So you can search a whole codebase for that one phrase and get every such spot in a list. Claude finds those spots on its own just fine — but describes each one differently, and forty differently worded notes do not add up to a list.
If you are changing this plugin, keep that order in mind. The guidance in SKILL.md and resources/ is sound practice and worth keeping, but it is not what makes the plugin useful. The value is in the workflow, the fixed write-up format, and the fact that it starts itself.
When to use it
At the start of an audit, a threat model, or an architecture review — any time the code is unfamiliar and somebody is about to go looking for problems in it.
Also useful when an earlier review turned up issues nobody could judge, because no one had mapped out how the system fits together.
How to run it
/audit-context-building:audit-context <path> [--focus <module>]That runs the workflow, in three steps:
- Get oriented. Map out the pieces of the system, the ways in from outside, who can reach them, and the data that sticks around between calls. Then pick the functions that carry the most weight.
- Analyze. One helper per function. Each writes its full notes to audit-context/functions/ and hands back only a short record.
- Pull it together. Work out the rules that span several functions — the ones no single write-up could state on its own — and save the result to audit-context/DOSSIER.md.
For a single function, you can run the audit-context-building:function-analyzer helper on its own. Either way the reading happens in a helper, not in your own session.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Audit Context Building?
Audit Context Building is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Understand a codebase before looking for bugs in it. Reads it function by function, records what each one assumes and depends on, and saves the write-ups to files instead of filling up the conversation.
How do I install Audit Context Building in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install audit-context-building@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Audit Context Building in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Audit Context Building in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Audit Context Building safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Supply Chain Risk Auditor Audit a project's npm, PyPI, and Go dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned upstreams, npm publisher concentration, and install scripts Plugin · trailofbits/skills
- Testing Handbook Skills Skills from the Trail of Bits Application Security Testing Handbook (appsec.guide) Plugin · trailofbits/skills
- Static Analysis Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection Plugin · trailofbits/skills
- Trailmark Builds source and binary code graphs for security analysis, context slicing, mutation testing, cryptographic protocol modeling, finding triage, and variant analysis. Plugin · trailofbits/skills
- Building Secure Contracts Comprehensive smart contract security toolkit based on Trail of Bits' Building Secure Contracts framework. Includes vulnerability scanners for 6 blockchains and 5 development guideline assistants. Plugin · trailofbits/skills
- Ask Questions If Underspecified Clarify ambiguous requirements by asking questions before implementing. Only when invoked explicitly. Plugin · trailofbits/skills
- Burpsuite Project Parser Search and extract data from Burp Suite project files (.burp) for security analysis Plugin · trailofbits/skills
- Agentic Actions Auditor Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference) Plugin · trailofbits/skills