Agent skill

Commit Security Scan

by codexstar69 in codexstar69/bug-hunter

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

MITAuto-check passedSecurity

Install Commit Security Scan

skills CLI
$ npx skills add codexstar69/bug-hunter --skill commit-security-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codexstar69/bug-hunter commit-security-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codexstar69/bug-hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/commit-security-scan .claude/skills/commit-security-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
commit-security-scan
GitHub stars
519
Token cost
~629 tokens
SKILL.md length
260 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

  • Works in 6 steps: Ensure threat-model context exists. → Resolve the changed-file scope. → Read the full contents of the changed… → …
  • The user asks for PR security review
  • SKILL.md covers Purpose, Inputs, Workflow and Output, plus 1 more section
  • Calls git

What it does

Commit Security Scan is an agent skill from codexstar69/bug-hunter. Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Threat modeling. It works with Git. The repository describes itself as: Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds… The licence is MIT.

When your agent uses it

  • The user asks for PR security review
  • Commit-diff scanning
  • Staged-change security checks
  • Branch-comparison security review

Example prompts

  • “/commit-security-scan”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Ensure threat-model context exists.
  2. Resolve the changed-file scope.
  3. Read the full contents of the changed source files, not just the patch.
  4. Focus on STRIDE-oriented issues in changed code
  5. Reuse Bug Hunter-native security conventions
  6. If the user wants only a focused security diff review, stop after the findings report.

What it can do on your machine

Read from SKILL.md and the folder at commit 3be6973. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Commit Security Scan loads about 629 tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 260 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~629

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codexstar69/bug-hunter at commit 3be6973, republished under its MIT licence (© codexstar69). 260 words, ~629 tokens.

Download SKILL.mdSave it as .claude/skills/commit-security-scan/SKILL.md (or your agent's skills folder).
name
commit-security-scan
description
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.

Commit Security Scan

This is a bundled local Bug Hunter companion skill. It is portable and self-contained: use .bug-hunter/* artifacts, never .factory/* paths.

Purpose

Review changed code for security issues only. This skill is optimized for:

  • PR review
  • staged diff review
  • branch diff review
  • commit / commit-range security scanning

Inputs

Resolve the scan scope from the user request:

  • PR review → use scripts/pr-scope.cjs
  • staged review → use git diff --cached --name-only
  • branch diff → use git diff --name-only <base>...<head>
  • commit range → use git diff --name-only <base>..<head>

Workflow

  1. Ensure threat-model context exists.

    • Preferred artifacts:
      • .bug-hunter/threat-model.md
      • .bug-hunter/security-config.json
    • If missing, run the bundled threat-model-generation skill first.
  2. Resolve the changed-file scope.

  3. Read the full contents of the changed source files, not just the patch.

  4. Focus on STRIDE-oriented issues in changed code:

    • Spoofing: auth/session/token mistakes
    • Tampering: SQLi, XSS, path traversal, command injection, mass assignment
    • Repudiation: security-sensitive actions with no auditability
    • Information Disclosure: IDOR, secret exposure, verbose errors
    • DoS: unbounded input, missing limits, expensive regex/queries
    • Elevation of Privilege: missing authorization, role bypass, privilege escalation
  5. Reuse Bug Hunter-native security conventions:

    • findings should be compatible with .bug-hunter/hunter-findings.json
    • use STRIDE + CWE labels
    • include confidence scores
  6. If the user wants only a focused security diff review, stop after the findings report. If the user wants deeper validation, hand off to the bundled vulnerability-validation skill.

Output

Preferred outputs:

  • .bug-hunter/hunter-findings.json when integrating with the main Bug Hunter pipeline
  • .bug-hunter/report.md as a rendered companion if needed

Notes

  • This skill is intentionally diff-scoped; it does not replace full-repository audits.
  • Use it as the lightweight security fast-path before invoking the broader security-review flow.

© codexstar69, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/commit-security-scan of codexstar69/bug-hunter.

Open the folder on GitHubat commit 3be6973

Compare with similar skills

Commit Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Commit Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Commit Security Scan this skillcodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Security Auditblueberrycongee/termcanvas406—~966Automated safety check: NotesMIT
Securitynotque/vexjoy-agent435—~2.6kAutomated safety check: NotesMIT
Repo SentinelMathews-Tom/armory327—~2.2kAutomated safety check: PassMIT
Security Reviewdanielvm-git/bigpowers256—~1.5kAutomated safety check: PassMIT
Cc Reviewdoccker/cc-use-exp1.1k—~541Automated safety check: PassCustom licence

Similar skills

  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    406 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security

    notque/vexjoy-agent

    Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

    435 GitHub stars~2.6k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Repo Sentinel

    Mathews-Tom/armory

    Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

    327 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    danielvm-git/bigpowers

    AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files.

    256 GitHub stars~1.5k tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Cc Review

    doccker/cc-use-exp

    结构化代码审查工作流,适用于显式 quick/full/security review;不负责普通实现或 bug 修复流程。

    1.1k GitHub stars~541 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from codexstar69/bug-hunter

All 11 skills in this repo
  • Bug Hunter

    codexstar69/bug-hunter

    Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

    519 GitHub stars~5k tokensUpdated 1 mo ago
    Auto-check passed
  • Doc Lookup

    codexstar69/bug-hunter

    Unified documentation lookup for Bug Hunter agents. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~592 tokensUpdated 1 mo ago
    Auto-check passed
  • Fixer

    codexstar69/bug-hunter

    Surgical code fixer for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Hunter

    codexstar69/bug-hunter

    Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon

    codexstar69/bug-hunter

    Codebase reconnaissance agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Referee

    codexstar69/bug-hunter

    Final arbiter for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Commit Security Scan

What does Commit Security Scan do?

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Commit Security Scan is an agent skill from codexstar69/bug-hunter. Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

When should I use Commit Security Scan?

Commit Security Scan fits situations like: the user asks for PR security review; commit-diff scanning; staged-change security checks; branch-comparison security review.

How do I install Commit Security Scan in Claude Code?

Run `npx skills add codexstar69/bug-hunter --skill commit-security-scan -a claude-code`. Or copy the skill folder (skills/commit-security-scan in codexstar69/bug-hunter) into .claude/skills/commit-security-scan in your project. Claude Code loads it when a task matches its description.

How do I install Commit Security Scan in Codex?

Run `npx skills add codexstar69/bug-hunter --skill commit-security-scan -a codex`. Or copy the skill folder (skills/commit-security-scan in codexstar69/bug-hunter) into .agents/skills/commit-security-scan in your project. Codex loads it when a task matches its description.

Can I use Commit Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codexstar69/bug-hunter --skill commit-security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commit-security-scan, .gemini/skills/commit-security-scan, .github/skills/commit-security-scan and .opencode/skills/commit-security-scan in your project.

What does Commit Security Scan need to run?

Going by SKILL.md and its folder, Commit Security Scan needs the command-line tools its instructions call (git).

Does Commit Security Scan access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Commit Security Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Commit Security Scan use?

Commit Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Commit Security Scan use?

About 629 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Commit Security Scan?

Skills that share tags, products or a category with Commit Security Scan: Security Audit (blueberrycongee/termcanvas, 406 stars), Security (notque/vexjoy-agent, 435 stars), Repo Sentinel (Mathews-Tom/armory, 327 stars) and Security Review (danielvm-git/bigpowers, 256 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Commit Security Scan?

codexstar69 (a GitHub user) maintains it in codexstar69/bug-hunter, which has 519 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 17, 2026.

Source: codexstar69/bug-hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.