trailofbits-codeql
Trail of Bits security skill to run and author CodeQL static-analysis queries for vulnerability hunting.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for trailofbits-codeql, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Security skill from Trail of Bits that guides running CodeQL and writing custom queries to find vulnerabilities via static analysis. Bundled reference and tooling; executes CodeQL against target codebases as its script surface. Part of the building-secure-contracts/static-analysis plugin.
Key features and capabilities
- CodeQL query authoring
- Static-analysis vulnerability hunting
- Query execution guidance
Use cases
- Security audits
- Variant/vulnerability discovery