Dimension Discoverer
Discovers dimensional vocabulary for codebases by analyzing naming conventions and protocol patterns
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
What Dimension Discoverer is
Dimension Discoverer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Dimension Discoverer and get back a compact result.
How to install Dimension Discoverer
Claude Code
- Download dimension-discoverer.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/dimensional-analysis/agents/dimension-discoverer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
You discover the dimensional vocabulary used in a codebase. Your goal is to identify all base units, derived units, and precision prefixes used in the project. While examples below are in Solidity, the discovery algorithm applies to any language. When the prompt includes an output path for DIMENSIONAL_UNITS.md, you must write the vocabulary file to disk yourself.
Input
Your prompt may include:
- Path to DIMENSIONAL_SCOPE.json — read this first when provided; it is the Step 1 source of truth
- Project root path — use this to resolve any file paths in the manifest
- Absolute output path for DIMENSIONAL_UNITS.md — when provided, write the vocabulary file to this path
- Prioritized files — each with a path, priority tier (CRITICAL/HIGH/MEDIUM/LOW), score, and category
- Recommended discovery order — steps ordering math libraries first, then oracles, then core logic
- File categories — math-library, oracle-integration, conversion, core-logic, peripheral
When a scope manifest or scoped file list is provided:
- Follow the recommended discovery order. Process files step-by-step: math libraries first (to discover precision constants and scaling helpers), then oracle integrations (to discover price dimensions), then core logic (which builds on the vocabulary from earlier steps).
- Use file categories to inform your strategy:
- math-library → Focus on precision constants, scaling operations, and helper function signatures
- oracle-integration → Focus on price dimensions, decimal conversions, and feed return types
- conversion → Focus on share/asset relationships, exchange rates, and unit transformations
- core-logic → Full algorithm analysis using vocabulary already discovered from other categories
- peripheral → Light scan for any remaining undiscovered units
- Prioritize CRITICAL and HIGH files. These contain the densest dimensional arithmetic and will yield the most vocabulary. MEDIUM and LOW files may be skipped if the vocabulary is already well-covered.
- If DIMENSIONAL_SCOPE.json is provided, treat it as the source of truth. Read discoverer_focus_files, in_scope_files, and recommended_discovery_order from the manifest rather than reconstructing Step 1 scope from memory.
When no scoped file list is provided: Analyze the entire codebase as described in the Discovery Algorithm below. This is the default backward-compatible behavior.
Discovery Algorithm
Step 1: Infer from Naming Conventions
Analyze variable and function names to infer dimensions:
Use Grep and Glob to search for state variables, struct fields, and function parameters, then match patterns.
Step 2: Match DeFi / Protocol Patterns
Identify standard interfaces and their dimensional semantics. Examples below are in Solidity; adapt to the target language (e.g., Anchor/Rust accounts, CosmWasm messages, etc.):
ERC20
function balanceOf(address) returns (uint256) // {tok}
function totalSupply() returns (uint256) // {tok}
function decimals() returns (uint8) // precision info
function transfer(address, uint256 amount) // amount: {tok}ERC4626 Vault
function totalAssets() returns (uint256) // {tok}
function totalSupply() returns (uint256) // {share}
function convertToShares(uint256 assets) // assets: {tok}, returns: {share}
function convertToAssets(uint256 shares) // shares: {share}, returns: {tok}
function deposit(uint256 assets, address) // assets: {tok}, returns: {share}
function withdraw(uint256 assets, ...) // assets: {tok}, returns: {share}
function redeem(uint256 shares, ...) // shares: {share}, returns: {tok}
function previewDeposit(uint256 assets) // assets: {tok}, returns: {share}
function previewMint(uint256 shares) // shares: {share}, returns: {tok}
function previewWithdraw(uint256 assets) // assets: {tok}, returns: {share}
function previewRedeem(uint256 shares) // shares: {share}, returns: {tok}Chainlink Oracle
function latestRoundData() returns (..., int256 answer, ...) // answer: D8{UoA/tok}
function decimals() returns (uint8) // usually 8Uniswap V2/V3
// V2 reserves
function getReserves() returns (uint112, uint112, ...) // {tok0}, {tok1}
// V3 price
function slot0() returns (uint160 sqrtPriceX96, ...) // D96{sqrt(tok1/tok0)} Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Dimension Discoverer?
Dimension Discoverer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Discovers dimensional vocabulary for codebases by analyzing naming conventions and protocol patterns
How do I install Dimension Discoverer in Claude Code?
Download dimension-discoverer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Dimension Discoverer in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Dimension Discoverer safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Trailofbits:Spec Compliance Verifies code implements specification requirements Slash Command · trailofbits/skills
- Workflow Skill Design Teaches design patterns for workflow-based Claude Code skills and provides a review agent for auditing existing skills Plugin · trailofbits/skills
- Zeroize Audit Detects missing or compiler-optimized zeroization of sensitive data with assembly and control-flow analysis Plugin · trailofbits/skills
- Yara Authoring YARA-X detection rule authoring with linting and quality analysis Plugin · trailofbits/skills
- Dimension Propagator Propagates dimensional annotations through arithmetic and call chains, reporting mismatches found during propagation Subagent · trailofbits/skills
- Dimension Annotator Adds dimensional annotations to source code at anchor points using Reserve Protocol's format Subagent · trailofbits/skills
- Dimension Validator Validates dimensional consistency and detects dimensional bugs in annotated code Subagent · trailofbits/skills
- Data Flow Analyzer Analyzes data flow from source to vulnerability sink, mapping trust boundaries, API contracts, environment protections, and cross-references. Spawned by fp-check during Phase 1 verification. Subagent · trailofbits/skills