Evolving The Data Model
TriliumNext/Trilium
A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…
IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install classmethod/tsumiki ipa-security-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ipa-security-check .claude/skills/ipa-security-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .claude/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install classmethod/tsumiki ipa-security-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ipa-security-check .agents/skills/ipa-security-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .agents/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install classmethod/tsumiki ipa-security-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ipa-security-check .cursor/skills/ipa-security-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .cursor/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/classmethod/tsumiki.git --path skills/ipa-security-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install classmethod/tsumiki ipa-security-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ipa-security-check .gemini/skills/ipa-security-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .gemini/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install classmethod/tsumiki ipa-security-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ipa-security-check .github/skills/ipa-security-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .github/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install classmethod/tsumiki ipa-security-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ipa-security-check .opencode/skills/ipa-security-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ipa-security-check" agent skill from https://github.com/classmethod/tsumiki/tree/main/skills/ipa-security-check into .opencode/skills/ipa-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ipa-security-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ipa-security-checkIPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。
Ipa Security Check is an agent skill from classmethod/tsumiki. IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 61 other files, including scripts (for example `agents/01-sql-injection.md`, `agents/02-os-command-injection.md` and `agents/03-directory-traversal.md`).
It sits in Databases, covering SQL. It works with SQL. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fa5aaff. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
ipa.go.jpFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ipa Security Check loads about 1.8k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 442 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from classmethod/tsumiki at commit fa5aaff, republished under its MIT licence (© classmethod). 442 words, ~1,781 tokens.
.claude/skills/ipa-security-check/SKILL.md (or your agent's skills folder). This skill also uses 58 other files; get the full folder from GitHub.IPA (情報処理推進機構) が公開する以下 5 資料の指摘事項に基づき、ローカルリポジトリのソースコード・設定ファイルを静的検査し、脆弱性候補を検出する。
| 略称 | 正式名称 | 主な検査内容 |
|---|---|---|
| SWS | 安全なウェブサイトの作り方 改訂第7版 | 11脆弱性 (SQLi/OSコマンド/トラバーサル/セッション/XSS/CSRF/HTTPヘッダ/メールヘッダ/クリックジャッキング/BoF/アクセス制御) |
| SQL | 安全なSQLの呼び出し方 | プレースホルダ使い分け・LIKE述語・識別子検証・文字コード問題 |
| WHC | ウェブ健康診断仕様 | 13診断項目のうち静的解析でカバー可能な観点 |
| OPS | 安全なウェブサイトの運用管理に向けての20ヶ条 | HTTPヘッダ・依存ライブラリ・設定ファイル類 |
| CL | セキュリティ実装チェックリスト | 改訂第7版 p.105-108 のチェックリスト |
すべての検出結果に IPA 原典の document / section / page / url を必ず添えて返す。
スラッシュコマンド /ipa-security-check で起動する。引数で対象スコープを指定する。
| 形式 | 動作 |
|---|---|
/ipa-security-check | カレント WD 全体をスキャン |
/ipa-security-check <path> | 指定パス/glob のみ (例: src/, **/*.php) |
/ipa-security-check --diff | 現ブランチと main の差分ファイルのみ |
/ipa-security-check --categories sqli,xss <path> | カテゴリ限定 |
/ipa-security-check --severity high | High 以上のみ |
/ipa-security-check --output report.md,report.sarif | 出力ファイル指定 |
自然文 (「IPA のセキュリティチェックをして」など) でも起動する。
lib/scope_resolver.md を読み、引数を解釈して対象ファイル一覧と言語マッピングを作るlib/shard_planner.md を読み、カテゴリごとにファイル数を数え、閾値超過時は N 分割するagents/ 配下 の検査系サブエージェント (14 体) を メインから並列起動 する (公式制約によりサブエージェントから二次サブエージェントは起動できないため、分割はメイン側で行う)findings[] を含む JSON を返す。メインは findings のみ集約してコード本文は文脈に保持せず、.tmp/ipa-security-check/findings_raw.json に書き出すscripts/snippet_hash.py を Bash で実行して findings_with_hash.json を作る15-false-positive-review エージェントを 5 件 / shard で並列起動し、返ってきた verdicts[] を結合して verdicts.json に保存scripts/render_report.py を Bash で実行する。スクリプトが内部で以下を行う:snippet_hash で findings にマージlib/triage_state.md 準拠) し、snippet_hash 一致で新 findings にステータス引き継ぎtemplates/report.md.tmpl を埋めて Markdown を出力、SARIF 2.1.0 も同時生成./security-reports/ipa-security-report-YYYY-MM-DD-NN.md と ./security-reports/ipa-security-report-YYYY-MM-DD-NN.sarif (--output で上書き可)。security-reports/ ディレクトリが存在しない場合は自動作成する。同日に複数回実行した場合は連番 (-01, -02, ...) が自動付与され、既存レポートを上書きしない中間ファイルの作業ディレクトリは .tmp/ipa-security-check/ (リポジトリルート直下、名前に tmp を含めること)。
詳細な分配ロジックは lib/orchestrator.md に従う。Claude は lib/orchestrator.md を読んでそのとおりに動くこと。
| 言語 | 拡張子 |
|---|---|
| PHP | .php |
| Java | .java, .jsp |
| Ruby | .rb, .erb |
| Python | .py |
| JavaScript / TypeScript | .js, .jsx, .ts, .tsx, .vue |
| C# / .NET | .cs, .cshtml, .aspx |
| Go | .go |
| 設定ファイル | .conf, nginx.conf, .htaccess, web.xml, *.yaml, *.yml, Dockerfile |
検出結果には 4 ステータスを管理できる。状態は Markdown レポート内の HTML コメントブロックに保持され、次回スキャン時に snippet_hash で引き継がれる。詳細は lib/triage_state.md。
| ステータス | 意味 | 次回スキャンでの扱い |
|---|---|---|
未対応 | 未着手 (新規 finding のデフォルト) | 通常表示 |
対応する | 修正予定 / 実施中 | 通常表示 |
問題なし | 確認の上、本物の脆弱性ではない | ## トリアージ済み (抑止) セクションへ移動。サマリから除外 |
保留 | 一旦保留 | ## トリアージ済み (抑止) セクションへ移動。サマリから除外 |
ユーザーは各 finding 直下の <!-- ipa-triage:begin ... ipa-triage:end --> ブロックの status: と note: を編集する。
snippet_hash は rule_id + file + 正規化された code_snippet の sha256 で計算するため、行番号が変動しても引き継げる。
15-false-positive-review エージェントが周辺コード/呼び出し元を再評価して likely_false_positive と判定した finding は ## 偽陽性候補 セクションへ移動 (本文の検出結果からは除外)。
誤判定と思う場合は対応する triage ブロックの status: を 対応する に変更すると次回スキャンで通常レポートに戻る。
ソースコードに以下のインラインマーカーを置くと検出段階で finding を生成しない (トリアージとは別軸)。
// ipa-skip: IPA-SWS-1-SQLI-001 reason: 内部固定値を埋め込んでいるためreason: は必須。
agents/ 配下に 15 体定義。
| エージェント | 担当 |
|---|---|
01-sql-injection | SQL インジェクション |
02-os-command-injection | OS コマンドインジェクション |
03-directory-traversal | ディレクトリトラバーサル |
04-session-management | セッション管理の不備 |
05-xss | クロスサイトスクリプティング |
06-csrf | クロスサイトリクエストフォージェリ |
07-http-header-injection | HTTP ヘッダインジェクション |
08-mail-header-injection | メールヘッダインジェクション |
09-clickjacking | クリックジャッキング |
10-buffer-overflow | バッファオーバーフロー |
11-access-control | アクセス制御の不備 |
safe-sql-details | 安全な SQL の呼び出し方 深掘り |
web-health-check | ウェブ健康診断 静的解析項目 |
operation-checklist | 運用 20ヶ条 + 実装チェックリスト |
| エージェント | 担当 |
|---|---|
15-false-positive-review | 検査エージェントの findings に対し周辺コード/呼び出し元を再 Read して偽陽性候補を識別 |
検査系 (01〜11 / safe-sql-details / web-health-check / operation-checklist) は以下の JSON 形式のみ返す。コード本文や中間ログは返さない。
{
"agent": "sql-injection",
"files_scanned": 142,
"findings": [
{
"rule_id": "IPA-SWS-1-SQLI-001",
"severity": "critical",
"category": "sql_injection",
"file": "src/users.php",
"line": 45,
"column": 12,
"code_snippet": "$sql = \"SELECT * FROM users WHERE id = \" . $_GET['id'];",
"message": "...",
"ipa": {
"document": "安全なウェブサイトの作り方 改訂第7版",
"section": "1.1 SQLインジェクション",
"page": "6-12",
"url": "https://www.ipa.go.jp/security/vuln/websecurity/about.html"
},
"remediation_type": "根本的解決",
"remediation": "プレースホルダによる SQL 文の組み立て",
"cwe": "CWE-89",
"fix_example": "..."
}
],
"errors": []
}
snippet_hash/fp_verdict/statusなどのトリアージ系フィールドは orchestrator (Phase 5・Phase 6) が後付けする。検査エージェントは付与しない。
15-false-positive-review の出力契約は agents/15-false-positive-review.md を参照。
.claude/skills/ipa-security-check/
├── SKILL.md ← 本ファイル (Claude が最初に読む)
├── commands/
│ └── ipa-security-check.md
├── agents/ ← 15 体のサブエージェント定義
│ ├── 01〜11, safe-sql-details, web-health-check, operation-checklist (検査 14 体)
│ └── 15-false-positive-review.md (偽陽性レビュー)
├── knowledge/ ← IPA 原文ベースの知識 (Skill 単独配布で完結)
├── rules/ ← YAML 検出シグネチャ
├── templates/ ← Markdown / SARIF テンプレート
├── scripts/ ← Bash 経由で呼ぶ Python 実装
│ ├── snippet_hash.py ← snippet_hash 計算 (Phase 5 入力準備)
│ └── render_report.py ← verdict/triage マージ + Markdown/SARIF 出力 (Step 7)
└── lib/
├── orchestrator.md
├── scope_resolver.md
├── shard_planner.md
├── triage_state.md ← ステータス保持・引き継ぎ仕様
└── output_formatter.md実行時の中間ファイルは .tmp/ipa-security-check/ 配下に置く (作業ディレクトリ名は必ず tmp を含める)。
ipa.document / section / page / url を必須付与knowledge/ rules/ を Skill 内に同梱。外部の docs/ を参照しないsnippet_hash (rule_id + file + 正規化された code_snippet の sha256) で同定する。行番号変動には耐える© classmethod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 58 other files (scripts) in skills/ipa-security-check of classmethod/tsumiki.
Open the folder on GitHubat commit fa5aaff
Ipa Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ipa Security Check this skillclassmethod/tsumiki | 974 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Evolving The Data ModelTriliumNext/Trilium | 38k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| SQL Optimization Patternsynulihao/AgentSkillOS | 617 | 10 repos | ~3.3k | Automated safety check: Pass | None | |
| SQL PortabilityHL7/sql-on-fhir | 150 | — | ~512 | Automated safety check: Pass | Custom licence | |
| DB Migrationskurealnum/dotfiles | 290 | — | ~820 | Automated safety check: Pass | None | |
| Contact FilterChatbotXIO/ChatbotX | 878 | — | ~2.5k | Automated safety check: Pass | Custom licence |
TriliumNext/Trilium
A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…
ynulihao/AgentSkillOS
Master SQL query optimization, indexing strategies, and EXPLAIN analysis to dramatically improve database performance and eliminate slow queries.
HL7/sql-on-fhir
Analyse whether a SQL query is portable across database implementations using sqlglot transpilation.
kurealnum/dotfiles
A skill your agent uses when generating or regenerating Drizzle migration files, changing database schema tables or columns, resolving migration sequence conflicts after rebase, reviewing migration…
ChatbotXIO/ChatbotX
Work with the ChatbotX contact filter system — the shared filter model behind the contacts list, conversations, and broadcast audiences.
MichealWayne/fe-tools
Add or modify utility functions in fe-tools. An agent skill from MichealWayne/fe-tools.
classmethod/tsumiki
This skill should be used when the user asks to "dev-context", "プロジェクトコンテキストを生成", "プロジェクトを分析", "generate project context", "analyze project", "コンテキストを更新".
classmethod/tsumiki
This skill should be used when the user asks to "dev-impl", "タスクを実装", "テストファースト実装", "implement task", "実装を開始", "クイック修正", "quick fix", "dev-impl auth 001".
classmethod/tsumiki
This skill should be used when the user asks to "dev-plan", "実装計画を作成", "要件からタスク分解", "create implementation plan", "plan tasks", "タスクを分割", "設計してタスクにする", "詳細要件定義", "full-spec plan", "EARS要件".
classmethod/tsumiki
This skill should be used when the user asks to "dev-run", "自動実装", "タスクを一括実装", "auto implement", "run all tasks", "タスクを自動実行", "バッチ実装", "dev-run auth 001 005".
classmethod/tsumiki
This skill should be used when the user asks to "dev-screen-spec", "画面仕様を生成", "画面仕様を更新", "screen spec", "generate screen spec", "update screen spec", "画面仕様ドキュメント".
classmethod/tsumiki
This skill should be used when the user asks to "dev-webtest", "Webテスト", "画面の動作確認", "E2Eテスト", "web test", "visual check", "モンキーテスト", "アクセシビリティチェック", "レスポンシブテスト", "フォームテスト".
Works with
Categories
IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。. Ipa Security Check is an agent skill from classmethod/tsumiki.
Ipa Security Check fits situations like: tasks that involve SQL.
Run `npx skills add classmethod/tsumiki --skill ipa-security-check -a claude-code`. Or copy the skill folder (skills/ipa-security-check in classmethod/tsumiki) into .claude/skills/ipa-security-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add classmethod/tsumiki --skill ipa-security-check -a codex`. Or copy the skill folder (skills/ipa-security-check in classmethod/tsumiki) into .agents/skills/ipa-security-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add classmethod/tsumiki --skill ipa-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ipa-security-check, .gemini/skills/ipa-security-check, .github/skills/ipa-security-check and .opencode/skills/ipa-security-check in your project.
SKILL.md names no scripts, command-line tools or credentials: Ipa Security Check is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: ipa.go.jp; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Ipa Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ipa Security Check: Evolving The Data Model (TriliumNext/Trilium, 38k stars), SQL Optimization Patterns (ynulihao/AgentSkillOS, 617 stars), SQL Portability (HL7/sql-on-fhir, 150 stars) and DB Migrations (kurealnum/dotfiles, 290 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
classmethod (a GitHub organization) maintains it in classmethod/tsumiki, which has 974 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on August 7, 2026.
Source: classmethod/tsumiki on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.