Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.

BSD-3-ClauseAuto-check passedSecurity

Install Pre PR Security Cycle

skills CLI
$ npx skills add InternationalColorConsortium/iccDEV --skill pre-pr-security-cycle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install InternationalColorConsortium/iccDEV pre-pr-security-cycle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/InternationalColorConsortium/iccDEV.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/pre-pr-security-cycle .claude/skills/pre-pr-security-cycle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pre-pr-security-cycle
GitHub stars
183
Token cost
~1.4k tokens
SKILL.md length
645 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.

  • Works in 9 steps: Implement the smallest complete change. → Build and run the nearest deterministic… → Run SAST for the changed surface. → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Scope, Loop, SAST Selection and Dynamic Checks, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pre PR Security Cycle is an agent skill from InternationalColorConsortium/iccDEV. Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. The repository describes itself as: iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. The licence is BSD-3-Clause.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/pre-pr-security-cycle”

Requirements

  • Python 3
  • Docker
  • Pre-approved tools (allowed-tools): bash, read, grep, glob, shell(git:*), shell(gh:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Implement the smallest complete change.
  2. Build and run the nearest deterministic tests.
  3. Run SAST for the changed surface.
  4. Run dynamic, sanitizer, packaging, or artifact checks for the changed
  5. Fix confirmed findings.
  6. Repeat only the checks affected by the fix.
  7. Freeze the head and record the evidence and base...HEAD contract matrix in
  8. If a re-review finds any new blocker, including one in the repair, stop
  9. Prepare a concise handoff.

What it can do on your machine

Read from SKILL.md and the folder at commit 3c2425d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • bash
    • read
    • grep
    • glob
    • shell(git:*)
    • shell(gh:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pre PR Security Cycle loads about 1.4k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 645 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from InternationalColorConsortium/iccDEV at commit 3c2425d, republished under its BSD-3-Clause licence (© InternationalColorConsortium). 645 words, ~1,437 tokens.

Download SKILL.mdSave it as .claude/skills/pre-pr-security-cycle/SKILL.md (or your agent's skills folder).
name
pre-pr-security-cycle
description
Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.
allowed-tools
bash, read, grep, glob, shell(git:*), shell(gh:*)

Pre-PR Security Cycle

Use this skill before opening, updating, or finalizing an iccDEV PR that touches C/C++, CMake, CI, release packaging, sanitizer policy, CodeQL, or other security automation.

Scope

  • Keep the branch focused on one feature, fix, or governance change.
  • Do not bundle opportunistic cleanup unless it is required for the check to pass.
  • Identify whether the change is contributor code, maintainer infrastructure, or both.
  • For maintainer infrastructure, prefer a conservative security-review loop: run the relevant local scanners, patch confirmed findings, retest, and record any accepted scanner noise with a clear rationale.
  • Runner-reduction changes must retain trusted-base sanitizer sourcing, sanitization for every workflow output, and path-gated coverage for container changes.

Loop

  1. Implement the smallest complete change.
  2. Build and run the nearest deterministic tests.
  3. Run SAST for the changed surface.
  4. Run dynamic, sanitizer, packaging, or artifact checks for the changed surface.
  5. Fix confirmed findings.
  6. Repeat only the checks affected by the fix.
  7. Freeze the head and record the evidence and base...HEAD contract matrix in docs/governance/UPSTREAM_PR_READINESS.md before requesting review. Map each changed cross-cutting surface to its producer, consumer, build/runtime behavior, platform or toolchain boundary, CI trigger, dependency owner, and local evidence.
  8. If a re-review finds any new blocker, including one in the repair, stop serial review and return to branch-only grooming until a maintainer directs the next step.
  9. Prepare a concise handoff.

For focused local iteration, run .github/scripts/preflight-safety-checks.sh --fast-lane=matlab for MATLAB-only work, or plain --fast-lane for other changed workflow/script surfaces. These skip local CodeQL database/query work. Do not add unrelated CTest coverage: MATLAB-only changes use the focused MATLAB build and QA, while the full local or hosted preflight remains the final workflow security signal.

SAST Selection

ChangeRequired static checks
Workflow YAMLWorkflow governance prompt, YAML parse, actionlint, zizmor, CodeQL Actions analysis, expression-in-run scan
Python scriptPython syntax check and CodeQL Python analysis
Shell scriptShellCheck and zizmor; CodeQL Actions covers inline workflow run: blocks, not standalone shell scripts
C/C++ or CMake security pathCodeQL local script or hosted ci-codeql-security; query changes also require a positive fixture and a safe negative control
Parser/profile/tool behaviorCode review hunting prompt plus sanitizer build where practical
Release, WASM, vcpkgGovernance prompt plus package/runtime smoke logs
Dockerfile or container imagehadolint, Trivy config/image scan, Dockle/Grype/Syft when practical

CodeQL does not replace YAML, shell, or permissions review.

For workflow changes, also review ../../../docs/workflow-security-trust-boundaries.md. PR workflows that build PR code must use trusted-base .github/scripts helpers for sanitizers, summaries, and reusable workflow logic; any PR-controlled helper execution must be test-only and explicitly visible in preflight output.

Show full SKILL.md (219 more words)Show less

Dynamic Checks

Choose the smallest dynamic check that proves the changed behavior:

  • CTest suite or focused regression for profile/tool changes.
  • ASAN/UBSAN/IntSan command for parser or untrusted input changes.
  • Docker runtime smoke and image vulnerability/secret scan for container changes.
  • MCP runtime changes must validate every affected Docker image variant. Assert that discovered CLI tools match TOOL_BINARIES and inspect optional-capability flags; do not use a fixed health-tool count shared across variants.
  • Dockerfile checks must not be advisory-only when container files changed: run hadolint and Trivy config, then build, scan, or smoke the affected image when practical.
  • Confirm that container-surface (image_definition_changed) changes select workflow-security gates without adding a Docker verification job or full PR matrix to the aggregate status.
  • For container changes, validate the same helper checks that the publishing workflow validates, including patch checkers, applicators, environment banners, and healthcheck semantics.
  • WASM validation and parity for Emscripten changes.
  • Release ZIP/checksum/artifact shape check for release packaging changes.
  • vcpkg consumer smoke for port/export changes.

Handoff

Report only merge-relevant evidence:

  • branch and commit SHA;
  • changed surface;
  • commands or workflow run IDs;
  • pass/fail conclusion and key sentinel counts;
  • known skips, suppressions, warnings, or deferred follow-ups;
  • reviewed cache/artifact/token/script exceptions and trust-boundary notes;
  • whether the PR is merge-ready.

Prefer a short human-golfed report over raw logs.

References

  • ../../../docs/pre-pr-security-cycle.md
  • ../../../docs/workflow-security-trust-boundaries.md
  • ../../../docs/build.md
  • ../../../docs/ctest.md
  • ../../../docs/codeql.md
  • ../../../docs/regression-workflow-governance.md
  • ../../../docs/governance/UPSTREAM_PR_READINESS.md
  • ../../prompts/pre-pr-security-cycle.prompt.md
  • ../../prompts/audit-workflow-governance.prompt.md
  • ../../prompts/build-and-test.prompt.md
  • ../../prompts/code-review-hunting.prompt.md

© InternationalColorConsortium, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/pre-pr-security-cycle of InternationalColorConsortium/iccDEV.

Open the folder on GitHubat commit 3c2425d

Compare with similar skills

Pre PR Security Cycle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pre PR Security Cycle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pre PR Security Cycle this skillInternationalColorConsortium/iccDEV183—~1.4kAutomated safety check: PassBSD-3-Clause
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner288—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    288 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Wp Phpstan

    Automattic/agent-skills

    A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

    211 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed

More from InternationalColorConsortium/iccDEV

All 23 skills in this repo
  • Afl Smoke

    InternationalColorConsortium/iccDEV

    Run or update the iccDEV AFL++ manual smoke workflow, seeds, and maintainer documentation.

    183 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Avx2 Clut Diagnostics

    InternationalColorConsortium/iccDEV

    Diagnose runtime-dispatched AVX2 3D CLUT interpolation, collect trace evidence, validate vector and masked-tail output, and prepare optimization handoff data.

    183 GitHub stars~850 tokensUpdated yesterday
    Auto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • iOS Clut Editor

    InternationalColorConsortium/iccDEV

    Build, review, and maintain the ios-clut-editor profile and 3D CLUT editing proof-of-concept app without repeating prior iOS review-loop failures.

    183 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • iOS Manual Examples

    InternationalColorConsortium/iccDEV

    Maintain the manual iOS example app CMake projects, local Xcode build helpers, device signing guard rails, and documentation.

    183 GitHub stars~796 tokensUpdated yesterday
    Auto-check passed
  • JSON Config Regression

    InternationalColorConsortium/iccDEV

    Validate iccDEV JSON/profile config parser changes with fail-closed regression gates and CLI exercises.

    183 GitHub stars~469 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Pre PR Security Cycle

What does Pre PR Security Cycle do?

Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff. Pre PR Security Cycle is an agent skill from InternationalColorConsortium/iccDEV. Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.

When should I use Pre PR Security Cycle?

Pre PR Security Cycle fits situations like: tasks that involve Static analysis and SAST.

How do I install Pre PR Security Cycle in Claude Code?

Run `npx skills add InternationalColorConsortium/iccDEV --skill pre-pr-security-cycle -a claude-code`. Or copy the skill folder (.github/skills/pre-pr-security-cycle in InternationalColorConsortium/iccDEV) into .claude/skills/pre-pr-security-cycle in your project. Claude Code loads it when a task matches its description.

How do I install Pre PR Security Cycle in Codex?

Run `npx skills add InternationalColorConsortium/iccDEV --skill pre-pr-security-cycle -a codex`. Or copy the skill folder (.github/skills/pre-pr-security-cycle in InternationalColorConsortium/iccDEV) into .agents/skills/pre-pr-security-cycle in your project. Codex loads it when a task matches its description.

Can I use Pre PR Security Cycle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add InternationalColorConsortium/iccDEV --skill pre-pr-security-cycle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pre-pr-security-cycle, .gemini/skills/pre-pr-security-cycle, .github/skills/pre-pr-security-cycle and .opencode/skills/pre-pr-security-cycle in your project.

What does Pre PR Security Cycle need to run?

SKILL.md names no scripts, command-line tools or credentials: Pre PR Security Cycle is instructions for the agent only. Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: bash, read, grep, glob, shell(git:*), shell(gh:*).

Does Pre PR Security Cycle access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pre PR Security Cycle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pre PR Security Cycle use?

Pre PR Security Cycle is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pre PR Security Cycle use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pre PR Security Cycle?

Skills that share tags, products or a category with Pre PR Security Cycle: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 288 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pre PR Security Cycle?

InternationalColorConsortium (a GitHub organization) maintains it in InternationalColorConsortium/iccDEV, which has 183 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: InternationalColorConsortium/iccDEV on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.