Agent skill

Security

by garagon in garagon/nanostack

Use before shipping to production. An agent skill from garagon/nanostack.

Apache-2.0Auto-check: notesSecurity

Install Security

skills CLI
$ npx skills add garagon/nanostack --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garagon/nanostack security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
207
Token cost
~3.7k tokens
SKILL.md length
1,490 words
Files
4 (incl. references)
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use before shipping to production. An agent skill from garagon/nanostack.

  • Works in 5 steps: Detect Stack → Scan → False Positive/Negative Awareness → …
  • The user asks to check security
  • SKILL.md covers Telemetry preamble, Intensity Mode, Setup (first run per project) and Graduated Rules, plus 10 more sections
  • Calls git, npm and jq; needs GITHUB_TOKEN

What it does

Security is an agent skill from garagon/nanostack. Use before shipping to production. Performs OWASP Top 10 audit and STRIDE threat modeling against the codebase. Supports --quick, --standard, --thorough modes. Also use when the user asks to check security, audit code, or review for vulnerabilities. Triggers on /security.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/owasp-checklist.md` and `templates/security-report.md`).

It sits in Security, covering Threat modeling, Security review and Web application vulnerabilities. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.

When your agent uses it

  • The user asks to check security
  • Review for vulnerabilities

Example prompts

  • “/security”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Detect Stack
  2. Scan
  3. False Positive/Negative Awareness
  4. STRIDE per component
  5. Produce Report

What it can do on your machine

Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • jq
    • pip
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 3.7k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 1,490 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:140
    git log --all --oneline -- '.env' '.env.local' '*.pem' '*.key' 2>/dev/null | head -10

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 1,490 words, ~3,725 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security
description
Use before shipping to production. Performs OWASP Top 10 audit and STRIDE threat modeling against the codebase. Supports --quick, --standard, --thorough modes. Also use when the user asks to check security, audit code, or review for vulnerabilities. Triggers on /security.
concurrency
read
depends_on
build
summary
Security audit. OWASP A01-A10, STRIDE threat modeling, secrets scan, dependency audit.
estimated_tokens
450

/security — Security Audit

You think like an attacker but report like a defender. The real attack surface is rarely the code you wrote. It is the secrets in git history, the dependency you forgot to update, the CI pipeline that leaks tokens, and the AI endpoint without rate limiting. Start there, not at the application logic.

Telemetry preamble

Defensive telemetry init. No-op if telemetry is disabled via NANOSTACK_NO_TELEMETRY=1, ~/.nanostack/.telemetry-disabled, or if the helpers are removed.

bash
_P="$HOME/.claude/skills/nanostack/bin/lib/skill-preamble.sh"
[ -f "$_P" ] && . "$_P" security
unset _P

Intensity Mode

ModeFlagScopeConfidence gate
Quick--quickOWASP A01-A03 (top 3) + secrets scan + dependency check9/10 — only verified findings
Standard(default)Full OWASP A01-A10 + STRIDE per component + dependencies7/10 — report anything with evidence
Thorough--thoroughFull OWASP + STRIDE + variant analysis + conflict detection + LLM security check3/10 — flag tentative findings marked as TENTATIVE

Auto-suggest:

  • Pre-commit on small changes → suggest --quick
  • Pre-ship standard feature → --standard (default)
  • Pre-ship auth/payment/infra, or first audit of a codebase → suggest --thorough

Thorough-only features:

  • Variant analysis: When a finding is VERIFIED, search the entire codebase for the same pattern. One confirmed SQL injection means there may be more.
  • Conflict detection: Cross-reference with /review artifacts in .nanostack/review/ for contradictions.
  • TENTATIVE findings: Below confidence gate but worth noting. Mark as TENTATIVE: <description>.

Setup (first run per project)

Resolve context — load plan, review artifacts, matched solutions, and config:

bash
~/.claude/skills/nanostack/bin/resolve.sh security --diff

The output is JSON with upstream_artifacts (plan and review paths), solutions (matched by file overlap and security tags), conflict_precedents (path to precedents doc), diarizations (module briefs), and config (intensity, detected stack, conflict precedence).

From the plan artifact (if present):

  • planned_files[] → focus your audit on these files and their dependencies. Deeper analysis on fewer files is better than shallow analysis on everything.
  • risks[] → treat each planned risk as a security hypothesis to verify. If the plan says "AWS SDK version compatibility" is a risk, check for insecure SDK usage patterns.

From config: use detected_stack to scope which checks to run (skip Python checks in a Go project). Use conflict_precedence for cross-skill conflicts.

Then check if security/config.json exists. If not, ask the user to classify the project:

What type of project is this?
1. Public-facing (users/customers on the internet)
2. Internal (employees/team only, no public access)
3. Compliance-driven (fintech, health, regulated)
4. Library/SDK (consumed by other developers)

Store the answer:

json
// security/config.json
{
  "project_type": "public_facing",
  "conflict_precedence": "security > review > qa",
  "configured_at": "2026-03-25"
}

This determines:

  • Conflict precedence: public_facing → security wins. internal → review wins. compliance → security wins hard.
  • Default intensity: public_facing/compliance → suggest --thorough on first audit. internal/library → --standard.
  • OWASP priority: public_facing → A01, A03, A07 first. internal → A02, A05, A09 first.

If config already exists, read it and skip setup.

Graduated Rules

<!-- Auto-maintained by bin/graduate.sh. Do not edit manually. -->
<!-- Each rule was promoted from a solution with 3+ applications and validation. -->
<!-- END GRADUATED RULES -->

Check these rules during your audit. Each one represents a proven security pattern from past sprints.

Process

1. Detect Stack

Auto-detect everything. Do NOT ask the user.

  • package.json → Node.js (check for next, express, fastify, hono)
  • requirements.txt / pyproject.toml → Python (flask, django, fastapi)
  • go.mod → Go (gin, echo, chi)
  • Database deps: prisma, drizzle, mongoose, sqlalchemy, gorm
  • BaaS: supabase, firebase, convex
  • Auth: next-auth, clerk, passport, lucia, jwt
  • AI/LLM: openai, anthropic, langchain, vercel ai sdk
  • Payments: stripe, paddle
  • Infra: Dockerfile, docker-compose.yml, .github/workflows/

Report one-line: Detected: Next.js 14 + Prisma + Stripe, Docker, GitHub Actions

2. Scan

CORE (always run): secrets, injection, auth, config, dependencies, data-exposure.

CONDITIONAL (only if detected): AI/LLM endpoints, payment webhook verification, Docker misconfig, CI/CD pipeline security, file upload handling.

For extended check patterns, reference the OWASP checklist at security/references/owasp-checklist.md.

Read security/references/owasp-checklist.md for the OWASP A01-A10 framework.

Secrets Scan (CRITICAL — always first)

Search for hardcoded credentials using regex patterns:

PatternWhat
AKIA[0-9A-Z]{16}AWS access key
sk_live_[a-zA-Z0-9]{24,}Stripe live key
sk-proj-[a-zA-Z0-9\-_]{20,}OpenAI project key
sk-ant-[a-zA-Z0-9\-_]{80,}Anthropic key
ghp_[a-zA-Z0-9]{36}GitHub PAT
-----BEGIN (RSA|EC|OPENSSH) PRIVATE KEYPrivate key in code
(postgres|mysql|mongodb\+srv):\/\/[^:\s]+:[^@\s]+@DB connection string with password

Context rules: In *.test.*, *.example, README*, or values containing xxx, TODO, placeholder → downgrade to INFO.

Git history check (mandatory):

bash
git log --all --oneline -- '.env' '.env.local' '*.pem' '*.key' 2>/dev/null | head -10

If results: secrets may be in history even if currently gitignored. CRITICAL — credentials must be rotated.

IMPORTANT: Credential redaction. When reporting secrets, NEVER show the full value. First 4 chars + **** (e.g., sk-pr****).

CI/CD Pipeline Security (if .github/workflows/ exists)
CheckWhat to look for
Unpinned actionsuses: action@main instead of uses: action@sha256
pull_request_targetRuns with write access on fork PRs — code injection vector
Secrets in logsecho ${{ secrets.* }} or debug mode exposing secrets
Overpermissioned GITHUB_TOKENpermissions: write-all when only contents: read needed
AI/LLM Security (if AI deps detected)
CheckWhat to look for
API keys in client bundleNEXT_PUBLIC_OPENAI, NEXT_PUBLIC_ANTHROPIC
Prompt injectionUser input interpolated into system prompts (prompt + req.body)
Missing rate limitingAI endpoints without rate limiter — attacker runs up your bill
Unsanitized LLM outputLLM response rendered as HTML without escaping
3. False Positive/Negative Awareness

False positives (skip): .env.example, sk_test_ keys, UUIDs, React/Angular output (XSS-safe by default, only flag escape hatches like dangerouslySetInnerHTML), eval() in build configs, 0.0.0.0 in Docker, SQL in migrations.

False negatives (don't miss): Auth on route but not on query (IDOR), secrets in git history, rate limiting on login but not password reset, SSRF via URL params to 169.254.169.254, dangerouslySetInnerHTML without DOMPurify.

4. STRIDE per component

Spoofing (impersonation?), Tampering (data integrity?), Repudiation (audit trail?), Info Disclosure (leaks?), DoS (overwhelm?), Elevation (privilege escalation?).

4. Produce Report

Report findings progressively. Don't wait until the end. As each phase completes, output its findings immediately so the user sees work happening.

Open with a summary line:

Security: CRITICAL (0) HIGH (1) MEDIUM (2) LOW (1) = 4 findings. Score: B

Scoring: A = 0 critical, 0 high, ≤3 medium. B = 0 critical, 1-2 high. C = 3+ high. D = 1-2 critical. F = 3+ critical.

Use security/templates/security-report.md for the full structure. Every finding must include:

  • What the vulnerability is (specific, not vague)
  • Where it exists (file path and line number)
  • How to exploit it (proof of concept or clear scenario)
  • Fix with actual code, before and after (not "consider sanitizing input")
  • Severity using the classification below

Always close with What's solid: 2-3 specific things the codebase does well on security. Not filler. If the auth is well implemented, say so and say why.

Show full SKILL.md (559 more words)Show less

Severity Classification

Severity: Critical (RCE, unauth admin, hardcoded creds), High (stored XSS, IDOR, privilege escalation), Medium (CSRF, info disclosure, missing rate limit), Low (headers, verbose errors, outdated non-vulnerable deps).

Conflict Detection

Always check for conflicts with prior /review findings. The resolver output from Setup includes upstream_artifacts.review (if a review artifact exists) and conflict_precedents (path to the precedents doc). When a conflict is detected, mark inline:

### SEC-005: Excessive error detail
**Conflicts with:** REV-003 → RESOLUTION: structured errors (code + generic msg to user, details to logs)

In --quick mode, apply default precedence (security > review) without documenting. In --standard mode, document conflicts inline. In --thorough mode, document conflicts AND flag as BLOCKING until user confirms.

After completing the audit and conflict detection, save the artifact. Run this command now — do not skip it. The save is validated against the per-phase schema (see reference/artifact-schema.md); a security artifact requires summary (object), findings (array), and context_checkpoint.

bash
SEC_JSON=$(jq -n \
  --arg  mode              "$SEC_MODE" \
  --argjson summary        '{"total_findings":0,"critical":0,"high":0,"medium":0,"low":0}' \
  --argjson findings       '[]' \
  --argjson conflicts      '[]' \
  --arg  checkpoint_summary "Security audit found N findings across OWASP categories." \
  '{
     phase: "security",
     mode: $mode,
     summary: $summary,
     findings: $findings,
     conflicts: $conflicts,
     context_checkpoint: {
       summary: $checkpoint_summary,
       key_files: [],
       decisions_made: [],
       open_questions: []
     }
   }')
~/.claude/skills/nanostack/bin/save-artifact.sh security "$SEC_JSON"

Mode Summary

AspectQuickStandardThorough
OWASP scopeA01-A03 onlyFull A01-A10Full + variant analysis
STRIDESkipPer componentPer component + attack trees
Dependenciesnpm audit onlyFull scanFull + license check
Conflict detectionAuto-resolveDocument inlineBLOCKING until resolved
Tentative findingsSkipSkipReport as TENTATIVE
Confidence gate9/107/103/10

Session state

Read profile, run_mode, autopilot, and plan_approval per reference/session-state-contract.md. When run_mode == report_only, do not apply fixes; only report findings.

Next Step

After the security audit is complete and the artifact is saved:

If autopilot == true: Return the artifact and findings to the caller. Do not invoke another specialist. /feature owns continuation and waits for the whole verification batch.

If critical or high findings are found: Report them without repairing product files. The caller handles repairs in the build step after all verification readers have stopped.

Otherwise: Read the next action from session state:

bash
~/.claude/skills/nanostack/bin/next-step.sh --json

Use .user_message for the prose and .next_phase for the phase name. The legacy positional form (next-step.sh security) is still supported.

When profile == "guided", the user-facing output follows the four-block skeleton in reference/plain-language-contract.md (Result / How to try / What was checked / What remains). Whether it is safe to try goes inside Result; do not add a separate block. Use plain words (no "vulnerability", "threat model", "STRIDE"). Example:

<!-- guided-output:start -->
Resultado: Es seguro para probar. No vi problemas que te expongan.

Como verlo:
1. Corre el comando que te indique mas arriba y segui las instrucciones.

Que revise:
- Nadie entra sin permiso a lo que deberia estar protegido.
- Los datos sensibles no quedan a la vista.
- Las entradas raras no rompen ni dejan escapar informacion.

Pendiente:
- No probe contra un ataque dirigido y sostenido.
- No revise servicios externos que no controlamos.
<!-- guided-output:end -->

Final Headline

After the user-facing message above, print one summary line as the very last thing — useful for autopilot logs and quick scanning:

[security] OK: grade <A-F>, <N critical, M high>. Next: <first pending skill or "/ship">.

Use WARN instead of OK if any critical or high findings exist.

After Fixes

When the caller returns a repaired build for verification, focus the new audit on changed code and affected trust boundaries:

  • CRITICAL/HIGH fixes: Re-audit only the affected files and the specific vulnerability class. Verify the fix resolves the finding. Save a new artifact.
  • MEDIUM/LOW fixes: Verify the specific fix by reading the changed code. Save a new artifact recording the current result and the narrower coverage; do not treat the original audit as evidence for a changed build.

Re-running the full OWASP scan after fixing a missing Content-Type header wastes time and tokens. Target the verification.

Telemetry finalize

Before returning control:

bash
_F="$HOME/.claude/skills/nanostack/bin/lib/skill-finalize.sh"
[ -f "$_F" ] && . "$_F" security success
unset _F

Pass abort or error instead of success if the audit did not complete normally.

Gotchas

  • Zero findings is valid. Don't manufacture findings.
  • Don't inflate severity. Calibrate to actual exploitability.
  • Show evidence. Input path, sink, missing sanitization. Not "could be vulnerable."
  • Run dependency scanning. npm audit, pip audit, go vuln check.
  • Auth ≠ authz. Logged in ≠ has permission.
  • Check git history for secrets. git log -p --all -S 'password\|secret\|key\|token'
  • Variant analysis in --thorough. One finding = search for the pattern elsewhere.

© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in security of garagon/nanostack.

  • SKILL.md
  • agents/openai.yaml
  • references/owasp-checklist.md
  • templates/security-report.md

Open the folder on GitHubat commit 0372aed

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillgaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
CybersecurityAgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT
Csono-session/pstack134—~12kAutomated safety check: NotesMIT
007sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT
Security Auditfossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    227 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    134 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed
  • Security Audit

    fossasia/eventyay-interpretation

    A skill your agent uses for security reviews of VoxBento code.

    1.6k GitHub stars~1.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 4 days ago
    SecurityAuto-check: notes

More from garagon/nanostack

All 14 skills in this repo
  • Nano

    garagon/nanostack

    A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).

    207 GitHub stars~3.3k tokensUpdated 27 days ago
    Auto-check passed
  • Nano Run

    garagon/nanostack

    First-time setup and guided sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~3k tokensUpdated 27 days ago
    Auto-check passed
  • Ship

    garagon/nanostack

    A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.

    207 GitHub stars~4.2k tokensUpdated 27 days ago
    Auto-check passed
  • Compound

    garagon/nanostack

    Document what you learned during this sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.2k tokensUpdated 27 days ago
    Auto-check passed
  • Conductor

    garagon/nanostack

    Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.6k tokensUpdated 27 days ago
    Auto-check passed
  • Feature

    garagon/nanostack

    Add a feature to an existing project with a full sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~1.4k tokensUpdated 27 days ago
    Auto-check passed

Categories

Questions about Security

What does Security do?

Use before shipping to production. An agent skill from garagon/nanostack. Security is an agent skill from garagon/nanostack. Use before shipping to production.

When should I use Security?

Security fits situations like: the user asks to check security; review for vulnerabilities.

How do I install Security in Claude Code?

Run `npx skills add garagon/nanostack --skill security -a claude-code`. Or copy the skill folder (security in garagon/nanostack) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add garagon/nanostack --skill security -a codex`. Or copy the skill folder (security in garagon/nanostack) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (git, npm, jq, pip and go) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in GITHUB_TOKEN.

Does Security access the network?

SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security use?

Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Cso (no-session/pstack, 134 stars) and 007 (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.

Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.