Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).
$ npx skills add epam/ai-dial-chat --skill dep-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install epam/ai-dial-chat dep-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dep-triage .claude/skills/dep-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .claude/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add epam/ai-dial-chat --skill dep-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install epam/ai-dial-chat dep-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/dep-triage .agents/skills/dep-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .agents/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add epam/ai-dial-chat --skill dep-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install epam/ai-dial-chat dep-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/dep-triage .cursor/skills/dep-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .cursor/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/epam/ai-dial-chat.git --path .claude/skills/dep-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add epam/ai-dial-chat --skill dep-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install epam/ai-dial-chat dep-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/dep-triage .gemini/skills/dep-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .gemini/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install epam/ai-dial-chat dep-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add epam/ai-dial-chat --skill dep-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/dep-triage .github/skills/dep-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .github/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add epam/ai-dial-chat --skill dep-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install epam/ai-dial-chat dep-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/dep-triage .opencode/skills/dep-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dep-triage" agent skill from https://github.com/epam/ai-dial-chat/tree/development/.claude/skills/dep-triage into .opencode/skills/dep-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dep-triageReviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).
Dep Triage is an agent skill from epam/ai-dial-chat. Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context). Use after /dep-scan emits CVE findings; reduces reviewer noise before human review.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning and Codebase knowledge for agents. The repository describes itself as: A default UI for AI DIAL. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3455656. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dep Triage loads about 1.6k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 662 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from epam/ai-dial-chat at commit 3455656, republished under its Apache-2.0 licence (© epam). 662 words, ~1,613 tokens.
.claude/skills/dep-triage/SKILL.md (or your agent's skills folder).Reads upstream scan findings, evaluates each in the repo's actual usage
context, and emits the same findings augmented with triage_outcome
(confirmed | false_positive) and a one-sentence triage_reason.
This is the triage step — does not run scanners itself. Always
downstream of /dep-scan (or another scan agent emitting the same
finding shape: cve, package, installed_version, fixed_version).
/dep-scan in a chained agent (needs: [scan-deps]).Read, Grep, Glob — to inspect repo source for package usageBash(git diff:*) — to scope which dependencies the PR touchedSkill — invocation onlyWrite — auto-granted; for stage-output.jsonupstream/scan-deps/stage-output.json — scan findings from the
upstream scan-deps agent (or compatible scanner)For each finding under payload.findings[]:
triage_outcome: confirmed)Mark confirmed if all three hold:
apps/, libs/, or
packages/.triage_outcome: false_positive)Mark FP if any one of these holds:
devDependencies /
peerDependencies and not exposed at build/runtime (test fixtures,
type generators, bundler internals).apps/, libs/, or
packages/.If you can't establish FP via one of the rules above, mark
confirmed. Better one extra reviewer click than missing a real CVE.
Capture uncertainty in triage_reason so the reviewer can re-evaluate
quickly.
Read upstream output. upstream/scan-deps/stage-output.json —
parse payload.findings[].
For each finding, follow the rubric:
Grep to find imports of package in apps/, libs/,
packages/.Read the importing files to check whether the
vulnerable API is actually used.package.json files to determine dependencies vs
devDependencies (path matters — root package.json vs
workspace package.jsons differ in semantics).pnpm-lock.yaml /
package-lock.json for pinned-safe versions.Augment each finding with two new fields:
triage_outcome: "confirmed" or "false_positive"triage_reason: one short sentence explaining the call. Reference
the rule number (1-5) for FPs.Recompute summary. Update the top-level summary field to
reflect post-triage counts:
"trivy: <N> raw → <C> confirmed, <F> false_positive".
Same top-level shape as the upstream scan, with two augmentations:
{
"stage": "triage-deps",
"status": "<see below>",
"summary": "trivy: <N> raw → <C> confirmed, <F> false positive",
"payload": {
"findings": [
{
"severity": "high",
"file": "package-lock.json",
"message": "<CVE>: ... (unchanged from scan)",
"suggested_fix": "...",
"cve": "...",
"package": "lodash",
"installed_version": "4.17.20",
"fixed_version": "4.17.21",
"triage_outcome": "confirmed",
"triage_reason": "Imported by libs/foo and the vulnerable .pickBy() is called in src/utils/groupBy.ts."
},
{
"severity": "high",
"file": "package-lock.json",
"message": "<CVE>: ...",
...,
"triage_outcome": "false_positive",
"triage_reason": "FP rule 2: vulnerable .template() function is not called anywhere under apps/ or libs/."
}
],
"triage_summary": {
"raw": <N>,
"confirmed": <C>,
"false_positive": <F>
}
}
}passed — all findings false_positive (no confirmed real risks)passed_with_findings — confirmed findings exist but only at
info/low/medium severityfailed — any confirmed finding at high or critical severityDo not downgrade severity. A confirmed-but-low-likelihood finding keeps its original severity (high/critical); the human reviewer decides whether to accept the risk. Triage filters the noise; it does not soften the signal.
libs/. A focused Grep for from '<package>' or
require('<package>') scopes the work.triage_reason. A future scheduled
re-triage can diff outcomes only if the reasoning is preserved.Emit all findings (confirmed and FP) under payload.findings[] for
the artifact — the artifact is the audit trail. The renderer (which
posts the sticky PR comment) can filter to confirmed-only for the
human view; the artifact retains the full record.
© epam, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/dep-triage of epam/ai-dial-chat.
Open the folder on GitHubat commit 3455656
Dep Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dep Triage this skillepam/ai-dial-chat | 504 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT | |
| Cve Remediationrundeck/rundeck | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
evdenis/cvehound
Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.
epam/ai-dial-chat
Deep codebase refactoring audit for AI DIAL Chat. An agent skill from epam/ai-dial-chat.
epam/ai-dial-chat
Read unresolved GitHub code review threads for the pull request associated with the current branch, classify each comment, and implement and verify required code fixes.
epam/ai-dial-chat
Interactively create OR update GitHub issues (Bug, Feature, Task) for the current repository.
epam/ai-dial-chat
Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.
epam/ai-dial-chat
Design-to-code workflow for Figma designs. An agent skill from epam/ai-dial-chat.
epam/ai-dial-chat
A skill your agent uses whenever the user wants to commit, push, or ship changes in a git repository.
Categories
Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context). Dep Triage is an agent skill from epam/ai-dial-chat. Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).
Dep Triage fits situations like: tasks that involve Vulnerability scanning; tasks that involve Codebase knowledge for agents.
Run `npx skills add epam/ai-dial-chat --skill dep-triage -a claude-code`. Or copy the skill folder (.claude/skills/dep-triage in epam/ai-dial-chat) into .claude/skills/dep-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add epam/ai-dial-chat --skill dep-triage -a codex`. Or copy the skill folder (.claude/skills/dep-triage in epam/ai-dial-chat) into .agents/skills/dep-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add epam/ai-dial-chat --skill dep-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-triage, .gemini/skills/dep-triage, .github/skills/dep-triage and .opencode/skills/dep-triage in your project.
SKILL.md names no scripts, command-line tools or credentials: Dep Triage is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dep Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dep Triage: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
epam (a GitHub organization) maintains it in epam/ai-dial-chat, which has 504 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.
Source: epam/ai-dial-chat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.