Release
Zeecka/AperiSolve
Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.
Stage a scanned repository into a private repo in the configured GitHub organisation.
$ npx skills add alpha-omega-security/scrutineer --skill fork -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alpha-omega-security/scrutineer fork --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fork .claude/skills/fork && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .claude/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alpha-omega-security/scrutineer/tree/main/skills/forkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alpha-omega-security/scrutineer --skill fork -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alpha-omega-security/scrutineer fork --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/fork .agents/skills/fork && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .agents/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpha-omega-security/scrutineer --skill fork -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alpha-omega-security/scrutineer fork --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/fork .cursor/skills/fork && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .cursor/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alpha-omega-security/scrutineer.git --path skills/fork--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alpha-omega-security/scrutineer --skill fork -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alpha-omega-security/scrutineer fork --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/fork .gemini/skills/fork && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .gemini/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alpha-omega-security/scrutineer forkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alpha-omega-security/scrutineer --skill fork -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/fork .github/skills/fork && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .github/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpha-omega-security/scrutineer --skill fork -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alpha-omega-security/scrutineer fork --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/fork .opencode/skills/fork && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fork" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/fork into .opencode/skills/fork/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fork", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
forkStage a scanned repository into a private repo in the configured GitHub organisation.
Fork is an agent skill from alpha-omega-security/scrutineer. Stage a scanned repository into a private repo in the configured GitHub organisation. Creates the repo (no fork relationship), seeds it with the upstream tree, writes scrutineer metadata under the configured metadata directory, files one issue per open finding, and gives an org team push access. The staging repo is the per-project working surface for triage, fix development, and the disclosure paper trail.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `schema.json`). Compatibility notes: Needs the gh CLI authenticated with a token that can create private repos in forkorg, write to issues there, and manage team repo access. Needs network access…
It sits in Security. It works with GitHub. The repository describes itself as: Security through scrutiny. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cce10ee. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comcwe.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Needs the gh CLI authenticated with a token that can create private repos in `fork_org`, write to issues there, and manage team repo access. Needs network access to api.github.com and the scrutineer API. github.com upstreams only for now; other hosts will route through the same skill once `host__owner__repo` naming generalises.
From compatibility in the SKILL.md frontmatter.
Fork loads about 3.3k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 1,200 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alpha-omega-security/scrutineer at commit cce10ee, republished under its MIT licence (© alpha-omega-security). 1,200 words, ~3,342 tokens.
.claude/skills/fork/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Stand up a private staging repo for one scanned upstream. The staging repo is a plain clone of the upstream tree (no GitHub fork relationship), lives in fork_org, and is the working surface for everything that follows: finding issues, PoC files, patch diffs, and validation reports all live here. Scrutineer's metadata sits at the repo root in the directory named by scrutineer.metadata_dir (default .scrutineer/). Run after a scan has produced findings; idempotent on re-runs.
Below, the placeholder {metadata_dir} stands for the value of scrutineer.metadata_dir from ./context.json. Substitute it verbatim before issuing any git or shell command.
./src — the upstream clone at the commit that was scanned./context.json — has repository.url, repository.full_name, repository.default_branch, scrutineer.api_base, scrutineer.token, scrutineer.repository_id, scrutineer.scan_id, scrutineer.fork_org, and scrutineer.metadata_dir./report.json — write what you didUse the gh CLI for every GitHub call. Do not use curl against api.github.com.
Read ./context.json. Refuse to continue (write {"error": "..."} to report.json and exit 0) if:
scrutineer.fork_org is missing or empty — the operator has not configured fork_org in scrutineer.yamlrepository.url does not have host github.com — other hosts get the same treatment but the host-prefix mapping (below) is hard-coded to gh for nowgh auth status fails — the runner has no GitHub credentialsDerive {owner}/{repo} from repository.full_name (fall back to parsing the path of repository.url, stripping a trailing .git).
The staging repo lives at {fork_org}/{host}__{owner}__{repo}, lowercased:
host is gh for github.comowner and repo come straight from the upstream URLSo https://github.com/madler/zlib becomes {fork_org}/gh__madler__zlib. Deterministic and collision-free across hosts, so no probing for free slots.
If scrutineer already knows the staging repo (GET {api_base}/repositories/{repository_id} has a non-empty fork), use it as {staging} and skip to step 3. The field is named fork for legacy reasons; semantically it is the staging repo URL.
Check whether it already exists:
gh repo view {fork_org}/{host}__{owner}__{repo}If view succeeds, record "created": "exists" and skip to step 3.
Otherwise create it:
gh repo create {fork_org}/{host}__{owner}__{repo} --private \
--description "scrutineer staging for {owner}/{repo}"Then seed it from ./src. The goal is a default branch on the staging repo that contains the upstream tree at its full history (so VIDs, fingerprints, locations, and patches all resolve the same way they do on the upstream):
cd ./src
# Make sure history is complete enough to push. Shallow clones cannot be pushed.
git fetch --unshallow origin || true
git remote add scrutineer-staging https://github.com/{fork_org}/{host}__{owner}__{repo}.git
git push scrutineer-staging HEAD:{repository.default_branch}If git fetch --unshallow fails (the clone was already complete) ignore it. If the push fails because of unshallow, record "error": "could not push full history" and exit 0 — half-seeded repos cause more confusion than they fix.
Record "created": "created" and persist the resolved name back to scrutineer so the next run skips the probe:
PATCH {api_base}/repositories/{repository_id}
Authorization: Bearer {token}
{"fork": "{fork_org}/{host}__{owner}__{repo}"}Build the per-repo metadata block:
# {metadata_dir}/metadata.yaml
upstream:
url: {repository.url}
host: github.com
owner: {owner}
repo: {repo}
seeded_at: {ISO-8601 timestamp, UTC}
seeded_commit: {git -C ./src rev-parse HEAD}
last_scan_at: {same timestamp, refreshed on every run}
last_scan_id: {scan_id}
last_scan_commit: {same as seeded_commit on first run; refresh on re-runs}On re-runs only the last_scan_* fields change.
The simplest write path is one commit per skill run carrying every file under {metadata_dir} that changed in this run. Clone the staging repo into a temp working tree, write the files, commit, push:
TMP=$(mktemp -d)
git clone --depth 1 https://github.com/{fork_org}/{host}__{owner}__{repo}.git "$TMP/staging"
cd "$TMP/staging"
mkdir -p {metadata_dir}
# write {metadata_dir}/metadata.yaml and per-finding files (see step 4) here
git add {metadata_dir}
git -c user.email=scrutineer@local -c user.name=scrutineer \
commit -m "scrutineer: scan {scan_id} at {short-commit}" -m "Updated {metadata_dir} from scrutineer run."
git push origin {repository.default_branch}The commit author is local; the push uses the gh CLI's credentials. One commit per run keeps the history readable.
Fetch the repository's findings: GET {api_base}/repositories/{repository_id}/findings with Authorization: Bearer {token}. Include findings whose status is one of new, enriched, triaged, ready, reported, acknowledged, fixed. Skip rejected, duplicate, and published — those do not have a staging-side life. Record skipped ones under "skipped" with the status as reason.
For each remaining finding fetch the full record (GET {api_base}/findings/{id}) so you have its prose, severity, status, CVSS, CWE, disclosure_draft, and suggested_fix.
In the staging working tree, write the following files under {metadata_dir}/findings/{finding_id}/:
metadata.yaml:finding_id: {id}
title: {title}
severity: {severity}
status: {status}
cwe: {cwe}
cvss_vector: {cvss_vector}
location: {location}
opened_at: {ISO-8601, set on first appearance; do not overwrite on re-runs}
last_updated_at: {ISO-8601, refreshed every run}
issue_url: {will be set in step 5 once the issue is filed; leave empty for now}disclosure-draft.md: contents of the finding's disclosure_draft field. Omit if empty.patch.diff: contents of suggested_fix. Omit if empty.If a finding directory already exists in the clone, preserve the opened_at field from the existing metadata.yaml; everything else is overwritten by the new run's values. Validation reports and PoC files written by other skills (fix-validation, future PoC writer) live in the same directory and are also preserved across re-runs.
List existing issues on the staging repo once, capturing the marker line from each body:
gh api repos/{fork_org}/{host}__{owner}__{repo}/issues --paginate \
--jq '.[] | {number, body, state, labels: [.labels[].name]}'Every issue this skill files carries a [scrutineer-finding:{finding_id}] marker on its last line. Skip a finding whose marker already appears in any existing issue body; back-fill its issue_url in metadata.yaml from the existing issue. Record it under "skipped_issues" with reason "already filed".
For each remaining finding, build the issue body. Use disclosure_draft when present; otherwise assemble from the finding's six-step prose. Drop any section whose source field is empty.
{title}
> Staged by scrutineer from finding {finding_id} (scan {scan_id}).
## Summary
{first sentence of rating, or "Severity: {severity}" if rating is empty}
## Location
`{location}` on `{owner}/{repo}`
## Details
{trace}
## Trigger
{boundary}
## Reproduction
{validation}
## Impact
{rating}
## Reach
{reach}
## References
- {repository.html_url}/blob/{default_branch}/{location path without :line}
- https://cwe.mitre.org/data/definitions/{n}.html (one per CWE)
- {each URL in prior_art}
[scrutineer-finding:{finding_id}]The marker on the last line is the dedup contract — do not move it, do not change its shape.
File the issue with severity labelled:
gh issue create -R {fork_org}/{host}__{owner}__{repo} \
--title "{title}" \
--body-file ./issue-{finding_id}.md \
--label "severity:{severity-lowercase}"Create the severity:{level} label first if it does not exist:
gh label create "severity:{level}" -R {fork_org}/{host}__{owner}__{repo} \
--color "{matching colour}" --description "Finding severity" --forceColours: severity:critical #8b0000, severity:high #dc3545, severity:medium #ffc107, severity:low #6c757d. --force makes label creation idempotent across runs.
Status labels (status:*) are not applied by this skill yet; they belong with a future state-sync pass. Filing them prematurely would conflict with the future taxonomy.
Capture the issue URL from the create response. Update {metadata_dir}/findings/{finding_id}/metadata.yaml with issue_url. Then write the issue link back to scrutineer:
POST {api_base}/findings/{id}/references with {"url": "<issue_url>", "tags": "staging-issue", "summary": "Issue on {fork_org} staging repo"}POST {api_base}/findings/{id}/communications with {"channel": "github-issue", "direction": "outbound", "actor": "fork", "body": "Issue #{number} opened on {fork_org}/{host}__{owner}__{repo}"}Do not change the finding's status. A staging issue is not a report upstream.
After all writes, the working tree should contain one updated {metadata_dir}/metadata.yaml, the per-finding directories with refreshed metadata and (where present) draft/patch files, and an unmodified upstream tree. Commit and push as described in step 3.
List the org's teams once:
gh api orgs/{fork_org}/teams --paginate --jq '.[].slug'Pick at most one team whose slug matches the repository, trying these signals in order and stopping at the first hit:
{owner} and check whether any team slug is a substring of it or vice versa. eclipse-platform or eclipse-ee4j matches an eclipse team, apache matches apache, a kubernetes-sigs repo matches kubernetes or cncf. Also check GET {api_base}/repositories/{repository_id}/maintainers — if a maintainer's affiliation or the repo's funding/SECURITY.md (already in ./src) names a foundation that appears as a team slug, prefer that.package_managers[0].name from brief ./src, mapped the same way as the GHSA ecosystem enum: Bundler→ruby/rubygems, npm/Yarn/pnpm→npm/javascript/nodejs, Cargo→rust, Go Modules→go/golang, pip/Poetry→python/pypi, Maven/Gradle→java/maven, Composer→php.languages[0].name from brief ./src, lowercased.Match by normalising both the candidate and each team slug (lowercase, strip non-alphanumerics) and testing whether either contains the other. If nothing matches, leave "team": null and move on — do not invent a team.
Give the team push access on the staging repo:
gh api -X PUT orgs/{fork_org}/teams/{team-slug}/repos/{fork_org}/{host}__{owner}__{repo} \
-f permission=pushIdempotent — re-running with the same team produces the same access.
Write ./report.json:
{
"fork_org": "fork-central",
"upstream": "owner/repo",
"staging": "fork-central/gh__owner__repo",
"created": "created",
"seeded_commit": "abc123...",
"scanned_at": "2026-05-04T12:00:00Z",
"issues": [
{"finding_id": 17, "number": 3, "url": "https://github.com/fork-central/gh__owner__repo/issues/3"}
],
"skipped_issues": [{"finding_id": 18, "reason": "already filed"}],
"skipped": [{"finding_id": 19, "reason": "duplicate"}],
"team": "rust",
"notes": "anything that did not go cleanly",
"error": null
}created is one of created, exists. team is the slug you gave push access, or null.
fork_org is unset; the operator must opt in.report-upstream against the github.com upstream.status:* labels — that taxonomy belongs to the future state-sync pass.© alpha-omega-security, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/fork of alpha-omega-security/scrutineer.
Open the folder on GitHubat commit cce10ee
Fork next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fork this skillalpha-omega-security/scrutineer | 231 | — | ~3.3k | Automated safety check: Pass | MIT | |
| ReleaseZeecka/AperiSolve | 850 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Triage Codeqlnetdata/netdata | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | |
| Security AdvisoryMidnightBSD/src | 114 | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Security Vulnerability Analysiseclipse-ankaios/ankaios | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 |
Zeecka/AperiSolve
Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.
netdata/netdata
Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.
MidnightBSD/src
Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…
eclipse-ankaios/ankaios
Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
openclaw/clawscan
A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…
alpha-omega-security/scrutineer
Default pipeline scrutineer runs when a repository is added.
alpha-omega-security/scrutineer
Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references.
alpha-omega-security/scrutineer
Run bandit against the Python source in the repository and map its hits into the findings shape.
alpha-omega-security/scrutineer
Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.
alpha-omega-security/scrutineer
Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.
alpha-omega-security/scrutineer
Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.
Works with
Categories
Stage a scanned repository into a private repo in the configured GitHub organisation. Fork is an agent skill from alpha-omega-security/scrutineer. Stage a scanned repository into a private repo in the configured GitHub organisation.
Fork fits situations like: security work in your project.
Run `npx skills add alpha-omega-security/scrutineer --skill fork -a claude-code`. Or copy the skill folder (skills/fork in alpha-omega-security/scrutineer) into .claude/skills/fork in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alpha-omega-security/scrutineer --skill fork -a codex`. Or copy the skill folder (skills/fork in alpha-omega-security/scrutineer) into .agents/skills/fork in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpha-omega-security/scrutineer --skill fork -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fork, .gemini/skills/fork, .github/skills/fork and .opencode/skills/fork in your project.
Going by SKILL.md and its folder, Fork needs the command-line tools its instructions call (gh and git). Our summary lists: Node.js. Compatibility (from SKILL.md): Needs the gh CLI authenticated with a token that can create private repos in `fork_org`, write to issues there, and manage team repo access. Needs network access to api.github.com and the scrutineer API. github.com upstreams only for now; other hosts will route through the same skill once `host__owner__repo` naming generalises..
SKILL.md names 2 domains. In commands or code: github.com and cwe.mitre.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fork is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fork: Release (Zeecka/AperiSolve, 850 stars), Triage Codeql (netdata/netdata, 81k stars), Security Advisory (MidnightBSD/src, 114 stars) and Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alpha-omega-security (a GitHub organization) maintains it in alpha-omega-security/scrutineer, which has 231 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 8, 2026.
Source: alpha-omega-security/scrutineer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.