Dimensional Analysis
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol. Prevents dimensional mismatches and catches formula bugs early.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 3.0.3
- Author
- Coriolan Pinhas & Benjamin Samuels
What Dimensional Analysis is
Dimensional Analysis is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Dimensional Analysis adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Dimensional Analysis
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install dimensional-analysis@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Dimensional Analysis in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/dimensional-analysis/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Add dimensional annotations to codebases and detect dimensional bugs. Uses an annotation format inspired by Reserve Protocol's Solidity conventions, but applicable to any language or protocol performing numeric arithmetic with mixed units, precisions, or scaling factors.
Overview
This plugin runs one automatic workflow:
- Discover the dimensional vocabulary in your codebase (tokens, shares, prices, etc.)
- Annotate your code with dimensional comments like D18{tok}, D27{UoA/tok}
- Propagate dimensions through arithmetic and call paths
- Validate dimensional consistency and detect bugs
Annotation Format
Based on Reserve Protocol's format (shown here in Solidity, but adaptable to any language):
// State variables
uint256 public tvlFee; // D18{1/s} demurrage fee on AUM
uint256 public lastPoke; // {s}
// Struct fields
struct RebalanceLimits {
uint256 low; // D18{BU/share} (0, 1e27]
uint256 spot; // D18{BU/share} (0, 1e27]
uint256 high; // D18{BU/share} (0, 1e27]
}
// Function parameters (NatSpec)
/// @param weights D27{tok/BU} Basket weight ranges
/// @param prices D27{UoA/tok} Prices for each token
/// @return price D27{buyTok/sellTok}
// Inline arithmetic
// D27{buyTok/sellTok} = D27{UoA/sellTok} * D27 / D27{UoA/buyTok}
…Usage
The skill always executes in full-auto mode. Any supplied mode argument is ignored.
Workflow orchestration for all four phases lives in skills/dimensional-analysis/SKILL.md.
Automatic Behavior
- Uses existing DIMENSIONAL_UNITS.md if present; otherwise auto-generates and saves it
- Persists DIMENSIONAL_SCOPE.json as a source-of-truth manifest for large repos
- Applies annotations directly without approval gates
- Uses best-guess inference for uncertainties and flags them in output
- Reports results in a single summary at the end
Coverage Guarantees
- All in-scope arithmetic files from scanner output are required scope (CRITICAL/HIGH/MEDIUM/LOW)
- Discoverer narrowing (for vocabulary speed) does not reduce annotation or validation scope
- Each in-scope file must be marked as completed in Phase 2, Phase 3, and Phase 4 before finalization
Agents
Requirements
- A codebase performing numeric arithmetic with mixed units, precisions, or scaling factors
- Most effective for DeFi protocols (Solidity, Rust/Anchor, CosmWasm, etc.) but works with any language
- Optional for Solidity projects: slither-mcp for enhanced static analysis
References
See the references/ directory for:
- dimension-algebra.md - Rules for dimensional arithmetic
- common-dimensions.md - DeFi dimension vocabulary
- bug-patterns.md - Dimensional bug patterns with examples
- annotate.md - Full annotated protocol examples (ERC-4626, AMM, Lending)
Author
Coriolan Pinhas & Benjamin Samuels - Trail of Bits
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Dimensional Analysis?
Dimensional Analysis is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol. Prevents dimensional mismatches and catches formula bugs early.
How do I install Dimensional Analysis in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install dimensional-analysis@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Dimensional Analysis in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Dimensional Analysis in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Dimensional Analysis safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Rust Review Dedup Judge Deduplication judge for the rust-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over same-function candidates, including the same bug filed under different bug classes. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Rust Review Comprehensive Rust security code review with specialized bug-finding agents covering the safe/unsafe boundary, memory safety in unsafe blocks, concurrency, panic-induced DoS, recursion-induced stack overflow, FFI, and async runtime hazards Plugin · trailofbits/skills
- Seatbelt Sandboxer Generate minimal macOS Seatbelt sandbox configurations for applications Plugin · trailofbits/skills
- Rust Review Worker Runs one assigned rust-review cluster task and writes finding files to the run's output directory. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Dwarf Expert Analyze DWARF debug information: parse and search DIEs with dwarfdump and readelf, verify debug info integrity, and write DWARF parsing code Plugin · trailofbits/skills
- Differential Review Security-focused differential review of code changes with git history analysis and blast radius estimation Plugin · trailofbits/skills
- Entry Point Analyzer Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports. Plugin · trailofbits/skills
- Devcontainer Setup Create pre-configured devcontainers with Claude Code and language-specific tooling Plugin · trailofbits/skills