| name | yara-rule-authoring |
| description | Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module. |
| source_skill_id | trailofbits-skills-plugins-yara-authoring-skills-yara-rule-authoring-skill-md |
| category | Security, compliance & risk |
| source_mirror | ../../../../../skills/by-category/security-compliance-risk/security-reference/yara-rule-authoring/SKILL.md |
| benchmark_status | artifact_gated |
yara-rule-authoring
Use this skill when the task matches the description above or the source path clearly applies. Start with this concise entrypoint; open ../../../../../skills/by-category/security-compliance-risk/security-reference/yara-rule-authoring/SKILL.md only when implementation details, commands, assets, or references are needed.
Workflow
- Confirm the task matches this skill's scope.
- Read the local source mirror if more detail is required.
- Follow repository-level
AGENTS.md; use one AI session only.
- Keep claims tied to files, commands, citations, or benchmark artifacts.
Verification
- Source mirror:
../../../../../skills/by-category/security-compliance-risk/security-reference/yara-rule-authoring/SKILL.md
- Source commit:
e8cc5baf9329ccb491bfa200e82eacbac83b1ead
- Static benchmark results: see
docs/benchmark-results.md
- Runtime artifacts recorded by this entrypoint:
0
- Assigned scenarios:
skill-proof-trailofbits-skills-plugins-yara-authoring-skills-yara-rule-authoring-skill-md, security-compliance-and-risk-owasp-benchmark, security-compliance-and-risk-owasp-juice-shop, security-compliance-and-risk-kubernetes-examples
Do not claim this skill passed a runtime benchmark until a validated artifact exists.