Security Advisory
MidnightBSD/src
Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…
Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .claude/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .claude/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .agents/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .agents/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .cursor/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .cursor/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/eclipse-ankaios/ankaios.git --path .github/skills/security-vulnerability-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .gemini/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .gemini/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .github/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .github/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .opencode/skills/security-vulnerability-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-vulnerability-analysis" agent skill from https://github.com/eclipse-ankaios/ankaios/tree/main/.github/skills/security-vulnerability-analysis into .opencode/skills/security-vulnerability-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vulnerability-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-vulnerability-analysisAnalyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.
Security Vulnerability Analysis is an agent skill from eclipse-ankaios/ankaios. Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. Use for security report triage, safe reproduction, CVE recommendations, CVSS 3.1 and CVSS 4.0 scoring, CWE and CAPEC classification, embargo planning, Eclipse Foundation CVE requests, and GitHub security advisories.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/disclosure-workflow.md`, `references/scoring-and-classification.md` and `scripts/calculate_cvss.py`).
It sits in Security, covering Vulnerability scanning. It works with GitHub. The repository describes itself as: Eclipse Ankaios provides workload and container orchestration for embedded devices like automotive HPCs. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ae46412. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Vulnerability Analysis loads about 1.5k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 744 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from eclipse-ankaios/ankaios at commit ae46412, republished under its Apache-2.0 licence (© eclipse-ankaios). 744 words, ~1,489 tokens.
.claude/skills/security-vulnerability-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Guide the user through evidence-based vulnerability triage and coordinated disclosure. Treat all non-public report details as confidential until publication.
Accept any of these inputs:
For a URL, use available authenticated GitHub tooling only when it already has access. A GitHub extension is optional: it can make private advisory retrieval easier, but it does not grant permission by itself. Never request credentials or tokens in chat. If the advisory cannot be accessed, ask the user to paste its description and omit unnecessary confidential or personal data.
Before analysis, establish:
Do not dismiss an issue merely because one proof-of-concept input has limited impact. Distinguish that observation from nearby inputs and platform behavior that could produce the claimed impact.
Follow the stages in order. At each stage, distinguish verified facts, reasoned conclusions, assumptions, and unknowns.
Inspect the smallest relevant code path, configuration, release behavior, and available evidence. Identify:
Give a preliminary result of one of:
Likely vulnerabilitySecurity hardening / defense in depthLikely non-security bugInsufficient evidenceExplain what evidence would change the result. This is a recommendation, not the Eclipse Foundation Security Team's final classification.
If the issue is likely non-security, stop before exploit development unless the user asks to continue. Recommend normal defect handling without disclosing confidential report details.
If the issue remains plausibly security-related, try to reproduce it locally when the environment can be isolated and recovery is understood. Otherwise give the user exact reproduction and evidence-collection steps.
Before running a proof of concept:
Collect evidence for both the vulnerable behavior and the security boundary impact. Re-test a patched build with the same behavior-focused check. Never place embargoed details in public logs, issues, branches, CI, or commit messages.
Use scoring and classification guidance.
Produce:
request, probably request, probably not, or not enough evidence.Use Eclipse and GitHub workflow as the source of truth for sequencing, gates, and embargo constraints. Produce a status-aware checklist showing only applicable pending steps, their prerequisites, owner if known, and the information needed to complete each one.
Return a living assessment with these sections:
Confidentiality statusExecutive assessmentEvidence and unknownsReproduction result or planSecurity boundary and impactCVE recommendationCVSS v3.1CVSS v4.0CWE and CAPEC mappingsFix and regression-test requirementsEclipse/GitHub follow-up checklistInclude vectors alongside scores. Mark preliminary outputs clearly and update them when new evidence changes the analysis.
© eclipse-ankaios, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in .github/skills/security-vulnerability-analysis of eclipse-ankaios/ankaios.
Open the folder on GitHubat commit ae46412
Security Vulnerability Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Vulnerability Analysis this skilleclipse-ankaios/ankaios | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Security AdvisoryMidnightBSD/src | 114 | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Warp Vulnerability Triagewarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cve Doctorgetlago/lago-front | 163 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Deal With Security Advisorypaperclipai/paperclip | 99k | — | ~2k | Automated safety check: Pass | MIT | |
| Snapshotboostsecurityio/poutine | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 |
MidnightBSD/src
Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
getlago/lago-front
Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.
paperclipai/paperclip
Handle confidential GitHub Security Advisory response for Paperclip.
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
openshift-eng/ai-helpers
Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.
eclipse-ankaios/ankaios
Check Ankaios examples by building and running each example in the devcontainer and validating they work correctly.
eclipse-ankaios/ankaios
Manage requirement tracing — write new or update existing requirements/design decisions, link implementations and tests to existing ones, and maintain tracing consistency.
eclipse-ankaios/ankaios
Check Ankaios tutorials by executing safe documented shell steps and validating expected outputs.
Works with
Categories
Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. Security Vulnerability Analysis is an agent skill from eclipse-ankaios/ankaios. Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.
Security Vulnerability Analysis fits situations like: security report triage; safe reproduction; CVE recommendations; CVSS 3.1 and CVSS 4.0 scoring.
Run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a claude-code`. Or copy the skill folder (.github/skills/security-vulnerability-analysis in eclipse-ankaios/ankaios) into .claude/skills/security-vulnerability-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a codex`. Or copy the skill folder (.github/skills/security-vulnerability-analysis in eclipse-ankaios/ankaios) into .agents/skills/security-vulnerability-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-vulnerability-analysis, .gemini/skills/security-vulnerability-analysis, .github/skills/security-vulnerability-analysis and .opencode/skills/security-vulnerability-analysis in your project.
Going by SKILL.md and its folder, Security Vulnerability Analysis needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Vulnerability Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Vulnerability Analysis: Security Advisory (MidnightBSD/src, 114 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Cve Doctor (getlago/lago-front, 163 stars) and Deal With Security Advisory (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
eclipse-ankaios (a GitHub organization) maintains it in eclipse-ankaios/ankaios, which has 125 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.
Source: eclipse-ankaios/ankaios on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.