Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
完成した差分・PR・検証証拠に残る Unknown(未確認の前提・調査されていない影響・ 不足している証拠)を横断合成する evidence-sufficiency のメタ観点。個別 defect の 検出は既存 skill へ委譲し、本 skill は「そのリスク種別を調査した証拠が残っているか」 の meta 評価のみを行う。通常は finding verification 後の…
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .claude/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .claude/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .agents/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .agents/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .cursor/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .cursor/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hashgraph-online/awesome-codex-plugins.git --path plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .gemini/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .gemini/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .github/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .github/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins unknown-coverage-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review .opencode/skills/unknown-coverage-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "unknown-coverage-review" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review into .opencode/skills/unknown-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unknown-coverage-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
unknown-coverage-review完成した差分・PR・検証証拠に残る Unknown(未確認の前提・調査されていない影響・ 不足している証拠)を横断合成する evidence-sufficiency のメタ観点。個別 defect の 検出は既存 skill へ委譲し、本 skill は「そのリスク種別を調査した証拠が残っているか」 の meta 評価のみを行う。通常は finding verification 後の…
Unknown Coverage Review is an agent skill from hashgraph-online/awesome-codex-plugins. 完成した差分・PR・検証証拠に残る Unknown(未確認の前提・調査されていない影響・ 不足している証拠)を横断合成する evidence-sufficiency のメタ観点。個別 defect の 検出は既存 skill へ委譲し、本 skill は「そのリスク種別を調査した証拠が残っているか」 の meta 評価のみを行う。通常は finding verification 後の generic 合成ステップとして、 明示的 Security Audit では SecurityAuditCoverage 専用 profile として report-only で実行する。 残存 Unknown は既存 Unknown Coverage 構造へ出力し、新しい語彙・schema は作らない。
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `fixtures/01-pass-evidence-sufficient.md`, `fixtures/02-needs-review-nonblocking-unknown.md` and `fixtures/03-fail-blocking-compat-unknown.md`).
It sits in Security, covering Security review. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
claude.comaihero.devzenn.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Unknown Coverage Review loads about 2.6k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 794 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its MIT licence (© hashgraph-online). 794 words, ~2,648 tokens.
.claude/skills/unknown-coverage-review/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.由来 / Inspired by: Thariq「A Field Guide to Finding Your Unknowns」(The map is not the territory: Plan やプロンプトは現実のコードベースを圧縮した地図であり、地図と土地の差分に Unknown が潜む)と Matt Pocock「
/grill-me」(実装前に質問を重ね共有理解を作る)から着想した概念の再実装。原著者を名指しする nominative fair use に留め、endorsement は主張しない。
通常のレビューは「壊れている箇所(defect)」を指す。 本観点は 「そのリスク種別を調査した証拠が残っているか(evidence-sufficiency)」 を横断合成する。問いが直交するため、defect 検出とは混載しない。
AI coding agent の実行能力が上がるほど、見逃しは単純なコード品質から 要件・暗黙知・影響範囲・運用条件・移行条件などの「未確認の未知(Unknown)」 へ移る。 チェックリストを満たしても、レビュー対象外の前提や未確認領域が残れば誤った判断につながる。 本観点は大量の質問を生成しない。利用 profile が許可した evidence を調査し、以下を構造化して出力する。
Select exactly one profile before reviewing.
genericDefault profile for the existing diff / PR review flow. It preserves the current post-finding-verification pre-execution gate, diff requirement, delegation rules, and verdict mapping.
security-auditUse only when river-review-security-audit explicitly invokes this skill for a focused or full repository/subsystem security audit.
This profile evaluates Phase 3 SecurityAuditCoverage evidence sufficiency and may run without a current diff.
Its contract is defined in SECURITY-AUDIT-PROFILE.md.
Do not infer this profile from security-looking files or keywords.
Do not relax the generic profile's diff requirement to make Security Audit work.
最初に判定する。満たさない場合は以降の generic 観点を実行せず NO_REVIEW を返す。
diff があり、差分が リポジトリ内で実行されるコード・migration・schema・公開 API・設定のいずれかに触れる。docs・コメントのみの差分は対象外とする。dist/**・*.map・lockfile・自動生成 manifest)は Gate 判定からもレビュー対象からも除外する。plan / review-self などの artifact が欠損しても動作する。欠損した観点は finding を出さず skippedSkills に記録してデグレードする(artifact-input-contract の既定挙動)。plan / test-cases artifact は schema の inputContext enum・実行側 availableContexts に供給元が存在しない optional evidence のため、frontmatter inputContext には宣言せず本 Gate の記述で扱う(宣言すると deterministic 経路で常に skipped になる)。plan artifact 欠損時、PR 本文へ前提・open question が inline 列挙されていれば列挙分のみ部分評価する(外部 issue は取得・推測しない)。計画 issue の bare 参照(#NNNN)のみなら skip し skippedSkills に記録する。この分岐は registry skill assumption-resolution-trace と同一ルールに揃える。plan artifact 経由で受け取る同一の artifact-driven パターンに従う(artifact-input-contract.md)。欠損時は上記と同じデグレード(skippedSkills)を適用する。PlanGate への依存は必須にしない。Run only when all are true:
river-review-security-audit focused or full-audit flowSecurityAuditCoverage ledger is availableA current diff is not required for this profile.
That exception is profile-local and must not alter generic routing or generic pre-execution behavior.
If the audit context is implicit, the ledger is absent, or the caller is a normal PR review, return NO_REVIEW for this profile.
Issue #1470 の 6 カテゴリを、defect ではなく evidence-sufficiency の meta 質問として扱う。各観点の defect 検出は既存 skill へ委譲する(DELEGATION.md)。本観点は委譲先が扱わない 残余(証拠が足りているかの合成)のみを検出する。
The security-audit profile does not mechanically apply all six generic perspectives; use the four checks and false-positive guards in SECURITY-AUDIT-PROFILE.md.
| # | 観点 | 核心の meta 問い |
|---|---|---|
| 1 | Requirement / Intent Unknowns | 「曖昧な仕様を推測で実装した箇所に、確認した証拠があるか」 |
| 2 | Repository / Impact Unknowns | 「影響範囲を repo 全体で検索・確認した証拠があるか」 |
| 3 | Runtime / Operational Unknowns | 「migration・再実行・外部依存・監視を検証した証拠があるか」 |
| 4 | Security / Data Unknowns | 「認証境界・入力検証・不可逆変更を確認した証拠があるか」 |
| 5 | Validation Unknowns | 「失敗系・境界・実利用経路を観測した証拠があるか」 |
| 6 | Plan / Assumption Traceability | 「Plan の Assumption が解消され、新規 Unknown が記録された証拠があるか」 |
観点 3〜5 は既存の運用・影響・検証系 skill の多くが applyTo: docs/**(upstream 設計文書向け)で、コードのみの diff では空振りする。本観点はその空白を「証拠の有無」の meta として拾う(設計 §1 の Partial / Gap)。
「AIコードレビューの「見逃し」を3か月ログしたら、5つの盲点タイプに全部収まった」(井本 賢 / 2026-07-06)が報告した5盲点タイプのうち、境界条件・契約違反・意味的矛盾は既存の registry skill でカバー済み(対応先は DELEGATION.md の「追加 Unknown 種別」節を参照)。**状態遷移(不正な遷移)・副作用(隠れた副作用)**の2類型は専用 defect 検出 skill が未整備のため、DELEGATION.md「追加 Unknown 種別(#1517 由来)」節に暫定的な evidence-sufficiency の meta 問いとして記録する。中期の軽量 detector 化は issue #1517 を参照。
重複指摘を避けるため、個別 defect の検出は既存 registry skill に委譲し、本観点は 証拠充足の meta 評価のみを行う。委譲表・証拠要件・分界は DELEGATION.md を SSoT とする。委譲先が finding を出す領域を本観点は重複指摘しない。
Security Audit では Phase 3 schema/runtime validator も既存 owner である。shape、taxonomy、duplicate、summary drift を本 skill で再実装しない。
report-only 契約に従う。本観点はマージを止めない。判定素材を返すだけで、反復・停止・エスカレーションは caller の責務である。
gate.decision へ写像する(loop-convergence-contract.md「Unknown Coverage verdict の写像」表が SSoT)。| verdict | 既存語彙 | 条件 |
|---|---|---|
pass | GO / GO_WITH_OBSERVATION | Blocking Unknown なし・必要証拠あり。resolution が merge 後の観測で足りる非 Blocking Unknown のみ残る場合は GO_WITH_OBSERVATION |
needs_review | ESCALATE(要人間) | merge 前に解消すべき非 Blocking Unknown / 証拠不足 → severity: major + §4 残リスク |
fail | NO_GO(要修正) | セキュリティ / データ損失 / 互換性 / 不可逆の重大 Blocking Unknown → severity: critical |
判別軸は resolution の実行タイミング(merge 前 / merge 後) に置く。非 Blocking Unknown が残ること自体は needs_review を意味しない。その resolution が merge 後の観測(次回 eval run・運用レビュー等)で足りるなら pass(GO_WITH_OBSERVATION)に倒し、merge 前に解消すべきものだけを needs_review(ESCALATE)に倒す。
判定原則: Unknown の存在だけで自動的に fail にはしない。severity・blocking・根拠・復旧可能性で判断し、未確認と「確認済みでリスク受容」を区別する。fail-safe(判定不能 → NO_GO / ESCALATE)は src/lib/gate-decision.mjs の決定論純関数が担う。resolution が merge 後の観測で足りる非 Blocking Unknown を finding として出す場合、severity は minor / info に制限する(major 以上を出しながら verdict: pass に写像すると矛盾するため)。
resolution の追跡先明示: GO_WITH_OBSERVATION へ写像する残存 Unknown の resolution には、追跡可能な観測先(次回 eval run / follow-up issue / 運用レビュー等)を明示する。追跡先の無い resolution は放置されると観測ではなく単なる未解消に陥るため、その場合は needs_review(ESCALATE)へ倒す。
skippedSkills の出力例: plan / review-self 欠損時は該当観点を skippedSkills に記録し、finding は出さずデグレードする(artifact-input-contract.md と同じ語彙・review-artifact.md の id / reasons スキーマに整合)。例:
"skippedSkills": [
{ "id": "unknown-coverage-review#6", "reasons": ["plan artifact missing"] }
]file:line は差分内にあること(VERIFICATION の evidence 規則)。差分外の推測に基づく Unknown は finding にせず question として返す。info 相当として扱い、保持の優先順は findings(severity 降順)→ questions とし、上限超過分は優先度の低い側(questions → 低 severity findings)から切り捨てる。Use the profile-local guards in SECURITY-AUDIT-PROFILE.md. In particular, do not require every attack class, do not treat a valid exclusion as a gap, do not treat low evidence volume as insufficient by itself, and do not flag zero findings unless the report makes an unsupported safety inference.
© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (references) in plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review of hashgraph-online/awesome-codex-plugins.
Open the folder on GitHubat commit 9e7b281
Unknown Coverage Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Unknown Coverage Review this skillhashgraph-online/awesome-codex-plugins | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skillward AuditFangcun-AI/SkillWard | 143 | — | ~2.9k | Automated safety check: Pass | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Fangcun-AI/SkillWard
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
hashgraph-online/awesome-codex-plugins
Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.
hashgraph-online/awesome-codex-plugins
Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).
hashgraph-online/awesome-codex-plugins
A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…
hashgraph-online/awesome-codex-plugins
Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…
hashgraph-online/awesome-codex-plugins
Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.
hashgraph-online/awesome-codex-plugins
Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.
Categories
完成した差分・PR・検証証拠に残る Unknown(未確認の前提・調査されていない影響・ 不足している証拠)を横断合成する evidence-sufficiency のメタ観点。個別 defect の 検出は既存 skill へ委譲し、本 skill は「そのリスク種別を調査した証拠が残っているか」 の meta 評価のみを行う。通常は finding verification 後の…. Unknown Coverage Review is an agent skill from hashgraph-online/awesome-codex-plugins.
Unknown Coverage Review fits situations like: tasks that involve Security review.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a claude-code`. Or copy the skill folder (plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review in hashgraph-online/awesome-codex-plugins) into .claude/skills/unknown-coverage-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a codex`. Or copy the skill folder (plugins/s977043/river-review/skills/agent-skills/unknown-coverage-review in hashgraph-online/awesome-codex-plugins) into .agents/skills/unknown-coverage-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill unknown-coverage-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unknown-coverage-review, .gemini/skills/unknown-coverage-review, .github/skills/unknown-coverage-review and .opencode/skills/unknown-coverage-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Unknown Coverage Review is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: claude.com, aihero.dev and zenn.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Unknown Coverage Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Unknown Coverage Review: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.
Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.