Leanspec Development
codervisor/leanspec
Development workflows, commands, publishing, CI/CD, changelog management, and contribution guidelines for LeanSpec.
Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer.
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alpha-omega-security/scrutineer subprojects --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/subprojects .claude/skills/subprojects && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .claude/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojectsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alpha-omega-security/scrutineer subprojects --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/subprojects .agents/skills/subprojects && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .agents/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alpha-omega-security/scrutineer subprojects --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/subprojects .cursor/skills/subprojects && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .cursor/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alpha-omega-security/scrutineer.git --path skills/subprojects--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alpha-omega-security/scrutineer subprojects --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/subprojects .gemini/skills/subprojects && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .gemini/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alpha-omega-security/scrutineer subprojectsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/subprojects .github/skills/subprojects && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .github/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alpha-omega-security/scrutineer subprojects --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/subprojects .opencode/skills/subprojects && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "subprojects" agent skill from https://github.com/alpha-omega-security/scrutineer/tree/main/skills/subprojects into .opencode/skills/subprojects/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprojects", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
subprojectsEnumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer.
Subprojects is an agent skill from alpha-omega-security/scrutineer. Enumerate scannable sub-folders inside a repository. Identifies monorepo packages, workspaces, and discrete modules so the analyst can scope deep-dive scans to a specific sub-path instead of treating a huge tree as one unit. Runs at repo level; writes back a list that surfaces on the repo overview.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `schema.json`). Compatibility notes: Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.
It sits in Development, covering Monorepo tooling. It works with npm and Rust. The repository describes itself as: Security through scrutiny. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e4f95f9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.
From compatibility in the SKILL.md frontmatter.
Subprojects loads about 1.4k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 605 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alpha-omega-security/scrutineer at commit e4f95f9, republished under its MIT licence (© alpha-omega-security). 605 words, ~1,446 tokens.
.claude/skills/subprojects/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.List the discrete scannable units inside a repository so the analyst can scope security scans to a sub-path instead of the whole tree. A repository with a single package at the root gets an empty list — that is the expected shape for the common case. A monorepo like apache/airflow or kubernetes/kubernetes gets a row per sub-package.
./src — the repository at HEAD. Read-only../context.json — has scrutineer.api_base, scrutineer.token, scrutineer.repository_id. Not finding-scoped, not sub-path-scoped (this skill produces sub-paths; it does not consume one)../report.json — write the enumeration here../schema.json — output shape.A subproject is a sub-folder that looks like an independently buildable, scannable unit. Heuristics, in descending order of signal strength:
Explicit monorepo declarations. If the repo has any of these at the root, the file names the workspaces directly. Expand any globs against ./src and emit one row per matched directory:
pnpm-workspace.yaml — packages: glob listlerna.json — packages: arraynx.json / workspace.json — NX workspace layoutturbo.json alongside a root package.json with a workspaces fieldgo.work — use (...) listCargo.toml with [workspace].memberspyproject.toml with [tool.uv.workspace].members or Rye/hatch equivalentsSub-folder package manifests. Scan sub-folders (depth ≤ 3, skip node_modules, vendor, .git, dist, build, target) for any of the manifests below. Run this even when a workspace declaration exists, then union the two sets — go.work and friends are often incomplete.
go.mod → go-modulepackage.json with a name field → npm-packagepyproject.toml / setup.py / setup.cfg → python-packageCargo.toml with [package] → rust-cratecomposer.json → composer-packagepom.xml or build.gradle[.kts] → maven/gradle-moduleGemfile and/or *.gemspec → ruby-gemPackage.swift → swift-packageDockerfile alongside a README in a services/ or apps/ tree → serviceCluster by top-level directory. If heuristic 2 produces many hits under a common parent (e.g. providers/amazon, providers/google each has its own pyproject.toml), keep each sub-folder as its own row rather than rolling them up — an analyst may want to scan just one cloud provider's code.
testdata/, fixtures/, examples/, vendor/, third_party/, external/ almost always ship code that is not the project itself — skip them.dist/, build/, out/, target/, node_modules/, .venv/, __pycache__/ — same.Write ./report.json:
{
"subprojects": [
{
"path": "airflow-core",
"name": "airflow-core",
"kind": "python-package",
"description": "Core Airflow scheduler, webserver, and DAG runtime."
},
{
"path": "airflow-ctl",
"name": "airflow-ctl",
"kind": "python-package",
"description": "Airflow CLI distributed as a separate package."
},
{
"path": "providers/amazon",
"name": "apache-airflow-providers-amazon",
"kind": "python-package",
"description": "AWS provider package. Ships operators, hooks, and sensors for S3, EMR, Glue, and other AWS services."
}
]
}Fields:
path — required, relative to repo root, no leading slash. This is what scrutineer stores on Scan.sub_path when the analyst scans it.name — short human label. Use the package's own name when the manifest has one (name in package.json, module path in go.mod, [package].name in Cargo.toml); otherwise the last segment of path.kind — the detection hit: go-module, npm-package, python-package, rust-crate, composer-package, maven-module, gradle-module, ruby-gem, swift-package, service, etc. Free-form; the UI renders it as a badge.description — one or two sentences. Read the README in the sub-folder if present, or infer from the package name and directory structure. Keep it specific ("AWS provider package", not "code for AWS").notes field to "truncated to 50 of N".© alpha-omega-security, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/subprojects of alpha-omega-security/scrutineer.
Open the folder on GitHubat commit e4f95f9
Subprojects next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Subprojects this skillalpha-omega-security/scrutineer | 231 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Leanspec Developmentcodervisor/leanspec | 296 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Nx Run Tasksnomcopter/react-mosaic | 4.8k | 7 repos | ~613 | Automated safety check: Pass | Custom licence | |
| Migrate Internal Package into GhostTryGhost/Ghost | 55k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Cutting A ReleaseTriliumNext/Trilium | 38k | — | ~3.2k | Automated safety check: Pass | AGPL-3.0 | |
| Link Workspace Packagesnomcopter/react-mosaic | 4.8k | 5 repos | ~760 | Automated safety check: Pass | Custom licence |
codervisor/leanspec
Development workflows, commands, publishing, CI/CD, changelog management, and contribution guidelines for LeanSpec.
nomcopter/react-mosaic
Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.
TryGhost/Ghost
Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
nomcopter/react-mosaic
Link workspace packages in monorepos (npm, yarn, pnpm, bun).
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
alpha-omega-security/scrutineer
Default pipeline scrutineer runs when a repository is added.
alpha-omega-security/scrutineer
Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references.
alpha-omega-security/scrutineer
Run bandit against the Python source in the repository and map its hits into the findings shape.
alpha-omega-security/scrutineer
Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.
alpha-omega-security/scrutineer
Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.
alpha-omega-security/scrutineer
Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.
Categories
Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer. Subprojects is an agent skill from alpha-omega-security/scrutineer. Enumerate scannable sub-folders inside a repository.
Subprojects fits situations like: tasks that involve Monorepo tooling.
Run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a claude-code`. Or copy the skill folder (skills/subprojects in alpha-omega-security/scrutineer) into .claude/skills/subprojects in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a codex`. Or copy the skill folder (skills/subprojects in alpha-omega-security/scrutineer) into .agents/skills/subprojects in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/subprojects, .gemini/skills/subprojects, .github/skills/subprojects and .opencode/skills/subprojects in your project.
SKILL.md names no scripts, command-line tools or credentials: Subprojects is instructions for the agent only. Compatibility (from SKILL.md): Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Subprojects is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Subprojects: Leanspec Development (codervisor/leanspec, 296 stars), Nx Run Tasks (nomcopter/react-mosaic, 4.8k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars) and Cutting A Release (TriliumNext/Trilium, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alpha-omega-security (a GitHub organization) maintains it in alpha-omega-security/scrutineer, which has 231 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 7, 2026.
Source: alpha-omega-security/scrutineer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.