Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
A skill your agent uses when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open…
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementary --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .claude/skills/issta-supplementary && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .claude/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementaryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementary --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .agents/skills/issta-supplementary && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .agents/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementary --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .cursor/skills/issta-supplementary && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .cursor/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/brycewang-stanford/Awesome-Journal-Skills.git --path ISSTA-Skills/skills/issta-supplementary--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementary --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .gemini/skills/issta-supplementary && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .gemini/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementaryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .github/skills/issta-supplementary && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .github/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills issta-supplementary --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ISSTA-Skills/skills/issta-supplementary .opencode/skills/issta-supplementary && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "issta-supplementary" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/ISSTA-Skills/skills/issta-supplementary into .opencode/skills/issta-supplementary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "issta-supplementary", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
issta-supplementaryA skill your agent uses when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open…
Issta Supplementary is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open, splitting a testing/analysis paper between body and package, anonymity of supplementary material, and keeping decision-critical evidence inside the reviewed pages.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: Journal-specific Claude Code/Codex skill packs covering mainstream journals — AER, QJE, Nature, Cell, 管理世界, 经济研究 & 200+ more — your fast track to getting published. | 覆盖主流期刊的… The licence is MIT.
Read from SKILL.md and the folder at commit 932eb23. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Issta Supplementary loads about 1k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 444 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from brycewang-stanford/Awesome-Journal-Skills at commit 932eb23, republished under its MIT licence (© brycewang-stanford). 444 words, ~1,026 tokens.
.claude/skills/issta-supplementary/SKILL.md (or your agent's skills folder).Use this when deciding where each piece of content belongs. ISSTA's 18-page limit counts appendices against the total, so there is no unlimited appendix to absorb overflow: the body must stand on its own, and the artifact — not a separate PDF supplement — is where extra material goes. Reopen the current call to confirm whether any in-PDF appendix or separate upload is permitted this cycle.
| Content | Where it belongs | Reviewer attention |
|---|---|---|
| Technique definition, threat model | Body | Read closely — graded for soundness |
| Headline results + statistics | Body | Read closely — graded for evaluation |
| Threats to validity | Body | Expected; its absence is noticed |
| Full per-subject result tables | Artifact | Skimmed if a body claim is contested |
| Raw fuzzing/analysis logs | Artifact | Rarely opened; ship for completeness |
| The runnable tool | Artifact (evaluated separately) | Run by artifact evaluators, not always by PC |
Assume a PC reviewer reads the 18 pages and dips into the artifact only to resolve a doubt. Design the body so no such dip is required to accept the paper.
A submission presenting a new taint-analysis with a soundness argument and a large evaluation: the body keeps the analysis rules, the soundness sketch, the evaluation protocol, and the two decision-critical result tables (precision/recall against ground truth, and a comparison to one established baseline); the artifact holds the full implementation, the complete per-benchmark tables, alternative sensitivity configurations, and the scripts that regenerate every table. Nothing needed to accept the paper lives only in the artifact, because artifact inspection by the PC is discretionary.
Body (<= 18 pp) Artifact
- analysis rules - full analyzer implementation
- soundness sketch - complete per-benchmark tables
- evaluation protocol - extra sensitivity configs
- 2 headline tables - table-regeneration scripts + raw logs
- threats to validity - pinned subjects (SHAs)[Split status] Ready / Needs fixes / Not ready
[Body carries] <decision-critical items present in the 18 pages>
[Artifact carries] <supporting material>
[Page-budget risk] <appendix competing with the body?>
[Anonymity checks] passed / issues
[Main-paper dependency] <what breaks if the artifact is never opened>© brycewang-stanford, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ISSTA-Skills/skills/issta-supplementary of brycewang-stanford/Awesome-Journal-Skills.
Open the folder on GitHubat commit 932eb23
Issta Supplementary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Issta Supplementary this skillbrycewang-stanford/Awesome-Journal-Skills | 1.2k | — | ~1k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when running and reporting the analysis for an Annals of the American Association of Geographers manuscript — spatial statistics and modeling, remote-sensing accuracy, or…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when positioning an Annals of the American Association of Geographers manuscript in the literature — engaging geographic scholarship across the relevant area and the…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when responding to an Annals of the American Association of Geographers decision letter (major/minor revision) — building a point-by-point response to the subject editor and…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when defending the research design of an Annals of the American Association of Geographers manuscript — spatial/quantitative analysis and GIScience, remote-sensing and…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when you need to understand how the Annals of the American Association of Geographers evaluates a manuscript — double-anonymous review routed through a subject editor by…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when running the final pre-submission preflight for the Annals of the American Association of Geographers via ScholarOne Manuscripts — area/article-type selection…
Categories
A skill your agent uses when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open…. Issta Supplementary is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open, splitting a testing/analysis paper between body and package, anonymity of supplementary material, and keeping decision-critical evidence inside the reviewed pages.
Issta Supplementary fits situations like: deciding what lives in the ISSTA 18-page body versus the artifact and any appendix; covering the no-unlimited-appendix reality; what reviewers will and will not open; splitting a testing/analysis paper between body and package.
Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a claude-code`. Or copy the skill folder (ISSTA-Skills/skills/issta-supplementary in brycewang-stanford/Awesome-Journal-Skills) into .claude/skills/issta-supplementary in your project. Claude Code loads it when a task matches its description.
Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a codex`. Or copy the skill folder (ISSTA-Skills/skills/issta-supplementary in brycewang-stanford/Awesome-Journal-Skills) into .agents/skills/issta-supplementary in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill issta-supplementary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/issta-supplementary, .gemini/skills/issta-supplementary, .github/skills/issta-supplementary and .opencode/skills/issta-supplementary in your project.
SKILL.md names no scripts, command-line tools or credentials: Issta Supplementary is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Issta Supplementary is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Issta Supplementary: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
brycewang-stanford (a GitHub user) maintains it in brycewang-stanford/Awesome-Journal-Skills, which has 1,231 GitHub stars. The repository holds 2,387 skills in this directory. The repository was last updated on September 27, 2026.
Source: brycewang-stanford/Awesome-Journal-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.