Forensify
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…
$ npx skills add guardana/guardana --skill docs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install guardana/guardana docs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/docs .claude/skills/docs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .claude/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/guardana/guardana/tree/main/.claude/skills/docsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add guardana/guardana --skill docs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install guardana/guardana docs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/docs .agents/skills/docs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .agents/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add guardana/guardana --skill docs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install guardana/guardana docs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/docs .cursor/skills/docs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .cursor/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/guardana/guardana.git --path .claude/skills/docs--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add guardana/guardana --skill docs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install guardana/guardana docs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/docs .gemini/skills/docs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .gemini/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install guardana/guardana docsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add guardana/guardana --skill docs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/docs .github/skills/docs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .github/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add guardana/guardana --skill docs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install guardana/guardana docs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/docs .opencode/skills/docs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "docs" agent skill from https://github.com/guardana/guardana/tree/main/.claude/skills/docs into .opencode/skills/docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
docsDocumentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…
Docs is an agent skill from guardana/guardana. Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass that makes a page shorter and truer without inventing a claim. Use for "update the docs", "the README is stale", "simplify this page", "add a usage page", or when /ship needs the five places answered.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Technical documentation and Prompt injection and agent security. The repository describes itself as: Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ae7ee8b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Docs loads about 1k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 515 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from guardana/guardana at commit ae7ee8b, republished under its Apache-2.0 licence (© guardana). 515 words, ~1,030 tokens.
.claude/skills/docs/SKILL.md (or your agent's skills folder).Target: $ARGUMENTS
| where | when it needs an edit |
|---|---|
CHANGELOG.md under [Unreleased] | any user-visible change — say why, not only what |
FEATURES.md | a new capability, or one whose shape changed (a registry test refuses a built-in rule or evaluator missing from it) |
docs/ | a new command gets usage-<command>.md; a changed one gets its page reconciled; docs/index.md lists it under the right heading |
site/index.html | a headline claim moved: a count, a run mode, what the terminal demo prints |
ROADMAP.md | the direction moved — delete what shipped, add what was deferred with the reason |
Then uv run python scripts/generate_docs.py for a rule, evaluator or taxonomy change — never
edit docs/generated/ by hand — and the four --check scripts prove the site agrees.
docs/**/*.md starts with front matter: title, nav_order (unique), summary,
status (stable / beta / draft; design documents take the first word of their
**Status:** line). A page missing any of them fails build_site.py.docs/index.md; the nav is built from that map and refuses a page it
cannot reach. Only docs/work/ is left out — it is work in flight, not documentation.test_docs_consistency.py); no page promises
a version that already shipped (**v0.x, "coming in 0.x"); every count in prose equals the
registry (test_docs_pages_state_the_real_counts.py, test_landing_page.py,
test_readme_rule_table.py); the built site equals its sources (test_documentation_site.py).docs/design/README.md).One page, one job, the answer first. A usage-*.md page says what the command does, the
command to type, what it writes, its exit codes, then the options — in fenced blocks, never in
prose. History, incidents and measurements belong in CHANGELOG.md or
docs/maintainers/lessons.md, not on a user page: a user page that explains why a rule exists
three times is a page nobody finishes. A sentence that a test could pin (a count, a flag, a
path) is written so the test can find it; a sentence nothing can check is a claim to cut.
scout: size, last commit, which tests pin the page, which pages link to it.text-broker work (content-model): a rewrite comes back with
every path, flag, count, rule id and link byte-identical, and a verdict that CUTS a sentence
needs both engines to agree. The facts stay yours: a model never changes a number.uv run pytest packages/guardana-core/tests/test_docs_consistency.py packages/guardana-core/tests/test_documentation_site.py -q
and scripts/ci_local.sh --quiet before the commit.The maintainer-facing pages (docs/maintainers/), CONTRIBUTING.md and CLAUDE.md follow the
same rules; CLAUDE.md additionally has a line budget the setup gate enforces, and the story
behind a rule goes to docs/maintainers/lessons.md.
© guardana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/docs of guardana/guardana.
Open the folder on GitHubat commit ae7ee8b
Docs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Docs this skillguardana/guardana | 129 | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Skylos Securityduriantaco/skylos | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Plugin Scanneriflytek/skillhub | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Security GuidejnMetaCode/shellward | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 |
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
iflytek/skillhub
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
jnMetaCode/shellward
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
OWASP/secure-agent-playbook
Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.
guardana/guardana
Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule…
guardana/guardana
Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a…
guardana/guardana
Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…
guardana/guardana
Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.
guardana/guardana
Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined.
guardana/guardana
Run this project's verification — the full local CI mirror (ruff, mypy, import contract, pytest with PostgreSQL, coverage floors, dogfood, generated docs and site, the isolated example suites, the…
Categories
Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…. Docs is an agent skill from guardana/guardana. Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass that makes a page shorter and truer without inventing a claim.
Docs fits situations like: update the docs; the README is stale; simplify this page; add a usage page.
Run `npx skills add guardana/guardana --skill docs -a claude-code`. Or copy the skill folder (.claude/skills/docs in guardana/guardana) into .claude/skills/docs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add guardana/guardana --skill docs -a codex`. Or copy the skill folder (.claude/skills/docs in guardana/guardana) into .agents/skills/docs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guardana/guardana --skill docs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docs, .gemini/skills/docs, .github/skills/docs and .opencode/skills/docs in your project.
Going by SKILL.md and its folder, Docs needs the command-line tools its instructions call (uv). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Docs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Docs: Forensify (alexgreensh/repo-forensics, 188 stars), Skylos Security (duriantaco/skylos, 843 stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars) and Plugin Scanner (iflytek/skillhub, 5.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
guardana (a GitHub organization) maintains it in guardana/guardana, which has 129 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.
Source: guardana/guardana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.