Agent skill

Vuln Check

by ccch1mneyyy in ccch1mneyyy/dsh-TUI

Check resolved dependencies and relevant code paths for security vulnerabilities.

MITAuto-check passedDevelopment

Install Vuln Check

skills CLI
$ npx skills add ccch1mneyyy/dsh-TUI --skill vuln-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccch1mneyyy/dsh-TUI vuln-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccch1mneyyy/dsh-TUI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vuln-check .claude/skills/vuln-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vuln-check
GitHub stars
4.3k
Token cost
~467 tokens
SKILL.md length
233 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Check resolved dependencies and relevant code paths for security vulnerabilities.

  • Works in 4 steps: Read package.json and pnpm-lock.yaml for… → Trace untrusted inputs through guards to… → Report findings by severity with… → …
  • Security checks
  • Calls pnpm
  • Use audit for a broader correctness and maintainability assessment

What it does

Vuln Check is an agent skill from ccch1mneyyy/dsh-TUI. Check resolved dependencies and relevant code paths for security vulnerabilities. Use for security checks or /vuln-check; use audit for a broader correctness and maintainability assessment.

Its SKILL.md is about 470 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with DeepSeek. The repository describes itself as: DSH's officially top-recommended TUI plugin — high performance, low overhead, cute pixel whale, smooth mouse interaction. One-command install via npm. / DSH 官方首推的 TUI…. The licence is MIT.

When your agent uses it

  • Security checks
  • Use audit for a broader correctness and maintainability assessment

Example prompts

  • “/vuln-check”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read package.json and pnpm-lock.yaml for the affected dependency paths. Use current advisory data, such as pnpm audit, and record the…
  2. Trace untrusted inputs through guards to sensitive operations: shell execution, filesystem access, plugin capabilities, and terminal…
  3. Report findings by severity with location, trigger, impact, evidence, and the smallest effective remedy. Separate confirmed issues from…
  4. State the scope, sources checked, and gaps. If advisories are unavailable, report that the dependency check is incomplete; absence of…

What it can do on your machine

Read from SKILL.md and the folder at commit 7090991. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vuln Check loads about 467 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 233 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~467

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccch1mneyyy/dsh-TUI at commit 7090991, republished under its MIT licence (© ccch1mneyyy). 233 words, ~467 tokens.

Download SKILL.mdSave it as .claude/skills/vuln-check/SKILL.md (or your agent's skills folder).
name
vuln-check
description
Check resolved dependencies and relevant code paths for security vulnerabilities. Use for security checks or /vuln-check; use audit for a broader correctness and maintainability assessment.

Assess the requested security surface with evidence. A check returns findings; implement remediation when the user has requested it.

  1. Read package.json and pnpm-lock.yaml for the affected dependency paths. Use current advisory data, such as pnpm audit, and record the resolved version, advisory, affected range, and verified fixed version where available. Distinguish a dependency advisory match from a demonstrated exploit path in this project.
  2. Trace untrusted inputs through guards to sensitive operations: shell execution, filesystem access, plugin capabilities, and terminal escape output. For paths, check containment and symlink behavior where relevant; normalization alone does not prevent traversal. Inspect actual validation and authorization before treating a suspicious API as a vulnerability. Scan committed repository files for potential secrets; report only the path, line, and secret type, never the value or a source excerpt.
  3. Report findings by severity with location, trigger, impact, evidence, and the smallest effective remedy. Separate confirmed issues from leads needing verification. Preserve the upstream peer/dev dependency contract when proposing upgrades.
  4. State the scope, sources checked, and gaps. If advisories are unavailable, report that the dependency check is incomplete; absence of findings is not a claim that the project is vulnerability-free.

Report potential secrets only by path, line, and type, never their value or a source excerpt. Do not run automatic dependency fixes as part of a check; for requested remediation, make targeted changes and validate the affected paths.

© ccch1mneyyy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/vuln-check of ccch1mneyyy/dsh-TUI.

Open the folder on GitHubat commit 7090991

Compare with similar skills

Vuln Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vuln Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vuln Check this skillccch1mneyyy/dsh-TUI4.3k—~467Automated safety check: PassMIT
Roo Conflict Resolutionzgsm-ai/costrict4.5k—~2.3kAutomated safety check: PassApache-2.0
Deepseek Automationzhu1090093659/deepseek-pp1.9k—~2.1kAutomated safety check: NotesApache-2.0
Deep Reviewdyad-sh/dyad22k—~1.4kAutomated safety check: PassCustom licence
Readable Verilog GeneratorEriemon/verilog-generator313—~5.4kAutomated safety check: PassApache-2.0
Dsh Upgrade AuditNanmiCoder/dsh-auto-mode1641 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Roo Conflict Resolution

    zgsm-ai/costrict

    Provides comprehensive guidelines for resolving merge conflicts intelligently using git history and commit context.

    4.5k GitHub stars~2.3k tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Deepseek Automation

    zhu1090093659/deepseek-pp

    A skill your agent uses when implementing, resuming, reviewing, or verifying the DeepSeek++ Codex-style automation feature in this repository.

    1.9k GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Deep Review

    dyad-sh/dyad

    Deep multi-agent code review run locally — a fleet of parallel finder agents reviews the diff from independent angles, then adversarial verifier agents reproduce each finding before it is reported.

    22k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Readable Verilog Generator

    Eriemon/verilog-generator

    A skill your agent uses when creating, writing, reviewing, annotating, repairing, refactoring, or validating readable Verilog RTL, including synthesizable Verilog-2001 .v files, existing-RTL…

    313 GitHub stars~5.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Dsh Upgrade Audit

    NanmiCoder/dsh-auto-mode

    Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

    164 GitHub starsUsed in 1 repo~2.5k tokens
    DevelopmentAuto-check passed
  • Skillhone

    Tencent/SkillHone

    Local Issue, pull-request, and Wiki workbench for agent skills.

    169 GitHub stars~3.4k tokensUpdated 21 days ago
    DevelopmentAuto-check passed

More from ccch1mneyyy/dsh-TUI

All 9 skills in this repo
  • Review

    ccch1mneyyy/dsh-TUI

    Review or de-slop concrete changes in ccch1mneyyy/dsh-TUI at maintainer level: PR numbers or URLs, branches, commit ranges, patch files, staged or unstaged worktrees, and scoped repository-hygiene…

    4.3k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Dsh Tui Guide

    ccch1mneyyy/dsh-TUI

    A skill your agent uses when the user asks about dsh-tui itself (usage, shortcuts, config, themes, migration, VS Code).

    4.3k GitHub stars~323 tokensUpdated today
    Auto-check passed
  • PR

    ccch1mneyyy/dsh-TUI

    Open or update a pull request in this repository, including writing or rewriting its description.

    4.3k GitHub stars~601 tokensUpdated today
    Auto-check passed
  • Audit

    ccch1mneyyy/dsh-TUI

    Audit the repository or a broad subsystem for security, correctness, and maintainability risks.

    4.3k GitHub stars~405 tokensUpdated today
    Auto-check passed
  • Bug

    ccch1mneyyy/dsh-TUI

    Turn a reported defect into an actionable bug report or issue draft.

    4.3k GitHub stars~342 tokensUpdated today
    Auto-check passed
  • PR Comments

    ccch1mneyyy/dsh-TUI

    Read and triage existing pull request review comments, or address them when requested.

    4.3k GitHub stars~353 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Vuln Check

What does Vuln Check do?

Check resolved dependencies and relevant code paths for security vulnerabilities. Vuln Check is an agent skill from ccch1mneyyy/dsh-TUI. Check resolved dependencies and relevant code paths for security vulnerabilities.

When should I use Vuln Check?

Vuln Check fits situations like: security checks; use audit for a broader correctness and maintainability assessment.

How do I install Vuln Check in Claude Code?

Run `npx skills add ccch1mneyyy/dsh-TUI --skill vuln-check -a claude-code`. Or copy the skill folder (.agents/skills/vuln-check in ccch1mneyyy/dsh-TUI) into .claude/skills/vuln-check in your project. Claude Code loads it when a task matches its description.

How do I install Vuln Check in Codex?

Run `npx skills add ccch1mneyyy/dsh-TUI --skill vuln-check -a codex`. Or copy the skill folder (.agents/skills/vuln-check in ccch1mneyyy/dsh-TUI) into .agents/skills/vuln-check in your project. Codex loads it when a task matches its description.

Can I use Vuln Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccch1mneyyy/dsh-TUI --skill vuln-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln-check, .gemini/skills/vuln-check, .github/skills/vuln-check and .opencode/skills/vuln-check in your project.

What does Vuln Check need to run?

Going by SKILL.md and its folder, Vuln Check needs the command-line tools its instructions call (pnpm).

Does Vuln Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vuln Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vuln Check use?

Vuln Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vuln Check use?

About 467 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vuln Check?

Skills that share tags, products or a category with Vuln Check: Roo Conflict Resolution (zgsm-ai/costrict, 4.5k stars), Deepseek Automation (zhu1090093659/deepseek-pp, 1.9k stars), Deep Review (dyad-sh/dyad, 22k stars) and Readable Verilog Generator (Eriemon/verilog-generator, 313 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vuln Check?

ccch1mneyyy (a GitHub user) maintains it in ccch1mneyyy/dsh-TUI, which has 4,278 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 11, 2026.

Source: ccch1mneyyy/dsh-TUI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.