Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install baserproject/basercms basercms-security-advisory --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .claude/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .claude/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisoryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install baserproject/basercms basercms-security-advisory --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .agents/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .agents/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install baserproject/basercms basercms-security-advisory --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .cursor/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .cursor/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/baserproject/basercms.git --path .agents/skills/basercms-security-advisory--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install baserproject/basercms basercms-security-advisory --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .gemini/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .gemini/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install baserproject/basercms basercms-security-advisoryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .github/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .github/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add baserproject/basercms --skill basercms-security-advisory -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install baserproject/basercms basercms-security-advisory --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/baserproject/basercms.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/basercms-security-advisory .opencode/skills/basercms-security-advisory && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "basercms-security-advisory" agent skill from https://github.com/baserproject/basercms/tree/5.4.x/.agents/skills/basercms-security-advisory into .opencode/skills/basercms-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "basercms-security-advisory", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
basercms-security-advisorybaserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…
Basercms Security Advisory is an agent skill from baserproject/basercms. baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAはアドバイザリforkで使えないためローカル検証(/code-review・basercms-unittest)を正とする点、push反映待ちリトライ、共有ファイルのhunk分割、base追従の定番競合解決を収録。
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `scripts/build-integration.sh`, `scripts/common.sh` and `scripts/create-fork-branch.sh`).
It sits in Development. It works with Git. The repository describes itself as: baserCMS : Based Website Development Project. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 748b4f6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 8 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitcomposerghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Basercms Security Advisory loads about 1.4k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 410 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from baserproject/basercms at commit 748b4f6, republished under its MIT licence (© baserproject). 410 words, ~1,446 tokens.
.claude/skills/basercms-security-advisory/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage 含む)を、一覧→検証→課題別修正→フォーク/ブランチ/PR→ローカル検証まで一気通貫で扱う。スクリプトは scripts/ 配下。base ブランチは実行時の現在のブランチ(事前に対象リリースブランチを checkout しておく)。
gh CLI 認証済み。対象 upstream は BCSA_UPSTREAM(既定 baserproject/basercms)。/code-review、テストはローカル Docker(basercms-unittest)が正。<owner>/basercms-<小文字GHSA>、remote=sec-<小文字GHSA(先頭ghsa-除去)>、ブランチ=security/<GHSA-ID>。scripts/list-advisories.sh [--state triage] で state別件数と一覧を取得し、triage を抽出する。
scripts/fetch-advisory.sh <GHSA-ID> で詳細を取得し、現在のブランチの実コードと突き合わせて「的確 / 不正確 / 非該当」を判定する。対象が多い場合は読み取り専用の並列サブエージェントで分担する。フレームワークのデフォルト保護(ORM バインド / slug エンコード / h() 出力)で再現しないものは非該当として却下し、具体的な PoC を要求する。
同一 sink の重複アドバイザリ、共有ファイルの hunk 分割、非該当の却下を整理する。重複の扱い(複数 fork へ同一修正 / 片方を重複クローズ)など判断が要る点はユーザーに確認する。
アドバイザリ単位で:
scripts/create-fork-branch.sh <GHSA-ID> — フォーク作成 → remote 追加 → 現ブランチ起点でブランチ作成git checkout … -- file で全取りせず hunk 単位で手適用)scripts/push-with-retry.sh <remote> security/<GHSA-ID> — フォーク反映待ちのリトライ付き pushscripts/open-pr.sh <GHSA-ID> [--title T] [--body-file F] — base=現ブランチで PR 作成scripts/build-integration.sh [統合ブランチ名] — 現ブランチ+全 security/GHSA-* をマージ(競合は停止)scripts/run-tests.sh — ローカル全テスト(詳細は basercms-unittest)<個人フォーク名>)へ push して GHA を回す(アドバイザリ fork では GHA は動かない)origin/base が進んだら各 PR ブランチへ base をマージし、push し直す。定番競合:
order() → orderBy()(CakePHP 5.2 改名)realpath() === false バイパス修正 × $fullPath 検証 の併合アドバイザリ fork の PR を GitHub 上でマージすると、base ブランチには 「Merge commit from fork」という 1 コミット(squash) として入る。security/<GHSA-ID> ブランチ自体は base の祖先にならないため、git merge-base --is-ancestor や git branch --merged では「未マージ」に見える。取り込み確認は内容差分で行う。
base=$(git merge-base security/<GHSA-ID> origin/5.4.x)
files=$(git diff --name-only $base security/<GHSA-ID>)
git diff --name-only origin/5.4.x security/<GHSA-ID> -- ${=files} # zsh。bash は $filesgit log <branch>..origin/5.4.x -- <file> で「取り込み後に別コミットで触られた」だけかを確認する。security/* は git branch -D で削除する(削除は承認を得てから。10/22 など次回リリース分・顧客向けパッチ(consolidated-5.2.x)・未取り込み分は残す)。remote rejected (failure)。終了コードでリトライ(-> 等の文字列で成功誤検知しない)。PluginsService の basename と php 実行パス検証は別アドバイザリ。hunk 単位で分けて適用。CreateReleaseCommandTest(実 composer 実行)は単体では緑。環境要因を切り分ける。permission.php の Api/Admin と Admin の auth 整合は、管理画面 SPA(ビルド済み JS まで)の依存を確認してから変更。ReleaseGuard は「ローカルタグのうち committer date が最新のもの」より大きいバージョンしか通さない(系列別の比較は無い)。5.4.0 の後に 5.3.1 を出すなら、リリース作業用クローンで git tag -d 5.4.0 してから vendor/bin/monorepo-builder release 5.3.1 を実行し、終わったら git fetch origin --tags で戻す。リモートのタグには影響しない。.gitignore に上位系列だけのプラグイン(webroot/bc_burger_editor・webroot/bc_mcp のシンボリックリンク)が無いと、そのままタグに入る。リリース前に git status --short が空であることを確認し、系列ごとの .gitignore を揃える。混入したら git rm --cached と .gitignore 追記で直す。repo.packagist.org/p2/<vendor>/<pkg>.json への反映は数分遅れる。Root composer.json requires ... does not match the constraint はこの遅れが原因なことが多い。composer show --all <pkg> で versions を確認し、数分待って再実行。キャッシュ削除はホストではなくアップデートを実行しているコンテナ内で行う。split_monorepo.yml の一覧)から gh api --method DELETE /repos/baserproject/<repo>/git/refs/tags/<ver> で消す。Packagist は再クロールで「No longer found in upstream」となり自動で消える。5.x ブランチに残ったリリースコミット(VERSION.txt 1 行目・composer.json)は X.Y.Z-dev に戻すコミットを別途入れる。| スクリプト | 引数 | 役割 |
|---|---|---|
| list-advisories.sh | [--state S] | アドバイザリ一覧・集計 |
| fetch-advisory.sh | <GHSA-ID> | 個別詳細取得(/tmp/bc-advisories へ保存) |
| create-fork-branch.sh | <GHSA-ID> | フォーク作成→remote→現ブランチ起点ブランチ |
| push-with-retry.sh | <remote> <branch> [max] | 反映待ちリトライ push |
| open-pr.sh | <GHSA-ID> [--title T] [--body-file F] | base=現ブランチで PR 作成 |
| build-integration.sh | [統合ブランチ名] | 全 PR を統合ブランチへマージ |
| run-tests.sh | [--filter X] | ローカル全テスト(basercms-unittest 連携) |
basercms-unittestcakephp-migration / php-migration / basercms-plugin-migration© baserproject, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts) in .agents/skills/basercms-security-advisory of baserproject/basercms.
Open the folder on GitHubat commit 748b4f6
Basercms Security Advisory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Basercms Security Advisory this skillbaserproject/basercms | 190 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Codebase Knowledge Graph Q&AEgonex-AI/Understand-Anything | 85k | 1 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Code Design Rationale Investigatorcursor/plugins | 10k | 9 repos | ~2.6k | Automated safety check: Pass | None | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 85k | 1 repos | ~1.4k | Automated safety check: Pass | MIT |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Egonex-AI/Understand-Anything
Answers questions about a codebase by searching a prebuilt knowledge graph of its files, functions, classes and dependencies, not by rereading every source file.
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
Egonex-AI/Understand-Anything
Gives an in-depth explanation of one file, function or module by reading the project's knowledge graph and checking that the graph is still fresh.
baserproject/basercms
baserCMS の「通常プラグイン(サードパーティ/単体配布)」を monorepo の「コアプラグイン」に昇格させる手順。「コアプラグインに変更」「コアプラグイン化」「通常プラグインをコアに昇格」「monorepo に取り込む」等のときに参照する。プラグイン名の規約変更(bc- プレフィックス付与・CamelCase→ハイフン区切り)、.git/シンボリックリンク/standalone…
baserproject/basercms
baserCMS プラグインを 5.2系 から 5.3系(PHP 8.5 / CakePHP 5.2.x ベース、開発中)へ移行する際の baserCMS 固有の破壊的変更・非推奨・テスト基盤対応のレシピ集。「プラグインを5.3に対応」「baserCMS 5.3 マイグレーション」「PluginCollection::create(): $config null given」「Plugin…
baserproject/basercms
baserCMS の plugins/baser-core/VERSION.txt に、リリース分の変更履歴(NEW/CHG/BUG)をコミットログから生成して追記する手順。「VERSION.txt を更新して」「リリースノートを作って」「変更履歴をまとめて」「今回のリリース分の変更点を書き出して」「前回リリースからの差分を VERSION.txt…
baserproject/basercms
baserCMS(CakePHP5 / PHPUnit)のユニットテストをローカル Docker 環境で実行・調査する手順。「ユニットテストを実行して」「全テストを走らせて」「このテストだけ流して」「テスト失敗を調べて」「プラグイン単体でテストを動かしたい」「プラグインにテスト環境を導入したい」等のときに参照する。コンテナ名・実行コマンド・権限自動承認のためのコマンド整形・失敗の集計と切り分け方…
baserproject/basercms
baserCMS 4系(CakePHP 2.10ベース)+ jQuery プロジェクトの開発ルール集。「baserCMS 4 で開発」「4系のプラグインを修正」「CakePHP 2系のコードを書く」「app/Plugin 配下の Controller/Model/View」「テーマの…
baserproject/basercms
baserCMS5(CakePHP5)の開発・移行を Claude Code で進めるときに、着手前に一度参照する「推奨ワークフロー環境セットアップ」スキル(提案ベース・実行は opt-in)。「5系プラグインの開発や移行をこれから始める」「どう進めるのがベストか」「設計→計画→実装の進め方/環境を整えたい」「パーミッションを整理して Auto mode…
Works with
Categories
baserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAは…. Basercms Security Advisory is an agent skill from baserproject/basercms.
Basercms Security Advisory fits situations like: development work in your project.
Run `npx skills add baserproject/basercms --skill basercms-security-advisory -a claude-code`. Or copy the skill folder (.agents/skills/basercms-security-advisory in baserproject/basercms) into .claude/skills/basercms-security-advisory in your project. Claude Code loads it when a task matches its description.
Run `npx skills add baserproject/basercms --skill basercms-security-advisory -a codex`. Or copy the skill folder (.agents/skills/basercms-security-advisory in baserproject/basercms) into .agents/skills/basercms-security-advisory in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add baserproject/basercms --skill basercms-security-advisory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/basercms-security-advisory, .gemini/skills/basercms-security-advisory, .github/skills/basercms-security-advisory and .opencode/skills/basercms-security-advisory in your project.
Going by SKILL.md and its folder, Basercms Security Advisory needs a shell for the scripts in its folder and the command-line tools its instructions call (git, composer and gh). Our summary lists: A Bash shell; Docker.
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Basercms Security Advisory is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Basercms Security Advisory: Finishing a Development Branch (obra/superpowers, 296k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Codebase Knowledge Graph Q&A (Egonex-AI/Understand-Anything, 85k stars) and Code Design Rationale Investigator (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
baserproject (a GitHub organization) maintains it in baserproject/basercms, which has 190 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.
Source: baserproject/basercms on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.