Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer.

MITAuto-check passedDevelopment

Install Subprojects

skills CLI
$ npx skills add alpha-omega-security/scrutineer --skill subprojects -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alpha-omega-security/scrutineer subprojects --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alpha-omega-security/scrutineer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/subprojects .claude/skills/subprojects && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
subprojects
GitHub stars
231
Token cost
~1.4k tokens
SKILL.md length
605 words
Files
2
Skills in repo
48
Repo updated
First seen
Licence
MIT

At a glance

Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer.

  • Works in 3 steps: Explicit monorepo declarations. If the… → Sub-folder package manifests. Scan… → Cluster by top-level directory. If…
  • Tasks that involve Monorepo tooling
  • SKILL.md covers Workspace, How to identify subprojects, What NOT to emit and Output, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Subprojects is an agent skill from alpha-omega-security/scrutineer. Enumerate scannable sub-folders inside a repository. Identifies monorepo packages, workspaces, and discrete modules so the analyst can scope deep-dive scans to a specific sub-path instead of treating a huge tree as one unit. Runs at repo level; writes back a list that surfaces on the repo overview.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `schema.json`). Compatibility notes: Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.

It sits in Development, covering Monorepo tooling. It works with npm and Rust. The repository describes itself as: Security through scrutiny. The licence is MIT.

When your agent uses it

  • Tasks that involve Monorepo tooling

Example prompts

  • “/subprojects”

Requirements

  • Compatibility (from SKILL.md): Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Explicit monorepo declarations. If the repo has any of these at the root, the file names the workspaces directly. Expand any globs against…
  2. Sub-folder package manifests. Scan sub-folders (depth ≤ 3, skip node_modules, vendor, .git, dist, build, target) for any of the manifests…
  3. Cluster by top-level directory. If heuristic 2 produces many hits under a common parent (e.g. providers/amazon, providers/google each has…

What it can do on your machine

Read from SKILL.md and the folder at commit e4f95f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.

    From compatibility in the SKILL.md frontmatter.

Context cost

Subprojects loads about 1.4k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 605 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alpha-omega-security/scrutineer at commit e4f95f9, republished under its MIT licence (© alpha-omega-security). 605 words, ~1,446 tokens.

Download SKILL.mdSave it as .claude/skills/subprojects/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
subprojects
description
Enumerate scannable sub-folders inside a repository. Identifies monorepo packages, workspaces, and discrete modules so the analyst can scope deep-dive scans to a specific sub-path instead of treating a huge tree as one unit. Runs at repo level; writes back a list that surfaces on the repo overview.
compatibility
Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src.
license
MIT
metadata.scrutineer.version
1
metadata.scrutineer.output_file
report.json
metadata.scrutineer.output_kind
subprojects

subprojects

List the discrete scannable units inside a repository so the analyst can scope security scans to a sub-path instead of the whole tree. A repository with a single package at the root gets an empty list — that is the expected shape for the common case. A monorepo like apache/airflow or kubernetes/kubernetes gets a row per sub-package.

Workspace

  • ./src — the repository at HEAD. Read-only.
  • ./context.json — has scrutineer.api_base, scrutineer.token, scrutineer.repository_id. Not finding-scoped, not sub-path-scoped (this skill produces sub-paths; it does not consume one).
  • ./report.json — write the enumeration here.
  • ./schema.json — output shape.

How to identify subprojects

A subproject is a sub-folder that looks like an independently buildable, scannable unit. Heuristics, in descending order of signal strength:

  1. Explicit monorepo declarations. If the repo has any of these at the root, the file names the workspaces directly. Expand any globs against ./src and emit one row per matched directory:

    • pnpm-workspace.yaml — packages: glob list
    • lerna.json — packages: array
    • nx.json / workspace.json — NX workspace layout
    • turbo.json alongside a root package.json with a workspaces field
    • go.work — use (...) list
    • root Cargo.toml with [workspace].members
    • pyproject.toml with [tool.uv.workspace].members or Rye/hatch equivalents
  2. Sub-folder package manifests. Scan sub-folders (depth ≤ 3, skip node_modules, vendor, .git, dist, build, target) for any of the manifests below. Run this even when a workspace declaration exists, then union the two sets — go.work and friends are often incomplete.

    • go.mod → go-module
    • package.json with a name field → npm-package
    • pyproject.toml / setup.py / setup.cfg → python-package
    • Cargo.toml with [package] → rust-crate
    • composer.json → composer-package
    • pom.xml or build.gradle[.kts] → maven/gradle-module
    • Gemfile and/or *.gemspec → ruby-gem
    • Package.swift → swift-package
    • Dockerfile alongside a README in a services/ or apps/ tree → service
  3. Cluster by top-level directory. If heuristic 2 produces many hits under a common parent (e.g. providers/amazon, providers/google each has its own pyproject.toml), keep each sub-folder as its own row rather than rolling them up — an analyst may want to scan just one cloud provider's code.

What NOT to emit

  • The root as a subproject. A repo with one package at the root has zero subprojects; scrutineer already treats root as the default scan scope.
  • Test fixtures, examples, vendored deps. Folders called testdata/, fixtures/, examples/, vendor/, third_party/, external/ almost always ship code that is not the project itself — skip them.
  • Build outputs. dist/, build/, out/, target/, node_modules/, .venv/, __pycache__/ — same.
  • Nested workspaces with no independent manifest. If a sub-folder has no manifest and is not named by a workspace declaration, it is not a subproject; it is just a sub-folder.
Show full SKILL.md (206 more words)Show less

Output

Write ./report.json:

json
{
  "subprojects": [
    {
      "path": "airflow-core",
      "name": "airflow-core",
      "kind": "python-package",
      "description": "Core Airflow scheduler, webserver, and DAG runtime."
    },
    {
      "path": "airflow-ctl",
      "name": "airflow-ctl",
      "kind": "python-package",
      "description": "Airflow CLI distributed as a separate package."
    },
    {
      "path": "providers/amazon",
      "name": "apache-airflow-providers-amazon",
      "kind": "python-package",
      "description": "AWS provider package. Ships operators, hooks, and sensors for S3, EMR, Glue, and other AWS services."
    }
  ]
}

Fields:

  • path — required, relative to repo root, no leading slash. This is what scrutineer stores on Scan.sub_path when the analyst scans it.
  • name — short human label. Use the package's own name when the manifest has one (name in package.json, module path in go.mod, [package].name in Cargo.toml); otherwise the last segment of path.
  • kind — the detection hit: go-module, npm-package, python-package, rust-crate, composer-package, maven-module, gradle-module, ruby-gem, swift-package, service, etc. Free-form; the UI renders it as a badge.
  • description — one or two sentences. Read the README in the sub-folder if present, or infer from the package name and directory structure. Keep it specific ("AWS provider package", not "code for AWS").

Constraints

  • Empty list is the correct output for a single-package repo. Do not invent subprojects to avoid an empty array.
  • Do not include the root directory as a row. Root is implicit.
  • Do not add more than ~50 rows. If a monorepo is bigger than that, keep workspace-declared entries first, then fill the remainder by file count (largest first), and set the top-level notes field to "truncated to 50 of N".
  • Scrutineer replaces the full set on each re-run, so missing rows from a previous run will disappear — do not try to merge with prior output.

© alpha-omega-security, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/subprojects of alpha-omega-security/scrutineer.

  • SKILL.md
  • schema.json

Open the folder on GitHubat commit e4f95f9

Compare with similar skills

Subprojects next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Subprojects compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Subprojects this skillalpha-omega-security/scrutineer231—~1.4kAutomated safety check: PassMIT
Leanspec Developmentcodervisor/leanspec296—~2.5kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k7 repos~613Automated safety check: PassCustom licence
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Link Workspace Packagesnomcopter/react-mosaic4.8k5 repos~760Automated safety check: PassCustom licence

Similar skills

  • Leanspec Development

    codervisor/leanspec

    Development workflows, commands, publishing, CI/CD, changelog management, and contribution guidelines for LeanSpec.

    296 GitHub stars~2.5k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 7 repos~613 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 5 repos~760 tokens
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from alpha-omega-security/scrutineer

All 48 skills in this repo
  • Triage

    alpha-omega-security/scrutineer

    Default pipeline scrutineer runs when a repository is added.

    231 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Zizmor

    alpha-omega-security/scrutineer

    Audit GitHub Actions workflows with zizmor and explain reported hits using bundled trust-boundary references.

    231 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Bandit

    alpha-omega-security/scrutineer

    Run bandit against the Python source in the repository and map its hits into the findings shape.

    231 GitHub stars~615 tokensUpdated today
    Auto-check: notes
  • Compliance

    alpha-omega-security/scrutineer

    Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.

    231 GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Dependencies

    alpha-omega-security/scrutineer

    Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

    231 GitHub stars~596 tokensUpdated today
    Auto-check passed
  • History

    alpha-omega-security/scrutineer

    Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

    231 GitHub stars~2.9k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Subprojects

What does Subprojects do?

Enumerate scannable sub-folders inside a repository. An agent skill from alpha-omega-security/scrutineer. Subprojects is an agent skill from alpha-omega-security/scrutineer. Enumerate scannable sub-folders inside a repository.

When should I use Subprojects?

Subprojects fits situations like: tasks that involve Monorepo tooling.

How do I install Subprojects in Claude Code?

Run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a claude-code`. Or copy the skill folder (skills/subprojects in alpha-omega-security/scrutineer) into .claude/skills/subprojects in your project. Claude Code loads it when a task matches its description.

How do I install Subprojects in Codex?

Run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a codex`. Or copy the skill folder (skills/subprojects in alpha-omega-security/scrutineer) into .agents/skills/subprojects in your project. Codex loads it when a task matches its description.

Can I use Subprojects in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpha-omega-security/scrutineer --skill subprojects -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/subprojects, .gemini/skills/subprojects, .github/skills/subprojects and .opencode/skills/subprojects in your project.

What does Subprojects need to run?

SKILL.md names no scripts, command-line tools or credentials: Subprojects is instructions for the agent only. Compatibility (from SKILL.md): Needs network access to the scrutineer API only for logging; the enumeration itself is filesystem-only against ./src..

Does Subprojects access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Subprojects safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Subprojects use?

Subprojects is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Subprojects use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Subprojects?

Skills that share tags, products or a category with Subprojects: Leanspec Development (codervisor/leanspec, 296 stars), Nx Run Tasks (nomcopter/react-mosaic, 4.8k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars) and Cutting A Release (TriliumNext/Trilium, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Subprojects?

alpha-omega-security (a GitHub organization) maintains it in alpha-omega-security/scrutineer, which has 231 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 7, 2026.

Source: alpha-omega-security/scrutineer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.