Token导航 LogoToken导航TokenDH.com
开发规范只读github未标认证来源可访问clear审计通过

guidelines-advisor指导方针顾问

Agent Skill

guidelines-advisor 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

46,560

周安装

1,996

GitHub Stars

4,868

下载量

16,320
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:guidelines-advisor(指导方针顾问)
来源仓库:https://github.com/trailofbits/skills
仓库路径:skills/guidelines-advisor
安装命令:
npx skills add https://github.com/trailofbits/skills --skill guidelines-advisor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/trailofbits/skills --skill guidelines-advisor

简介

智能合约开发顾问应用 Trail of Bits 的安全和设计指南来系统地分析代码库。

  • 执行五个阶段的分析,涵盖文档生成、架构审查、可升级性评估、实施质量检查和依赖性评估
  • 评估 11 个综合领域,包括函数组合、继承模式、事件日志记录、常见陷阱、代理安全性和测试覆盖率
  • 生成适合您的代码库的简单英语系统描述、架构图和 NatSpec 文档建议
  • 提供优先级建议(关键、高、中、低)以及具体的文件参考和可操作的后续步骤,以做好生产准备

SKILL.md

Guidelines Advisor

Purpose

Systematically analyzes the codebase and provides guidance based on Trail of Bits' development guidelines:

  1. Generate documentation and specifications (plain English descriptions, architectural diagrams, code documentation)
  2. Optimize on-chain/off-chain architecture (only if applicable)
  3. Review upgradeability patterns (if your project has upgrades)
  4. Check delegatecall/proxy implementations (if present)
  5. Assess implementation quality (functions, inheritance, events)
  6. Identify common pitfalls
  7. Review dependencies
  8. Evaluate test suite and suggest improvements

Framework: Building Secure Contracts - Development Guidelines


How This Works

Phase 1: Discovery & Context

Explores the codebase to understand:

  • Project structure and platform
  • Contract/module files and their purposes
  • Existing documentation
  • Architecture patterns (proxies, upgrades, etc.)
  • Testing setup
  • Dependencies

Phase 2: Documentation Generation

Helps create:

  • Plain English system description
  • Architectural diagrams (using Slither printers for Solidity)
  • Code documentation recommendations (NatSpec for Solidity)

Phase 3: Architecture Analysis

Analyzes:

  • On-chain vs off-chain component distribution (if applicable)
  • Upgradeability approach (if applicable)
  • Delegatecall proxy patterns (if present)

Phase 4: Implementation Review

Assesses:

  • Function composition and clarity
  • Inheritance structure
  • Event logging practices
  • Common pitfalls presence
  • Dependencies quality
  • Testing coverage and techniques

Phase 5: Recommendations

Provides:

  • Prioritized improvement suggestions
  • Best practice guidance
  • Actionable next steps

Assessment Areas

I analyze 11 comprehensive areas covering all aspects of smart contract development. For detailed criteria, best practices, and specific checks, see ASSESSMENT_AREAS.md.

Quick Reference:

  1. Documentation & Specifications

- Plain English system descriptions - Architectural diagrams - NatSpec completeness (Solidity) - Documentation gaps identification

  1. On-Chain vs Off-Chain Computation

- Complexity analysis - Gas optimization opportunities - Verification vs computation patterns

  1. Upgradeability

- Migration vs upgradeability trade-offs - Data separation patterns - Upgrade procedure documentation

  1. Delegatecall Proxy Pattern

- Storage layout consistency - Initialization patterns - Function shadowing risks - Slither upgradeability checks

  1. Function Composition

- Function size and clarity - Logical grouping - Modularity assessment

  1. Inheritance

- Hierarchy depth/width - Diamond problem risks - Inheritance visualization

  1. Events

- Critical operation coverage - Event naming consistency - Indexed parameters

  1. Common Pitfalls

- Reentrancy patterns - Integer overflow/underflow - Access control issues - Platform-specific vulnerabilities

  1. Dependencies

- Library quality assessment - Version management - Dependency manager usage - Copied code detection

  1. Testing & Verification

- Coverage analysis - Fuzzing techniques - Formal verification - CI/CD integration

  1. Platform-Specific Guidance

- Solidity version recommendations - Compiler warning checks - Inline assembly warnings - Platform-specific tools

For complete details on each area including what I'll check, analyze, and recommend, see ASSESSMENT_AREAS.md.


Example Output

When the analysis is complete, you'll receive comprehensive guidance covering:

  • System documentation with plain English descriptions
  • Architectural diagrams and documentation gaps
  • Architecture analysis (on-chain/off-chain, upgradeability, proxies)
  • Implementation review (functions, inheritance, events, pitfalls)
  • Dependencies and testing evaluation
  • Prioritized recommendations (CRITICAL, HIGH, MEDIUM, LOW)
  • Overall assessment and path to production

For a complete example analysis report, see EXAMPLE_REPORT.md.


Deliverables

I provide four comprehensive deliverable categories:

1. System Documentation

  • Plain English descriptions
  • Architectural diagrams
  • Documentation gaps analysis

2. Architecture Analysis

  • On-chain/off-chain assessment
  • Upgradeability review
  • Proxy pattern security review

3. Implementation Review

  • Function composition analysis
  • Inheritance assessment
  • Events coverage
  • Pitfall identification
  • Dependencies evaluation
  • Testing analysis

4. Prioritized Recommendations

  • CRITICAL (address immediately)
  • HIGH (address before deployment)
  • MEDIUM (address for production quality)
  • LOW (nice to have)

For detailed templates and examples of each deliverable, see DELIVERABLES.md.


Assessment Process

When invoked, I will:

  1. Explore the codebase

- Identify all contract/module files - Find existing documentation - Locate test files - Check for proxies/upgrades - Identify dependencies

  1. Generate documentation

- Create plain English system description - Generate architectural diagrams (if tools available) - Identify documentation gaps

  1. Analyze architecture

- Assess on-chain/off-chain distribution (if applicable) - Review upgradeability approach (if applicable) - Audit proxy patterns (if present)

  1. Review implementation

- Analyze functions, inheritance, events - Check for common pitfalls - Assess dependencies - Evaluate testing

  1. Provide recommendations

- Present findings with file references - Ask clarifying questions about design decisions - Suggest prioritized improvements - Offer actionable next steps


Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"System is simple, description covers everything"Plain English descriptions miss security-critical detailsComplete all 5 phases: documentation, architecture, implementation, dependencies, recommendations
"No upgrades detected, skip upgradeability section"Upgradeability can be implicit (ownable patterns, delegatecall)Search for proxy patterns, delegatecall, storage collisions before declaring N/A
"Not applicable" without verificationPremature scope reduction misses vulnerabilitiesVerify with explicit codebase search before skipping any guideline section
"Architecture is straightforward, no analysis needed"Obvious architectures have subtle trust boundariesAnalyze on-chain/off-chain distribution, access control flow, external dependencies
"Common pitfalls don't apply to this codebase"Every codebase has common pitfallsSystematically check all guideline pitfalls with grep/code search
"Tests exist, testing guideline is satisfied"Test existence ≠ test qualityCheck coverage, property-based tests, integration tests, failure cases
"I can provide generic best practices"Generic advice isn't actionableProvide project-specific findings with file:line references
"User knows what to improve from findings"Findings without prioritization = no action planGenerate prioritized improvement roadmap with specific next steps

Notes

  • I'll only analyze relevant sections (won't hallucinate about upgrades if not present)
  • I'll adapt to your platform (Solidity, Rust, Cairo, etc.)
  • I'll use available tools (Slither, etc.) but work without them if unavailable
  • I'll provide file references and line numbers for all findings
  • I'll ask questions about design decisions I can't infer from code

Ready to Begin

What I'll need:

  • Access to your codebase
  • Context about your project goals
  • Any existing documentation or specifications
  • Information about deployment plans

Let's analyze your codebase and improve it using Trail of Bits' best practices!

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

28.23%
按下载量换算4,607

Codex

25.02%
按下载量换算4,083

OpenCode

19.52%
按下载量换算3,186

Gemini CLI

11.21%
按下载量换算1,829

Antigravity

7.75%
按下载量换算1,265

Cursor

3.74%
按下载量换算610

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills