Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Deep audit of a Frappe app for security, correctness, and customization defects.
$ npx skills add frappe/skills --skill deep-app-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install frappe/skills deep-app-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deep-app-audit .claude/skills/deep-app-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .claude/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/frappe/skills/tree/main/skills/deep-app-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add frappe/skills --skill deep-app-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install frappe/skills deep-app-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/deep-app-audit .agents/skills/deep-app-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .agents/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add frappe/skills --skill deep-app-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install frappe/skills deep-app-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/deep-app-audit .cursor/skills/deep-app-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .cursor/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/frappe/skills.git --path skills/deep-app-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add frappe/skills --skill deep-app-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install frappe/skills deep-app-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/deep-app-audit .gemini/skills/deep-app-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .gemini/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install frappe/skills deep-app-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add frappe/skills --skill deep-app-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/deep-app-audit .github/skills/deep-app-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .github/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add frappe/skills --skill deep-app-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install frappe/skills deep-app-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/deep-app-audit .opencode/skills/deep-app-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deep-app-audit" agent skill from https://github.com/frappe/skills/tree/main/skills/deep-app-audit into .opencode/skills/deep-app-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-app-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deep-app-auditDeep audit of a Frappe app for security, correctness, and customization defects.
Deep App Audit is an agent skill from frappe/skills. Deep audit of a Frappe app for security, correctness, and customization defects. Runs every security scope and every quality rule in a separate agent, verifies each candidate in a fresh context, and compiles one report. User-invoked only - run /deep-app-audit [app path] [options].
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 234 other files, including scripts (for example `agents.example.json`, `prompts/check.md` and `prompts/context.md`).
It sits in Development. The repository describes itself as: Agent skills for Frappe App development.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0bef982. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
jqsemgrepgituvpythoncurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deep App Audit loads about 5.4k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 3,004 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 3,004 words (~5,434 tokens).
“This skill audits one Frappe app checkout on three tracks and writes one report:”
SKILL.md and 231 other files (scripts) in skills/deep-app-audit of frappe/skills.
Open the folder on GitHubat commit 0bef982
Deep App Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deep App Audit this skillfrappe/skills | 147 | — | ~5.4k | Automated safety check: Pass | None | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
frappe/skills
Builds full-stack Frappe Framework applications end-to-end. An agent skill from frappe/skills.
frappe/skills
Turn a vulnerability report into a publication-ready GitHub Security Advisory.
frappe/skills
Fix a bug reported in a GitHub issue or a markdown file, without letting the report's noise and guesses into the main context.
frappe/skills
Review code for any Frappe application — a checklist distilled from years of engineering practice on correctness, security, performance, concurrency, readability, API design, and testing.
frappe/skills
Resolve merge conflicts in a Mergify backport pull request. An agent skill from frappe/skills.
frappe/skills
Write prose in "Simplified Technical English". An agent skill from frappe/skills.
Categories
Deep audit of a Frappe app for security, correctness, and customization defects. Deep App Audit is an agent skill from frappe/skills. Deep audit of a Frappe app for security, correctness, and customization defects.
Deep App Audit fits situations like: development work in your project.
Run `npx skills add frappe/skills --skill deep-app-audit -a claude-code`. Or copy the skill folder (skills/deep-app-audit in frappe/skills) into .claude/skills/deep-app-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add frappe/skills --skill deep-app-audit -a codex`. Or copy the skill folder (skills/deep-app-audit in frappe/skills) into .agents/skills/deep-app-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add frappe/skills --skill deep-app-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-app-audit, .gemini/skills/deep-app-audit, .github/skills/deep-app-audit and .opencode/skills/deep-app-audit in your project.
Going by SKILL.md and its folder, Deep App Audit needs the command-line tools its instructions call (jq, semgrep, git, uv, python and curl). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
No licence was found for Deep App Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deep App Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
frappe (a GitHub organization) maintains it in frappe/skills, which has 147 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on September 30, 2026.
Source: frappe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.