Audit Skills
sickn33/agentic-awesome-skills
Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.
Safely unpack and investigate existing archives through evidence-first static analysis.
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .claude/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .claude/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifactsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .agents/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .agents/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .cursor/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .cursor/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AetherKiri/Aether.git --path .agents/skills/unpack-investigate-artifacts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .gemini/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .gemini/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AetherKiri/Aether unpack-investigate-artifactsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .github/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .github/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .opencode/skills/unpack-investigate-artifacts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "unpack-investigate-artifacts" agent skill from https://github.com/AetherKiri/Aether/tree/main/.agents/skills/unpack-investigate-artifacts into .opencode/skills/unpack-investigate-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpack-investigate-artifacts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
unpack-investigate-artifactsSafely unpack and investigate existing archives through evidence-first static analysis.
Unpack Investigate Artifacts is an agent skill from AetherKiri/Aether. Safely unpack and investigate existing archives through evidence-first static analysis. Use when Codex is given a diagnostic ZIP or directory produced by a collection tool such as AetherKiri tools/diagnose.py, or a TAR, APK, IPA, .app bundle, crash archive, or opaque package, and needs to validate integrity, align events and markers, compare layers, or identify the first unsupported boundary without building, installing, launching, reproducing, or collecting from a device.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/safe_unpack.py`).
It sits in Security, covering Static analysis and SAST. It works with iOS and macOS. The repository describes itself as: A cross-platform, multi-runtime visual novel emulator using Godot 4 as the rendering layer. The licence is GPL-3.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d4e017a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Unpack Investigate Artifacts loads about 1.6k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 761 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from AetherKiri/Aether at commit d4e017a, republished under its GPL-3.0 licence (© AetherKiri). 761 words, ~1,648 tokens.
.claude/skills/unpack-investigate-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Begin with the artifact the user supplied. Do not build, install, launch, reproduce, or run any collection command. In particular, never invoke tools/diagnose.py from this skill; it consumes the package that script already produced.
Treat an existing out/diagnostics/<timestamp>-<platform>-<session>.zip or its matching directory as the primary input for this workflow. If the user says “the diagnostic package” without a path, locate the newest completed ZIP under out/diagnostics/; do not run tools/diagnose.py to create one.
After safe extraction, verify the bundle contract before interpreting it:
metadata.json identifies the requested session, platform, profile, Git revision, and capture mode;app-data/;events.jsonl is the normalized cross-layer stream; check JSON validity, session IDs, sequence continuity, clock basis, and queue_dropped before sorting or filtering it;incidents/marker-*-pre.jsonl and marker-*-post.jsonl preserve the marker windows when the UI marker was accepted;incidents/marker-*-state.json captures the bounded performance, input, memory, and plugin context sampled by that one-click marker;attachments/state-snapshot-*.json contains explicit in-app state snapshots and attachments/screenshot-*.png contains only user-requested screenshots;diagnostic_self_check events report which app-side facilities were reachable, but do not prove that unrelated runtime paths were healthy;platform/ contains raw host/platform evidence and collection errors or omissions;summary.md is a generated lead, not source evidence. Re-check every material statement against the structured events and raw platform files.An absent UI marker is not automatically a failed bundle. Check for a host marker with ui_marker_missing=true, then state which app-side boundary is unavailable. Treat a typed marker label, state snapshot, screenshot, and self-check as separate evidence with independent timestamps.
For ZIP-compatible packages and TAR archives, prefer:
python3 scripts/safe_unpack.py ARTIFACT OUTPUT_DIR --manifest OUTPUT_DIR.manifest.jsonThe script rejects traversal, links, special files, excessive member counts, and expanded-size limits. For unsupported formats, list with the narrowest available format-aware tool before choosing an extractor with equivalent protections.
Use rg --files first, then group files by role rather than dumping every path:
Keep secrets out of output. Report the presence and location of credentials, tokens, provisioning data, or personal content without printing their values.
Info.plist, architectures, frameworks, entitlements, dSYM/UUID matches, crash logs, device/build identity, and app Documents evidence.Read only the relevant variant. Do not infer runtime behavior solely from package layout.
For performance evidence, distinguish total duration from self-time and note whether tracing or logging could perturb timing. For rendering or missing UI, separate creation, enqueue, execution, upload, presentation, and input hit-testing.
Return a compact investigation report containing:
Do not claim a root cause when the artifact only establishes correlation or the failure lies beyond the captured boundary.
© AetherKiri, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in .agents/skills/unpack-investigate-artifacts of AetherKiri/Aether.
Open the folder on GitHubat commit d4e017a
Unpack Investigate Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Unpack Investigate Artifacts this skillAetherKiri/Aether | 154 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | |
| Audit Skillssickn33/agentic-awesome-skills | 47k | 2 repos | ~1.6k | Automated safety check: Warn | MIT | |
| macOS Reversezhaoxuya520/reverse-skill | 41k | 2 repos | ~366 | Automated safety check: Pass | MIT | |
| Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Conducting Mobile App Penetration Testmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Offensive MobileSnailSploit/Claude-Red | 7.4k | — | ~3.5k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
mukul975/Anthropic-Cybersecurity-Skills
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…
mukul975/Anthropic-Cybersecurity-Skills
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
dslsdzc/rev-skills
lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills.
AetherKiri/Aether
Prepare, validate, push, open, monitor, and merge paired pull requests across the public AetherKiri repository and private AetherInternal package without publishing private source or unrelated…
AetherKiri/Aether
Diagnose, implement, validate, commit, and document end-to-end compatibility fixes for KiriKiri games running in AetherKiri.
Categories
Safely unpack and investigate existing archives through evidence-first static analysis. Unpack Investigate Artifacts is an agent skill from AetherKiri/Aether. Safely unpack and investigate existing archives through evidence-first static analysis.
Unpack Investigate Artifacts fits situations like: Codex is given a diagnostic ZIP; directory produced by a collection tool such as AetherKiri tools/diagnose.py; needs to validate integrity; align events and markers.
Run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a claude-code`. Or copy the skill folder (.agents/skills/unpack-investigate-artifacts in AetherKiri/Aether) into .claude/skills/unpack-investigate-artifacts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a codex`. Or copy the skill folder (.agents/skills/unpack-investigate-artifacts in AetherKiri/Aether) into .agents/skills/unpack-investigate-artifacts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unpack-investigate-artifacts, .gemini/skills/unpack-investigate-artifacts, .github/skills/unpack-investigate-artifacts and .opencode/skills/unpack-investigate-artifacts in your project.
Going by SKILL.md and its folder, Unpack Investigate Artifacts needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and rg). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Unpack Investigate Artifacts is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Unpack Investigate Artifacts: Audit Skills (sickn33/agentic-awesome-skills, 47k stars), macOS Reverse (zhaoxuya520/reverse-skill, 41k stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Conducting Mobile App Penetration Test (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AetherKiri (a GitHub organization) maintains it in AetherKiri/Aether, which has 154 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.
Source: AetherKiri/Aether on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.