Clawsec Scanner
LeoYeAI/openclaw-master-skills
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcher --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .claude/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .claude/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcherType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcher --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .agents/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .agents/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcher --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .cursor/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .cursor/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/axelixlabs/axelix.git --path .agent_skills/security-vulnerabilities-patcher--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcher --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .gemini/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .gemini/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcherInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .github/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .github/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install axelixlabs/axelix security-vulnerabilities-patcher --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axelixlabs/axelix.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agent_skills/security-vulnerabilities-patcher .opencode/skills/security-vulnerabilities-patcher && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-vulnerabilities-patcher" agent skill from https://github.com/axelixlabs/axelix/tree/master/.agent_skills/security-vulnerabilities-patcher into .opencode/skills/security-vulnerabilities-patcher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerabilities-patcher", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-vulnerabilities-patcherCreate batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…
Security Vulnerabilities Patcher is an agent skill from axelixlabs/axelix. Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle builds. Use this skill whenever the user asks to fix CodeQL, Trivy, SARIF, Dependabot, SAST, SCA, CVE, GHSA, or security-check findings for the Axelix repository and wants patch-release-safe PRs that bundle related vulnerabilities by manifest or module area instead of one PR per CVE.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Dependency management, Static analysis and SAST and Vulnerability scanning. It works with Gradle, GitHub, Trivy and Spring Boot. The repository describes itself as: The source code of Axelix - a Delta Force for your Spring Boot ecosystem. The licence is LGPL-3.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f7d043e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Vulnerabilities Patcher loads about 4.2k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 1,713 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from axelixlabs/axelix at commit f7d043e, republished under its LGPL-3.0 licence (© axelixlabs). 1,713 words, ~4,241 tokens.
.claude/skills/security-vulnerabilities-patcher/SKILL.md (or your agent's skills folder).Turn GitHub security alerts into batched, Dependabot-style pull requests for axelixlabs/axelix.
The key idea is batch by Axelix dependency surface, not by individual CVE. The desired shape is:
master/front-end dependency updates,master/build.gradle.kts and directly coupled master backend build files,The goal is still patch-release safety: each PR should stay locally understandable and safe to review, but it may fix several vulnerabilities at once if they belong to the same surface.
Use this workflow for axelixlabs/axelix when the repository has security findings from:
security-check that is expected to fail on open HIGH/CRITICAL findings, and the user wants AI-authored remediation PRs.This skill is intentionally Axelix-specific. It assumes the target repository is axelixlabs/axelix and that its security workflow uploads Trivy SARIF into GitHub code scanning, so GitHub API queries can see both CodeQL and Trivy findings.
Batch by dependency surface, not by CVE. Group vulnerabilities that are fixed by the same manifest, lockfile, Gradle build, or tightly coupled module area.
Do not batch across unrelated Axelix surfaces.
master/front-end does not belong in the same PR as starter Gradle files. master/build.gradle.kts does not belong in the same PR as Docker base image remediation unless the same build surface truly requires it.
Prefer patch-safe remediations. Favor:
Do not break public APIs or contracts. The fix must be safe for a patch release. Avoid changes to public DTOs, REST contracts, starter configuration contracts, public Java APIs, or user-facing workflows unless the user explicitly accepts that risk.
Do not hide the problem. Do not "fix" alerts by suppressing them, loosening the scanner, or adding ignores unless the user explicitly asks for that path and understands the trade-off.
Do not invent vulnerability identifiers. Prefer real CVE identifiers when they exist. If some findings are GHSA-only, say so plainly instead of fabricating CVEs.
Use these batch boundaries by default unless the live alert data strongly suggests a better split:
master/front-end
Group vulnerabilities remediated through master/front-end/package.json, master/front-end/package-lock.json, or equivalent front-end dependency files.
Master backend Gradle
Group vulnerabilities remediated through master/build.gradle.kts, root Gradle version catalogs or shared Gradle declarations that primarily affect master backend dependencies.
Starters Gradle
Group vulnerabilities remediated through sbs/build.gradle.kts, sbs/axelix-spring-boot-2/build.gradle.kts, sbs/axelix-spring-boot-3/build.gradle.kts, or directly coupled starter build files.
Shared/common Gradle
If vulnerabilities live primarily in common/ modules or shared build logic, use a separate PR when that keeps the blast radius smaller and clearer.
Docker/image surface If Trivy image findings are fixed via Docker base image changes rather than application manifests, keep that in its own PR unless the user explicitly wants it combined.
When in doubt, ask: "Would a maintainer naturally review these updates together like a single Dependabot PR?" If not, split them.
Use GitHub's code scanning alerts API for:
Recommended command:
export GH_TOKEN="$GITHUB_PAT"
gh api "repos/OWNER/REPO/code-scanning/alerts?state=open&per_page=100" --paginateTypical fields worth extracting:
numberhtml_urltool.namemost_recent_instance.categoryrule.idrule.descriptionrule.security_severity_levelmost_recent_instance.location.pathmost_recent_instance.refFor this repository, expect Trivy categories such as trivy-artifacts and trivy-image.
Use GitHub's Dependabot alerts API for dependency vulnerabilities that include package and patched-version information.
Recommended command:
export GH_TOKEN="$GITHUB_PAT"
gh api "repos/OWNER/REPO/dependabot/alerts?state=open&per_page=100" --paginateTypical fields worth extracting:
numberhtml_urldependency.package.namedependency.manifest_pathsecurity_advisory.ghsa_idCVE when availablesecurity_advisory.cwessecurity_advisory.severitysecurity_vulnerability.first_patched_version.identifiersecurity_vulnerability.package.ecosystemGitHub alert payloads evolve. If an exact key is different in the live API response, use the equivalent returned field and do not invent missing data.
If a workflow failed but the finding is visible only in raw logs or artifacts and not in GitHub alerts, say that you are outside the API-driven path of this skill. You can still help manually, but do not pretend it came from the GitHub alerts API.
This skill must use the GITHUB_PAT environment variable for GitHub API access.
Before any gh api, gh pr, gh repo view, or other GitHub network call:
GITHUB_PAT is present in the environment.GITHUB_PAT is missing or empty, stop immediately.GITHUB_PAT is not set.Preferred pattern:
export GH_TOKEN="$GITHUB_PAT"Resolve OWNER/REPO from git first:
git remote get-url originExpect the default answer to be axelixlabs/axelix. If the current workspace points somewhere else, stop and confirm with the user before proceeding, because this skill is written specifically for the Axelix monorepo and its release-safety constraints.
Then confirm GitHub CLI authentication using GITHUB_PAT:
export GH_TOKEN="$GITHUB_PAT"
gh auth statusYou need enough access to:
If authentication is missing or insufficient, stop and explain what permission is needed rather than guessing.
Also resolve the default branch:
export GH_TOKEN="$GITHUB_PAT"
gh repo view OWNER/REPO --json defaultBranchRefFetch open alerts from every supported source that applies.
Before choosing what to fix, summarize counts by:
The summary should look like:
critical: Nhigh: Nmedium: Nlow: NAnd then a short source breakdown such as:
code-scanning / CodeQLcode-scanning / TrivydependabotAlso produce a surface grouping summary. For each alert, map it to the most likely Axelix batch boundary:
master/front-endmaster backend gradlestarters gradlecommon/shared gradledocker/imageother / needs reviewThe point of the summary is to show both the severity queue and the likely Dependabot-style PR buckets before you start fixing anything.
Do not choose a single vulnerability. Choose one batch.
Selection order:
If the most severe batch is not safely fixable under patch-release constraints, explain why and move to the next eligible batch. Do not force a risky fix just to satisfy queue order.
Do not send the subagent in blind. Collect and pass the exact context it needs:
OWNER/REPOmaster/front-end or starters gradleIf the workspace is dirty, prefer an isolated worktree subagent so the remediation branch does not interfere with unrelated local changes.
Prefer a best-of-n-runner subagent when available because it works in an isolated git worktree and is a good fit for one-branch-per-batch security work. If that is unavailable, use a normal writable subagent and be careful around local changes.
The subagent's job is to:
security label to that PR,Do not launch multiple fixing subagents in parallel unless the user explicitly asks for multiple independent batched PRs and the repository state makes that safe.
Use a prompt in this shape, filling in the real batch details:
You are fixing one batched security update for axelixlabs/axelix in an isolated branch.
Repository: OWNER/REPO
Base branch: DEFAULT_BRANCH
Chosen batch:
- Batch name: master/front-end | master backend gradle | starters gradle | common/shared gradle | docker/image
- Why this batch is grouped together: REASON
- Affected files: FILES
Alerts in this batch:
- ALERT 1: severity, CVE/GHSA, package or rule, current version, patched version, alert URL
- ALERT 2: severity, CVE/GHSA, package or rule, current version, patched version, alert URL
- ...
Constraints:
- Use the `GITHUB_PAT` environment variable for all GitHub access. If it is missing or empty, stop immediately and report that back to the parent agent without attempting any GitHub API call.
- Attribute the PR to the actual AI agent that created it, for example `Cursor`, `Claude`, `Codex`, or `Gemini`. Do not use a generic `AI` label when the runtime identity is known.
- The git commit author must also be that actual AI agent identity. Do not leave the commit authored by a human account or local default identity.
- Do not modify git config to achieve this. Use per-commit author metadata such as `git commit --author="ACTUAL_AI_AGENT_NAME <ACTUAL_AI_AGENT_NAME@local>"`.
- Fix only this dependency surface. Do not opportunistically update unrelated manifests or modules.
- Keep the change safe for a patch release.
- Do not introduce public API or public contract changes.
- Prefer the smallest same-major dependency upgrades or similarly low-risk grouped patch.
- If the only fix appears to require a breaking change, stop and report that instead of opening a PR.
- Do not suppress or ignore the alerts.
Required work:
1. Inspect the relevant files and understand the batch of vulnerabilities.
2. Implement the minimal safe grouped fix for this surface.
3. Run targeted verification that is appropriate for the touched modules.
4. Confirm the public API and public contract remain unchanged.
5. Commit using the actual AI agent as the git author, push, open a PR, assign the `security` label to it, and include explicit AI-agent attribution in the PR body.
Branch naming:
- Prefer `security/master-front-end-batch`
- Or `security/master-gradle-batch`
- Or `security/starters-gradle-batch`
PR title format:
- `[SECURITY][BATCH] Update master/front-end dependencies`
- `[SECURITY][BATCH] Update master backend Gradle dependencies`
- `[SECURITY][BATCH] Update starter Gradle dependencies`
PR labeling:
- Add the `security` label immediately after creating the PR.
- Prefer `gh pr edit --add-label "security"` with `GH_TOKEN="$GITHUB_PAT"` in the environment.
PR authorship:
- The git commit author must name the actual AI agent that created the patch.
- Prefer `git commit --author="Cursor <cursor@local>"` or `git commit --author="Claude <claude@local>"` with the truthful agent name for the current runtime.
- Use a clearly non-human local or noreply-style address if needed, but do not pretend to be a human contributor.
- The PR body must contain an `Authored by` line naming the actual AI agent that opened the PR.
PR body must include:
## Summary
- what dependency surface was updated
- which vulnerabilities or packages were addressed
- why this batch belongs together
- why this is safe for a patch release
## Test plan
- [x] list each verification command actually run
- [x] state explicitly that no public API or contract changes were introduced
## Attribution
- `Authored by: ACTUAL_AI_AGENT_NAME`
Return to the parent agent with:
- branch name
- commit author used
- commit SHA
- PR URL
- confirmation that the `security` label was applied
- confirmation of the AI agent name used in the PR attribution
- verification summary
- any remaining risk or follow-upThe subagent should verify the narrowest thing that gives real confidence:
master/front-end dependency changes, run the relevant package checks from that app.Do not add broad, expensive verification if a focused check is sufficient. Do not skip verification if any focused check is available.
Patch-release safety means:
After the subagent finishes, report:
If no safely fixable batch exists, say so clearly and explain the blocker instead of opening a risky PR.
GITHUB_PAT is present.security label.© axelixlabs, LGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agent_skills/security-vulnerabilities-patcher of axelixlabs/axelix.
Open the folder on GitHubat commit f7d043e
Security Vulnerabilities Patcher next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Vulnerabilities Patcher this skillaxelixlabs/axelix | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | |
| Clawsec ScannerLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Pipeline Security Gatesrevfactory/harness-100 | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Apply Renovate PRssivaprasadreddy/sivalabs-agent-skills | 188 | — | ~3k | Automated safety check: Pass | MIT | |
| Springboot Verificationaffaan-m/ECC | 276k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Performing Sca Dependency Scanning With Snykmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
LeoYeAI/openclaw-master-skills
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
revfactory/harness-100
CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.
sivaprasadreddy/sivalabs-agent-skills
Apply the changes from all open Renovate bot pull requests of a GitHub repository into the local working tree.
affaan-m/ECC
Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency…
mukul975/Anthropic-Cybersecurity-Skills
This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
axelixlabs/axelix
Review configuration property changes in the Axelix project for breaking changes and migration-policy compliance.
axelixlabs/axelix
Refine and triage GitHub backlog by finding open issues that are stale, obsolete, or resolved by another path.
axelixlabs/axelix
Pick open GitHub issues in the Axelix monorepo that are suitable for unpaid volunteer contributors working in their spare time.
axelixlabs/axelix
Prepare an Axelix minor lockstep release — the pre-release housekeeping changes, a hand-editable release-notes draft, and the post-release bump to the next -SNAPSHOT.
axelixlabs/axelix
Reviews changes in sbs/starter-domain for technology-agnostic domain logic, forbidden production dependencies, and Java 11+ compatibility.
axelixlabs/axelix
Reviews test code in GitHub pull requests for isolation, public-API contract coverage, AAA structure, and correct exception assertions.
Works with
Categories
Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…. Security Vulnerabilities Patcher is an agent skill from axelixlabs/axelix.kts, or starter Gradle builds.
Security Vulnerabilities Patcher fits situations like: the user asks to fix CodeQL; security-check findings for the Axelix repository and wants patch-release-safe PRs that bundle related vulnerabilities by manifest; module area instead of one PR per CVE.
Run `npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a claude-code`. Or copy the skill folder (.agent_skills/security-vulnerabilities-patcher in axelixlabs/axelix) into .claude/skills/security-vulnerabilities-patcher in your project. Claude Code loads it when a task matches its description.
Run `npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a codex`. Or copy the skill folder (.agent_skills/security-vulnerabilities-patcher in axelixlabs/axelix) into .agents/skills/security-vulnerabilities-patcher in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add axelixlabs/axelix --skill security-vulnerabilities-patcher -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-vulnerabilities-patcher, .gemini/skills/security-vulnerabilities-patcher, .github/skills/security-vulnerabilities-patcher and .opencode/skills/security-vulnerabilities-patcher in your project.
Going by SKILL.md and its folder, Security Vulnerabilities Patcher needs the command-line tools its instructions call (gh and git) and credentials named GH_TOKEN. Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Vulnerabilities Patcher is published under the LGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Vulnerabilities Patcher: Clawsec Scanner (LeoYeAI/openclaw-master-skills, 2.2k stars), Pipeline Security Gates (revfactory/harness-100, 1.3k stars), Apply Renovate PRs (sivaprasadreddy/sivalabs-agent-skills, 188 stars) and Springboot Verification (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
axelixlabs (a GitHub organization) maintains it in axelixlabs/axelix, which has 148 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.
Source: axelixlabs/axelix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.