Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized.

MITAuto-check passedSecurity

Install Embedded Native

skills CLI
$ npx skills add alpha-omega-security/scrutineer --skill embedded-native -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alpha-omega-security/scrutineer embedded-native --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/embedded-native .claude/skills/embedded-native && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
embedded-native
GitHub stars
231
Token cost
~425 tokens
SKILL.md length
138 words
Files
3 (incl. scripts)
Skills in repo
48
Repo updated
First seen
Licence
MIT

At a glance

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized.

  • Security work in your project
  • Runs Shell scripts from its folder; calls bash

What it does

Embedded Native is an agent skill from alpha-omega-security/scrutineer. Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. Runs when triage finds native-extension, submodule, or mixed native-language signals.

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `schema.json` and `scripts/scan.sh`). Compatibility notes: Requires the brief CLI (https://github.com/git-pkgs/brief) on PATH. Shallow submodule initialization is available for remote repository scans.

It sits in Security. It works with Git. The repository describes itself as: Security through scrutiny. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/embedded-native”

Requirements

  • A Bash shell
  • Compatibility (from SKILL.md): Requires the `brief` CLI (https://github.com/git-pkgs/brief) on PATH. Shallow submodule initialization is available for remote repository scans.

What it can do on your machine

Read from SKILL.md and the folder at commit cce10ee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the `brief` CLI (https://github.com/git-pkgs/brief) on PATH. Shallow submodule initialization is available for remote repository scans.

    From compatibility in the SKILL.md frontmatter.

Context cost

Embedded Native loads about 425 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 138 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~425

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alpha-omega-security/scrutineer at commit cce10ee, republished under its MIT licence (© alpha-omega-security). 138 words, ~425 tokens.

Download SKILL.mdSave it as .claude/skills/embedded-native/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
embedded-native
description
Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. Runs when triage finds native-extension, submodule, or mixed native-language signals.
compatibility
Requires the `brief` CLI (https://github.com/git-pkgs/brief) on PATH. Shallow submodule initialization is available for remote repository scans.
license
MIT
metadata.scrutineer.model
mid
metadata.scrutineer.version
1
metadata.scrutineer.output_file
report.json
metadata.scrutineer.output_kind
freeform
metadata.scrutineer.recurse_submodules
true
metadata.scrutineer.paths
**

embedded-native

Run Brief after Scrutineer has prepared the repository with recursive, depth-one Git submodules. A root Brief scan can omit files inside initialized submodules, so the bundled script runs Brief separately at each submodule root and keeps every report unchanged inside one envelope.

Run:

bash
bash ./scripts/scan.sh ./src ./report.json

The report contains schema_version, the root Brief report under root, Git submodule identities under components, and Brief reports under submodules. Scrutineer supplies components with each checkout-relative path, resolved source URL, exact gitlink commit, pinned package URL under purl, initialization status, and any identity error. Join a submodule Brief report to a component by resolving the report path relative to the root report path. Do not edit embedded-native-components.json, summarize, filter, merge, or infer components from the Brief results.

If Brief exits non-zero, read stderr and write {"error":"brief: ..."} to ./report.json. Do not install or modify Brief.

© alpha-omega-security, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in skills/embedded-native of alpha-omega-security/scrutineer.

  • SKILL.md
  • schema.json
  • scripts/scan.sh

Open the folder on GitHubat commit cce10ee

Compare with similar skills

Embedded Native next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Embedded Native compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Embedded Native this skillalpha-omega-security/scrutineer231—~425Automated safety check: PassMIT
Careful Mode Command Guardrailsgarrytan/gstack136k—~931Automated safety check: NotesMIT
DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassCustom licence
Defense In Depthsandgardenhq/sgai1373 repos~970Automated safety check: PassCustom licence
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Cc Reviewdoccker/cc-use-exp1.1k—~541Automated safety check: PassCustom licence

Similar skills

  • Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run.

    136k GitHub stars~931 tokensUpdated today
    SecurityAuto-check: notes
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Defense In Depth

    sandgardenhq/sgai

    A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

    137 GitHub starsUsed in 3 repos~970 tokens
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cc Review

    doccker/cc-use-exp

    结构化代码审查工作流,适用于显式 quick/full/security review;不负责普通实现或 bug 修复流程。

    1.1k GitHub stars~541 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    406 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes

More from alpha-omega-security/scrutineer

All 48 skills in this repo
  • Triage

    alpha-omega-security/scrutineer

    Default pipeline scrutineer runs when a repository is added.

    231 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Zizmor

    alpha-omega-security/scrutineer

    Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references.

    231 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bandit

    alpha-omega-security/scrutineer

    Run bandit against the Python source in the repository and map its hits into the findings shape.

    231 GitHub stars~615 tokensUpdated today
    Auto-check: notes
  • Compliance

    alpha-omega-security/scrutineer

    Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.

    231 GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Dependencies

    alpha-omega-security/scrutineer

    Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

    231 GitHub stars~596 tokensUpdated today
    Auto-check passed
  • History

    alpha-omega-security/scrutineer

    Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

    231 GitHub stars~2.9k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Embedded Native

What does Embedded Native do?

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. Embedded Native is an agent skill from alpha-omega-security/scrutineer. Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized.

When should I use Embedded Native?

Embedded Native fits situations like: security work in your project.

How do I install Embedded Native in Claude Code?

Run `npx skills add alpha-omega-security/scrutineer --skill embedded-native -a claude-code`. Or copy the skill folder (skills/embedded-native in alpha-omega-security/scrutineer) into .claude/skills/embedded-native in your project. Claude Code loads it when a task matches its description.

How do I install Embedded Native in Codex?

Run `npx skills add alpha-omega-security/scrutineer --skill embedded-native -a codex`. Or copy the skill folder (skills/embedded-native in alpha-omega-security/scrutineer) into .agents/skills/embedded-native in your project. Codex loads it when a task matches its description.

Can I use Embedded Native in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpha-omega-security/scrutineer --skill embedded-native -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/embedded-native, .gemini/skills/embedded-native, .github/skills/embedded-native and .opencode/skills/embedded-native in your project.

What does Embedded Native need to run?

Going by SKILL.md and its folder, Embedded Native needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell. Compatibility (from SKILL.md): Requires the `brief` CLI (https://github.com/git-pkgs/brief) on PATH. Shallow submodule initialization is available for remote repository scans..

Does Embedded Native access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Embedded Native safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Embedded Native use?

Embedded Native is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Embedded Native use?

About 425 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Embedded Native?

Skills that share tags, products or a category with Embedded Native: Careful Mode Command Guardrails (garrytan/gstack, 136k stars), DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars), Defense In Depth (sandgardenhq/sgai, 137 stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Embedded Native?

alpha-omega-security (a GitHub organization) maintains it in alpha-omega-security/scrutineer, which has 231 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 8, 2026.

Source: alpha-omega-security/scrutineer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.