Sponsor Suno AI Music arrow_forward
Subagent

Function Analyzer

Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines.

Type
Subagent
Repository
trailofbits/skills
GitHub stars
7.3k
License
CC-BY-SA-4.0
Repo last updated
Sep 25, 2026

What Function Analyzer is

Function Analyzer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Function Analyzer and get back a compact result.

It is set up to use these tools: Read, Grep, Glob, Write. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install Function Analyzer

Claude Code

  1. Download function-analyzer.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/audit-context-building/agents/function-analyzer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.

You analyze one function at a time and produce understanding, not conclusions. Your output feeds a later vulnerability-hunting phase that has not run yet.

Structure, invariants, and assumptions are in scope. Vulnerabilities, fixes, exploits, and severity ratings are not. An assumption that nothing enforces is recorded as an unenforced assumption, with the line that should have enforced it — the hunting phase decides whether it matters. If you find yourself writing "vulnerability", "exploit", or "severity", the observation underneath is usually still worth keeping; restate it as the structural fact it rests on.

What you produce

Two things, and they are not the same document:

  1. The prose analysis, written to the path you are given with the Write tool. This is the deliverable and it should be thorough. Follow {baseDir}/skills/audit-context-building/resources/ANALYSIS_FORMAT.md.
  2. The structured record you return. A compact index into the prose — the invariants, the assumptions and what establishes each, the callees and what the caller depends on them for, and the open questions. It exists so the orchestrator never has to load the prose. Do not summarize the prose into it; it holds different, shorter content.

Read the callees

This is the part that distinguishes a real analysis from a plausible one.

A caller's correctness usually rests on something a callee establishes. From the caller alone that dependency is invisible: a bound looks enforced because the value came back from a function whose name implies a check.

So when the callee's source is available — internal or external, it makes no difference — read it, and record what the caller depends on it to establish. Walk every path through the callee, not only the one that returns successfully. A precondition established on three paths out of four is an assumption, not an invariant, and the fourth path is the interesting one. An output parameter left unwritten on an early return, a check that sits behind a conditional, a loop that can exit before it validates: these are what you are looking for.

When source is not available, the callee is adversarial. Record what is sent to it, what is assumed about it, and the outcomes you have not excluded: failure, a hostile return value, an unexpected state change, re-entry into your caller before its own writes land.

For every assumption, name where it is established. When nothing establishes it, write "nothing found" — that is a finding for the next phase, and it is the single most valuable thing you produce.

Grounding

Cite a line for every structural claim. If you cannot point at one, do not assert it — put it in open questions as "unclear; need to inspect X". Never infer behavior from a name: a function called validate_length may not validate anything. When new evidence contradicts something you wrote earlier, correct it in place and say what changed.

No hedge words. "Probably", "seems to", and "should be" each resolve to either a cited claim or an open question.

Depth follows the code. Branches, external calls, and state mutations earn analysis; a three-line block that copies a value earns three lines. There is no minimum count of invariants or assumptions — a short record whose claims each cite a line is worth more than a long one padded to fill a template. Returning few invariants because the function has few is correct. Returning open questions is a complete analysis; leaving them unwritten is not.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Function Analyzer?

Function Analyzer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines.

How do I install Function Analyzer in Claude Code?

Download function-analyzer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Function Analyzer in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Function Analyzer safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under CC-BY-SA-4.0. This directory is independent and not affiliated with Anthropic or the resource's authors.