Portfolio concentration
85%
Top three share
Shows whether the organization is driven by one breakout repo or several visible projects.
Breadth
29 repos
Visible snapshot
22 repositories updated in the last 90 days.
Leading language
Python
Portfolio mix
Python (11), Unknown (6), Go (3)
Average size
121
Stars per repository
Useful for distinguishing one flagship-heavy publisher from a repeatable portfolio.
85%
of the visible star count comes from this organization's top three repositories.
121
stars per repository in this same snapshot.
Python
is the most common language here, with 22 repositories updated in the last 90 days.
Why this rank
This organization stands out because one flagship repo drives 59% of its visible star count.
Organization pages work best when you separate portfolio breadth from flagship concentration. In Trail of Bits's case, the visible top three repositories account for about 85% of total stars in this snapshot, which helps explain whether the organization is known for one breakout project or for a broader repeatable portfolio.
The dominant language mix here is Python (11), Unknown (6), Go (3). That makes this page useful not just for popularity checks, but also for seeing what technical shape an organization's public ecosystem actually has.
| # | Repository | Language | Stars |
|---|---|---|---|
| 1 | trailofbits/claude-code-config Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits | Shell | 2.1K |
| 2 | trailofbits/skills-curated Curated, community-vetted Claude Code plugin marketplace | Python | 474 |
| 3 | trailofbits/trailmark Build and query a graph database representation of source code | C | 453 |
| 4 | trailofbits/CoBRA Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation | C++ | 316 |
| 5 | trailofbits/idac idac - IDA Pro command line tool for agents and humans | Python | 44 |
| 6 | trailofbits/scribe Local transcription and speaker diarization with pyannote and parakeet | Python | 41 |
| 7 | trailofbits/overtly-malicious-skills Malicious skills for testing skill scanners | Python | 33 |
| 8 | trailofbits/trailmix | Rust | 23 |
| 9 | trailofbits/aicov gcov for what lines of code agents read | Python | 16 |
| 10 | trailofbits/codex-config | Shell | 15 |
| 11 | trailofbits/quantum-zk-proof-poc Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis | Python | 15 |
| 12 | trailofbits/coop Isolated VM environment for running Claude Code and Codex | Rust | 15 |
| 13 | trailofbits/micro ✨ Lightweight GitHub Actions workflow for AI vulnerability discovery (under development) | Python | 3 |
| 14 | trailofbits/tamarin-prover Main source code repository of the Tamarin prover for security protocol verification. | 1 | |
| 15 | trailofbits/boulder An ACME-based certificate authority, written in Go. | Go | 1 |
| 16 | trailofbits/tree-sitter-masm Miden Assembly grammar for tree-sitter | C | 1 |
| 17 | trailofbits/masm-lean Automatic translation of Miden assembly to Lean | Lean | 1 |
| 18 | trailofbits/background-agents An open-source background agents coding system | 1 | |
| 19 | trailofbits/binaryninja-finder | Python | 1 |
| 20 | trailofbits/restaurant-tester | Python | 0 |
| 21 | trailofbits/ptp-mldsa-native Patches for pq-code-package/mldsa-native | 0 | |
| 22 | trailofbits/rekor-watch | Go | 0 |
| 23 | trailofbits/go-jose An implementation of JOSE standards (JWE, JWS, JWT) in Go | 0 | |
| 24 | trailofbits/pkcs11key An interface to PKCS#11 devices that satisfies the crypto.Signer interface | 0 | |
| 25 | trailofbits/borp Boulder's version of go-gorp/gorp | 0 | |
| 26 | trailofbits/python-asn1-benchmark | Python | 0 |
| 27 | trailofbits/OCP-Security-SAFE Standardization of security reviews for datacenter products | Python | 0 |
| 28 | trailofbits/scroll-fv Formal verification of Scroll's zkvm-prover circuits in Lean 4 (Aeneas + Charon extraction, openvm-fv-derived RV32IM semantics) | Lean | 0 |
| 29 | trailofbits/bt-log Binary transparency log to make tampered artifact distribution auditable | Go | 0 |
Total stars are useful as a discovery signal, but they do not tell you whether a team maintains every repository equally. Pair this page with release cadence, maintainer activity, and the flagship concentration shown above before making adoption decisions.
For broader background on GitStar's ranking logic and editorial guidance, see Methodology & Editorial Standards.