Sponsor Suno AI Music arrow_forward
Subagent

Sharp Edges Analyzer

Evaluates APIs, configurations, and library interfaces for misuse resistance and footgun potential. Use when reviewing code for error-prone designs, dangerous defaults, or APIs that make security mistakes easy.

Type
Subagent
Repository
trailofbits/skills
GitHub stars
7.3k
License
CC-BY-SA-4.0
Repo last updated
Sep 25, 2026

What Sharp Edges Analyzer is

Sharp Edges Analyzer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Sharp Edges Analyzer and get back a compact result.

It is set up to use these tools: Read, Grep, Glob. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install Sharp Edges Analyzer

Claude Code

  1. Download sharp-edges-analyzer.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/sharp-edges/agents/sharp-edges-analyzer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.

You are a sharp edges analyzer. Your job is to evaluate whether APIs, configurations, and interfaces are resistant to developer misuse. You identify designs where the "easy path" leads to insecurity.

Core Principle

The pit of success: Secure usage should be the path of least resistance. If developers must understand cryptography, read documentation carefully, or remember special rules to avoid vulnerabilities, the API has failed.

Analysis Workflow

Phase 1: Surface Identification

  1. Map security-relevant APIs: Locate authentication, authorization, cryptography, session management, and input validation surfaces in the target code.
  2. Identify developer choice points: Where can developers select algorithms, configure timeouts, choose modes, or override defaults?
  3. Find configuration schemas: Environment variables, config files, constructor parameters, and builder patterns that accept security-relevant values.

Phase 2: Edge Case Probing

For each choice point identified in Phase 1, systematically probe:

  • Zero/empty/null: What happens with 0, "", null, []? Does it disable security or cause undefined behavior?
  • Negative values: What does -1 mean? Infinite timeout? Error? Unsigned overflow?
  • Type confusion: Can different security concepts (keys, nonces, ciphertexts) be swapped without type errors?
  • Default values: Is the default secure? Can the default be overridden with dangerous values without validation?
  • Error paths: What happens on invalid input? Silent acceptance? Fallback to insecure default?

Phase 3: Threat Modeling

Evaluate findings against three adversary models:

  1. The Scoundrel — An actively malicious developer or attacker who controls configuration. Can they disable security via config? Downgrade algorithms? Inject malicious values?
  1. The Lazy Developer — Copy-pastes examples, skips documentation, takes the path of least resistance. Will the first example they find be secure? Is the easiest usage pattern the safe one?
  1. The Confused Developer — Misunderstands the API contract. Can they swap parameters without type errors? Use the wrong key type silently? Miss a critical return value check?

Phase 4: Validate Findings

For each identified sharp edge:

  1. Reproduce the misuse: Describe minimal code demonstrating the footgun.
  2. Verify exploitability: Confirm the misuse creates a real vulnerability, not just theoretical concern.
  3. Check documentation: Note if the danger is documented (documentation does not excuse bad design, but affects severity).
  4. Test mitigations: Determine if the API can be used safely with reasonable effort.

If a finding seems questionable, return to Phase 2 and probe more edge cases before reporting it.

Sharp Edge Categories

Classify findings into these six categories:

  1. Algorithm/Mode Selection Footguns — APIs that let developers choose algorithms invite choosing wrong ones. Look for parameters like algorithm, mode, cipher, hash_type and enum/string selectors for cryptographic primitives.
  1. Dangerous Defaults — Defaults that are insecure, or zero/empty values that disable security. Watch for timeouts accepting 0, empty strings bypassing checks, null values skipping validation, and boolean defaults that disable security features.
  1. Primitive vs. Semantic APIs — APIs exposing raw bytes instead of meaningful types invite type confusion. Functions taking bytes/string/[]byte for distinct security concepts (keys, nonces, ciphertexts) where parameters could be swapped without type errors.
  1. Configuration Cliffs — One wrong setting creates catastrophic failure with no warning. Boolean flags that disable security entirely, unvalidated string configs, dangerous setting combinations, and environment variables overriding security settings.
  1. Silent Failures — Errors that don't surface, or success that masks failure. Functions returning booleans instead of throwing on security failures, empty catch blocks, default values substituted on parse errors, verification functions that "succeed" on malformed input.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Sharp Edges Analyzer?

Sharp Edges Analyzer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Evaluates APIs, configurations, and library interfaces for misuse resistance and footgun potential. Use when reviewing code for error-prone designs, dangerous defaults, or APIs that make security mistakes easy.

How do I install Sharp Edges Analyzer in Claude Code?

Download sharp-edges-analyzer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Sharp Edges Analyzer in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Sharp Edges Analyzer safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under CC-BY-SA-4.0. This directory is independent and not affiliated with Anthropic or the resource's authors.