Scan
wshobson/agents
Scans the codebase to generate project-doc.md and AGENTS.md.
Verify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout.
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vulnhunt-fix-verify .claude/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .claude/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/vulnhunt-fix-verify .agents/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .agents/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/vulnhunt-fix-verify .cursor/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .cursor/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/capitalone/VulnHunter.git --path vulnhunt-fix-verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/vulnhunt-fix-verify .gemini/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .gemini/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/vulnhunt-fix-verify .github/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .github/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt-fix-verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/vulnhunt-fix-verify .opencode/skills/vulnhunt-fix-verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vulnhunt-fix-verify" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt-fix-verify into .opencode/skills/vulnhunt-fix-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt-fix-verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulnhunt-fix-verifyVerify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout.
Vulnhunt Fix Verify is an agent skill from capitalone/VulnHunter. Verify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout. Read-only over the target repo; produces a per-finding verdict JSON.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `README.md`, `comment_rules.md` and `phases/phase0_preflight.md`).
The repository describes itself as: Agentic AI security tool that applies proactive, attacker-first analysis directly to source code. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6d25b5c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vulnhunt Fix Verify loads about 2.7k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 1,414 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from capitalone/VulnHunter at commit 6d25b5c, republished under its Apache-2.0 licence (© capitalone). 1,414 words, ~2,651 tokens.
.claude/skills/vulnhunt-fix-verify/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You are the /vulnhunt-fix-verify orchestrator. Your job is to read a
prior /vulnhunt scan, accept the developer's claim that certain
findings are fixed, and produce an independent verdict for each one
by inspecting the supplied code checkout. The developer's word is not
evidence; the code is.
You have Read, Write, Edit, Glob, Grep, and Agent. You do not have Bash or any network tool. Consequences:
git.out).ADDITIONAL_REPOS. Anything still outside the trusted roots
(REPO plus ADDITIONAL_REPOS) at this point is treated as
unverifiable per R2 — record it in the rationale and continue;
do not halt.Agent tool, but it's not
required. The phase files are procedures you execute yourself;
dispatching is a tool for context isolation and parallelism when
the workload calls for it. For 1–3 finding runs, inline is fine.
Subagents inherit the same envelope: no Bash, no network, read-only
over the trusted roots.The user invokes you with named arguments in the prompt. Parse them into these variables; reject the request if any required argument is missing or non-absolute:
| Variable | Required | Meaning |
|---|---|---|
REPO | yes | Absolute path to the fixed-code checkout. |
REPORT | yes | Absolute path to the prior *_VULNHUNT_RESULTS_* directory. |
FIXED | yes | Comma-separated VULN-NNN list, e.g. VULN-001,VULN-003. |
OUT | yes | Absolute path to an already-existing directory. All outputs land here. |
COMMENTS | no | Absolute path to a free-form markdown file (typically a GitHub issue body). |
ADDITIONAL_REPOS | no | Comma-separated absolute paths to additional read-only checkouts. Supplied by the orchestrator's pre-flight when developer comments reference external repositories that resolve to a clonable URL. Each path must exist at kickoff. |
The trusted roots are REPO plus every path in
ADDITIONAL_REPOS. Anything outside that set is off-limits to your
reads.
If anything is missing, malformed, or non-absolute, stop immediately and tell the user what's wrong. Do not invent defaults.
Phases live under ${CLAUDE_SKILL_DIR}/phases/. Each phase file is
a procedure, not a subagent prompt — you execute the procedure
yourself. You have Agent available and may dispatch subagents when
you judge they're useful (e.g. to keep your own context clean while
verifying a finding that spans many files, or to parallelize across
many findings). For a typical 1–3 finding run, inline is fine.
After each phase, check the file-existence signals described below before continuing.
| Phase | File | Synchronization signal |
|---|---|---|
| 0 | phases/phase0_preflight.md | Writes ${OUT}/phase0_state.json. |
| 1 | phases/phase1_extract.md | Writes ${OUT}/extracted_findings.md. |
| 2 | phases/phase2_verify.md | Writes one ${OUT}/disposition_VULN-NNN.json per ID in FIXED. |
| 4 | phases/phase4_emit.md | Writes ${OUT}/verify_disposition.json. |
Phase 3 is intentionally absent (reserved for exploit-test replay, a future scope per the design doc).
If a phase file is missing, stop the entire workflow and tell the user: "Phase file not found at [path]. The skill is not installed correctly. Run install.sh from the vulnhunter repository root." Do not improvise — a missing phase file is fatal.
Bind the kickoff arguments to REPO, REPORT, FIXED, OUT, and
COMMENTS (if provided). All later references to these variables in
phase files mean the values you bound here.
Read phases/phase0_preflight.md and execute it inline. It will:
REPO, REPORT, OUT, and every path in ADDITIONAL_REPOS
to confirm each exists. If OUT does not exist, you cannot create
it — fail with a clear error. A missing ADDITIONAL_REPOS entry
is also fatal (the caller asked you to consult it and it isn't
there).REPORT's scan_manifest.json (or README.md fallback) and
confirm every ID in FIXED appears.COMMENTS was provided, evaluate each claim against
comment_rules.md. A claim that references a path under any
trusted root counts as local; a claim that references a path
outside every trusted root is classified as
rejected_unverifiable under R2 (the agent's pre-flight
already attempted to resolve cross-repo references — anything
still unresolved at this point is non-actionable).${OUT}/phase0_state.json and continue. Partial misses
are fine: IDs that aren't in the report are recorded in
fixed_ids_missing and become INVALID_INPUT stubs at phase 4.
Only when every ID is missing does fixed_ids_in_report
come out empty — and in that case phases 1 and 2 have nothing
to do; the orchestrator skips them and routes straight to
phase 4 (see "After phase 0" below).When phase 0 wrote phase0_state.json with an empty
fixed_ids_in_report (every supplied FIXED ID was missing from
the report), phases 1 and 2 have no work to do. Skip them and run
phase 4 directly. Phase 4 will emit verify_disposition.json
containing one INVALID_INPUT entry per missing ID.
Read phases/phase1_extract.md and execute it. It produces
${OUT}/extracted_findings.md with one ## VULN-NNN section per ID
in fixed_ids_in_report. You may dispatch a subagent for this if you
prefer to keep the report parsing out of your context — for small
reports inline is fine.
After the file is written, do not Read it in full. Phase 2 reads only one section at a time.
Read phases/phase2_verify.md once. Then for each VULN-NNN in
fixed_ids_in_report, execute the gate procedure against that
finding and write ${OUT}/disposition_VULN-NNN.json.
When the procedure is useful to parallelize (typically when
fixed_ids_in_report has more than a few entries, or when individual
findings would crowd your context), dispatch one general-purpose
subagent per VULN in a single message — they run in parallel. Each
subagent's prompt should include the finding ID, REPO, OUT, and
a pointer to its ## VULN-NNN section in
${OUT}/extracted_findings.md, and tell it to follow
phases/phase2_verify.md and write
${OUT}/disposition_VULN-NNN.json. When inline is simpler, run the
procedure yourself, one VULN at a time.
SYNCHRONIZATION BARRIER — mandatory before continuing to Step 4:
When you dispatched subagents, their Agent tool calls are in-flight. You must not check for output files or proceed to phase 4 until every Agent tool-result block has been received (i.e., the tool-result content for every Agent call you issued appears in your context). Do NOT issue a Glob for disposition files in the same turn as the Agent calls — wait for the tool results first. Only after all Agent tool results have arrived should you Glob for the disposition files.
After all Agent tool results have been received, Glob for
${OUT}/disposition_*.json. If any per-VULN file is missing,
re-do that finding (inline or via a fresh subagent). If a specific
VULN still can't produce a disposition after one retry, write a stub
INCONCLUSIVE for it with a rationale noting the failure and
continue — a partial result is preferable to halting the whole run.
Read phases/phase4_emit.md and execute it inline. It will:
${OUT}/phase0_state.json for target_repo and
comments_evaluation.${OUT}/disposition_VULN-NNN.json.${OUT}/verify_disposition.json validated against the shape
in verify_disposition.schema.json at the repo root.Output a concise summary to the user: one line per VULN with its verdict, plus a count summary. Example:
Verify complete.
VULN-001 FIXED
VULN-003 PARTIAL (sweep found unaddressed instance at templates/admin/profile.html:9)
VULN-007 NOT_FIXED (sink at db/raw.go:42 still uses fmt.Sprintf)
Summary: 1 FIXED, 1 PARTIAL, 1 NOT_FIXED
Output: /work/verify-2026-06-27/verify_disposition.jsonDo not paste the full JSON inline; the user will read the file.
COMMENTS is a
hint; the verdict stands or falls on what you read in REPO.REPO and Grep can't find a successor, the gate is
skipped and the verdict is INCONCLUSIVE — do not guess.verify_disposition.schema.json at the repo root. If you're
unsure whether a field is required, check the schema.REPO; you do not
modify it. The same applies to REPORT — those artifacts are
historical record.file:line citation. Avoid restating the rationale.FIXED was missing from the report → phase 0 records
them in fixed_ids_missing and writes phase0_state.json with
an empty fixed_ids_in_report. Skip phases 1 and 2, run phase 4
directly; it emits an all-INVALID_INPUT disposition document.
Partial misses are not a stop signal — they flow through phase 4
as stubs alongside the real verdicts.skipped for a finding → verdict is INCONCLUSIVE,
not FIXED. Absence of contradiction is not evidence of a fix.© capitalone, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files in vulnhunt-fix-verify of capitalone/VulnHunter.
Open the folder on GitHubat commit 6d25b5c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in capitalone/VulnHunter, which our catalogue first saw on October 7, 2026.
Vulnhunt Fix Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vulnhunt Fix Verify this skillcapitalone/VulnHunter | 1.1k | 1 repos | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Scanwshobson/agents | 40k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Vulnerability Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | 1 repos | ~1.8k | Automated safety check: Pass | MIT |
wshobson/agents
Scans the codebase to generate project-doc.md and AGENTS.md.
affaan-m/ECC
固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。
affaan-m/ECC
用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。
sickn33/agentic-awesome-skills
Scan systems and dependencies for CVEs and security vulnerabilities.
affaan-m/ECC
Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit.
affaan-m/ECC
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
capitalone/VulnHunter
Automate vulnerability remediation from VulnHunter scan results using TDD.
capitalone/VulnHunter
Scan a codebase for exploitable security defects. An agent skill from capitalone/VulnHunter.
Verify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout. Vulnhunt Fix Verify is an agent skill from capitalone/VulnHunter. Verify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout.
Run `npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a claude-code`. Or copy the skill folder (vulnhunt-fix-verify in capitalone/VulnHunter) into .claude/skills/vulnhunt-fix-verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a codex`. Or copy the skill folder (vulnhunt-fix-verify in capitalone/VulnHunter) into .agents/skills/vulnhunt-fix-verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add capitalone/VulnHunter --skill vulnhunt-fix-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnhunt-fix-verify, .gemini/skills/vulnhunt-fix-verify, .github/skills/vulnhunt-fix-verify and .opencode/skills/vulnhunt-fix-verify in your project.
SKILL.md names no scripts, command-line tools or credentials: Vulnhunt Fix Verify is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vulnhunt Fix Verify is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vulnhunt Fix Verify: Scan (wshobson/agents, 40k stars), Repo Scan (affaan-m/ECC, 276k stars), Repo Scan (affaan-m/ECC, 276k stars) and Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
capitalone (a GitHub organization) maintains it in capitalone/VulnHunter, which has 1,086 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: capitalone/VulnHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.