Agent skill

Av False Positive

by kdeldycke in kdeldycke/dotfiles

Scan a release on VirusTotal. An agent skill from kdeldycke/dotfiles.

BSD-2-ClauseAuto-check: notes

Install Av False Positive

skills CLI
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdeldycke/dotfiles av-false-positive --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .claude/skills/av-false-positive && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
av-false-positive
GitHub stars
173
Token cost
~4.7k tokens
SKILL.md length
2,018 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
BSD-2-Clause

At a glance

Scan a release on VirusTotal. An agent skill from kdeldycke/dotfiles.

  • Works in 7 steps: resolve version and artifacts → retrieve or refresh VirusTotal results → collect results → …
  • SKILL.md covers Context and Instructions
  • Calls gh and git; reaches virustotal.com and github.com; needs VIRUSTOTAL_API_KEY

What it does

Av False Positive is an agent skill from kdeldycke/dotfiles. Scan a release on VirusTotal. Write submission instructions for each AV vendor that flags a false positive.

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Recommended model: Opus.

The repository describes itself as: 🍎 macOS dotfiles for Python developers. The licence is BSD-2-Clause.

Example prompts

  • “/av-false-positive”

Requirements

  • Python 3
  • A credential in VIRUSTOTAL_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus.
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, Agent

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. resolve version and artifacts
  2. retrieve or refresh VirusTotal results
  3. collect results
  4. print summary table
  5. generate per-vendor submission files
  6. download flagged binaries
  7. report

What it can do on your machine

Read from SKILL.md and the folder at commit 37173b9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • virustotal.com
    • github.com

    Also links to:

    • repomatic.net
    • microsoft.com
    • bitdefender.com
    • support.eset.com
    • symsubmit.symantec.com
    • avast.com
    • support.sophos.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VIRUSTOTAL_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code. Recommended model: Opus.

    From compatibility in the SKILL.md frontmatter.

Context cost

Av False Positive loads about 4.7k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 2,018 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdeldycke/dotfiles at commit 37173b9, republished under its BSD-2-Clause licence (© kdeldycke). 2,018 words, ~4,678 tokens.

Download SKILL.mdSave it as .claude/skills/av-false-positive/SKILL.md (or your agent's skills folder).
name
av-false-positive
description
Scan a release on VirusTotal. Write submission instructions for each AV vendor that flags a false positive.
allowed-tools
Bash, Read, Write, Grep, Glob, Agent
compatibility
Designed for Claude Code. Recommended model: Opus.
argument-hint
[version]

Context

!gh repo view --json nameWithOwner --jq '.nameWithOwner' 2>/dev/null !gh release view --json tagName --jq '.tagName' 2>/dev/null !grep -m1 'license' pyproject.toml 2>/dev/null !grep -m1 'name' pyproject.toml 2>/dev/null !grep -A1 '\[project.urls\]' pyproject.toml 2>/dev/null | head -5

Instructions

Scan release binaries on VirusTotal and generate per-vendor false-positive submission files for any flagged artifacts.

Step 1: resolve version and artifacts

If $ARGUMENTS is empty, use the latest release tag from the context above. Otherwise treat $ARGUMENTS as the version (accept both 6.2.1 and v6.2.1; normalize to bare version for filenames, v-prefixed for tags).

Detect the repository from the context (nameWithOwner). Extract the project name, license, and homepage URL from pyproject.toml.

Start from the scan history when present: docs/assets/virustotal-scans.csv holds one at-release snapshot per binary (tag, filename, SHA-256, scan date, per-category verdict counts), written by the release pipeline's scan-virustotal job. It identifies the flagged binaries of the target release without any API call, and the catalog in docs/binaries.md shows the same data at a glance. That job publishes through one long-lived scan-virustotal pull request each release appends to, so the newest release's records reach the default branch only once someone merges it: read the branch copy (git show origin/scan-virustotal:docs/assets/virustotal-scans.csv) before concluding the history carries nothing for the version. Fall back to listing release assets when neither copy has records for it:

shell-session
$ gh release view v{VERSION} --json assets --jq '.assets[].name'
Step 2: retrieve or refresh VirusTotal results

The release pipeline already uploaded every release binary at publication time, so a fresh upload is rarely needed. Per-engine detection details (which neither the CLI nor the scan history expose) always require querying the VT API directly via Python with the vt library. For a re-upload, use the scan-virustotal CLI command: it requires --tag and --binaries-dir, and --poll --records docs/assets/virustotal-scans.csv appends the fresh snapshot to the scan history (same-day re-scans replace their record; later dates accumulate, and the catalog keeps showing the earliest, at-release snapshot). Add --carry-from scan-virustotal, which restores the records still pending in that pull request before appending: without it the run writes a history missing every snapshot nobody has merged yet.

The VT API key comes from: $VIRUSTOTAL_API_KEY env var, or ask the user.

For each binary artifact (.bin, .exe):

  1. Download via gh release download.
  2. Compute SHA256 locally (must match the digest in the scan history, when present).
  3. Check GET /api/v3/files/{sha256} to see if VT already has results.
  4. If not found or results are stale (older than 7 days), upload via POST /api/v3/files.
  5. Poll GET /api/v3/analyses/{id} until status == "completed".
  6. Handle rate limits (HTTP 429) by waiting 60 seconds and retrying.
Step 3: collect results

For each artifact, record:

  • Filename, file size in bytes
  • SHA256
  • VT report URL: https://www.virustotal.com/gui/file/{sha256}
  • Total engines scanned
  • Number of malicious detections
  • For each engine that flagged it: engine name and detection name
  • The at-release snapshot from the scan history, when present: current counts below it mean earlier false-positive submissions are being processed

Also record the VT report URLs for the clean .whl and .tar.gz source distributions (used as evidence in every submission).

Step 4: print summary table

Print a markdown table:

ArtifactDetectionsVT reportVerdict
filenameN/M[link]Clean / FP (engines)
Step 5: generate per-vendor submission files

For each vendor in § Vendor definitions, check if any artifacts were flagged by that vendor's engine(s). If so, generate fp-submission-{vendor}.md at the project root.

Only generate a file for a vendor if at least one artifact was flagged by that vendor.

Output format: fully self-contained, zero cross-references

Each submission file must be optimized for copy-paste. The maintainer should be able to work through each submission without scrolling back or cross-referencing. Concretely:

  • Never write "copy from above" or "see the file section above". Every field value must be spelled out inline at the point of use.
  • For vendors requiring one submission per file: repeat the full form walkthrough for each binary as a separate ## Submission N section with --- separators.
  • For vendors accepting a single submission covering multiple files: one section is fine, but list every binary with its full details (SHA256, VT link, detection name, download URL) inline in the text.
  • Every pre-written text block must include the specific binary's VT scan link, the clean source distribution VT links, and the GitHub release link. No placeholders: use the actual URLs.
Dynamic project metadata

All submission text blocks must derive project details from pyproject.toml and git metadata:

  • Project name: from [project] name.
  • License: from [project] license.
  • Homepage/PyPI URL: from [project.urls].
  • Maintainer name: from git config user.name or [project] authors.
  • Previous FP reference: search the repo's GitHub issues for "false positive" or "VirusTotal" to find a prior reference issue. If none exists, omit the reference.
Vendor definitions

User-facing documentation of vendor portals, submission priority, and common issues is in docs/security.md § AV false-positive submissions.

Microsoft (engines: Microsoft)
  • Portal: https://www.microsoft.com/en-us/wdsi/filesubmission?persona=SoftwareDeveloper
  • Requires Microsoft account login. Select "Software developer" on the persona page.
  • One file per form submission. Generate a separate ## Submission N section per flagged binary.
  • Only include binaries where Microsoft's own engine returned category == "malicious". Windows ARM64 binaries are typically not flagged by Microsoft (only by MaxSecure), so check before including.
  • macOS binaries can be flagged by Microsoft too (with Wacatac variants): include them if detected.
  • Form fields per binary:
FieldValue
Microsoft security product used to scan the fileMicrosoft Defender Antivirus (Windows 10) or (Windows 11)
Company NameMaintainer name from project metadata
Do you have a Microsoft support case number?No
Select the fileUpload the exact filename
Should this file be removed from our database at a certain date?No
What do you believe this file is?Incorrectly detected as malware/malicious
Detection nameExact detection name for this binary
Definition version(leave blank)
Additional informationPaste the text below
  • Additional information: 1900 character limit. Include: binary's VT scan link, clean .whl and .tar.gz VT links, GitHub release link, project URL, PyPI URL, license, previous FP reference if found.
  • Known portal issues: the upload sometimes fails with CORS errors or stuck progress modals (auth session expiring mid-upload). Workaround: sign out, clear cookies for microsoft.com and wdsiprod.westus.cloudapp.azure.com, sign back in, submit immediately. Also check the URL doesn't have a duplicated ?persona=SoftwareDeveloper&persona=SoftwareDeveloper parameter.
BitDefender (engines: BitDefender, ALYac, Arcabit, Emsisoft, GData, MicroWorld-eScan, VIPRE)
  • Portal: https://www.bitdefender.com/submit/
  • BitDefender's engine powers ~6 downstream vendors. Fixing BitDefender removes the most detections per submission.
  • Only list artifacts flagged by the BitDefender engine itself (not downstream).
  • One file per submission. Max 25 MB per file upload.
  • The "Sensitive files / Screenshot" field is mandatory: instruct the user to take a screenshot of the VT report page showing the BitDefender detection row.
  • Form fields per binary:
FieldValue
Select the categoryFalse Positive
Full NameMaintainer name from project metadata
E-mail(user's email)
Sample typeFile
Attach a fileUpload the exact filename
Detection nameExact detection name
DescriptionPaste the pre-written text
Sensitive files / ScreenshotScreenshot of the VT report page showing the BitDefender detection
  • Generate one complete ## Submission N section per binary.
  • Known portal issues: the form sometimes returns "Your request could not be registered!" with no details. This is a backend issue on BitDefender's side. Retry later.
Show full SKILL.md (847 more words)Show less
ESET (engines: ESET-NOD32)
  • Method: email to samples@eset.com
  • Alternative portal: https://support.eset.com/en/kb141
  • Single email covering all flagged binaries. Attach files in a password-protected ZIP (password: infected).
  • Email attachment limit: ~24 MB. Nuitka binaries are ~23 MB each, so only one binary fits in the ZIP. Attach the first binary and reference all others by SHA256 and direct download URL in the email body so ESET can fetch them.
  • Email subject format: False positive: {detection_name} in {Project Name} {VERSION}
  • Email body must list per binary: filename, SHA256, detection name, VT report link, download URL. Also include clean source distribution VT links and GitHub release link.
  • ESET is the most reliable submission channel since it doesn't depend on any web portal being up.
Symantec / Broadcom (engines: Symantec)
  • Portal: https://symsubmit.symantec.com/false_positive
  • Click "Clean software incorrectly detected" on the landing page.
  • The FP form does not accept .exe or .bin file uploads. The file upload field only accepts images, logs, and text files (for supporting evidence). Use hash submission instead.
  • Hash submission accepts only one hash per form. To cover multiple binaries: submit the hash of one binary in the form field, and list all other binaries with their SHA256 hashes and VT links in the Additional Information text.
  • Single submission covering all binaries using the approach above.
  • The Additional Information field has a 5000 character limit.
  • Formatting caveat: the confirmation email renders the Additional Information as a single paragraph with no newlines. Use short, clearly separated lines and label each section (like Binary 1:, Binary 2:) so the text remains readable even when flattened.
  • Form structure has three fieldsets:

Product Details:

FieldValue
Which product were you using?Symantec Endpoint Protection 16.x (avoid "Don't know": it maps to UNKNOWN in their tracking system)
When did the detection occur?When downloading or uploading a file
Which type of detection?Download/File Insight (Reputation Based Detection) (best match for ML.Attribute.* detections; avoid "Don't know")
Detection NameExact detection name

Submission Details:

FieldValue
Submission TypeProvide an MD5 or SHA-256 hash of a file
File HashSHA256 of first binary

Additional Information (expand the collapsed section):

FieldValue
Recurring False Positive?Yes
Business Impact?Medium
Application Type?Third Party Application

Then paste the description text listing all binaries with SHA256, VT links, clean source VT links, and GitHub release link.

Your Details:

FieldValue
Contact NameMaintainer name from project metadata
Email Address(user's email)
Site ID Number(leave blank)
Avast/AVG (engines: Avast, AVG)
  • Portal: https://www.avast.com/submit-a-sample
  • Shared engine: one submission covers both Avast and AVG. Include artifacts flagged by either engine.
  • One file per submission. Select "I want to report a false detection (false positive)".
  • Generate one complete ## Submission N section per binary with all details inline.
  • Known portal issues: the form sometimes returns "An internal error occurred while sending the form." This is a backend issue. Retry later.
Sophos (engines: Sophos)
  • Portal: https://support.sophos.com/support/s/filesubmission
  • Max 25 MB total per submission (not per file). Nuitka binaries are ~23 MB each, so only one binary fits per submission.
  • One binary per form submission.
  • PUA detections require justification of the software's legitimate purpose. The description must explain what the project does and list its distribution channels.
  • Form fields per binary:
FieldValue
First NameMaintainer first name
Last NameMaintainer last name
Country(user's country)
Email Address(user's email)
About YouUsing a free product
Operating SystemWindows
Why do you want to send this sample?Paste the pre-written text
FileUpload the exact filename
  • Generate one complete ## Submission N section per binary.
Common rules for all vendors

Every binary entry in every submission file must include:

  • The binary's own VT report link (https://www.virustotal.com/gui/file/{sha256})
  • The VT report links for the clean .whl and .tar.gz (as comparison evidence)
  • The GitHub release link (https://github.com/{owner/repo}/releases/tag/v{VERSION})
  • The download URL for the binary (https://github.com/{owner/repo}/releases/download/v{VERSION}/{filename})

Pre-written text blocks must mention: Nuitka --onefile compilation, open-source project, GitHub and PyPI URLs, license from pyproject.toml, and the previous FP issue reference if one was found in the repo's GitHub issues.

Submission priority order
  1. Microsoft: most influential engine. ML detections (Sabsik, Wacatac) are the most impactful to fix.
  2. BitDefender: their engine powers ~6 downstream vendors. Highest detection-removal-per-submission ratio.
  3. ESET: reliable email channel, no portal dependency.
  4. Symantec: ML detections may take 3-7 business days.
  5. Avast/AVG: shared engine, one submission covers both.
  6. Sophos: PUA detections take up to 15 business days.
Step 6: download flagged binaries

Download all artifacts that appear in any submission file to $TMPDIR using gh release download with --pattern flags. These are needed for manual upload to vendor portals.

Step 7: report

Print a summary of what was generated:

  • Which fp-submission-*.md files were created (and which vendors were skipped because they had no detections)
  • Where the binaries were downloaded
  • Submission priority order and expected turnaround times
  • Note any vendor portals known to have intermittent issues (Microsoft, Avast, BitDefender)

Suggest a follow-up for after the vendors process the reports: re-running scan-virustotal --tag v{VERSION} --binaries-dir {dir} --poll --records docs/assets/virustotal-scans.csv --carry-from scan-virustotal appends the post-submission snapshot to the scan history, keeping the delisting trajectory on record without altering the at-release numbers shown in docs/binaries.md.

© kdeldycke, BSD-2-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in dotfiles/.agents/skills/av-false-positive of kdeldycke/dotfiles.

Open the folder on GitHubat commit 37173b9

Compare with similar skills

Av False Positive next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Av False Positive compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Av False Positive this skillkdeldycke/dotfiles173—~4.7kAutomated safety check: NotesBSD-2-Clause
Performing False Positive Reduction In Siemmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
False Positive Reviewerconorbronsdon/avoid-ai-writing4.9k—~1.1kAutomated safety check: PassMIT
Scanwshobson/agents40k—~2.2kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.5kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Performing False Positive Reduction In Siem

    mukul975/Anthropic-Cybersecurity-Skills

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • False Positive Reviewer

    conorbronsdon/avoid-ai-writing

    A skill your agent uses when a user asks what AI-writing flags mean, whether detector output proves AI authorship, or wants a careful interpretation of possible false positives, especially for…

    4.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Writing & ContentAuto-check passed
  • Scan

    wshobson/agents

    Scans the codebase to generate project-doc.md and AGENTS.md.

    40k GitHub stars~2.2k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Repo Scan

    affaan-m/ECC

    固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。

    276k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Repo Scan

    affaan-m/ECC

    用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。

    276k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Vulnerability Scanning

    sickn33/agentic-awesome-skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    47k GitHub starsUsed in 1 repo~2.8k tokens
    SecurityAuto-check passed

More from kdeldycke/dotfiles

All 25 skills in this repo
  • Agent Config Self Tune

    kdeldycke/dotfiles

    Audit and tune the configuration of coding agents across Claude Code and pi - settings files (settings.json, settings.local.json), permission rules, instruction files (CLAUDE.md, AGENTS.md), skill…

    173 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Audit Repo Issues

    kdeldycke/dotfiles

    Analyze a GitHub repository's issues and PRs to find unaddressed feature requests, dismissed ideas, maintenance signals, and opportunities relevant to the current project.

    173 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Brand Assets

    kdeldycke/dotfiles

    Create project logo and banner SVGs, then export them to light and dark PNG variants.

    173 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Fill Web Form

    kdeldycke/dotfiles

    Fill a web form using data extracted from local documents (PDFs, images, spreadsheets).

    173 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Rename With Dates

    kdeldycke/dotfiles

    Rename documents and files (PDFs, images, screenshots, etc.) by reading their content to extract the effective/publication date, then renaming them with a "YYYY-MM-DD - Clear descriptive title.ext"…

    173 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Repomatic Test Matrix

    kdeldycke/dotfiles

    Choose what a repository's CI test matrix covers. An agent skill from kdeldycke/dotfiles.

    173 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes

Questions about Av False Positive

What does Av False Positive do?

Scan a release on VirusTotal. An agent skill from kdeldycke/dotfiles. Av False Positive is an agent skill from kdeldycke/dotfiles. Scan a release on VirusTotal.

How do I install Av False Positive in Claude Code?

Run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a claude-code`. Or copy the skill folder (dotfiles/.agents/skills/av-false-positive in kdeldycke/dotfiles) into .claude/skills/av-false-positive in your project. Claude Code loads it when a task matches its description.

How do I install Av False Positive in Codex?

Run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a codex`. Or copy the skill folder (dotfiles/.agents/skills/av-false-positive in kdeldycke/dotfiles) into .agents/skills/av-false-positive in your project. Codex loads it when a task matches its description.

Can I use Av False Positive in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/av-false-positive, .gemini/skills/av-false-positive, .github/skills/av-false-positive and .opencode/skills/av-false-positive in your project.

What does Av False Positive need to run?

Going by SKILL.md and its folder, Av False Positive needs the command-line tools its instructions call (gh and git) and credentials named VIRUSTOTAL_API_KEY. Our summary lists: Python 3; A credential in VIRUSTOTAL_API_KEY. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, Agent. Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus..

Does Av False Positive access the network?

SKILL.md names 9 domains. In commands or code: virustotal.com and github.com; the agent is likely to contact these when it follows the instructions. As links in the text: repomatic.net, microsoft.com, bitdefender.com, support.eset.com, symsubmit.symantec.com, avast.com and support.sophos.com. This is read from the text; nothing was executed.

Is Av False Positive safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Av False Positive use?

Av False Positive is published under the BSD-2-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Av False Positive use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Av False Positive?

Skills that share tags, products or a category with Av False Positive: Performing False Positive Reduction In Siem (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), False Positive Reviewer (conorbronsdon/avoid-ai-writing, 4.9k stars), Scan (wshobson/agents, 40k stars) and Repo Scan (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Av False Positive?

kdeldycke (a GitHub user) maintains it in kdeldycke/dotfiles, which has 173 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 9, 2026.

Source: kdeldycke/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.