Agent skill

Basercms Security Advisory

by baserproject in baserproject/basercms

baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…

MITAuto-check passedDevelopment

Install Basercms Security Advisory

skills CLI
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install baserproject/basercms basercms-security-advisory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .claude/skills/basercms-security-advisory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
basercms-security-advisory
GitHub stars
190
Token cost
~1.4k tokens
SKILL.md length
410 words
Files
9 (incl. scripts)
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…

  • Works in 10 steps: 前提 → 一覧と分類 → 指摘の検証 → …
  • Development work in your project
  • SKILL.md covers 0. 前提, 1. 一覧と分類, 2. 指摘の検証 and 3. 修正方針の確定, plus 7 more sections
  • Runs Shell scripts from its folder; calls git, composer and gh

What it does

Basercms Security Advisory is an agent skill from baserproject/basercms. baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAはアドバイザリforkで使えないためローカル検証(/code-review・basercms-unittest)を正とする点、push反映待ちリトライ、共有ファイルのhunk分割、base追従の定番競合解決を収録。

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `scripts/build-integration.sh`, `scripts/common.sh` and `scripts/create-fork-branch.sh`).

It sits in Development. It works with Git. The repository describes itself as: baserCMS : Based Website Development Project. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “Use the basercms-security-advisory skill to basercm のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプ…”
  • “/basercms-security-advisory”

Requirements

  • A Bash shell
  • Docker

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. 前提
  2. 一覧と分類
  3. 指摘の検証
  4. 修正方針の確定
  5. 課題別フォーク/ブランチ/PR
  6. ローカル検証
  7. 最新 base への追従
  8. 落とし穴レシピ
  9. 補助スクリプト一覧
  10. 既存スキル連携

What it can do on your machine

Read from SKILL.md and the folder at commit 748b4f6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • composer
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Basercms Security Advisory loads about 1.4k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 410 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from baserproject/basercms at commit 748b4f6, republished under its MIT licence (© baserproject). 410 words, ~1,446 tokens.

Download SKILL.mdSave it as .claude/skills/basercms-security-advisory/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
basercms-security-advisory
description
baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAはアドバイザリforkで使えないためローカル検証(/code-review・basercms-unittest)を正とする点、push反映待ちリトライ、共有ファイルのhunk分割、base追従の定番競合解決を収録。
license
MIT

baserCMS セキュリティアドバイザリ対応ガイド

baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage 含む)を、一覧→検証→課題別修正→フォーク/ブランチ/PR→ローカル検証まで一気通貫で扱う。スクリプトは scripts/ 配下。base ブランチは実行時の現在のブランチ(事前に対象リリースブランチを checkout しておく)。

0. 前提

  • gh CLI 認証済み。対象 upstream は BCSA_UPSTREAM(既定 baserproject/basercms)。
  • Copilot レビューと GitHub Actions はアドバイザリのプライベートフォークでは使えない。レビューはローカル /code-review、テストはローカル Docker(basercms-unittest)が正。
  • フォーク full_name=<owner>/basercms-<小文字GHSA>、remote=sec-<小文字GHSA(先頭ghsa-除去)>、ブランチ=security/<GHSA-ID>。

1. 一覧と分類

scripts/list-advisories.sh [--state triage] で state別件数と一覧を取得し、triage を抽出する。

2. 指摘の検証

scripts/fetch-advisory.sh <GHSA-ID> で詳細を取得し、現在のブランチの実コードと突き合わせて「的確 / 不正確 / 非該当」を判定する。対象が多い場合は読み取り専用の並列サブエージェントで分担する。フレームワークのデフォルト保護(ORM バインド / slug エンコード / h() 出力)で再現しないものは非該当として却下し、具体的な PoC を要求する。

3. 修正方針の確定

同一 sink の重複アドバイザリ、共有ファイルの hunk 分割、非該当の却下を整理する。重複の扱い(複数 fork へ同一修正 / 片方を重複クローズ)など判断が要る点はユーザーに確認する。

4. 課題別フォーク/ブランチ/PR

アドバイザリ単位で:

  1. scripts/create-fork-branch.sh <GHSA-ID> — フォーク作成 → remote 追加 → 現ブランチ起点でブランチ作成
  2. 該当 hunk のみ適用(複数アドバイザリが同一ファイルを触る場合は git checkout … -- file で全取りせず hunk 単位で手適用)
  3. どの脆弱性をどう直したか明確なメッセージでコミット
  4. scripts/push-with-retry.sh <remote> security/<GHSA-ID> — フォーク反映待ちのリトライ付き push
  5. scripts/open-pr.sh <GHSA-ID> [--title T] [--body-file F] — base=現ブランチで PR 作成

5. ローカル検証

  1. scripts/build-integration.sh [統合ブランチ名] — 現ブランチ+全 security/GHSA-* をマージ(競合は停止)
  2. scripts/run-tests.sh — ローカル全テスト(詳細は basercms-unittest)
  3. 必要なら統合ブランチを個人フォーク(<個人フォーク名>)へ push して GHA を回す(アドバイザリ fork では GHA は動かない)

6. 最新 base への追従

origin/base が進んだら各 PR ブランチへ base をマージし、push し直す。定番競合:

  • order() → orderBy()(CakePHP 5.2 改名)
  • パス検証 realpath() === false バイパス修正 × $fullPath 検証 の併合

6b. リリース後の取り込み確認とブランチ整理

アドバイザリ fork の PR を GitHub 上でマージすると、base ブランチには 「Merge commit from fork」という 1 コミット(squash) として入る。security/<GHSA-ID> ブランチ自体は base の祖先にならないため、git merge-base --is-ancestor や git branch --merged では「未マージ」に見える。取り込み確認は内容差分で行う。

  1. 対象ブランチが変更したファイル一覧を取り、そのファイルだけを base と比較する(差分ゼロなら取り込み済み):
    base=$(git merge-base security/<GHSA-ID> origin/5.4.x)
    files=$(git diff --name-only $base security/<GHSA-ID>)
    git diff --name-only origin/5.4.x security/<GHSA-ID> -- ${=files}   # zsh。bash は $files
    差分が残るファイルは git log <branch>..origin/5.4.x -- <file> で「取り込み後に別コミットで触られた」だけかを確認する。
  2. 取り込み済みと確認できた security/* は git branch -D で削除する(削除は承認を得てから。10/22 など次回リリース分・顧客向けパッチ(consolidated-5.2.x)・未取り込み分は残す)。
  3. 同じファイルを触る複数のアドバイザリ(例 BlogTags API の v9g2 と 636g)は、先にマージした方の fork コミットに後の修正が同梱されていることがある。後の PR をマージしても差分ゼロなら、そのリリースで既に塞がっている。
  4. 5.3.x → 5.4.x の系列マージでは VERSION.txt 1 行目・composer.json・composer.lock が必ず競合する。バージョン値は上位系列(ours)を採用し、VERSION.txt には下位系列のリリースブロックだけを 5.4.x のブロックの下に追加する。
Show full SKILL.md (199 more words)Show less

7. 落とし穴レシピ

  • Copilot/GHA 不可: アドバイザリ fork では使えない。ローカル検証が正。
  • push 反映待ち: 新規 fork 直後は remote rejected (failure)。終了コードでリトライ(-> 等の文字列で成功誤検知しない)。
  • 共有ファイルの hunk 分割: 例 PluginsService の basename と php 実行パス検証は別アドバイザリ。hunk 単位で分けて適用。
  • 同一 sink の重複: 同一修正を複数 fork へ、または片方を重複クローズ。
  • 非該当の見極め: framework デフォルト保護で再現しないものは却下。報告時点のブランチ状態まで遡って確認。
  • フルスイートのフレイキー: CreateReleaseCommandTest(実 composer 実行)は単体では緑。環境要因を切り分ける。
  • 認可境界: permission.php の Api/Admin と Admin の auth 整合は、管理画面 SPA(ビルド済み JS まで)の依存を確認してから変更。
  • 古い系列を後からリリースするとき monorepo-builder が止まる: ReleaseGuard は「ローカルタグのうち committer date が最新のもの」より大きいバージョンしか通さない(系列別の比較は無い)。5.4.0 の後に 5.3.1 を出すなら、リリース作業用クローンで git tag -d 5.4.0 してから vendor/bin/monorepo-builder release 5.3.1 を実行し、終わったら git fetch origin --tags で戻す。リモートのタグには影響しない。
  • prepare release が未追跡ファイルを巻き込む: monorepo-builder の release は作業ツリーの未追跡ファイルもコミットする。下位系列(5.3.x)の .gitignore に上位系列だけのプラグイン(webroot/bc_burger_editor・webroot/bc_mcp のシンボリックリンク)が無いと、そのままタグに入る。リリース前に git status --short が空であることを確認し、系列ごとの .gitignore を揃える。混入したら git rm --cached と .gitignore 追記で直す。
  • Packagist の反映は Web 表示より遅れる: split ワークフロー成功後、packagist.org のページに新バージョンが出ていても、Composer が読む repo.packagist.org/p2/<vendor>/<pkg>.json への反映は数分遅れる。Root composer.json requires ... does not match the constraint はこの遅れが原因なことが多い。composer show --all <pkg> で versions を確認し、数分待って再実行。キャッシュ削除はホストではなくアップデートを実行しているコンテナ内で行う。
  • 誤ってタグを出したときの取り下げ: 本体だけでなく split 先の全リポジトリ(split_monorepo.yml の一覧)から gh api --method DELETE /repos/baserproject/<repo>/git/refs/tags/<ver> で消す。Packagist は再クロールで「No longer found in upstream」となり自動で消える。5.x ブランチに残ったリリースコミット(VERSION.txt 1 行目・composer.json)は X.Y.Z-dev に戻すコミットを別途入れる。

8. 補助スクリプト一覧

スクリプト引数役割
list-advisories.sh[--state S]アドバイザリ一覧・集計
fetch-advisory.sh<GHSA-ID>個別詳細取得(/tmp/bc-advisories へ保存)
create-fork-branch.sh<GHSA-ID>フォーク作成→remote→現ブランチ起点ブランチ
push-with-retry.sh<remote> <branch> [max]反映待ちリトライ push
open-pr.sh<GHSA-ID> [--title T] [--body-file F]base=現ブランチで PR 作成
build-integration.sh[統合ブランチ名]全 PR を統合ブランチへマージ
run-tests.sh[--filter X]ローカル全テスト(basercms-unittest 連携)

9. 既存スキル連携

  • 連絡・記録・公開物は本スキルの範囲外: 報告者への返信コメント、GHSA の受理/深刻度/影響・修正版/credits/重複クローズなどメタ情報の更新、CVE 申請状況、JPCERT/JVN との往復、ベンダステートメント、公式サイトの脆弱性情報ページ原稿、管理表/課題/チャットへの記録、リリース当日チェックは、脆弱性ハンドリング(調整・広報)側の手順で扱う。本スキルは「コードの検証・修正・フォーク/PR・ローカル検証」に集中し、結論(該当/非該当、ブランチ名、PR URL、テスト結果)を返す。
  • テスト実行: basercms-unittest
  • 移行起因の競合・非推奨: cakephp-migration / php-migration / basercms-plugin-migration

© baserproject, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts) in .agents/skills/basercms-security-advisory of baserproject/basercms.

  • SKILL.md
  • scripts/build-integration.sh
  • scripts/common.sh
  • scripts/create-fork-branch.sh
  • scripts/fetch-advisory.sh
  • scripts/list-advisories.sh
  • scripts/open-pr.sh
  • scripts/push-with-retry.sh
  • scripts/run-tests.sh

Open the folder on GitHubat commit 748b4f6

Compare with similar skills

Basercms Security Advisory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Basercms Security Advisory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Basercms Security Advisory this skillbaserproject/basercms190—~1.4kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Codebase Knowledge Graph Q&AEgonex-AI/Understand-Anything85k1 repos~1.2kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Codebase Knowledge Graph Q&A

    Egonex-AI/Understand-Anything

    Answers questions about a codebase by searching a prebuilt knowledge graph of its files, functions, classes and dependencies, not by rereading every source file.

    85k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Understand Explain

    Egonex-AI/Understand-Anything

    Gives an in-depth explanation of one file, function or module by reading the project's knowledge graph and checking that the graph is still fresh.

    85k GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed

More from baserproject/basercms

All 15 skills in this repo
  • Basercms Core Plugin Convert

    baserproject/basercms

    baserCMS の「通常プラグイン(サードパーティ/単体配布)」を monorepo の「コアプラグイン」に昇格させる手順。「コアプラグインに変更」「コアプラグイン化」「通常プラグインをコアに昇格」「monorepo に取り込む」等のときに参照する。プラグイン名の規約変更(bc- プレフィックス付与・CamelCase→ハイフン区切り)、.git/シンボリックリンク/standalone…

    190 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Basercms Plugin 5x Update

    baserproject/basercms

    baserCMS プラグインを 5.2系 から 5.3系(PHP 8.5 / CakePHP 5.2.x ベース、開発中)へ移行する際の baserCMS 固有の破壊的変更・非推奨・テスト基盤対応のレシピ集。「プラグインを5.3に対応」「baserCMS 5.3 マイグレーション」「PluginCollection::create(): $config null given」「Plugin…

    190 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Basercms Release Note

    baserproject/basercms

    baserCMS の plugins/baser-core/VERSION.txt に、リリース分の変更履歴(NEW/CHG/BUG)をコミットログから生成して追記する手順。「VERSION.txt を更新して」「リリースノートを作って」「変更履歴をまとめて」「今回のリリース分の変更点を書き出して」「前回リリースからの差分を VERSION.txt…

    190 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Basercms Unittest

    baserproject/basercms

    baserCMS(CakePHP5 / PHPUnit)のユニットテストをローカル Docker 環境で実行・調査する手順。「ユニットテストを実行して」「全テストを走らせて」「このテストだけ流して」「テスト失敗を調べて」「プラグイン単体でテストを動かしたい」「プラグインにテスト環境を導入したい」等のときに参照する。コンテナ名・実行コマンド・権限自動承認のためのコマンド整形・失敗の集計と切り分け方…

    190 GitHub stars~4.9k tokensUpdated 2 days ago
    Auto-check passed
  • Basercms4 Development

    baserproject/basercms

    baserCMS 4系(CakePHP 2.10ベース)+ jQuery プロジェクトの開発ルール集。「baserCMS 4 で開発」「4系のプラグインを修正」「CakePHP 2系のコードを書く」「app/Plugin 配下の Controller/Model/View」「テーマの…

    190 GitHub stars~877 tokensUpdated 2 days ago
    Auto-check passed
  • Basercms5 Claude Workflow Setup

    baserproject/basercms

    baserCMS5(CakePHP5)の開発・移行を Claude Code で進めるときに、着手前に一度参照する「推奨ワークフロー環境セットアップ」スキル(提案ベース・実行は opt-in)。「5系プラグインの開発や移行をこれから始める」「どう進めるのがベストか」「設計→計画→実装の進め方/環境を整えたい」「パーミッションを整理して Auto mode…

    190 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Basercms Security Advisory

What does Basercms Security Advisory do?

baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…. Basercms Security Advisory is an agent skill from baserproject/basercms.

When should I use Basercms Security Advisory?

Basercms Security Advisory fits situations like: development work in your project.

How do I install Basercms Security Advisory in Claude Code?

Run `npx skills add baserproject/basercms --skill basercms-security-advisory -a claude-code`. Or copy the skill folder (.agents/skills/basercms-security-advisory in baserproject/basercms) into .claude/skills/basercms-security-advisory in your project. Claude Code loads it when a task matches its description.

How do I install Basercms Security Advisory in Codex?

Run `npx skills add baserproject/basercms --skill basercms-security-advisory -a codex`. Or copy the skill folder (.agents/skills/basercms-security-advisory in baserproject/basercms) into .agents/skills/basercms-security-advisory in your project. Codex loads it when a task matches its description.

Can I use Basercms Security Advisory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add baserproject/basercms --skill basercms-security-advisory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/basercms-security-advisory, .gemini/skills/basercms-security-advisory, .github/skills/basercms-security-advisory and .opencode/skills/basercms-security-advisory in your project.

What does Basercms Security Advisory need to run?

Going by SKILL.md and its folder, Basercms Security Advisory needs a shell for the scripts in its folder and the command-line tools its instructions call (git, composer and gh). Our summary lists: A Bash shell; Docker.

Does Basercms Security Advisory access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Basercms Security Advisory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Basercms Security Advisory use?

Basercms Security Advisory is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Basercms Security Advisory use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Basercms Security Advisory?

Skills that share tags, products or a category with Basercms Security Advisory: Finishing a Development Branch (obra/superpowers, 296k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Codebase Knowledge Graph Q&A (Egonex-AI/Understand-Anything, 85k stars) and Code Design Rationale Investigator (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Basercms Security Advisory?

baserproject (a GitHub organization) maintains it in baserproject/basercms, which has 190 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.

Source: baserproject/basercms on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.