Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Look up a vulnerability by ID or list all vulnerabilities for a package
$ npx skills add davepoon/buildwithclaude --skill vuln -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install davepoon/buildwithclaude vuln --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .claude/skills/vuln && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .claude/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vulnType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add davepoon/buildwithclaude --skill vuln -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install davepoon/buildwithclaude vuln --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .agents/skills/vuln && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .agents/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill vuln -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install davepoon/buildwithclaude vuln --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .cursor/skills/vuln && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .cursor/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/davepoon/buildwithclaude.git --path plugins/vulnetix/skills/vuln--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add davepoon/buildwithclaude --skill vuln -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install davepoon/buildwithclaude vuln --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .gemini/skills/vuln && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .gemini/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install davepoon/buildwithclaude vulnInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add davepoon/buildwithclaude --skill vuln -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .github/skills/vuln && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .github/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill vuln -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install davepoon/buildwithclaude vuln --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .opencode/skills/vuln && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vuln" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/vuln into .opencode/skills/vuln/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulnLook up a vulnerability by ID or list all vulnerabilities for a package
Vuln is an agent skill from davepoon/buildwithclaude. Look up a vulnerability by ID or list all vulnerabilities for a package
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 10bfc43. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGlobGrepEditWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghpipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vuln loads about 3.6k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 1,509 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Glob, Grep, Edit, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from davepoon/buildwithclaude at commit 10bfc43, republished under its MIT licence (© davepoon). 1,509 words, ~3,601 tokens.
.claude/skills/vuln/SKILL.md (or your agent's skills folder).This skill serves two purposes based on the argument provided:
This skill does not modify application code -- it only updates .vulnetix/memory.yaml to track findings. Use /vulnetix:fix for remediation, /vulnetix:exploits for exploit analysis, or /vulnetix:remediation for a context-aware remediation plan.
Determine the mode from the argument:
Vuln lookup mode -- argument matches any known vulnerability identifier pattern:
CVE-* (e.g., CVE-2021-44228)GHSA-* (e.g., GHSA-jfh8-3a1q-hjz9)PYSEC-*, GO-*, RUSTSEC-*, EUVD-*, OSV-*, GSD-*, VDB-*, GCVE-*SNYK-*, ZDI-*, MSCVE-*, MSRC-*, RHSA-*, TALOS-*, EDB-*WORDFENCE-*, PATCHSTACK-*, MFSA*, JVNDB-*, CNVD-*, BDU:*, HUNTR-*DSA-*, DLA-*, USN-*, ALSA-*, RLSA-*, MGASA-*, OPENSUSE-*, FreeBSD-*, BIT-*The VDB accepts 78+ identifier formats in total.
Package vulns mode -- argument does not match any vuln-id pattern. Treat it as a package name.
If ambiguous, prefer vuln lookup mode (vuln IDs are more structured). If the vuln lookup returns an error or empty response, fall back to package vulns mode automatically.
This skill reads and updates the .vulnetix/memory.yaml file in the repository root. This file is shared with /vulnetix:fix, /vulnetix:exploits, /vulnetix:package-search, /vulnetix:exploits-search, and /vulnetix:remediation.
The canonical schema is defined in /vulnetix:fix. This skill creates or updates base vulnerability fields: aliases, package, ecosystem, discovery, versions, severity, safe_harbour, and status. It does not modify threat_model or cwss (owned by /vulnetix:exploits).
At the start of every invocation:
.vulnetix/memory.yaml exists in the repo root.vulnetix/scans/*.cdx.json -- if CycloneDX SBOMs exist from prior scans, cross-reference for additional contextPreviously seen: <vulnId> -- <developer-friendly status> (as of <date>)
Priority: <P1/P2/P3/P4> (<score>) -- "<priority description>" (if cwss data exists)
Last decision: <developer-friendly decision> -- "<reason>"
Dependabot: <alert state, PR state if available>Known history for <package>:
- CVE-2021-44228 -- Fixed (2024-01-15), P1 (87.5)
- CVE-2023-1234 -- Investigating (2024-03-01)Vuln lookup mode (after Step L6):
status: under_investigation, decision.choice: investigating, discovery.source: userseverity and safe_harbour if newer. Do NOT change status or decision.history: event: lookupPackage vulns mode (after Step P7):
For each vulnerability that affects the installed version and is not already tracked:
status: under_investigation, decision.choice: investigating, discovery.source: scan, decision.reason: "Discovered via /vulnetix:vuln <package>"history: event: discoveredFor existing entries, do not change status or decision -- only update severity if newer.
Use developer-friendly language when surfacing status:
not_affected --> "Not affected"affected --> "Vulnerable"fixed --> "Fixed"under_investigation --> "Investigating"When gh CLI is available (check with gh auth status 2>/dev/null), query Dependabot alerts to enrich the output.
Vuln lookup mode: Query alerts matching the vuln ID:
gh api repos/{owner}/{repo}/dependabot/alerts --jq '[.[] | select(.security_advisory.cve_id == "'"$ARGUMENTS"'" or .security_advisory.ghsa_id == "'"$ARGUMENTS"'")] | first'Package vulns mode: Query alerts for the package:
gh api repos/{owner}/{repo}/dependabot/alerts?state=open --jq '[.[] | select(.dependency.package.name == "'"$PACKAGE_NAME"'")] | length'Use this workflow when the argument matches a vulnerability identifier pattern.
Check for and load .vulnetix/memory.yaml as described in "Reading Prior State" above. Display any prior state before proceeding.
vulnetix vdb vuln "$ARGUMENTS" -o jsonCLI Reference (from vulnetix vdb vuln docs):
-o json returns machine-readable outputExtract: identity, aliases, description, dates, CVSS vectors/scores, EPSS, KEV status/deadline, CWE IDs, affected products with version ranges and fixed versions, reference URLs.
vulnetix vdb metrics "$ARGUMENTS" -o jsonCLI Reference (from vulnetix vdb metrics docs):
Merge with Step L2 data. If this call fails, continue with Step L2 data alone.
Use Glob and Grep to assess repo impact:
Detect manifest files:
package.json, package-lock.json, yarn.lock, pnpm-lock.yaml --> npmgo.mod, go.sum --> goCargo.toml, Cargo.lock --> cargorequirements.txt, pyproject.toml, Pipfile, poetry.lock, uv.lock --> pypiGemfile, Gemfile.lock --> rubygemspom.xml, build.gradle, gradle.lockfile --> mavencomposer.json, composer.lock --> packagistSearch for affected packages from VDB response using Grep in manifests/lockfiles
Determine installed version (lockfile --> manifest --> installed artifacts --> unknown). Report source transparently.
Assess dependency relationship -- direct vs transitive, whether installed version is in vulnerable range
Cross-reference CycloneDX SBOMs in .vulnetix/scans/*.cdx.json
Identity:
<Vuln ID> (<alias1>, <alias2>, ...)
<Description -- first 2-3 sentences>
Published: <date> | Modified: <date>Severity Table:
| Metric | Score | Vector |
|---|---|---|
| CVSS v3.1 | 10.0 (Critical) | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVSS v4.0 | 10.0 (Critical) | ... |
| EPSS | 0.97 (97% chance of exploitation within 30 days) | -- |
| CISA KEV | Listed (deadline: YYYY-MM-DD) | -- |
Affected Packages:
| Package | Ecosystem | Vulnerable Range | Fixed In |
|---|---|---|---|
| log4j-core | maven | < 2.17.1 | 2.17.1 |
Repository Impact:
| Package | Installed Version | Source | Affected? | Relationship |
|---|---|---|---|---|
| log4j-core | 2.14.1 | lockfile: pom.xml | Yes (in range) | Direct |
If no affected packages found: "No affected packages detected in this repository."
References: List top advisory and reference URLs.
Next Steps:
/vulnetix:exploits $ARGUMENTS for exploit intelligence and threat modeling"/vulnetix:fix $ARGUMENTS for fix intelligence and manifest edits"/vulnetix:remediation $ARGUMENTS for a context-aware remediation plan"/vulnetix:exploits-search --ecosystem <eco> to discover related exploited vulnerabilities"Update .vulnetix/memory.yaml as described in "Writing Updated State" above. If the user provides a decision during the conversation, record it using the risk treatment categories defined in /vulnetix:exploits.
Use this workflow when the argument does not match a vulnerability identifier pattern.
Check for and load .vulnetix/memory.yaml. Display any known history for the queried package before proceeding.
Use Glob to identify manifest files (same manifest list as Step L4 above). Determine which ecosystems the repository uses.
Determine if the queried package is installed. Resolve using the priority chain:
package-lock.json, yarn.lock, pnpm-lock.yamlpoetry.lock, Pipfile.lock, uv.lockgo.sumCargo.lockGemfile.lockgradle.lockfilecomposer.locknode_modules/<pkg>/package.json, pip show <pkg>)If not installed: "Not currently installed -- no existing version detected."
Version Source Label: 4.17.1 (from lockfile: package-lock.json), ^4.17.0 (from manifest: package.json -- constraint, not exact), Not installed
vulnetix vdb vulns "$ARGUMENTS" -o jsonCLI Reference (from vulnetix vdb vulns docs):
--limit int -- Maximum results (default 100)--offset int -- Results to skip for pagination (default 0)-o, --output string -- Output format: json or pretty (default "pretty")Pagination modifiers -- parse user message:
--limit 20--offset <previous_offset + limit>--limit 500Vulnerabilities for <package>@<version> (<version source>)
Total: N known vulnerabilities (M affect your version)
| # | ID | Severity | Affects You? | Fixed In | Status | EPSS |
|---|-----------------|----------|-------------|----------|--------------|-------|
| 1 | CVE-2024-XXXXX | critical | Yes | 4.18.3 | -- | 0.45 |
| 2 | CVE-2023-YYYYY | high | Yes | 4.17.3 | Fixed | 0.12 |
| 3 | CVE-2022-ZZZZZ | medium | No (>=4.17) | 4.17.0 | -- | 0.03 |Summary: M of N affect your version -- X critical, Y high, Z medium
Pagination info (if truncated): Showing 1-20 of 47. Say "next page" or "page 3" for more.
Actionable recommendations:
"Run /vulnetix:fix <vuln-id> to remediate" or "Run /vulnetix:remediation <vuln-id> for a context-aware remediation plan""Run /vulnetix:exploits <vuln-id> for exploit analysis""Run /vulnetix:vuln <vuln-id> for detailed vulnerability info""Run /vulnetix:exploits-search --ecosystem <eco> to find exploited vulnerabilities in your ecosystem"Update .vulnetix/memory.yaml as described in "Writing Updated State" above. Only create stub entries for vulns that affect the installed version to prevent memory file bloat.
Vuln lookup mode:
vdb vuln returns error/empty, try falling back to package vulns mode (the argument might be a package name)vdb metrics fails, continue with vdb vuln data alonePackage vulns mode:
vdb vulns returns error, suggest checking vulnetix vdb status<package>. This doesn't guarantee safety -- the package may not be indexed yet."/vulnetix:package-searchBoth modes:
.vulnetix/memory.yaml cannot be written, warn but do not block/vulnetix:fix or /vulnetix:remediation for that/vulnetix:exploits for single-vuln analysis or /vulnetix:exploits-search for broad discovery.vulnetix/memory.yaml after the lookup© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/vulnetix/skills/vuln of davepoon/buildwithclaude.
Open the folder on GitHubat commit 10bfc43
Vuln next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vuln this skilldavepoon/buildwithclaude | 3.6k | — | ~3.6k | Automated safety check: Notes | MIT | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 480 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
davepoon/buildwithclaude
A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…
davepoon/buildwithclaude
Activate this agent for any future-oriented question that requires deep quantitative analysis, historical precedents, and structured scenario planning.
davepoon/buildwithclaude
Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.
davepoon/buildwithclaude
Download YouTube videos with customizable quality and format options.
davepoon/buildwithclaude
Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.
davepoon/buildwithclaude
Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.
Categories
Look up a vulnerability by ID or list all vulnerabilities for a package. Vuln is an agent skill from davepoon/buildwithclaude.
Vuln fits situations like: security work in your project.
Run `npx skills add davepoon/buildwithclaude --skill vuln -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/vuln in davepoon/buildwithclaude) into .claude/skills/vuln in your project. Claude Code loads it when a task matches its description.
Run `npx skills add davepoon/buildwithclaude --skill vuln -a codex`. Or copy the skill folder (plugins/vulnetix/skills/vuln in davepoon/buildwithclaude) into .agents/skills/vuln in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill vuln -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln, .gemini/skills/vuln, .github/skills/vuln and .opencode/skills/vuln in your project.
Going by SKILL.md and its folder, Vuln needs the command-line tools its instructions call (gh and pip). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Edit, Write.
SKILL.md contains no URLs. Its commands use gh and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Vuln is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vuln: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,604 GitHub stars. The repository holds 245 skills in this directory. The repository was last updated on October 6, 2026.
Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.