Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan.
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .claude/skills/deep-security-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .claude/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .agents/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .agents/skills/deep-security-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .agents/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .cursor/skills/deep-security-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .cursor/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/CoWork-OS/CoWork-OS.git --path resources/plugin-packs/codex-security/skills/deep-security-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .gemini/skills/deep-security-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .gemini/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .github/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .github/skills/deep-security-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .github/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install CoWork-OS/CoWork-OS deep-security-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/deep-security-scan .opencode/skills/deep-security-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deep-security-scan" agent skill from https://github.com/CoWork-OS/CoWork-OS/tree/main/resources/plugin-packs/codex-security/skills/deep-security-scan into .opencode/skills/deep-security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-security-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deep-security-scanA skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan.
Deep Security Scan is an agent skill from CoWork-OS/CoWork-OS. Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths.
Its SKILL.md is about 8.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Security review and Threat modeling. The repository describes itself as: Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0ace02b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deep Security Scan loads about 8.6k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 3,848 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from CoWork-OS/CoWork-OS at commit 0ace02b, republished under its MIT licence (© CoWork-OS). 3,848 words, ~8,634 tokens.
.claude/skills/deep-security-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Deep Security Scan is a higher-recall repository-wide wrapper around Codex Security. It preserves the ordinary Codex Security phase model and final report shape, but repeats the most variance-sensitive phase, finding discovery, before centralized judgment.
The wrapper owns orchestration only:
$codex-security:finding-discovery$codex-security:validation, $codex-security:attack-path-analysis, and final report assembly onceDo not replace Codex Security's established scan rules with custom shortcuts.
Before starting, confirm that the Codex Security plugin skills needed by this workflow are available:
$codex-security:security-scan$codex-security:threat-model$codex-security:finding-discovery$codex-security:validation$codex-security:attack-path-analysisIf any required skill is unavailable, stop and say that this Codex Security installation does not include the required scan skills. Do not silently degrade into a different workflow.
This workflow also requires parallel delegated workers for repeated discovery. Treat explicit invocation of Deep Security Scan as the user's request for this fanout workflow. If delegation is unavailable in the current environment, do not claim Deep Security Scan ran; explain the limitation and offer an ordinary Codex Security scan as the fallback path.
When delegated discovery workers are spawned from the current scan thread, inherit the parent worker configuration. Do not override agent_type, model, or reasoning effort on a full-history fork; use the host's inherited defaults so the spawn call does not fail before discovery begins.
../../references/final-report.md.These invariants are part of the workflow contract. Do not relax, reinterpret, or replace them with coordinator improvisation.
6 usable discovery workers per completed round<discovery_dir>/rank_input.csv plus one exhaustive shared <discovery_dir>/deep_review_input.csv before the first discovery round, and every discovery worker must consume that same shared worklist pair without regenerating, reranking, or overwriting itfinding_discovery_report.md candidate shape through every merge pass; the merged report is the canonical candidate inventory, not a later summary derived from some other inventoryfindings/<candidate_id>/candidate_ledger.jsonl record that names the absorbed worker candidates and ledgers it subsumes before centralized validation begins$codex-security:security-scan first and follow its repository-wide scan semantics exactly.$codex-security:security-scan; if the user requested a PR, commit, branch diff, or working-tree diff, direct them to ordinary $codex-security:security-diff-scan. Do not silently widen the scope.repo_namesecurity_scans_dirscan_idscan_dirartifacts_dircontext_dirdiscovery_dircoverage_dirreconciliation_dirfindings_dir<context_dir>/threat_model.md path for the later canonical validation threat model that will be synthesized only after the discovery loop reaches a terminal state.<discovery_dir>/rank_input.csv once using Codex Security's ordinary deterministic repository-wide worklist helper for the resolved repositoryrank_input.csv row into <discovery_dir>/deep_review_input.csv and declare that worklist pair authoritative and exhaustive for every workerrank_output.csv; repo-wide Deep Security Scan does not use ranked truncation in this versionDo not let individual discovery workers reinterpret the scan target, but do let them independently generate their own repository-level threat models at worker-specific paths before discovery begins.
Run discovery in synchronous rounds:
6 independent discovery workers per round10 rounds totalAlways run at least one round.
After each round:
Do not keep completed discovery workers open across rounds. Later rounds should consume only the preserved artifacts, not live worker threads. Before spawning any later round, confirm that every completed worker from the prior round has been closed.
While a discovery round is active, keep the coordinator neutral. It may perform orchestration bookkeeping and artifact-health checks, but it must not run its own target-specific discovery lane, form candidate hypotheses, queue likely finding families, or do repository-grounded validation preparation before the round closes.
This stop rule measures discovery saturation only. It does not claim that validated findings or final reportable findings have saturated; validation and report assembly still happen once after the discovery loop completes.
If the first round finds no plausible candidates, write the appropriate canonical no-findings discovery artifact and continue directly to the final Codex Security no-findings assembly path.
Execute this checklist in order for every completed round. Do not skip steps.
finding_discovery_report.mdEach discovery worker must be independent:
<discovery_dir>/rank_input.csv and exhaustive <discovery_dir>/deep_review_input.csv inputs$codex-security:validation, no top-level $codex-security:attack-path-analysis, and no final report assemblyThe goal is not shallow parallelism; the goal is independent high-quality discovery diversity from repeated same-brief stochastic passes.
Use this canonical brief for every discovery worker. Do not prepend or append extra coordinator prose, skill-path boilerplate, themed emphasis, candidate-family hints, prior-round novelty hints, or coordinator-invented specialty lanes. Only substitute the resolved target details, round id, worker id, and worker-specific output paths required for the run.
Run the Codex Security threat-model phase and then the finding-discovery phase only.
Use the provided resolved scan target exactly as given.
First generate your own repository-level threat model for that resolved target using the ordinary `$codex-security:threat-model` rules, but write it only to your worker-specific threat-model output path. Do not read, reuse, overwrite, or infer a shared coordinator threat model.
Then run `$codex-security:finding-discovery` using your own worker-specific repository threat model as the threat-model source of truth.
Do not reinterpret the target, run the top-level `$codex-security:validation` phase, run the top-level `$codex-security:attack-path-analysis` phase, assemble the final report, or edit repository files.
Your task is to enumerate technically plausible, distinct security finding candidates as comprehensively as possible for this scope.
Apply the ordinary `$codex-security:finding-discovery` rules in full:
- stay grounded in the code and your worker-specific threat model
- preserve separate root causes rather than cosmetic variants
- keep independently reachable instances separate
- preserve concrete source, closest-control, sink, impact, and affected-location evidence
- consume the parent-provided authoritative `<discovery_dir>/rank_input.csv` and exhaustive `<discovery_dir>/deep_review_input.csv` exactly as supplied; do not regenerate, rerank, overwrite, or reinterpret them
- treat those standard-path worklists as shared inputs while writing every worker output only to the explicit worker-specific artifact paths supplied for this discovery pass
- for repository-wide scans, perform the normal Codex Security repo-wide deep-review, seed-research, work-ledger, raw-candidate, candidate-ledger, dedupe, repository-coverage-ledger, and frontier-pass work required by finding discovery
- for repository-wide scans, preserve any candidate-local validation evidence and candidate-local attack-path facts that the current Codex Security discovery workflow requires before dedupe; those receipts are discovery support artifacts, not permission to run the later centralized top-level phases
- for repository-wide worker candidate JSONL, use one canonical machine-readable affected-location shape only:
- `affected_locations` must be an array of objects
- every object must contain `label`, `path`, and `lines`
- `detail` may be included when it materially helps later merge or validation
- use `lines` as a string even for one line, such as `"154"`
- do not emit string-only locations such as `"src/file.py:154"`, alternate `file` or `line` keys, or separate-only `source_locations` / `root_locations` / `sink_locations` fields without also materializing the unified `affected_locations` array
Return your worker-specific threat model plus the normal discovery artifact set for your worker-specific artifact paths, with enough detail for later centralized semantic merging and validation.Keep the canonical Codex Security scan paths for the final merged pipeline. Put repeated discovery worker artifacts under the canonical artifacts_dir without overwriting one another:
<artifacts_dir>/
02_discovery/
rank_input.csv
deep_review_input.csv
deep_discovery/
round-01/
worker-01/
threat_model.md
finding_discovery_report.md
seed_research.md
work_ledger.jsonl
raw_candidates.jsonl
dedupe_report.md
deduped_candidates.jsonl
repository_coverage_ledger.md
findings/
<candidate_id>/
candidate_ledger.jsonl
worker-02/
...
round-02/
...Workers write their worker-local repository-wide discovery artifact set to their assigned paths while sharing only the standard-path <discovery_dir>/rank_input.csv and exhaustive <discovery_dir>/deep_review_input.csv.
Give each worker explicit worker-specific output paths so the discovery reports and repository-wide ledgers do not overwrite one another.
For repository-wide workers, the machine-readable candidate streams must use this canonical affected-location contract in both raw_candidates.jsonl and deduped_candidates.jsonl:
{
"affected_locations": [
{
"label": "root_control",
"path": "src/example.py",
"lines": "154",
"detail": "Optional concise reason this location matters"
}
]
}Treat this as a schema contract, not presentation guidance:
affected_locations is always an array of objectslabel, path, and lines are required on every itemdetail is optionallines is always a string, including single-line locationsfile, line, or parallel source/root/sink-only arrays in place of the canonical arrayMerge at the level of the underlying actionable candidate, not at the level of title similarity.
Treat two candidates as the same cluster only when a careful security reviewer would consider them the same underlying issue, or when one is a narrower or more specific restatement of the other and keeping both would double-count the same candidate.
Do not merge merely because candidates:
Remediation-subsumption is required for merge eligibility:
When candidates truly merge:
Use a preserving merge, not a lossy summary:
When candidates overlap but remain materially distinct, keep them separate.
After each merge pass, retain:
finding_discovery_report.md in Codex Security's normal discovery-report shape<reconciliation_dir>/deduped_candidates.jsonl path<reconciliation_dir>/dedupe_report.md path<findings_dir>/<candidate_id>/candidate_ledger.jsonl per merged candidate, recording the discovery provenance, absorbed worker candidate ids, and absorbed worker-ledger paths that justify that canonical candidateSuggested placement:
<artifacts_dir>/deep_merge/
round-01_merge_record.md
round-01_candidate_inventory.md
round-02_merge_record.md
round-02_candidate_inventory.md
canonical_candidate_inventory.mdAlso write and continuously update the canonical merged discovery report at Codex Security's standard final discovery path:
<discovery_dir>/finding_discovery_report.mdThis report is not a selective promotion list, triage summary, or second consolidation layer. It is the lossless canonical merged candidate set in the same artifact shape that ordinary $codex-security:finding-discovery would hand to validation.
Validation and later phases must consume this canonical merged discovery report, not the raw per-worker discovery outputs and not a hand-pruned rewrite of the merged set.
Invariant:
canonical_candidate_inventory.md must also appear substantively in finding_discovery_report.mdcanonical_candidate_inventory.md must also appear in <reconciliation_dir>/deduped_candidates.jsonl and have a canonical <findings_dir>/<candidate_id>/candidate_ledger.jsonlfinding_discovery_report.md may improve wording, synthesize complementary evidence, and normalize candidate formatting, but it may not drop, suppress, or silently collapse a canonical candidateFor repository-wide scans, assemble the worker discovery support artifacts into canonical artifacts before validation. This is repository-wide workflow plumbing for Codex Security's normal downstream phases, not a second semantic merge, candidate triage layer, or reportability filter.
<discovery_dir>/rank_input.csv<discovery_dir>/deep_review_input.csv<context_dir>/seed_research.md<discovery_dir>/work_ledger.jsonl<discovery_dir>/raw_candidates.jsonl<reconciliation_dir>/dedupe_report.md<reconciliation_dir>/deduped_candidates.jsonl<findings_dir>/<candidate_id>/candidate_ledger.jsonl<coverage_dir>/repository_coverage_ledger.mdWrite the canonical consolidated versions back to the numbered standard paths above so $codex-security:validation receives the normal repository-wide inputs it expects.
These support-artifact assemblies are mechanical context assembly only:
finding_discovery_report.mdfinding_discovery_report.md, treat that as a consistency problem to repair before validation, not as authority to drop the candidateEnter the centralized tail only after the discovery loop has a recorded terminal state:
It is not valid to continue into validation, attack-path analysis, or final report assembly merely because:
Before the centralized tail begins, ensure the discovery artifacts contain the terminal evidence needed to justify it:
finding_discovery_report.md, with a one-to-one substantive correspondence to the final canonical candidate inventory<reconciliation_dir>/deduped_candidates.jsonl plus canonical <findings_dir>/<candidate_id>/candidate_ledger.jsonl records aligned one-to-one with the final canonical candidate inventorysaturated or cappedIf those artifacts or that terminal state are missing, resume the discovery loop or stop with an internal workflow failure. Do not finalize the scan.
Once the recorded terminal state is present:
finding_discovery_report.md against the underlying discovery evidence<reconciliation_dir>/deduped_candidates.jsonl and the canonical per-candidate ledgers match the same merged candidate set and preserve worker provenance<context_dir>/threat_model.md path<context_dir>/threat_model.md exists, then run $codex-security:validation once over the canonical merged discovery inputs$codex-security:attack-path-analysis once over the surviving validated findings and closure rows that require it../../references/final-report.mdDo not bypass validation simply because a candidate recurred across multiple discovery workers. Recurrence is search evidence, not reportability proof.
../../references/final-report.md, and include both final report paths in the response.saturated or capped.canonical_candidate_inventory.md and finding_discovery_report.md as a workflow failure. The discovery report may refine merged prose, but it may not omit canonical candidates before validation.canonical_candidate_inventory.md, <discovery_dir>/finding_discovery_report.md, <reconciliation_dir>/deduped_candidates.jsonl, and canonical per-candidate ledgers as a workflow failure. Centralized validation must receive one coherent canonical candidate set.affected_locations output as a worker-artifact defect that must be repaired before semantic merge. Lossless mechanical normalization is acceptable only for trivial equivalent variants such as line -> lines or file -> path; string-only locations or alternate location inventories that cannot be mapped without interpretation are incomplete worker outputs, not merge inputs.no thread with id, preserve the clean pre-round state, retry the full round once with the same canonical worker brief, and do not count the failed attempt toward round progress.© CoWork-OS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in resources/plugin-packs/codex-security/skills/deep-security-scan of CoWork-OS/CoWork-OS.
Open the folder on GitHubat commit 0ace02b
Deep Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deep Security Scan this skillCoWork-OS/CoWork-OS | 477 | — | ~8.6k | Automated safety check: Pass | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 520 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 157 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Threat Mitigation Mappingwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | |
| Audit Browser Security Boundariesnordstjernen-web/northstar-browser | 127 | — | ~920 | Automated safety check: Pass | GPL-3.0 | |
| Security Auditblueberrycongee/termcanvas | 405 | — | ~966 | Automated safety check: Notes | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
wshobson/agents
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
codexstar69/bug-hunter
Run a focused STRIDE-based security review using Bug Hunter-native artifacts.
CoWork-OS/CoWork-OS
Manage Calendly scheduling via the v2 API. An agent skill from CoWork-OS/CoWork-OS.
CoWork-OS/CoWork-OS
Rewrite AI-generated text to sound natural and human-written.
CoWork-OS/CoWork-OS
Comprehensive marketing strategy across 25 disciplines — positioning, copywriting frameworks, buyer psychology, SEO, CRO, paid ads, funnel architecture, content strategy, growth loops, analytics…
CoWork-OS/CoWork-OS
Interact with Moltbook — the social network for AI agents. An agent skill from CoWork-OS/CoWork-OS.
CoWork-OS/CoWork-OS
Query Polymarket prediction markets — search events, check odds and prices, view trending markets, track price momentum, get orderbook depth, analyze volume, and monitor market resolution timelines.
CoWork-OS/CoWork-OS
Create or update AgentSkills for CoWork-OSS. An agent skill from CoWork-OS/CoWork-OS.
Categories
A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Deep Security Scan is an agent skill from CoWork-OS/CoWork-OS. Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan.
Deep Security Scan fits situations like: the user asks for a deep; variance-reducing repository-wide Codex Security scan; working-tree diffs.
Run `npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a claude-code`. Or copy the skill folder (resources/plugin-packs/codex-security/skills/deep-security-scan in CoWork-OS/CoWork-OS) into .claude/skills/deep-security-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a codex`. Or copy the skill folder (resources/plugin-packs/codex-security/skills/deep-security-scan in CoWork-OS/CoWork-OS) into .agents/skills/deep-security-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CoWork-OS/CoWork-OS --skill deep-security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-security-scan, .gemini/skills/deep-security-scan, .github/skills/deep-security-scan and .opencode/skills/deep-security-scan in your project.
SKILL.md names no scripts, command-line tools or credentials: Deep Security Scan is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Deep Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.6k tokens (SKILL.md is roughly 35k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deep Security Scan: Commit Security Scan (codexstar69/bug-hunter, 520 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
CoWork-OS (a GitHub organization) maintains it in CoWork-OS/CoWork-OS, which has 477 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 9, 2026.
Source: CoWork-OS/CoWork-OS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.