Fory Release
apache/fory
Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.
Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements
$ npx skills add jmagly/aiwg --skill banned-api-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jmagly/aiwg banned-api-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .claude/skills/banned-api-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .claude/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jmagly/aiwg --skill banned-api-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jmagly/aiwg banned-api-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .agents/skills/banned-api-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .agents/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jmagly/aiwg --skill banned-api-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jmagly/aiwg banned-api-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .cursor/skills/banned-api-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .cursor/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jmagly/aiwg.git --path agentic/code/plugins/security-engineering/skills/banned-api-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jmagly/aiwg --skill banned-api-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jmagly/aiwg banned-api-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .gemini/skills/banned-api-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .gemini/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jmagly/aiwg banned-api-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jmagly/aiwg --skill banned-api-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .github/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .github/skills/banned-api-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .github/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jmagly/aiwg --skill banned-api-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jmagly/aiwg banned-api-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .opencode/skills/banned-api-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "banned-api-audit" agent skill from https://github.com/jmagly/aiwg/tree/main/agentic/code/plugins/security-engineering/skills/banned-api-audit into .opencode/skills/banned-api-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "banned-api-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
banned-api-auditScan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements
Banned API Audit is an agent skill from jmagly/aiwg. Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts (for example `banlists/c.yaml`, `banlists/cpp.yaml` and `banlists/go.yaml`).
It works with C++ and Rust. The repository describes itself as: Cognitive architecture for AI-augmented software development. Specialized agents, structured workflows, and multi-platform deployment. Claude Code · Codex · Copilot · Cursor ·… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit dda238f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (JavaScript and Shell), which the agent can run.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
curl.segithub.comdocs.oasis-open.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Banned API Audit loads about 2.2k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 546 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jmagly/aiwg at commit dda238f, republished under its MIT licence (© jmagly). 546 words, ~2,156 tokens.
.claude/skills/banned-api-audit/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.You are the Banned API Auditor — scan source code for prohibited functions and APIs declared in the project banlist, report violations with full context, and exit with a CI-suitable status code.
"Eliminate CVE classes by construction." Banning a dangerous API is cheaper than vigilance. The audit makes the ban enforceable: every CI run rejects any new occurrence; existing violations are tracked until remediated or explicitly excepted.
--starter <language> (optional)Use a bundled starter banlist instead of (or in addition to) the project banlist. Useful for a first-time audit before the project has its own banned-apis.yaml. Valid: c, cpp, python, node, go, rust.
--fail-on-violation (optional)Exit non-zero when ANY violation is found. Default: exit 0 always (report-only mode for first runs and migration audits).
--paths <glob>... (optional)Limit the scan to these paths. Overrides paths: declarations in the banlist. Useful for scoped PR audits.
--format text|json|both|sarif (default both)text to stdout, json to .aiwg/security/banned-api-audit/, or both.
--sarif (optional)Also emit SARIF 2.1.0 to .aiwg/security/banned-api-audit/ for code-scanning ingest.
Look for .aiwg/security/banned-apis.yaml.
If --starter <lang> is set, merge the bundled starter into the active banlist (project banlist wins on pattern conflict).
If neither exists, emit a guided message:
No banlist found. Bootstrap with:
aiwg run skill banned-api-audit -- --starter c
Or seed your own at .aiwg/security/banned-apis.yamlDefault exclusions (always applied unless --paths overrides):
test/**, tests/**, **/*_test.*, **/*.test.*vendor/**, node_modules/**, target/**, dist/**, build/**.git/**, .aiwg/**, .claude/**, .codex/**, .factory/**Project banlist paths: declarations narrow further (e.g., src/** only).
For each (language, pattern) pair:
# Word-boundary literal pattern
rg -n --type <lang> -w '<pattern>' <paths>
# Regex pattern (when prefixed re:)
rg -n --type <lang> '<regex>' <paths>Language → ripgrep --type mapping:
c → ccpp → cpppython → pynode → js,ts,tsx,jsxgo → gorust → rustFor each candidate violation, check the source line and the preceding 2 lines for:
AIWG-allow:banned-apis reason="..."When present, classify as excepted (not a violation). Record the reason in the report so security reviewers can grep all exceptions periodically.
Text report format:
Banned API Audit — 2026-05-21T17:30:00Z
Banlist: .aiwg/security/banned-apis.yaml (24 patterns across 3 languages)
Paths: src/, lib/
Excluded: test/, tests/, vendor/, node_modules/
VIOLATIONS (3)
src/auth/token.c:42: strcpy(buf, user_input);
pattern: strcpy (language: c)
reason: Unbounded copy — buffer overflow vector
replacement: strncpy_s, strlcpy, or snprintf with bounds
src/parser/json.c:118: sprintf(out, "%s/%s", base, path);
pattern: sprintf (language: c)
reason: Unbounded format expansion — overflow + format-string risk
replacement: snprintf with explicit buffer size
src/util/legacy.py:7: user = pickle.loads(payload)
pattern: re:pickle\.loads?\b (language: python)
reason: Arbitrary code execution on untrusted input
replacement: json, msgpack, or signed pickle with integrity check
EXCEPTIONS (1)
src/compat/curses_wrapper.c:33: char *tok = strtok(buf, " ");
pattern: strtok
reason: curses interop requires strtok per legacy API contract
SUMMARY
Violations: 3
Exceptions: 1
Patterns: 24
Files scanned: 184JSON report (machine-readable, suitable for SARIF conversion or CI dashboard ingest):
{
"schemaVersion": "1",
"auditedAt": "2026-05-21T17:30:00Z",
"banlistPath": ".aiwg/security/banned-apis.yaml",
"patterns": 24,
"filesScanned": 184,
"violations": [
{
"file": "src/auth/token.c",
"line": 42,
"column": 5,
"match": "strcpy(buf, user_input);",
"pattern": "strcpy",
"language": "c",
"reason": "Unbounded copy — buffer overflow vector",
"replacement": "strncpy_s, strlcpy, or snprintf with bounds",
"severity": "HIGH"
}
],
"exceptions": [ /* same shape, plus exceptionReason */ ]
}0 — no violations, OR violations present but --fail-on-violation not set1 — banlist missing AND no --starter flag2 — violations present AND --fail-on-violation set3 — ripgrep not installed or other tooling failureGitea Actions:
- name: Banned-API audit
run: aiwg run skill banned-api-audit -- --fail-on-violationGitHub Actions:
- name: Banned-API audit
run: aiwg run skill banned-api-audit -- --fail-on-violationBundled at banlists/:
c.yaml — C dangerous functions (strcpy, sprintf, gets, strtok, atoi)cpp.yaml — C++ overlay (auto_ptr, gets, strcpy)python.yaml — eval, exec, pickle.loads, subprocess shell=Truenode.yaml — eval, new Function, child_process.execgo.yaml — shell-string commands, weak hashes, HTML templating footgunsrust.yaml — unsafe/transmute/unwrap review gates, shell-string commandsUsers seed their project banlist via --starter <lang> and customize.
The CRITICAL applied-cryptography rules (no-unauthenticated-encryption, no-adhoc-kdf, no-key-reuse-across-purposes) are enforced separately by their own audit paths. This skill does not replace them; it complements them with HIGH-severity language-level policy.
Cycle 2 adds:
scripts/audit.sh / scripts/audit.mjs reference implementation.schema.json documenting the banlist YAML shape.0 clean/report-only, 1 banlist/schema problem, 2 violations with --fail-on-violation, 3 tooling failure..aiwg/security/curl-checklist-gap-analysis.md row 2 — Audit context© jmagly, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (scripts) in agentic/code/plugins/security-engineering/skills/banned-api-audit of jmagly/aiwg.
Open the folder on GitHubat commit dda238f
Banned API Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Banned API Audit this skilljmagly/aiwg | 220 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Fory Releaseapache/fory | 4.6k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| SeekDB Code Reviewoceanbase/seekdb | 3.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Fory Version Bumpapache/fory | 4.6k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Add Grammarafnanenayet/diffsitter | 2.4k | — | ~1.9k | Automated safety check: Notes | MIT | |
| Fory Performance Optimizationapache/fory | 4.6k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
apache/fory
Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.
oceanbase/seekdb
Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.
apache/fory
Bump Apache Fory release or post-release development versions across Java, Kotlin, Scala, Python, Rust, Go, C++, C, Dart, JavaScript, Swift, integration tests, examples, and source docs.
afnanenayet/diffsitter
Step-by-step guide for adding a new tree-sitter language grammar to diffsitter.
apache/fory
Run profile-driven bottleneck optimization across Apache Fory implementations (Java, C++, Python/Cython, Go, Rust, Swift, C, JavaScript/TypeScript, Dart, Kotlin, Scala).
crossbind/crossbind
A skill your agent uses when a user wants to call C++ or Rust from JavaScript or TypeScript; add a native library such as GDAL, SQLite, OpenSSL, GEOS or PROJ to a browser, Node.js, Cloudflare Worker…
jmagly/aiwg
Review editorial phrase patterns and suggest contextual alternatives; legacy name does not imply authorship detection.
jmagly/aiwg
Apply a voice profile to transform content. An agent skill from jmagly/aiwg.
jmagly/aiwg
Run mutation testing to validate test quality beyond code coverage.
jmagly/aiwg
Configure TDD enforcement via pre-commit hooks and CI coverage gates.
jmagly/aiwg
Detect project type, AIWG framework state, team configuration, and active work to summarize status and recommend next actions
jmagly/aiwg
Manage artifact metadata, versioning, ownership, and review history across the SDLC lifecycle
Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements. Banned API Audit is an agent skill from jmagly/aiwg.
Run `npx skills add jmagly/aiwg --skill banned-api-audit -a claude-code`. Or copy the skill folder (agentic/code/plugins/security-engineering/skills/banned-api-audit in jmagly/aiwg) into .claude/skills/banned-api-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jmagly/aiwg --skill banned-api-audit -a codex`. Or copy the skill folder (agentic/code/plugins/security-engineering/skills/banned-api-audit in jmagly/aiwg) into .agents/skills/banned-api-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jmagly/aiwg --skill banned-api-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/banned-api-audit, .gemini/skills/banned-api-audit, .github/skills/banned-api-audit and .opencode/skills/banned-api-audit in your project.
Going by SKILL.md and its folder, Banned API Audit needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (rg). Our summary lists: Node.js; A Bash shell.
SKILL.md names 3 domains. As links in the text: curl.se, github.com and docs.oasis-open.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Banned API Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Banned API Audit: Fory Release (apache/fory, 4.6k stars), SeekDB Code Review (oceanbase/seekdb, 3.1k stars), Fory Version Bump (apache/fory, 4.6k stars) and Add Grammar (afnanenayet/diffsitter, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jmagly (a GitHub user) maintains it in jmagly/aiwg, which has 220 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.
Source: jmagly/aiwg on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.