Scan
wshobson/agents
Scans the codebase to generate project-doc.md and AGENTS.md.
Scan how you actually work with your coding agent and surface what to encode next.
$ npx skills add coleam00/skills --skill opportunity-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install coleam00/skills opportunity-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/opportunity-scan .claude/skills/opportunity-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .claude/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add coleam00/skills --skill opportunity-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install coleam00/skills opportunity-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/opportunity-scan .agents/skills/opportunity-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .agents/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coleam00/skills --skill opportunity-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install coleam00/skills opportunity-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/opportunity-scan .cursor/skills/opportunity-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .cursor/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/coleam00/skills.git --path .claude/skills/opportunity-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add coleam00/skills --skill opportunity-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install coleam00/skills opportunity-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/opportunity-scan .gemini/skills/opportunity-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .gemini/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install coleam00/skills opportunity-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add coleam00/skills --skill opportunity-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/opportunity-scan .github/skills/opportunity-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .github/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coleam00/skills --skill opportunity-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install coleam00/skills opportunity-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/opportunity-scan .opencode/skills/opportunity-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "opportunity-scan" agent skill from https://github.com/coleam00/skills/tree/main/.claude/skills/opportunity-scan into .opencode/skills/opportunity-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "opportunity-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
opportunity-scanScan how you actually work with your coding agent and surface what to encode next.
Opportunity Scan is an agent skill from coleam00/skills. Scan how you actually work with your coding agent and surface what to encode next. Point it at ONE run's artifacts to find what would have prevented a specific failure (the reactive loop — 'that went wrong, what should change in the AI layer?'), or at a window of session logs to find recurring patterns worth building (the proactive scan). Agent-agnostic. Outputs a shape-only HTML report. Use to evolve your system from real usage.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: The agent skills I actually use to build software with coding agents. The PIV loop, planning, worktrees, and the meta-skills for building your own AI Layer. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 847be08. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Opportunity Scan loads about 2.4k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,397 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from coleam00/skills at commit 847be08, republished under its MIT licence (© coleam00). 1,397 words, ~2,359 tokens.
.claude/skills/opportunity-scan/SKILL.md (or your agent's skills folder).Reads your agent's own capabilities plus one target you choose, and recommends which primitive each finding should become. Agent-agnostic (Claude Code, Codex, PI, …). It maps what it finds to the full primitive palette (rules · skill · hook · subagent · MCP · automation/workflow), and it works for any agent because it learns that agent's capabilities first.
Two targets, one skill — this is the whole design:
Same skill, same output shape — you're just changing what it reads.
This is a discovery tool — what to change — NOT a quality eval (whether a built thing is good). Keep the two separate.
Read $ARGUMENTS as prose, not as positional slots. Only input 1 is required. Input 2 is free-form and will
contain spaces, so never split arguments on whitespace and never bind them by position — a steer typed without
quotes is still one steer. If something is missing, ask for it once, in a single message, not one question
at a time.
What to scan (required) — exactly one of:
~/.claude/projects/ + ~/.claude/history.jsonl; Codex → ~/.codex/sessions/; PI → your extension's
log dir. Default window: the last 2 weeks.This choice is what makes the scan reactive or proactive. Nothing else changes.
Your steer (optional — ask once, accept "nothing specific") — one input, whose meaning follows the target:
Either way: you supply the steer, the target supplies the evidence.
The agent's own capability docs (optional — normally resolve this yourself) — so the scan knows what your
agent can become (its real extension points). Work it out; do not ask first. Identify which agent you are
running as and find its own extensibility docs (for Claude Code that is code.claude.com/docs). Only ask if you
genuinely cannot determine it, or if the user wants you pointed somewhere specific. Never assume a fixed set of
extension points: read them from whatever docs you actually find.
Learn your own capabilities. Determine which agent you are running as and read its capability docs (input 3, which you normally resolve yourself). Write a short internal list of this agent's extension points (rules, skill, hook, subagent, MCP/tool, automation/workflow, whatever the docs describe). Use what the docs say — do not assume a fixed set.
Read the target — branch on what input 1 was:
jq/grep/sort | uniq -c) so only frequencies and representative samples enter your context, never whole
log files.Either way: if you can't locate or parse the target, ask the user rather than invent.
Find what to change — the question differs by target:
Both targets: pick the best-fit primitive (from step 1's list) and say why. If input 2 was given, weight it — on a run, the named symptom's prevention leads the report (and if the evidence says the symptom was actually something else, say so plainly); on logs, surface what the user said they care about even when it isn't the most frequent pattern, and say plainly when a high-frequency pattern is not worth encoding. And propose each change in the house style of the artifacts that already exist: skim a couple of the project's current rules/skills/agents first and shape the recommendation to look like them, so what it suggests is something the user would actually build. Examples of the mapping:
Write the report as a single self-contained HTML file (see the contract below), then tell the user where it is.
Let the analysis drive the report. Which sections exist, what goes in them, how deep each goes, how many opportunities, which quotes or numbers are worth pulling out — all of that comes from what you actually found, NOT from this skill. Do not box the report into a fixed set of sections, do not seed findings, do not tell it what to conclude. If the data is rich, the report is rich; if a single finding deserves its own deep section, give it one; if something surprising turns up, surface it.
Only the rendering is prescribed:
.html file (inline CSS), opens in any browser.The rule: this skill governs how to put it on the page, never what goes on the page.
Do exactly these four steps, clearly. Don't add scoring frameworks, config, or extra passes it doesn't need. If a step can't complete (docs or the target not found), stop and ask — never fabricate the analysis. Scan one target per run. If someone wants both the reactive and the proactive view, that's two runs and two reports — mixing "what broke in this loop" with "what I keep repeating across a month" produces a report that answers neither question well.
© coleam00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/opportunity-scan of coleam00/skills.
Open the folder on GitHubat commit 847be08
Opportunity Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Opportunity Scan this skillcoleam00/skills | 676 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Scanwshobson/agents | 40k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Vulnerability Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Harness MCP Scanruvnet/ruflo | 74k | — | ~429 | Automated safety check: Notes | MIT |
wshobson/agents
Scans the codebase to generate project-doc.md and AGENTS.md.
affaan-m/ECC
固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。
affaan-m/ECC
用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。
sickn33/agentic-awesome-skills
Scan systems and dependencies for CVEs and security vulnerabilities.
ruvnet/ruflo
Static security scan of a harness's declared MCP surface via harness mcp-scan {path}.
affaan-m/ECC
Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit.
coleam00/skills
Measure whether a repository's AI instructions still earn their place, by running the same real task many times with the layer intact and with it stripped, then grading every rule against what…
coleam00/skills
Take a PRD and build a dark factory around it - a repository that takes work in as an issue and ships validated code out with nobody at the keyboard - one component at a time, into the user's actual…
coleam00/skills
Take real control of the desktop - list and focus windows, type, paste, click, scroll, and screenshot - on Windows, macOS or Linux, and drive other coding-agent sessions running in terminals.
coleam00/skills
Audit any second brain, notes folder, or agent memory for facts that have quietly stopped being true, then fix the worst one so it stops recurring.
coleam00/skills
Build a personal signal engine from scratch - a system that reads every source someone cares about each day (changelogs and release notes, communities, feeds, videos, papers), makes a quick decision…
coleam00/skills
Create one or more git worktrees for parallel development, each on its own branch with gitignored config copied in, dependencies installed, and a health check, by fanning out a setup subagent per…
Scan how you actually work with your coding agent and surface what to encode next. Opportunity Scan is an agent skill from coleam00/skills. Scan how you actually work with your coding agent and surface what to encode next.
Opportunity Scan fits situations like: evolve your system from real usage.
Run `npx skills add coleam00/skills --skill opportunity-scan -a claude-code`. Or copy the skill folder (.claude/skills/opportunity-scan in coleam00/skills) into .claude/skills/opportunity-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add coleam00/skills --skill opportunity-scan -a codex`. Or copy the skill folder (.claude/skills/opportunity-scan in coleam00/skills) into .agents/skills/opportunity-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coleam00/skills --skill opportunity-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/opportunity-scan, .gemini/skills/opportunity-scan, .github/skills/opportunity-scan and .opencode/skills/opportunity-scan in your project.
SKILL.md names no scripts, command-line tools or credentials: Opportunity Scan is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Opportunity Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Opportunity Scan: Scan (wshobson/agents, 40k stars), Repo Scan (affaan-m/ECC, 276k stars), Repo Scan (affaan-m/ECC, 276k stars) and Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
coleam00 (a GitHub user) maintains it in coleam00/skills, which has 676 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 7, 2026.
Source: coleam00/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.