Agent skill

Calimero Security Fix

by calimero-network in calimero-network/core

Fixes a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing test first, add the limit or gate in the shared function every caller goes through…

Custom licenceAuto-check passedTesting & QA

Install Calimero Security Fix

skills CLI
$ npx skills add calimero-network/core --skill calimero-security-fix -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install calimero-network/core calimero-security-fix --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/calimero-network/core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/calimero-security-fix .claude/skills/calimero-security-fix && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
calimero-security-fix
GitHub stars
171
Token cost
~614 tokens
SKILL.md length
338 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Custom licence

At a glance

Fixes a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing test first, add the limit or gate in the shared function every caller goes through…

  • Works in 9 steps: Reproduce through the real entry point,… → Commit the test first and watch it fail… → Add the limit constant for any unbounded… → …
  • Asked to fix a vulnerability
  • SKILL.md covers Steps and Mistakes to avoid
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Calimero Security Fix is an agent skill from calimero-network/core. Fixes a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing test first, add the limit or gate in the shared function every caller goes through, review for bypasses, and open a neutral PR. Use when asked to fix a vulnerability, an audit finding, a DoS or an authorization gap in core.

Its SKILL.md is about 610 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test-driven development and Audit readiness. The repository describes itself as: Calimero - Peer-to-peer application platform with local-first governance, CRDT state sync, and WASM execution.

When your agent uses it

  • Asked to fix a vulnerability
  • An audit finding
  • An authorization gap in core

Example prompts

  • “Use the calimero-security-fix skill to fix a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing…”
  • “/calimero-security-fix”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Reproduce through the real entry point, the way an attacker would: a gossip message, a sync stream, an HTTP request or a guest call, not a…
  2. Commit the test first and watch it fail on master for the stated reason, not for a setup error.
  3. Add the limit constant for any unbounded input, named and declared with the other constants of its file.
  4. Fix in the shared function that every caller goes through.
  5. Run two review rounds with fresh agents, each looking for bypasses, regressions for honest users (a member who left and rejoined, a…
  6. Rebase onto current master and rerun the gates right before opening: ./scripts/check-like-ci.py, which includes the feature-gated test…
  7. Use a neutral title and body: say what the code now does, not how to exploit what it did, and answer the template's Trust boundary block.
  8. Check open PRs for the same files and for a schema version number someone else has already claimed.
  9. Pair SDK changes with the matching mero-js PR, named in the body as sdk-ref: .

What it can do on your machine

Read from SKILL.md and the folder at commit 64f9209. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Calimero Security Fix loads about 614 tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 338 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~614

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 338 words (~614 tokens).

“The rules a fix must satisfy are in CODING_STANDARDS.md ("Security: trust boundaries"). This skill is the workflow; it does not repeat them.”

— opening of SKILL.md by calimero-network, Custom licence
name
calimero-security-fix

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .cursor/skills/calimero-security-fix of calimero-network/core.

Open the folder on GitHubat commit 64f9209

Compare with similar skills

Calimero Security Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Calimero Security Fix compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Calimero Security Fix this skillcalimero-network/core171—~614Automated safety check: PassCustom licence
TDDpietheinstrengholt/rssmonster56430 repos~906Automated safety check: PassMIT
TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph11211 repos~2.4kAutomated safety check: PassNone
TDDsanity-io/sanity6.4k20 repos~1kAutomated safety check: PassMIT
Test Driven Developmentfarm-fe/farm5.6k51 repos~2.5kAutomated safety check: PassMIT
Tapd Story PipelineTencentBlueKing/bk-bcs840—~2.6kAutomated safety check: PassCustom licence

Similar skills

  • TDD

    pietheinstrengholt/rssmonster

    Test-driven development. An agent skill from pietheinstrengholt/rssmonster.

    564 GitHub starsUsed in 30 repos~906 tokens
    Testing & QAAuto-check passed
  • TDD Workflow

    hellangleZ/burn-in-cceverywhere-ralph

    A skill your agent uses when writing new features, fixing bugs, or refactoring code.

    112 GitHub starsUsed in 11 repos~2.4k tokens
    Testing & QAAuto-check passed
  • TDD

    sanity-io/sanity

    Official

    Test-driven development with red-green-refactor loop. An agent skill from sanity-io/sanity.

    6.4k GitHub starsUsed in 20 repos~1k tokens
    Testing & QAAuto-check passed
  • A skill your agent uses when implementing any feature or bugfix, before writing implementation code

    5.6k GitHub starsUsed in 51 repos~2.5k tokens
    Testing & QAAuto-check passed
  • Tapd Story Pipeline

    TencentBlueKing/bk-bcs

    单需求实现流水线——把一个 TAPD 需求从零推进到代码提交。自动串联技术澄清、 开发计划、任务拆分、TDD 实现、架构/安全校验、代码提交六个阶段。

    840 GitHub stars~2.6k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Absolute Init

    maddhruv/absolute

    One-time setup for absolute: interview how you want it to behave (output style, autonomy, TDD strictness, spec dir, families) + detect the stack once, then write .absolute.config.json (project…

    219 GitHub starsUsed in 1 repo~3k tokens
    Testing & QAAuto-check passed

More from calimero-network/core

  • Core PR Helper

    calimero-network/core

    Suggests one appropriate branch name and a PR description in the project template (title, Description, Test plan, Documentation update) for Calimero core.

    171 GitHub stars~614 tokensUpdated yesterday
    Auto-check passed
  • Dead Code Cleanup

    calimero-network/core

    Detects and removes dead code introduced by AI agents. An agent skill from calimero-network/core.

    171 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Unreachable Subsystems

    calimero-network/core

    Finds code that compiles, lints clean and is referenced, but that nothing can actually reach — dead islands whose items reference each other while the outermost edge points at a route, command, or…

    171 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Questions about Calimero Security Fix

What does Calimero Security Fix do?

Fixes a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing test first, add the limit or gate in the shared function every caller goes through…. Calimero Security Fix is an agent skill from calimero-network/core. Fixes a security finding in calimero-network/core - reproduce it through the real entry point, commit a failing test first, add the limit or gate in the shared function every caller goes through, review for bypasses, and open a neutral PR.

When should I use Calimero Security Fix?

Calimero Security Fix fits situations like: asked to fix a vulnerability; an audit finding; an authorization gap in core.

How do I install Calimero Security Fix in Claude Code?

Run `npx skills add calimero-network/core --skill calimero-security-fix -a claude-code`. Or copy the skill folder (.cursor/skills/calimero-security-fix in calimero-network/core) into .claude/skills/calimero-security-fix in your project. Claude Code loads it when a task matches its description.

How do I install Calimero Security Fix in Codex?

Run `npx skills add calimero-network/core --skill calimero-security-fix -a codex`. Or copy the skill folder (.cursor/skills/calimero-security-fix in calimero-network/core) into .agents/skills/calimero-security-fix in your project. Codex loads it when a task matches its description.

Can I use Calimero Security Fix in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add calimero-network/core --skill calimero-security-fix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/calimero-security-fix, .gemini/skills/calimero-security-fix, .github/skills/calimero-security-fix and .opencode/skills/calimero-security-fix in your project.

What does Calimero Security Fix need to run?

SKILL.md names no scripts, command-line tools or credentials: Calimero Security Fix is instructions for the agent only.

Does Calimero Security Fix access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Calimero Security Fix safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Calimero Security Fix use?

Calimero Security Fix has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Calimero Security Fix use?

About 614 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Calimero Security Fix?

Skills that share tags, products or a category with Calimero Security Fix: TDD (pietheinstrengholt/rssmonster, 564 stars), TDD Workflow (hellangleZ/burn-in-cceverywhere-ralph, 112 stars), TDD (sanity-io/sanity, 6.4k stars) and Test Driven Development (farm-fe/farm, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Calimero Security Fix?

calimero-network (a GitHub organization) maintains it in calimero-network/core, which has 171 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: calimero-network/core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.