Openai Security Ownership Map
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install datopian/portaljs portaljs-add-dataset --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/portaljs-add-dataset .claude/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .claude/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-datasetType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install datopian/portaljs portaljs-add-dataset --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/portaljs-add-dataset .agents/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .agents/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install datopian/portaljs portaljs-add-dataset --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/portaljs-add-dataset .cursor/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .cursor/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/datopian/portaljs.git --path skills/portaljs-add-dataset--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install datopian/portaljs portaljs-add-dataset --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/portaljs-add-dataset .gemini/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .gemini/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install datopian/portaljs portaljs-add-datasetInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/portaljs-add-dataset .github/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .github/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add datopian/portaljs --skill portaljs-add-dataset -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install datopian/portaljs portaljs-add-dataset --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/datopian/portaljs.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/portaljs-add-dataset .opencode/skills/portaljs-add-dataset && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "portaljs-add-dataset" agent skill from https://github.com/datopian/portaljs/tree/main/skills/portaljs-add-dataset into .opencode/skills/portaljs-add-dataset/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "portaljs-add-dataset", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
portaljs-add-datasetAdd a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.
Portaljs Add Dataset is an agent skill from datopian/portaljs. Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal. Appends an entry to datasets.json so the catalog and showcase render it automatically; routes the data by source (local file vs remote URL) — R2 via Git LFS by default, remote URLs by passthrough. Use when registering a new dataset in a scaffolded portal.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/reference.md`). Compatibility notes: Claude Code with PortalJS portals (Next.js 14, React 18, Node 18+). Runs from any project via the plugin, a personal ~/.claude/commands install, or a portaljs…
It sits in Documents & Office, covering CSV and tabular files and Project scaffolding. It works with Git and npm. The repository describes itself as: 🌀 AI-native framework for building data portals. Scaffold a full portal from a brief and load datasets in minutes with agentic skills — any backend (CKAN, GitHub, Frictionless). The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d5c096a. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(npm:*)Bash(npx:*)Bash(git:*)Bash(curl:*)Bash(mkdir:*)Bash(cp:*)WebFetchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
data.portaljs.comAlso links to:
git-lfs.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code with PortalJS portals (Next.js 14, React 18, Node 18+). Runs from any project via the plugin, a personal ~/.claude/commands install, or a portaljs clone.
From compatibility in the SKILL.md frontmatter.
Portaljs Add Dataset loads about 1.6k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 675 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from datopian/portaljs at commit d5c096a, republished under its MIT licence (© datopian). 675 words, ~1,589 tokens.
.claude/skills/portaljs-add-dataset/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Register a dataset in a PortalJS (portaljs-catalog) portal. The skill appends one entry to
datasets.json — the single source of truth for the catalog — and routes the underlying
bytes by source first, then size: a local file defaults to R2 via Git LFS, a remote URL
defaults to passthrough (no copy). No per-dataset page is created; the catalog at /search
lists the new entry and the dynamic showcase route pages/[owner]/[slug].tsx renders it
automatically at /@<namespace>/<slug>. Supported formats for the showcase preview: CSV,
TSV, JSON (array), and GeoJSON.
portaljs-new-portal) with datasets.json,
package.json, and pages/[owner]/[slug].tsx present.git and git-lfs installed, and an Arc account token
(or an OSS Giftless key) to mint a push-scoped LFS credential.The canonical, full step-by-step workflow is
.claude/commands/portaljs-add-dataset.md —
the single source of truth. Read and follow it when executing. Summary:
$ARGUMENTS — source (file path or URL), portal directory (default
.), dataset name/slug, description, namespace. If the source is missing, interview the
user; never dead-end.datasets.json, package.json, and
pages/[owner]/[slug].tsx exist.Content-Type header
(CSV, TSV, JSON array, or GeoJSON); reject anything else and ask for a conversion.public/data/ (fenced exception for
bundled samples or an OSS-no-R2 fallback).datasets.json — slug, namespace, name, description, file
(the routed path/URL), format — keeping (namespace, slug) unique.npx next build; fix errors (commonly malformed JSON) before
reporting success.datasets.json (one entry appended).data/<slug>.<ext> tracked via Git LFS (R2 default), or
public/data/<slug>.<ext> (inline exception). Nothing is created for remote passthrough.npx next build passes./search and renders at /@<namespace>/<slug>.| Symptom | Cause | Fix |
|---|---|---|
| Fetch fails for a URL source | Non-200 status or unreachable host | Report the HTTP status and ask the user to confirm the URL is publicly accessible. |
| "Not a portaljs-catalog portal" | datasets.json missing | This is an older single-page template; ask the user how to proceed rather than failing silently. |
| Unsupported format | Extension/content-type isn't csv/tsv/json/geojson | Ask the user to convert the source before continuing. |
git lfs push has nothing to stream | git lfs install --local never ran, so raw bytes were committed instead of a pointer | Run git lfs install --local before git lfs track, re-add and re-commit the file. |
| R2 PUT returns 400 | A broad http.extraHeader was set and replayed onto the presigned URL | Use the _jwt Basic-auth piggyback in lfs.url only — never a global http.extraHeader. |
(namespace, slug) clash | Another entry already uses that pair | Ask the user for a different slug or namespace. |
next build fails | Malformed JSON in datasets.json | Print the build log, fix the JSON, rebuild before reporting success. |
/portaljs-add-dataset ./data/co2-emissions.csv namespace=climateMoves the file into data/, tracks it with Git LFS, pushes it to R2, and appends a manifest
entry whose file is the resulting https://data.portaljs.com/... URL.
/portaljs-add-dataset https://example.org/open-data/trade.csv namespace=tradeDetects the format from the response headers and records the URL as-is in datasets.json —
no bytes are copied.
/portaljs-add-dataset https://example.org/boundaries.geojson namespace=reference adopt=trueDownloads the file, then routes it as a local file through the Git LFS → R2 path so it is hosted and versioned under the portal (useful when in-browser range queries are needed).
/portaljs-add-dataset ./samples/demo.csv namespace=referenceWhen the portal has no R2 credentials (OSS self-host) or the file is bundled sample data,
the skill copies it into public/data/ instead, per the .gitattributes inline fence.
.claude/commands/portaljs-add-dataset.mdreferences/reference.mdportaljs-new-portal, portaljs-add-chart, portaljs-add-map, portaljs-define-schema© datopian, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/portaljs-add-dataset of datopian/portaljs.
Open the folder on GitHubat commit d5c096a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in datopian/portaljs, which our catalogue first saw on October 7, 2026.
Portaljs Add Dataset next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Portaljs Add Dataset this skilldatopian/portaljs | 2.4k | 1 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Openai Security Ownership Maptrailofbits/skills-curated | 513 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Slidev CLI Skilldskilld-dev/vue-ecosystem-skills | 181 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Download Statsnubjs/nub | 4.4k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Deadline Prepdavila7/claude-code-templates | 32k | — | ~739 | Automated safety check: Pass | MIT | |
| Init Projectflonat/flonat-research | 146 | — | ~929 | Automated safety check: Pass | MIT |
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
skilld-dev/vue-ecosystem-skills
Build, present, and ship Slidev decks with @slidev/cli. An agent skill from skilld-dev/vue-ecosystem-skills.
nubjs/nub
Generate download-stats CSVs and a chart for nub across its distribution channels (npm + GitHub release assets, which subsume Homebrew).
davila7/claude-code-templates
Generate a structured demo outline from your session's change log and git history.
flonat/flonat-research
Bootstrap a new research project. An agent skill from flonat/flonat-research.
kepano/obsidian-skills
Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.
datopian/portaljs
Migrate a whole ArcGIS Hub site into a PortalJS Arc portal end-to-end.
datopian/portaljs
Add a chart (line, bar, area, pie, or scatter) to a dataset's showcase in a PortalJS portal.
datopian/portaljs
Make a PortalJS portal harvestable by national/EU/US open-data portals — emit standards-compliant DCAT catalog feeds (DCAT 2/3, DCAT-AP, DCAT-US, national profiles) in JSON-LD, Turtle, and RDF/XML…
datopian/portaljs
Auto-ingest a geospatial file (GeoJSON, Shapefile, GeoPackage, KML/KMZ, FlatGeobuf, CSV-with-geometry) into a PortalJS portal on the user's own machine, with no server.
datopian/portaljs
Render a GeoJSON dataset on an interactive Leaflet map in the Views section of a dataset's showcase.
datopian/portaljs
Add another file (resource) to an EXISTING dataset in a PortalJS portal — a data dictionary, methodology, or an additional data file.
Categories
Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal. Portaljs Add Dataset is an agent skill from datopian/portaljs. Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.
Portaljs Add Dataset fits situations like: registering a new dataset in a scaffolded portal; tasks that involve CSV and tabular files; tasks that involve Project scaffolding.
Run `npx skills add datopian/portaljs --skill portaljs-add-dataset -a claude-code`. Or copy the skill folder (skills/portaljs-add-dataset in datopian/portaljs) into .claude/skills/portaljs-add-dataset in your project. Claude Code loads it when a task matches its description.
Run `npx skills add datopian/portaljs --skill portaljs-add-dataset -a codex`. Or copy the skill folder (skills/portaljs-add-dataset in datopian/portaljs) into .agents/skills/portaljs-add-dataset in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add datopian/portaljs --skill portaljs-add-dataset -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/portaljs-add-dataset, .gemini/skills/portaljs-add-dataset, .github/skills/portaljs-add-dataset and .opencode/skills/portaljs-add-dataset in your project.
Going by SKILL.md and its folder, Portaljs Add Dataset needs the command-line tools its instructions call (git and npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Bash(npx:*), Bash(git:*), Bash(curl:*), Bash(mkdir:*), Bash(cp:*), WebFetch. Compatibility (from SKILL.md): Claude Code with PortalJS portals (Next.js 14, React 18, Node 18+). Runs from any project via the plugin, a personal ~/.claude/commands install, or a portaljs clone..
SKILL.md names 2 domains. In commands or code: data.portaljs.com; the agent is likely to contact it when it follows the instructions. As links in the text: git-lfs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Portaljs Add Dataset is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 914 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Portaljs Add Dataset: Openai Security Ownership Map (trailofbits/skills-curated, 513 stars), Slidev CLI Skilld (skilld-dev/vue-ecosystem-skills, 181 stars), Download Stats (nubjs/nub, 4.4k stars) and Deadline Prep (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
datopian (a GitHub organization) maintains it in datopian/portaljs, which has 2,358 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.
Source: datopian/portaljs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.