npx skills add ...
npx skills add trailofbits/skills --skill testing-handbook-generator
Generates Claude Code skills from the Trail of Bits Testing Handbook (appsec.guide), analyzing handbook pages and emitting SKILL.md files with the structure each skill type requires. Use when creating or refreshing a skill from handbook content, or when the user names the testing handbook or appsec.guide. Not for answering security testing questions — the generated skills cover those.
npx skills add trailofbits/skills --skill testing-handbook-generator
Generate and maintain Claude Code skills from the Trail of Bits Testing Handbook.
Invoke this skill when:
Do NOT use for:
The skill needs the Testing Handbook repository. See discovery.md for full details.
Quick reference: Check ./testing-handbook, ../testing-handbook, ~/testing-handbook → ask user → clone as last resort.
Repository: https://github.com/trailofbits/testing-handbook
ONLY modify these locations:
plugins/testing-handbook-skills/skills/[skill-name]/* - Generated skills (as siblings to testing-handbook-generator)plugins/testing-handbook-skills/skills/testing-handbook-generator/* - Self-improvementREADME.md - Add generated skills to tableNEVER modify or analyze:
plugins/property-based-testing/, plugins/static-analysis/, etc.)Do not scan or pull into context any skills outside of testing-handbook-skills/. Generate skills based solely on handbook content and resources referenced from it.
| Handbook Section | Skill Type | Template |
|---|---|---|
/static-analysis/[tool]/ | Tool Skill | tool-skill.md |
/fuzzing/[lang]/[fuzzer]/ | Fuzzer Skill | fuzzer-skill.md |
/fuzzing/techniques/ | Technique Skill | technique-skill.md |
/crypto/[tool]/ | Domain Skill | domain-skill.md |
/web/[tool]/ | Tool Skill | tool-skill.md |
| Signal | Indicates |
|---|---|
_index.md with bookCollapseSection: true | Major tool/topic |
| Numbered files (00-, 10-, 20-) | Structured content |
techniques/ subsection | Methodology content |
99-resources.md or 91-resources.md | Has external links |
| Signal | Action |
|---|---|
draft: true in frontmatter | Skip section |
| Empty directory | Skip section |
| Template/placeholder file | Skip section |
GUI-only tool (e.g., web/burp/) | Skip section (Claude cannot operate GUI tools) |
Starting skill generation?
Generation uses a two-pass approach to solve forward reference problems (skills referencing other skills that don't exist yet).
Generate all skills in parallel without the Related Skills section:
Pass 1 agents:
## Related Skills\n\n<!-- PASS2: populate after all skills exist -->references: DEFERREDAfter all Pass 1 agents complete, run Pass 2 to populate Related Skills:
Pass 2 process:
ls -d skills/*/SKILL.mdSee agent-prompt.md for the full prompt template with:
pass variable)After Pass 1: Aggregate output reports, verify all skills generated. After Pass 2: Run validator to check cross-references.
If an agent fails or produces invalid output:
| Failure Type | Detection | Recovery Action |
|---|---|---|
| Agent crashed | No output report | Re-run single agent with same inputs |
| Validation failed | Output report shows errors | Check gaps/warnings, manually patch or re-run |
| Wrong skill type | Content doesn't match template | Re-run with corrected type parameter |
| Missing content | Output report lists gaps | Accept if minor, or provide additional related_sections |
| Pass 2 broken ref | Validator shows missing skill | Check if skill was skipped, update reference |
Important: Do NOT re-run the entire parallel batch for a single agent failure. Fix individual failures independently.
To regenerate a single skill without re-running the entire batch:
Regeneration workflow:
skills/{skill-name}/SKILL.md (overwrites existing)uv run scripts/validate-skills.py --skill {skill-name}Generated skills are written to:
Each skill gets its own directory for potential supporting files (as siblings to testing-handbook-generator).
Before delivering generated skills:
uv run scripts/validate-skills.pyREADME.md updated with generated skills tableREADME.md Skills Cross-Reference graph updatedAfter generating skills, update the repository's main README.md to list them.
Format: Add generated skills to the same "Available Plugins" table, directly after testing-handbook-skills. Use plain text testing-handbook-generator as the author (no link).
Example:
After generating skills, update the README.md's Skills Cross-Reference section with the mermaid graph showing skill relationships.
Process:
SKILL.md and extract its ## Related Skills section-->) for primary technique dependencies-.->) for alternative tool suggestionsEdge classification:
| Relationship | Arrow Style | Example |
|---|---|---|
| Fuzzer → Technique | --> | libfuzzer --> harness-writing |
| Tool → Tool (alternative) | -.-> | semgrep -.-> codeql |
| Fuzzer → Fuzzer (alternative) | -.-> | libfuzzer -.-> aflpp |
| Technique → Technique | --> | harness-writing --> coverage-analysis |
Validation: After updating, run validate-skills.py to verify all referenced skills exist.
After each generation run, reflect on what could improve future runs.
Capture improvements to:
Update process:
SKILL.md - Workflow, decision tree, quick reference updatestemplates/*.md - Template improvementsdiscovery.md - Detection logic updatestesting.md - New validation checksExample self-improvement:
Do:
Don't:
For first-time use: Start with discovery.md to understand the handbook analysis process.
For template reference: See templates/ directory for skill type templates.
For validation: See testing.md for quality assurance methodology.