Strix Code Vulnerability Scan
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/generating-executive-summary .claude/skills/generating-executive-summary && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .claude/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summaryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/generating-executive-summary .agents/skills/generating-executive-summary && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .agents/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/generating-executive-summary .cursor/skills/generating-executive-summary && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .cursor/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/generating-executive-summary--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/generating-executive-summary .gemini/skills/generating-executive-summary && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .gemini/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summaryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/generating-executive-summary .github/skills/generating-executive-summary && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .github/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/generating-executive-summary .opencode/skills/generating-executive-summary && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "generating-executive-summary" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/generating-executive-summary into .opencode/skills/generating-executive-summary/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generating-executive-summary", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
generating-executive-summaryCompose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.
Generating Executive Summary is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Computes a single engagement risk score (0-100, severity-weighted with OWASP-breadth and governance terms), rolls up findings into headline counts, names the top-3 remediation priorities with effort + impact estimates, and produces a 1-2 page markdown document for a C-level or board audience. Elides technical detail; the vulnerability report is the deep document. Use when: closing an engagement, preparing the…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/exec_summary.py`). Compatibility notes: Designed for Claude Code
It sits in Security, covering Summarization, Web application vulnerabilities and Test coverage. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteBash(python3:*)GlobFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Generating Executive Summary loads about 2.2k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 220 tokens; SKILL.md has 730 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Write(.env)- Edit(.env)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 730 words, ~2,229 tokens.
.claude/skills/generating-executive-summary/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.The vulnerability report is comprehensive — every finding, full detail, every reference. The C-level reader doesn't open it. They ask their security lead "what should I tell the board?" The security lead needs a one-page answer.
That one-page answer is the executive summary. It states the engagement's bottom line:
The summary doesn't omit anything important; it just compresses. The vulnerability report remains the deep artifact for anyone who needs the technical detail.
This skill consumes the enriched findings JSONL (after OWASP mapping) + the OWASP coverage report + the ROE, computes the risk score, picks the top remediation priorities deterministically, and renders the document.
| Finding | Severity | Threshold | Affected control |
|---|---|---|---|
| Input findings file missing | CRITICAL | Source JSONL doesn't exist | (operational) |
| OWASP coverage report missing | HIGH | Coverage referenced but not present | (operational) |
| ROE missing | MEDIUM | Can still generate summary but lacks scope/authz context | (operational) |
| Exec summary written cleanly | INFO | Confirmation | (informational) |
| Risk score >75 (high engagement risk) | HIGH | Computed risk score elevated | (advisory) |
| Risk score >90 (critical engagement risk) | CRITICAL | Engagement exposed material risk; needs urgent action | (advisory) |
The single risk score is the headline number on the exec summary. The composition is deterministic and documented:
risk = clamp(0, 100,
20 * count(CRITICAL)
+ 10 * count(HIGH)
+ 3 * count(MEDIUM)
+ 1 * count(LOW)
+ 0 * count(INFO)
+ 5 * (count(distinct OWASP categories touched) - 5 if >5 else 0)
- 10 * 1 if engagement was authorized cleanly and in-scope (governance bonus)
)The first five terms weight by severity. The OWASP-coverage term adds 5 points per category beyond 5 (a broader-finding engagement implies broader risk surface). The governance bonus is a -10 adjustment when ROE was clean — explicit recognition that finding problems in a well-governed engagement is HEALTHIER than finding the same problems in a chaotic engagement.
Score interpretation:
| Score | Reading |
|---|---|
| 0-25 | Low risk: clean engagement OR very narrow scope |
| 26-50 | Moderate risk: typical engagement with manageable findings |
| 51-75 | Elevated risk: significant findings, remediation planning required |
| 76-90 | High risk: material findings; executive attention warranted |
| 91-100 | Critical risk: urgent remediation required; consider treating as incident |
The skill picks top-3 priorities deterministically by:
Each priority gets:
Effort + impact are heuristic estimates based on the source
skill's category — operator can override via --priority-overrides
for cases where the heuristic is wrong.
engagement/findings/all-with-owasp.jsonl
(output of mapping-findings-to-owasp-top10) OR an explicit
--source FILEengagement/reports/owasp-coverage.md
(referenced; optional)engagement/roe.yaml (referenced for scope summary)ls engagements/acme-2026-q2/findings/all-with-owasp.jsonl
ls engagements/acme-2026-q2/reports/owasp-coverage.md
ls engagements/acme-2026-q2/roe.yamlAll three should exist for a complete summary. The skill works without the coverage report or ROE but the summary is less complete.
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/Options:
Usage: exec_summary.py PATH [OPTIONS]
Options:
--source FILE Findings JSONL (default: PATH/findings/all-with-owasp.jsonl)
--coverage FILE OWASP coverage report (default: PATH/reports/owasp-coverage.md)
--roe FILE ROE (default: PATH/roe.yaml)
--summary-output FILE Output path (default: PATH/reports/executive-summary.md)
--output FILE Operational findings output
--format FMT json | jsonl | markdown (default: markdown)
--min-severity SEV default info
--priority-overrides FILE YAML overriding the top-3 prioritiesIf the score is in 76-100 range, the operator should sanity-check before delivering: did the underlying findings actually warrant the elevated reading, or did a few INFO-tagged findings get mis-categorized as HIGH?
The exec summary is intended as a standalone artifact. Deliver to the customer's exec readout meeting, along with the full vulnerability report.
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/python3 ./scripts/exec_summary.py engagements/acme-2026-q2/ \
--summary-output engagements/acme-2026-q2/reports/board-summary.md# priorities-override.yaml
- title: "Hardcoded AWS access key in source"
effort: Hours
impact: Material
rationale: This is the single highest-priority remediation regardless of count.python3 ./scripts/exec_summary.py engagements/acme-2026-q2/ \
--priority-overrides priorities-override.yamlJSON / JSONL / Markdown per lib/report.py for operational
findings. PRIMARY output: the executive-summary markdown
document.
Operational Finding includes:
id — exec::<issue>severity — variescategory — executive-summarysummary — what was generatedevidence — risk score, finding count, top priorities, output pathreferences/THEORY.md — Executive-summary writing as a
technical-communication discipline, single-number risk
scoring tradeoffs, why deterministic priority selection beats
human-curated for reproducibility, how the score interpretation
bands were chosen, comparison with CVSS / DREAD / STRIDE risk
modelsreferences/PLAYBOOK.md — Per-audience customizations (board,
C-suite, security leadership, customer auditor), summary length
guidelines, common rewrite patterns, integration with the
composing + mapping skills, post-delivery follow-up cadence© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/.curated/generating-executive-summary of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Generating Executive Summary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Generating Executive Summary this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 68k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Fix Strix Security Findingsusestrix/strix | 68k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| OWASP Top 10 Testing with Strixusestrix/strix | 68k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 |
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
usestrix/strix
Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Generating Executive Summary is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.
Generating Executive Summary fits situations like: : closing an engagement; preparing the exec-readout meeting; packaging for board review; producing a one-page narrative for auditor / insurer / board.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a claude-code`. Or copy the skill folder (skills/.curated/generating-executive-summary in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/generating-executive-summary in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a codex`. Or copy the skill folder (skills/.curated/generating-executive-summary in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/generating-executive-summary in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generating-executive-summary, .gemini/skills/generating-executive-summary, .github/skills/generating-executive-summary and .opencode/skills/generating-executive-summary in your project.
Going by SKILL.md and its folder, Generating Executive Summary needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Generating Executive Summary is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Generating Executive Summary: Strix Code Vulnerability Scan (usestrix/strix, 68k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Fix Strix Security Findings (usestrix/strix, 68k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.