Php Framework Audit
wgpsec/AboutSecurity
PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。
A skill your agent uses when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins…
$ npx skills add ericrisco/rsc-harness --skill wordpress -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness wordpress --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wordpress .claude/skills/wordpress && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .claude/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpressType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill wordpress -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness wordpress --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/wordpress .agents/skills/wordpress && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .agents/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill wordpress -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness wordpress --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/wordpress .cursor/skills/wordpress && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .cursor/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/wordpress--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill wordpress -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness wordpress --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/wordpress .gemini/skills/wordpress && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .gemini/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness wordpressInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill wordpress -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/wordpress .github/skills/wordpress && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .github/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill wordpress -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness wordpress --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/wordpress .opencode/skills/wordpress && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wordpress" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/wordpress into .opencode/skills/wordpress/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wordpressA skill your agent uses when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins…
Wordpress is an agent skill from ericrisco/rsc-harness. Use when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins with block.json and proper hooks, wp-config security hardening, performance (object cache, asset loading, autoloaded options), and WP-CLI operations. NOT a Laravel app (that is laravel).
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/hardening.md`).
It sits in Backend & APIs, covering Backend development and Security review. It works with WordPress, PHP, Laravel and WooCommerce. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
schemas.wp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AUTH_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wordpress loads about 3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,046 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,046 words, ~2,967 tokens.
.claude/skills/wordpress/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You are building the WordPress application layer — themes, plugins, the dashboard/CLI surface, security, and stores — for someone treating WordPress as the product. Know the difference between a functions.php hack and a real plugin. Refuse to paste secrets into the dashboard file editor. Pick block themes over page builders by default. Reach for wp before clicking through wp-admin.
This is not generic PHP. If there is no WordPress API in sight (value objects, Composer/PSR-4, PHPStan), that is php. A Laravel app is laravel.
Target current. Stale version assumptions are the most common way WP code rots.
wp_enqueue_block_style, theme.json v3).WP_DEVELOPMENT_MODE to all so theme.json edits are not cached for 30+ seconds. Why: without it you will edit theme.json, see nothing change, and waste an hour.// wp-config.php — local dev only, never on production
define( 'WP_DEVELOPMENT_MODE', 'all' );
define( 'WP_DEBUG', true );
define( 'SCRIPT_DEBUG', true );Pick the lightest artifact that survives an update. The failure mode is everyone reaching for functions.php or editing files that get overwritten.
| You need to… | Artifact | Do NOT |
|---|---|---|
| One-line tweak, site-specific behavior | mu-plugin in wp-content/mu-plugins/ | dump it in the active theme's functions.php |
| Change look of a third-party theme | child theme | edit the parent theme — updates wipe it |
| Reusable feature, hooks, blocks, CPTs | standalone plugin | hide app logic in functions.php |
| Full custom front end | block theme + theme.json v3 | reach for a page builder for structural layout |
| Sell products | block theme + WooCommerce | hand-roll a cart |
A block theme is theme.json + HTML templates in templates/ and parts/. Start from a v3 skeleton:
{
"$schema": "https://schemas.wp.org/trunk/theme.json",
"version": 3,
"settings": {
"appearanceTools": true,
"color": {
"palette": [
{ "slug": "base", "color": "#ffffff", "name": "Base" },
{ "slug": "contrast", "color": "#111111", "name": "Contrast" }
]
},
"typography": {
"fluid": true,
"fontFamilies": [
{ "fontFamily": "system-ui, sans-serif", "slug": "system", "name": "System" }
]
},
"layout": { "contentSize": "640px", "wideSize": "1100px" }
},
"styles": {
"color": { "background": "var(--wp--preset--color--base)", "text": "var(--wp--preset--color--contrast)" }
}
}Templates resolve by hierarchy: templates/index.html is the fallback; single.html, archive.html, page.html, 404.html override it. Reusable chunks live in parts/ (header.html, footer.html).
Register patterns by dropping PHP-headered HTML in patterns/; they appear in the inserter automatically. Enqueue CSS per block so it only loads when the block renders:
add_action( 'init', function () {
wp_enqueue_block_style( 'core/group', array(
'handle' => 'mytheme-group',
'src' => get_theme_file_uri( 'assets/blocks/group.css' ),
'path' => get_theme_file_path( 'assets/blocks/group.css' ),
) );
} );Rule: never hand-write <link>/<script> tags in templates — the browser cannot cache them and you lose dependency management. Always enqueue. And never edit a parent theme directly; make a child theme.
A plugin is a folder with a headered main file. That header is what makes it a plugin:
<?php
/**
* Plugin Name: Acme Books
* Description: Registers the book CPT and a related block.
* Version: 1.0.0
* Requires PHP: 8.4
* Requires at least: 6.9
*/
defined( 'ABSPATH' ) || exit; // never expose a direct hitHooks split two ways: actions fire at a point in execution (add_action('init', …)); filters transform a value and must return it (add_filter('the_content', …)). Confusing them is a top-five WP bug.
Register a block from a block.json — never duplicate metadata in PHP:
add_action( 'init', function () {
register_block_type( __DIR__ . '/build/related-books' ); // reads block.json
} );Register a custom post type with explicit capabilities and labels:
add_action( 'init', function () {
register_post_type( 'book', array(
'public' => true,
'show_in_rest' => true, // required for the block editor
'supports' => array( 'title', 'editor', 'thumbnail' ),
'labels' => array( 'name' => 'Books', 'singular_name' => 'Book' ),
) );
} );Every write path needs a capability check + nonce, and every output/query needs escaping/sanitizing. This is the line between a plugin and a vulnerability.
// Bad — SQL injection, no auth
$rows = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} WHERE post_author = $id" );
// Good — capability, nonce, prepared statement
if ( ! current_user_can( 'edit_posts' ) ) { wp_die( 'nope' ); }
check_admin_referer( 'acme_save' );
$rows = $wpdb->get_results( $wpdb->prepare(
"SELECT * FROM {$wpdb->posts} WHERE post_author = %d", $id
) );
echo esc_html( $rows[0]->post_title );Sanitize on input (sanitize_text_field, absint), escape on output (esc_html, esc_attr, esc_url, wp_kses for allowed HTML).
The single highest-impact habit is keeping core, plugins, and themes updated — 2024 saw 7,966 new ecosystem vulnerabilities, +34% YoY, and the vast majority hit known-vulnerable extensions. Baseline wp-config.php constants:
define( 'DISALLOW_FILE_EDIT', true ); // kills dashboard Theme/Plugin editor; SFTP/Git unaffected
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
define( 'FORCE_SSL_ADMIN', true );Use Application Passwords (WP 5.6+) for REST/API machine auth — individually revocable, cannot log into wp-login.php, and the right answer when a script or nextjs front end needs to talk to WP. Never reuse the admin password in a script.
For the full block — file-permission matrix (dirs 755 / files 644 / wp-config 600), DISALLOW_FILE_MODS, nginx/.htaccess security headers, login lockdown, XML-RPC and user-enumeration disabling, version-disclosure removal — see references/hardening.md. Generic OWASP/threat-modeling not tied to the WP attack surface is secure-coding.
Two caches, different jobs: an object cache (Redis/Memcached via a drop-in) memoizes DB query results across requests; a page cache stores whole rendered HTML pages. You usually want both. Then:
Full Redis wiring, the autoload audit query, transients, and a WP-tied Core Web Vitals checklist are in references/performance.md. Generic CWV/load-testing methodology divorced from WordPress is the performance sibling.
HPOS (High-Performance Order Storage) is the default order datastore for new installs since WooCommerce 8.2 — orders live in dedicated tables, not wp_posts. Enable/migrate and verify with WP-CLI:
wp wc hpos enable # turn on custom order tables
wp wc cot sync # backfill/sync existing orders
wp wc cot verify_cot_data # confirm parity before flipping authorityAny plugin that touches orders must declare HPOS compatibility, or WooCommerce disables it in HPOS mode:
add_action( 'before_woocommerce_init', function () {
if ( class_exists( \Automattic\WooCommerce\Utilities\FeaturesUtil::class ) ) {
\Automattic\WooCommerce\Utilities\FeaturesUtil::declare_compatibility(
'custom_order_tables', __FILE__, true
);
}
} );Store/checkout/product setup checklist and migration caveats: references/woocommerce.md. A Shopify store is the shopify sibling.
wp is the operational backbone — scriptable, faster than the dashboard, and safe on serialized data.
wp-env start (Dockerized WP). Scaffold a block/plugin with npx @wordpress/create-block acme-block.wp search-replace is serialization-safe — never run a raw SQL REPLACE on the DB, it corrupts serialized arrays. Dry-run first:wp search-replace 'https://staging.example.com' 'https://example.com' --all-tables --dry-run
wp db export backup.sql # always export before a real run
wp search-replace 'https://staging.example.com' 'https://example.com' --all-tablesDISABLE_WP_CRON true and run wp cron event run --due-now from real system cron.| Anti-pattern | Why it's wrong | Do instead |
|---|---|---|
App logic in functions.php | Dies with the theme; not portable | Standalone plugin or mu-plugin |
| Editing a parent theme / core files | Wiped on update | Child theme; hooks/filters |
query_posts() | Breaks the main query, no pagination | WP_Query or pre_get_posts |
$wpdb->query("… $var …") | SQL injection | $wpdb->prepare() with %d/%s |
<script src>/<link> in templates | Not cached, no dependency graph | wp_enqueue_script/style, wp_enqueue_block_style |
| Secrets pasted in dashboard file editor | Logged, world-readable, version-control blind | wp-config.php constants + DISALLOW_FILE_EDIT |
| Page builder for structural layout | Bloat, lock-in, broken CWV | Block theme + patterns |
| Disabling auto-updates, never patching | 7,966 vulns/yr land on stale plugins | WP_AUTO_UPDATE_CORE; wp plugin update --all |
Raw SQL REPLACE to change URLs | Corrupts serialized data | wp search-replace |
| Order-touching plugin without HPOS declaration | WooCommerce disables it | FeaturesUtil::declare_compatibility |
scripts/verify.sh <path> statically scans theme/plugin/config code for these anti-patterns — committed DB creds or AUTH_KEY/salt literals, missing DISALLOW_FILE_EDIT when a wp-config.php is in scope, eval(/base64_decode(, query_posts(, unprepared $wpdb interpolation, and hardcoded <script src=/<link rel="stylesheet"> in PHP templates. Read-only; exits 0 on a clean or empty target, non-zero on any FAIL so it can gate CI.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/wordpress of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Wordpress next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wordpress this skillericrisco/rsc-harness | 156 | — | ~3k | Automated safety check: Pass | MIT | |
| Php Framework Auditwgpsec/AboutSecurity | 1.8k | — | ~767 | Automated safety check: Notes | None | |
| WooCommerce Backend Conventionswoocommerce/woocommerce | 11k | 1 repos | ~614 | Automated safety check: Pass | Custom licence | |
| Wordpresssickn33/agentic-awesome-skills | 47k | 2 repos | ~348 | Automated safety check: Pass | MIT | |
| Auditing Php Applicationstrilwu/secskills | 156 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT |
wgpsec/AboutSecurity
PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。
woocommerce/woocommerce
Guides agents writing or changing WooCommerce backend PHP so new classes, hooks and unit tests follow the project's conventions.
sickn33/agentic-awesome-skills
Complete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening.
trilwu/secskills
Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins…. Wordpress is an agent skill from ericrisco/rsc-harness.json and proper hooks, wp-config security hardening, performance (object cache, asset loading, autoloaded options), and WP-CLI operations.
Wordpress fits situations like: hardening WordPress sites; wooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json; plugins with block.json and proper hooks; wp-config security hardening.
Run `npx skills add ericrisco/rsc-harness --skill wordpress -a claude-code`. Or copy the skill folder (skills/wordpress in ericrisco/rsc-harness) into .claude/skills/wordpress in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill wordpress -a codex`. Or copy the skill folder (skills/wordpress in ericrisco/rsc-harness) into .agents/skills/wordpress in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill wordpress -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wordpress, .gemini/skills/wordpress, .github/skills/wordpress and .opencode/skills/wordpress in your project.
Going by SKILL.md and its folder, Wordpress needs a shell for the scripts in its folder, the command-line tools its instructions call (npx) and credentials named AUTH_KEY. Our summary lists: Node.js; A Bash shell; A credential in AUTH_KEY.
SKILL.md names 1 domain. In commands or code: schemas.wp.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Wordpress is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wordpress: Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars), WooCommerce Backend Conventions (woocommerce/woocommerce, 11k stars), Wordpress (sickn33/agentic-awesome-skills, 47k stars) and Auditing Php Applications (trilwu/secskills, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.