Agent skill

Ipa Security Check

by classmethod in classmethod/tsumiki

IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。

MITAuto-check passedDatabases

Install Ipa Security Check

skills CLI
$ npx skills add classmethod/tsumiki --skill ipa-security-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install classmethod/tsumiki ipa-security-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ipa-security-check .claude/skills/ipa-security-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ipa-security-check
GitHub stars
974
Token cost
~1.8k tokens
SKILL.md length
442 words
Files
59 (incl. scripts)
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。

  • Works in 7 steps: lib/scope_resolver.md… → lib/shard_planner.md… → agents/ 配下 の検査系サブエージェント (14 体) を… → …
  • Tasks that involve SQL
  • SKILL.md covers このスキルが行うこと, 起動方法, 実行手順 (Claude が行うこと) and 対応言語, plus 6 more sections
  • Reaches ipa.go.jp

What it does

Ipa Security Check is an agent skill from classmethod/tsumiki. IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 61 other files, including scripts (for example `agents/01-sql-injection.md`, `agents/02-os-command-injection.md` and `agents/03-directory-traversal.md`).

It sits in Databases, covering SQL. It works with SQL. The licence is MIT.

When your agent uses it

  • Tasks that involve SQL

Example prompts

  • “/ipa-security-check”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. lib/scope_resolver.md を読み、引数を解釈して対象ファイル一覧と言語マッピングを作る
  2. lib/shard_planner.md を読み、カテゴリごとにファイル数を数え、閾値超過時は N 分割する
  3. agents/ 配下 の検査系サブエージェント (14 体) を メインから並列起動 する (公式制約によりサブエージェントから二次サブエージェントは起動できないため、分割はメイン側で行う)
  4. 各サブエージェントは findings[] を含む JSON を返す。メインは findings のみ集約してコード本文は文脈に保持せず、.tmp/ipa-security-check/findings_raw.json に書き出す
  5. Phase 5 (偽陽性レビュー)
  6. Phase 6 + 出力 (Step 7): scripts/render_report.py を Bash で実行する。スクリプトが内部で以下を行う
  7. デフォルトの保存先は ./security-reports/ipa-security-report-YYYY-MM-DD-NN.md と ./security-reports/ipa-security-report-YYYY-MM-DD-NN.sarif (--output…

What it can do on your machine

Read from SKILL.md and the folder at commit fa5aaff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ipa.go.jp

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ipa Security Check loads about 1.8k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 442 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from classmethod/tsumiki at commit fa5aaff, republished under its MIT licence (© classmethod). 442 words, ~1,781 tokens.

Download SKILL.mdSave it as .claude/skills/ipa-security-check/SKILL.md (or your agent's skills folder). This skill also uses 58 other files; get the full folder from GitHub.
name
ipa-security-check
description
IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。

IPA Security Check Skill

このスキルが行うこと

IPA (情報処理推進機構) が公開する以下 5 資料の指摘事項に基づき、ローカルリポジトリのソースコード・設定ファイルを静的検査し、脆弱性候補を検出する。

略称正式名称主な検査内容
SWS安全なウェブサイトの作り方 改訂第7版11脆弱性 (SQLi/OSコマンド/トラバーサル/セッション/XSS/CSRF/HTTPヘッダ/メールヘッダ/クリックジャッキング/BoF/アクセス制御)
SQL安全なSQLの呼び出し方プレースホルダ使い分け・LIKE述語・識別子検証・文字コード問題
WHCウェブ健康診断仕様13診断項目のうち静的解析でカバー可能な観点
OPS安全なウェブサイトの運用管理に向けての20ヶ条HTTPヘッダ・依存ライブラリ・設定ファイル類
CLセキュリティ実装チェックリスト改訂第7版 p.105-108 のチェックリスト

すべての検出結果に IPA 原典の document / section / page / url を必ず添えて返す。

起動方法

スラッシュコマンド /ipa-security-check で起動する。引数で対象スコープを指定する。

形式動作
/ipa-security-checkカレント WD 全体をスキャン
/ipa-security-check <path>指定パス/glob のみ (例: src/, **/*.php)
/ipa-security-check --diff現ブランチと main の差分ファイルのみ
/ipa-security-check --categories sqli,xss <path>カテゴリ限定
/ipa-security-check --severity highHigh 以上のみ
/ipa-security-check --output report.md,report.sarif出力ファイル指定

自然文 (「IPA のセキュリティチェックをして」など) でも起動する。

実行手順 (Claude が行うこと)

  1. lib/scope_resolver.md を読み、引数を解釈して対象ファイル一覧と言語マッピングを作る
  2. lib/shard_planner.md を読み、カテゴリごとにファイル数を数え、閾値超過時は N 分割する
  3. agents/ 配下 の検査系サブエージェント (14 体) を メインから並列起動 する (公式制約によりサブエージェントから二次サブエージェントは起動できないため、分割はメイン側で行う)
  4. 各サブエージェントは findings[] を含む JSON を返す。メインは findings のみ集約してコード本文は文脈に保持せず、.tmp/ipa-security-check/findings_raw.json に書き出す
  5. Phase 5 (偽陽性レビュー):
    • scripts/snippet_hash.py を Bash で実行して findings_with_hash.json を作る
    • 15-false-positive-review エージェントを 5 件 / shard で並列起動し、返ってきた verdicts[] を結合して verdicts.json に保存
  6. Phase 6 + 出力 (Step 7): scripts/render_report.py を Bash で実行する。スクリプトが内部で以下を行う:
    • verdict を snippet_hash で findings にマージ
    • 既存 Markdown レポートから triage ブロックを抽出 (lib/triage_state.md 準拠) し、snippet_hash 一致で新 findings にステータス引き継ぎ
    • templates/report.md.tmpl を埋めて Markdown を出力、SARIF 2.1.0 も同時生成
  7. デフォルトの保存先は ./security-reports/ipa-security-report-YYYY-MM-DD-NN.md と ./security-reports/ipa-security-report-YYYY-MM-DD-NN.sarif (--output で上書き可)。security-reports/ ディレクトリが存在しない場合は自動作成する。同日に複数回実行した場合は連番 (-01, -02, ...) が自動付与され、既存レポートを上書きしない

中間ファイルの作業ディレクトリは .tmp/ipa-security-check/ (リポジトリルート直下、名前に tmp を含めること)。

詳細な分配ロジックは lib/orchestrator.md に従う。Claude は lib/orchestrator.md を読んでそのとおりに動くこと。

対応言語

言語拡張子
PHP.php
Java.java, .jsp
Ruby.rb, .erb
Python.py
JavaScript / TypeScript.js, .jsx, .ts, .tsx, .vue
C# / .NET.cs, .cshtml, .aspx
Go.go
設定ファイル.conf, nginx.conf, .htaccess, web.xml, *.yaml, *.yml, Dockerfile

トリアージ (ステータス管理)

検出結果には 4 ステータスを管理できる。状態は Markdown レポート内の HTML コメントブロックに保持され、次回スキャン時に snippet_hash で引き継がれる。詳細は lib/triage_state.md。

ステータス意味次回スキャンでの扱い
未対応未着手 (新規 finding のデフォルト)通常表示
対応する修正予定 / 実施中通常表示
問題なし確認の上、本物の脆弱性ではない## トリアージ済み (抑止) セクションへ移動。サマリから除外
保留一旦保留## トリアージ済み (抑止) セクションへ移動。サマリから除外

ユーザーは各 finding 直下の <!-- ipa-triage:begin ... ipa-triage:end --> ブロックの status: と note: を編集する。 snippet_hash は rule_id + file + 正規化された code_snippet の sha256 で計算するため、行番号が変動しても引き継げる。

Show full SKILL.md (170 more words)Show less
偽陽性候補

15-false-positive-review エージェントが周辺コード/呼び出し元を再評価して likely_false_positive と判定した finding は ## 偽陽性候補 セクションへ移動 (本文の検出結果からは除外)。 誤判定と思う場合は対応する triage ブロックの status: を 対応する に変更すると次回スキャンで通常レポートに戻る。

誤検知のインライン抑止 (補助)

ソースコードに以下のインラインマーカーを置くと検出段階で finding を生成しない (トリアージとは別軸)。

// ipa-skip: IPA-SWS-1-SQLI-001  reason: 内部固定値を埋め込んでいるため

reason: は必須。

サブエージェント一覧

agents/ 配下に 15 体定義。

検査エージェント (14 体): Phase 1〜4 で並列起動
エージェント担当
01-sql-injectionSQL インジェクション
02-os-command-injectionOS コマンドインジェクション
03-directory-traversalディレクトリトラバーサル
04-session-managementセッション管理の不備
05-xssクロスサイトスクリプティング
06-csrfクロスサイトリクエストフォージェリ
07-http-header-injectionHTTP ヘッダインジェクション
08-mail-header-injectionメールヘッダインジェクション
09-clickjackingクリックジャッキング
10-buffer-overflowバッファオーバーフロー
11-access-controlアクセス制御の不備
safe-sql-details安全な SQL の呼び出し方 深掘り
web-health-checkウェブ健康診断 静的解析項目
operation-checklist運用 20ヶ条 + 実装チェックリスト
レビューエージェント (1 体): Phase 5 で並列起動
エージェント担当
15-false-positive-review検査エージェントの findings に対し周辺コード/呼び出し元を再 Read して偽陽性候補を識別

出力契約 (検査サブエージェント → メイン)

検査系 (01〜11 / safe-sql-details / web-health-check / operation-checklist) は以下の JSON 形式のみ返す。コード本文や中間ログは返さない。

json
{
  "agent": "sql-injection",
  "files_scanned": 142,
  "findings": [
    {
      "rule_id": "IPA-SWS-1-SQLI-001",
      "severity": "critical",
      "category": "sql_injection",
      "file": "src/users.php",
      "line": 45,
      "column": 12,
      "code_snippet": "$sql = \"SELECT * FROM users WHERE id = \" . $_GET['id'];",
      "message": "...",
      "ipa": {
        "document": "安全なウェブサイトの作り方 改訂第7版",
        "section": "1.1 SQLインジェクション",
        "page": "6-12",
        "url": "https://www.ipa.go.jp/security/vuln/websecurity/about.html"
      },
      "remediation_type": "根本的解決",
      "remediation": "プレースホルダによる SQL 文の組み立て",
      "cwe": "CWE-89",
      "fix_example": "..."
    }
  ],
  "errors": []
}

snippet_hash / fp_verdict / status などのトリアージ系フィールドは orchestrator (Phase 5・Phase 6) が後付けする。検査エージェントは付与しない。

15-false-positive-review の出力契約は agents/15-false-positive-review.md を参照。

ファイル構成

.claude/skills/ipa-security-check/
├── SKILL.md                ← 本ファイル (Claude が最初に読む)
├── commands/
│   └── ipa-security-check.md
├── agents/                 ← 15 体のサブエージェント定義
│   ├── 01〜11, safe-sql-details, web-health-check, operation-checklist (検査 14 体)
│   └── 15-false-positive-review.md (偽陽性レビュー)
├── knowledge/              ← IPA 原文ベースの知識 (Skill 単独配布で完結)
├── rules/                  ← YAML 検出シグネチャ
├── templates/              ← Markdown / SARIF テンプレート
├── scripts/                ← Bash 経由で呼ぶ Python 実装
│   ├── snippet_hash.py     ← snippet_hash 計算 (Phase 5 入力準備)
│   └── render_report.py    ← verdict/triage マージ + Markdown/SARIF 出力 (Step 7)
└── lib/
    ├── orchestrator.md
    ├── scope_resolver.md
    ├── shard_planner.md
    ├── triage_state.md     ← ステータス保持・引き継ぎ仕様
    └── output_formatter.md

実行時の中間ファイルは .tmp/ipa-security-check/ 配下に置く (作業ディレクトリ名は必ず tmp を含める)。

重要な原則

  • IPA 原典への出典明記: すべての finding に ipa.document / section / page / url を必須付与
  • Skill 単独配布: knowledge/ rules/ を Skill 内に同梱。外部の docs/ を参照しない
  • メイン文脈の節約: サブエージェントは findings / verdicts JSON のみ返却
  • ネスト禁止準拠: サブエージェントは二次サブエージェントを起動しない。分割はメイン側で行う
  • 偽陽性レビューの分離: 検出フェーズと FP 判定フェーズは分離する。FP 判定は周辺コードを再 Read して行う
  • トリアージ状態は Markdown 内に保持: 専用状態ファイルは作らず、レポート自体が状態を持つ (Git で履歴管理可)
  • 完全一致抑止: snippet_hash (rule_id + file + 正規化された code_snippet の sha256) で同定する。行番号変動には耐える

© classmethod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 58 other files (scripts) in skills/ipa-security-check of classmethod/tsumiki.

  • SKILL.md
  • agents/01-sql-injection.md
  • agents/02-os-command-injection.md
  • agents/03-directory-traversal.md
  • agents/04-session-management.md
  • agents/05-xss.md
  • agents/06-csrf.md
  • agents/07-http-header-injection.md
  • agents/08-mail-header-injection.md
  • agents/09-clickjacking.md
  • agents/10-buffer-overflow.md
  • agents/11-access-control.md
  • agents/15-false-positive-review.md
  • agents/operation-checklist.md
  • agents/safe-sql-details.md
  • agents/web-health-check.md
  • commands/ipa-security-check.md
  • knowledge/01_sql_injection.md
  • … and 41 more

Open the folder on GitHubat commit fa5aaff

Compare with similar skills

Ipa Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ipa Security Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ipa Security Check this skillclassmethod/tsumiki974—~1.8kAutomated safety check: PassMIT
Evolving The Data ModelTriliumNext/Trilium38k—~2.1kAutomated safety check: PassAGPL-3.0
SQL Optimization Patternsynulihao/AgentSkillOS61710 repos~3.3kAutomated safety check: PassNone
SQL PortabilityHL7/sql-on-fhir150—~512Automated safety check: PassCustom licence
DB Migrationskurealnum/dotfiles290—~820Automated safety check: PassNone
Contact FilterChatbotXIO/ChatbotX878—~2.5kAutomated safety check: PassCustom licence

Similar skills

  • Evolving The Data Model

    TriliumNext/Trilium

    A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…

    38k GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed
  • SQL Optimization Patterns

    ynulihao/AgentSkillOS

    Master SQL query optimization, indexing strategies, and EXPLAIN analysis to dramatically improve database performance and eliminate slow queries.

    617 GitHub starsUsed in 10 repos~3.3k tokens
    DatabasesAuto-check passed
  • SQL Portability

    HL7/sql-on-fhir

    Analyse whether a SQL query is portable across database implementations using sqlglot transpilation.

    150 GitHub stars~512 tokensUpdated yesterday
    DatabasesAuto-check passed
  • DB Migrations

    kurealnum/dotfiles

    A skill your agent uses when generating or regenerating Drizzle migration files, changing database schema tables or columns, resolving migration sequence conflicts after rebase, reviewing migration…

    290 GitHub stars~820 tokensUpdated 5 mo ago
    DatabasesAuto-check passed
  • Contact Filter

    ChatbotXIO/ChatbotX

    Work with the ChatbotX contact filter system — the shared filter model behind the contacts list, conversations, and broadcast audiences.

    878 GitHub stars~2.5k tokensUpdated today
    DatabasesAuto-check passed
  • Add Utils Function

    MichealWayne/fe-tools

    Add or modify utility functions in fe-tools. An agent skill from MichealWayne/fe-tools.

    207 GitHub stars~602 tokensUpdated 29 days ago
    DatabasesAuto-check passed

More from classmethod/tsumiki

All 14 skills in this repo
  • Dev Context

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-context", "プロジェクトコンテキストを生成", "プロジェクトを分析", "generate project context", "analyze project", "コンテキストを更新".

    974 GitHub stars~755 tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Impl

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-impl", "タスクを実装", "テストファースト実装", "implement task", "実装を開始", "クイック修正", "quick fix", "dev-impl auth 001".

    974 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Plan

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-plan", "実装計画を作成", "要件からタスク分解", "create implementation plan", "plan tasks", "タスクを分割", "設計してタスクにする", "詳細要件定義", "full-spec plan", "EARS要件".

    974 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Run

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-run", "自動実装", "タスクを一括実装", "auto implement", "run all tasks", "タスクを自動実行", "バッチ実装", "dev-run auth 001 005".

    974 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Screen Spec

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-screen-spec", "画面仕様を生成", "画面仕様を更新", "screen spec", "generate screen spec", "update screen spec", "画面仕様ドキュメント".

    974 GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Webtest

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-webtest", "Webテスト", "画面の動作確認", "E2Eテスト", "web test", "visual check", "モンキーテスト", "アクセシビリティチェック", "レスポンシブテスト", "フォームテスト".

    974 GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Ipa Security Check

What does Ipa Security Check do?

IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。. Ipa Security Check is an agent skill from classmethod/tsumiki.

When should I use Ipa Security Check?

Ipa Security Check fits situations like: tasks that involve SQL.

How do I install Ipa Security Check in Claude Code?

Run `npx skills add classmethod/tsumiki --skill ipa-security-check -a claude-code`. Or copy the skill folder (skills/ipa-security-check in classmethod/tsumiki) into .claude/skills/ipa-security-check in your project. Claude Code loads it when a task matches its description.

How do I install Ipa Security Check in Codex?

Run `npx skills add classmethod/tsumiki --skill ipa-security-check -a codex`. Or copy the skill folder (skills/ipa-security-check in classmethod/tsumiki) into .agents/skills/ipa-security-check in your project. Codex loads it when a task matches its description.

Can I use Ipa Security Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add classmethod/tsumiki --skill ipa-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ipa-security-check, .gemini/skills/ipa-security-check, .github/skills/ipa-security-check and .opencode/skills/ipa-security-check in your project.

What does Ipa Security Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Ipa Security Check is instructions for the agent only. Our summary lists: Python 3.

Does Ipa Security Check access the network?

SKILL.md names 1 domain. In commands or code: ipa.go.jp; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ipa Security Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ipa Security Check use?

Ipa Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ipa Security Check use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ipa Security Check?

Skills that share tags, products or a category with Ipa Security Check: Evolving The Data Model (TriliumNext/Trilium, 38k stars), SQL Optimization Patterns (ynulihao/AgentSkillOS, 617 stars), SQL Portability (HL7/sql-on-fhir, 150 stars) and DB Migrations (kurealnum/dotfiles, 290 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ipa Security Check?

classmethod (a GitHub organization) maintains it in classmethod/tsumiki, which has 974 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on August 7, 2026.

Source: classmethod/tsumiki on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.