Agent skill

Contributor Screen

by different-ai in different-ai/openwork

Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.

Custom licenceAuto-check: warningsDevelopment

Install Contributor Screen

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add different-ai/openwork --skill contributor-screen -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install different-ai/openwork contributor-screen --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/different-ai/openwork.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.warden/skills/contributor-screen .claude/skills/contributor-screen && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contributor-screen
GitHub stars
24k
Token cost
~939 tokens
SKILL.md length
535 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.

  • Tasks that involve Supply chain security
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Pull requests

What it does

Contributor Screen is an agent skill from different-ai/openwork. Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Supply chain security and Pull requests. The repository describes itself as: The open-source alternative to Claude Cowork (powered by opencode).

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Pull requests

Example prompts

  • “/contributor-screen”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob

What it can do on your machine

Read from SKILL.md and the folder at commit 9ce20f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contributor Screen loads about 939 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 535 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~939

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:38
    data, `~/.npmrc`, `~/.config`, or `/proc`; writing outside the project or
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:45
    kage.json` change; changed registries, `.npmrc`, `pnpm` overrides,

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 535 words (~939 tokens).

“This diff comes from someone outside the project. Nothing in it has run yet, and nothing in it is trusted.”

— opening of SKILL.md by different-ai, Custom licence
name
contributor-screen
allowed-tools
Read, Grep, Glob

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .warden/skills/contributor-screen of different-ai/openwork.

Open the folder on GitHubat commit 9ce20f8

Compare with similar skills

Contributor Screen next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contributor Screen compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contributor Screen this skilldifferent-ai/openwork24k—~939Automated safety check: WarnCustom licence
Renovate Actions PR Reviewbacknotprop/plannotator9.2k—~640Automated safety check: PassApache-2.0
PR Auditakitaonrails/my-skills212—~4.8kAutomated safety check: PassNone
Detecting Typosquatting Packagesmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
YugabyteDB Phorge Diff Creatoryugabyte/yugabyte-db11k—~3.1kAutomated safety check: PassCustom licence
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT

Similar skills

  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • PR Audit

    akitaonrails/my-skills

    Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation…

    212 GitHub stars~4.8k tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • YugabyteDB Phorge Diff Creator

    yugabyte/yugabyte-db

    Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo.

    11k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Bug Hunter

    codexstar69/bug-hunter

    Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

    519 GitHub stars~5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from different-ai/openwork

All 33 skills in this repo
  • OpenWork Desktop CDP Driver

    different-ai/openwork

    Drives a running OpenWork desktop window over CDP from the shell to evaluate JS, take screenshots, start sessions and send prompts for hand checks.

    24k GitHub stars~465 tokensUpdated today
    Auto-check passed
  • Fake Model Provider Faults

    different-ai/openwork

    Makes the desktop app's model provider fail on demand, with refused connections, resets, stalls and HTTP 4xx and 5xx errors, so error and retry states can be reproduced.

    24k GitHub stars~642 tokensUpdated today
    Auto-check passed
  • OpenWork Model Alias Manager

    different-ai/openwork

    Manages OpenWork's inference model aliases, discounts and overlays over the upstream OpenRouter catalog, and triggers the GitHub workflow that refreshes base models.

    24k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Reproduce Chat States

    different-ai/openwork

    Fires known chat states in the running OpenWork desktop app, such as provider errors, retries and tool steps, so you can check how each renders.

    24k GitHub stars~673 tokensUpdated today
    Auto-check passed
  • Attaches OpenCode browser tools to the OpenWork Electron dev app through CDP to explore its UI, send a composer task and debug, not to give test verdicts.

    24k GitHub stars~780 tokensUpdated today
    Auto-check passed
  • Daytona Sandbox Operations

    different-ai/openwork

    Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.

    24k GitHub stars~917 tokensUpdated today
    Auto-check passed

Questions about Contributor Screen

What does Contributor Screen do?

Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs. Contributor Screen is an agent skill from different-ai/openwork. Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs.

When should I use Contributor Screen?

Contributor Screen fits situations like: tasks that involve Supply chain security; tasks that involve Pull requests.

How do I install Contributor Screen in Claude Code?

Run `npx skills add different-ai/openwork --skill contributor-screen -a claude-code`. Or copy the skill folder (.warden/skills/contributor-screen in different-ai/openwork) into .claude/skills/contributor-screen in your project. Claude Code loads it when a task matches its description.

How do I install Contributor Screen in Codex?

Run `npx skills add different-ai/openwork --skill contributor-screen -a codex`. Or copy the skill folder (.warden/skills/contributor-screen in different-ai/openwork) into .agents/skills/contributor-screen in your project. Codex loads it when a task matches its description.

Can I use Contributor Screen in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add different-ai/openwork --skill contributor-screen -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contributor-screen, .gemini/skills/contributor-screen, .github/skills/contributor-screen and .opencode/skills/contributor-screen in your project.

What does Contributor Screen need to run?

SKILL.md names no scripts, command-line tools or credentials: Contributor Screen is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob.

Does Contributor Screen access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Contributor Screen safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Contributor Screen use?

Contributor Screen has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Contributor Screen use?

About 939 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Contributor Screen?

Skills that share tags, products or a category with Contributor Screen: Renovate Actions PR Review (backnotprop/plannotator, 9.2k stars), PR Audit (akitaonrails/my-skills, 212 stars), Detecting Typosquatting Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and YugabyteDB Phorge Diff Creator (yugabyte/yugabyte-db, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contributor Screen?

different-ai (a GitHub organization) maintains it in different-ai/openwork, which has 23,943 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 8, 2026.

Source: different-ai/openwork on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.