Repository

alpha-omega-security/scrutineer agent skills

Every skill in the alpha-omega-security/scrutineer repository on GitHub, ranked by score, with the commands to install them.
skills
48
GitHub stars
242

GitHub description: “Security through scrutiny”

Stars
242 (40 forks)
Licence
MIT
Last push
Oct 2026
Created
Apr 2026

Install all skills

skills CLI (any agent)
npx skills add alpha-omega-security/scrutineer

Add --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).

Skills in alpha-omega-security/scrutineer, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills in alpha-omega-security/scrutineer, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Default pipeline scrutineer runs when a repository is added.

alpha-omega-security/scrutineer242—~2.9kAutomated safety check: PassMITyesterday
2

Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
3

Run bandit against the Python source in the repository and map its hits into the findings shape.

alpha-omega-security/scrutineer242—~615Automated safety check: NotesMITyesterday
4

Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: NotesMITyesterday
5

Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

alpha-omega-security/scrutineer242—~596Automated safety check: PassMITyesterday
6

Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

alpha-omega-security/scrutineer242—~2.9kAutomated safety check: NotesMITyesterday
7

Identify the real maintainers of a repository and the best way to contact them about a security issue.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
8

File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
9

Scan the available Git history for secrets with Betterleaks and map detections into the findings shape.

alpha-omega-security/scrutineer242—~417Automated safety check: NotesMITyesterday
10
10.Sbom

Generate a CycloneDX SBOM for the repository via git-pkgs sbom.

alpha-omega-security/scrutineer242—~290Automated safety check: PassMITyesterday
11

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer242—~439Automated safety check: PassMITyesterday
12

Re-audit every past GHSA/CVE advisory published against this repository, anchored on each advisory's fix commit, for four failure modes, a regression of the original bug, a bypass of the fix, an…

alpha-omega-security/scrutineer242—~3.5kAutomated safety check: NotesMITyesterday
13

Decide whether a finding's suggested fix is a breaking change for top dependents.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: PassMITyesterday
14

Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
15

Draft the disclosure content for a finding in GitHub Security Advisory shape.

alpha-omega-security/scrutineer242—~4kAutomated safety check: PassMITyesterday
16

For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding.

alpha-omega-security/scrutineer242—~989Automated safety check: PassMITyesterday
17

Compare open findings in one repository and record how they relate.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: PassMITyesterday
18

Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records.

alpha-omega-security/scrutineer242—~2.1kAutomated safety check: NotesMITyesterday
19
19.Fork

Stage a scanned repository into a private repo in the configured GitHub organisation.

alpha-omega-security/scrutineer242—~3.3kAutomated safety check: PassMITyesterday
20

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
21

Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
22

Assess a repository's security posture and its readiness to receive a vulnerability report.

alpha-omega-security/scrutineer242—~1.7kAutomated safety check: PassMITyesterday
23

Check whether known sinks in this application's dependencies are reachable from its own trust boundaries.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
24

Independently re-attack one immutable proposed patch with root-cause variants and a benign control.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: NotesMITyesterday
25

Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits.

alpha-omega-security/scrutineer242—~951Automated safety check: PassMITyesterday
26

After a finding has been marked fixed, watch the upstream for a release that contains the fix.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
27

File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available.

alpha-omega-security/scrutineer242—~2.6kAutomated safety check: PassMITyesterday
28

Cheap finding classifier. An agent skill from alpha-omega-security/scrutineer.

alpha-omega-security/scrutineer242—~3.1kAutomated safety check: PassMITyesterday
29

Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: PassMITyesterday
30

High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness.

alpha-omega-security/scrutineer242—~3.2kAutomated safety check: PassMITyesterday
31

Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: NotesMITyesterday
32

Focused static audit for attacker-controlled reads, requests, parsers, or error paths that can disclose files, metadata, secrets, or internal responses.

alpha-omega-security/scrutineer242—~2.2kAutomated safety check: NotesMITyesterday
33

Focused static audit for attacker-controlled data reaching command execution, dynamic evaluation, unsafe deserialization, or server-side template execution.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: NotesMITyesterday
34

Audit package manager clients, registries, and proxies against a bundled threat model.

alpha-omega-security/scrutineer242—~1kAutomated safety check: NotesMITyesterday
35

Focused static audit for real personal or customer-identifying data committed to source or exposed through logs, URLs, telemetry, exports, and responses.

alpha-omega-security/scrutineer242—~3kAutomated safety check: NotesMITyesterday
36

Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: NotesMITyesterday
37

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized.

alpha-omega-security/scrutineer242—~425Automated safety check: PassMITyesterday
38

Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
39

Run brief --json to produce a structured overview of the repository.

alpha-omega-security/scrutineer242—~435Automated safety check: PassMITyesterday
40

Derive a project's security contract from its source and docs, then emit it as structured data other skills can cite.

alpha-omega-security/scrutineer242—~6.8kAutomated safety check: PassMITyesterday
41

Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control.

alpha-omega-security/scrutineer242—~5.7kAutomated safety check: PassMITyesterday
42

Fetch published GHSA and CVE advisories affecting any package this repository produces, via advisories.ecosyste.ms.

alpha-omega-security/scrutineer242—~696Automated safety check: PassMITyesterday
43

Judge whether a validated finding can affect a real release build, and record the attacker position, preconditions, impact, counterevidence, and facts that could change that conclusion.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
44

Normalize an externally-produced security report in an arbitrary format into scrutineer findings.

alpha-omega-security/scrutineer242—~1kAutomated safety check: PassMITyesterday
45

Fetch repository metadata (description, default branch, languages, license, stars, archived, icon) from repos.ecosyste.ms and save it on the repository row.

alpha-omega-security/scrutineer242—~748Automated safety check: PassMITyesterday
46

Look up every package this repository publishes across all registries via packages.ecosyste.ms, with downloads, dependent counts, latest version, registry URL and supply-chain risk flags.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
47

Extract bounded operational lessons from a settled triage cohort without changing finding dispositions or suppressions.

alpha-omega-security/scrutineer242—~874Automated safety check: PassMITyesterday
48

Starting from one confirmed finding, search this repository's current source for distinct sibling instances of the same root cause and emit only validated new findings.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: NotesMITyesterday

Questions, answered from the data.

What is the best skill in alpha-omega-security/scrutineer?

Triage from alpha-omega-security/scrutineer ranks first of the 48 skills in alpha-omega-security/scrutineer listed here, with the highest score: its repository has 242 GitHub stars, its SKILL.md loads about 2.9k tokens and it passes the automated safety check with no findings. Next come Zizmor and Bandit.

Are the skills in alpha-omega-security/scrutineer official?

None yet. All 48 skills in alpha-omega-security/scrutineer listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How do I install all skills from alpha-omega-security/scrutineer?

Run npx skills add alpha-omega-security/scrutineer in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.